RealHD

40 posts

RealHD banner
RealHD

RealHD

@Purified_HD

Operations Manager for @demipact

Katılım Eylül 2024
14 Takip Edilen108 Takipçiler
Sabitlenmiş Tweet
RealHD
RealHD@Purified_HD·
Those of you that would like to see a DETAILED document including steps taken and full results can do so here: drive.google.com/file/d/1TIixF_… Those that would like more info regarding the actual files must send me a message. I will NOT be giving these files out to anyone who asks, you must tell me who you are, what you plan to do with them, and provide proof you are a legitimate researcher or security professional. If you were affected by this modpack, follow the remediation steps in the document immediately, especially check your email filter rules for anything you did not create.
English
7
22
122
60.8K
miie
miie@Westleys_Minion·
@Purified_HD how did you decompile the .exe? i got as far as decompiling the mod itself but couldnt manage to get any further
English
1
0
2
6.6K
RealHD
RealHD@Purified_HD·
So a friend of mine got hacked through a fake Minecraft modpack on CurseForge called "Better Survival Mods" by an author named "kwwn". I spent the day tracing it back and here is what I found. The modpack zip had a fake Fabric mod hidden in the overrides folder called...
English
48
904
10.5K
552.3K
RealHD
RealHD@Purified_HD·
@FakeEma72350095 When a file is named something like javaw.exe and has no digital signature, malwarebytes knows its a sus file
English
0
0
16
4.5K
Dan
Dan@FakeEma72350095·
@Purified_HD Really weird dumb question, but how would malwarebytes know that its malicious? Don’t things have to be reported to them for them to detect?
English
1
0
3
5.4K
Hawu
Hawu@HaruIsNotADog·
@Purified_HD thank you for the report. It was very comprehensive
English
1
0
5
1.1K
RealHD
RealHD@Purified_HD·
Those of you that would like to see a DETAILED document including steps taken and full results can do so here: drive.google.com/file/d/1TIixF_… Those that would like more info regarding the actual files must send me a message. I will NOT be giving these files out to anyone who asks, you must tell me who you are, what you plan to do with them, and provide proof you are a legitimate researcher or security professional. If you were affected by this modpack, follow the remediation steps in the document immediately, especially check your email filter rules for anything you did not create.
English
7
22
122
60.8K
RealHD
RealHD@Purified_HD·
@CPUGenius11 they messed with my friends :/ they get spicy HD
English
0
0
192
10.7K
RealHD
RealHD@Purified_HD·
@Mh1rir I have reported it to like 4 different agencies by now. They fucked with my people I don't care about morals anymore LUL
English
3
1
347
23.6K
RealHD
RealHD@Purified_HD·
@xikitng1 Yes, you are fine if you didn't download the modpack and launch it.
English
0
0
2
4.1K
RealHD
RealHD@Purified_HD·
@DeniiPacco Yeah its all the same, they use the overrides folder to inject that mod, the moment you launch Minecraft then that exe runs.
English
1
0
1
65
idiot.jpeg
idiot.jpeg@DeniiPacco·
@Purified_HD yep uh. i think i fell for something very similar to this?? modpack name + server they told me to go was called SeoCraft and was also for Fabric, did use Modrinth to run it. whoops
English
2
0
2
140
RealHD
RealHD@Purified_HD·
x.com/Purified_HD/st… Full documentation of this Malware can be found in my newest post
RealHD@Purified_HD

Those of you that would like to see a DETAILED document including steps taken and full results can do so here: drive.google.com/file/d/1TIixF_… Those that would like more info regarding the actual files must send me a message. I will NOT be giving these files out to anyone who asks, you must tell me who you are, what you plan to do with them, and provide proof you are a legitimate researcher or security professional. If you were affected by this modpack, follow the remediation steps in the document immediately, especially check your email filter rules for anything you did not create.

English
0
4
326
56.4K
RealHD
RealHD@Purified_HD·
I will be posting a full report on my page in a moment.
English
1
0
489
50.6K
Hawu
Hawu@HaruIsNotADog·
@Purified_HD @discord_support I did. Also put this into your information. The hacker has information on chrome through session tokens. Its listed under Turkey. They will add tags to certain email addresses and mute incoming emails. Its why the victims dont get notified for changes made to their account.
Hawu tweet media
English
1
0
12
1.1K
Prolxzket
Prolxzket@prolxzket·
@Purified_HD Sure thing. How can i reach out to you? Your dms are closed
English
1
0
0
2.2K
RealHD
RealHD@Purified_HD·
@KenleyCheung Feel free to reach out in DMs and I would be happy to.
English
0
0
0
1.1K
Kenley
Kenley@KenleyCheung·
@Purified_HD Would you be able to share IOCs associated with this threat actor?
English
1
0
2
1.2K
RealHD
RealHD@Purified_HD·
@CalickLive The JAR was hosted in the overrides folder. From there when you inject it, the jar then opens to "install" itself into the mod pack. When it opens it completes the payload
English
1
0
26
11.8K
CalickLive
CalickLive@CalickLive·
@Purified_HD how could you tell that the mod was fake in the modpack? did you have to check them all manually?
English
1
0
6
14K
RealHD
RealHD@Purified_HD·
@AvelineMelena All saved google passwords and session tokens to bypass 2FA
English
1
0
1
205
RealHD
RealHD@Purified_HD·
@ArtOfEaglebrace no, this was a zip that was uploaded. When they uploaded it the overrides dir had a jar in it that was infected.
English
0
0
42
18.3K
Eaglebrace
Eaglebrace@ArtOfEaglebrace·
@Purified_HD Thats interesting to hear, so this is one of those slip-trough fuckers that by passes curseforge detector. Have you reached out to any moderation on curseforge for take down? does this invidual have any other ''project'' at their hands that would be good to know about?
English
1
0
56
23.6K
RealHD
RealHD@Purified_HD·
@prolxzket I have all of that info already. If you want you can reach out and I can give you the info.
English
1
0
9
11.5K
Prolxzket
Prolxzket@prolxzket·
@Purified_HD plsss send the malware to me, ive been looking for this all day. Also, it would be nice to include some IOCs next time, like the file hash and stuff like that
English
1
0
3
13.8K
RealHD
RealHD@Purified_HD·
@Brainslime2 They were given a zip and told to upload it. upon doing so there was a jar which on open executed a download order on an .exe from drop box then slept for about 10-15 seconds then ran the .exe, was targeted towards google saved passwords
English
1
0
12
11.4K
Brainslime1
Brainslime1@Brainslime2·
@Purified_HD was the friend just given a zip or was this mod actually hosted on curse
English
1
0
3
13.2K
RealHD
RealHD@Purified_HD·
@HaruIsNotADog @discord_support best of luck, if you haven't already install Malwarebytes and run it. if you cant get to their website then your PC is still infected.
English
1
0
7
1.1K