Andro24

35 posts

Andro24

Andro24

@Andro24_

@sigmacheat Katılım Haziran 2019
220 Takip Edilen104 Takipçiler
Andro24
Andro24@Andro24_·
@RealNormalFacts @OmikronSigma It's literally the official JRE from Oracle... You can check the hashes and the file signatures by yourself. We needed a newer JRE than the one that comes with Minecraft because of some new Java features.
English
0
0
1
0
Interesting Facts
Interesting Facts@RealNormalFacts·
@Andro24_ @OmikronSigma When will you address the reasoning behind the custom JRE downloaded not from Oracle but directly from Sigma Client website? Seems extremely fishy to me🧐
English
1
0
0
0
Andro24
Andro24@Andro24_·
And another malware that pretends to be Sigma. This time, it's a dropper that downloads a stealer (Raccoon Stealer) hosted on GitHub. The stealer steals user's browser data, email credentials, crypto wallets, and more. 𝘕𝘪𝘤𝘦 𝘵𝘺𝘱𝘰 𝘢𝘵 '𝘴𝘵𝘦𝘢𝘭𝘦𝘳' 𝘋𝘢𝘷𝘪𝘥...
Andro24 tweet mediaAndro24 tweet mediaAndro24 tweet media
English
4
1
13
0
Andro24
Andro24@Andro24_·
@_Raph9213 DnSpy pour la décompilation de l'assembly .NET, et IDA Pro pour la décompilation du code machine.
Français
0
0
2
0
͏
͏@Raph9213·
@Andro24_ C'est quoi les applications dans les 2 derniers screen ?
Français
1
0
1
0
Andro24
Andro24@Andro24_·
Also, the virustotal link is just a scan of a txt file renamed as an executable lmao
Andro24 tweet media
English
1
0
4
0
Andro24
Andro24@Andro24_·
@ItsSkriptic Not our fault if you got a bad cpu/gpu ¯\_(ツ)_/¯ OT: we'll add optifine on 1.16 soon.
English
0
0
0
0
Andro24
Andro24@Andro24_·
Some ppl tried to spread a botnet by making a fake version of Sigma (my software), but they forgot to disable the registration on their admin panel 🤦‍♂️ They also left their directory opened. cc @malwrhunterteam 2.56.214.165 app.any.run/tasks/1ee4d2a2…
Andro24 tweet mediaAndro24 tweet mediaAndro24 tweet mediaAndro24 tweet media
English
3
1
16
0
Andro24
Andro24@Andro24_·
Most of the strings are encrypted (with AES) but the key is ofc in the binary file. So here's the server's host and port decrypted : eyesoflucifer[.]duckdns[.]org:1337 (the ip is down, and looks residential)
Andro24 tweet media
English
0
0
4
0
Andro24
Andro24@Andro24_·
Pro tip: don't try to get a cracked version of Sigma5 they're viruses. This video's one is a dropper. The dropped executable connects to a server with SSL, and then invokes a payload sent from it. Malwarebytes detects it has a ransomware.
Andro24 tweet mediaAndro24 tweet mediaAndro24 tweet mediaAndro24 tweet media
English
3
3
10
0
Andro24
Andro24@Andro24_·
Looks like it also allows you to create files anywhere🤔
Andro24 tweet media
English
0
0
2
0
Andro24
Andro24@Andro24_·
Update, it looks like they're using a 2-year-old version of "BlackNET" that can be downloaded here : github.com/decay88/BlackN… And at first glance, you can see that it's vulnerable to SQL injection😂
English
1
0
2
0
Andro24 retweetledi
Omikron 🇫🇷
Omikron 🇫🇷@OmikronSigma·
Dear Community, I have heard your fears and concerns about the state of the Hypixel Network. The increase of hackers is ruining the fun of honest players. Consequently I have decided to personally address this issue and I am proud to announce that cheaters can go fuck themselves
English
15
11
48
0
Omikron 🇫🇷
Omikron 🇫🇷@OmikronSigma·
@stelerio salut je me suis fais ban alors que je cheatais même pas, j'ai essayé d'ajouter le gars proposé sur la raison du ban sur discord mais y a une erreur ça fonctionne pas :( Help svp! Ah aussi y a un gars il m'a insulté, si vous pouviez le mute ce serait sympas
Omikron 🇫🇷 tweet mediaOmikron 🇫🇷 tweet mediaOmikron 🇫🇷 tweet media
Français
5
5
11
0