Pages:
Author

Topic: TEMP: Investigation into scotaloo - page 5. (Read 13806 times)

vip
Activity: 1316
Merit: 1043
👻
July 19, 2013, 12:36:26 AM
I actually don't give a fuck about the IP 49.176.67.225 Smiley

So is that a refusal to answer? Are you giving theymos permission to check the logs and disclose if its your IP or not?

It's best that you just choose an answer now and stick to it, there is a lot the community does not know...
If by "your IP" you are asking if I used it or not, then yes Smiley

I'd actually like to thank you for bringing minecraft.exe to my attention.
newbie
Activity: 42
Merit: 0
July 19, 2013, 12:29:17 AM
I actually don't give a fuck about the IP 49.176.67.225 Smiley

So is that a refusal to answer? Are you giving theymos permission to check the logs and disclose if its your IP or not?

It's best that you just choose an answer now and stick to it, there is a lot the community does not know...
vip
Activity: 1316
Merit: 1043
👻
July 19, 2013, 12:12:53 AM
I actually don't give a fuck about the IP 49.176.67.225 Smiley

Yes, I've used it before. I've been doing some digging on a RAT file that has the phone home set to my IP:

BTCTalkAccs pointed me to this virustotal analysis of a DarkComet/DarkKomet RAT with the name 'minecraft.exe':

https://www.virustotal.com/en/file/9970283d1c08091f9260a5bbbc76220ed7b88b75d8352bcbfe35c4730f608262/analysis/

This RAT is set to phone home to: 58.111.143.105:200, which is my IP and on the port 200. However, this is quite meaningless as anyone can do that - it's no different than linking to another webpage. This is the first time I became aware of 'minecraft.exe', and a search on 9970283d1c08091f9260a5bbbc76220ed7b88b75d8352bcbfe35c4730f608262 doesn't turn up anything.

It also has the file name MSRSAAP.EXE, which turns up on virustotal here:

https://www.virustotal.com/en/file/4589cc7f0791e87906da850d27306637d01a71fb6aca9cee74be84c5bfff65c2/analysis/

The SHA hash doesn't also turn up anything other than virustotal on Google, but there are a lot of info on the name MSRSAAP.EXE.

http://answers.yahoo.com/question/index?qid=20120219155647AAN5JIV
http://softwaredownloadpro.com/question14580.html
http://translate.googleusercontent.com/translate_c?depth=1&hl=en&prev=/search%3Fq%3DMSRSAAP.EXE%26safe%3Doff%26client%3Dfirefox-a%26hs%3DFi4%26sa%3DN%26rls%3Dorg.mozilla:en-US:official%26biw%3D1920%26bih%3D940&rurl=translate.google.com&sl=ru&u=http://otvet.mail.ru/question/76611000&usg=ALkJrhiiM8v8n5hHgMTrWiy8ZWjVQYIGJg

This malware has been posted by the user "manolz" as some anti-anticheat or something:
http://www.gamersoul.com/forums/showthread.php?185177-Hackshield-AntiHook-NoShield-0-1-beta/page3

Also on youtube by "iCrack Trainers" (shell youtube account):
http://www.youtube.com/watch?v=VaKLmM40428

So, there's two possibilities:

1) I've been spreading malware disguised as anticheat bypasses and trainers for games that has been documented in English, Chinese and Russian while using my own IP address and have been doing it from 2012 or earlier decides to make a new RAT and upload it to virustotal and do nothing with it.

2) Someone who wants to frame me / plant false evidence and has a history of making game-related malware makes a new RAT that connects to my IP and port 200 (which isn't even open), uploads it to virustotal and does nothing with it.

If you look at the date (2013-06-09), you'll see that exactly a week earlier MoneyPakTrader got butthurt that I penetrated his website (which deals with currency exchange) - without doing any malicious damage - and found my IP address:

https://bitcointalksearch.org/topic/scammer-tradefortress-p-ted-my-site-without-permission-no-damage-afaik-closed-223665
June 02, 2013, 05:36:28 PM

(I also have some other info on MoneyPakTrader, in relation to some of his other suspicious activites).

Given by the dates of MSRSAAP.EXE, I think it's also possible that it back when I was running a tor exit node on this IP and someone wanted to cloak their identity and tried to use Tor to do that. Obviously it didn't connect (not only is the port not open, but also you can't use tor to do this AFAIK as the command server packets will not be tunneled back), so they did nothing with minecraft.exe and somehow this was uploaded on June 09th (maybe because they got arrested, had HDD seized and had all the files analyzed)? I'm still leaning towards MoneyPakTrader.

You decide. Thanks for digging that out, BTCTalkAccounts!
hero member
Activity: 686
Merit: 504
always the student, never the master.
July 18, 2013, 11:30:36 PM
I don't see why I should Smiley

there's more smoke and mirrors in here than a whore house on the French Riviera
vip
Activity: 1316
Merit: 1043
👻
July 18, 2013, 11:28:09 PM
I don't see why I should Smiley
vip
Activity: 1316
Merit: 1043
👻
July 18, 2013, 11:21:23 PM
No. I'm actually looking in who planted the RAT in the first place, but it does seem unlikely that it is from you.
vip
Activity: 1316
Merit: 1043
👻
July 18, 2013, 10:19:28 PM
The fact that I'm in Sydney is public knowledge, and I'm sure everyone who is investigating you is "secretly a scammer" Cheesy

Of course, Thornleigh isn't as public though, but still, I don't reveal my hand.

I got to go guys cya later! xoxox

I had a chat with BTCTalkAccounts on IRC. His hand consists of "pretty certain" dox.. Of someone else.

Plus a planted RAT that "phones home" to my IP and a port that never existed.

In other words, full of shit  Smiley Feel free to post everything here and get laughed at.
BCB
vip
Activity: 1078
Merit: 1002
BCJ
July 18, 2013, 08:34:54 PM
geolocation
vip
Activity: 1316
Merit: 1043
👻
July 18, 2013, 08:33:42 PM
IP geolocation services aren't that accurate, you know.
vip
Activity: 1316
Merit: 1043
👻
July 18, 2013, 08:26:58 PM
tradefortress is like Agent Smith from the matrix. that's exactly who he reminds me of

lol, not really, he's more like some random dude who lives near Sydney who is 'all talk' and is secretly a scammer too.
The fact that I'm in Sydney is public knowledge, and I'm sure everyone who is investigating you is "secretly a scammer" Cheesy
hero member
Activity: 686
Merit: 504
always the student, never the master.
July 18, 2013, 08:21:16 PM
hm.... here's the old one 76.190.237.222

doubt you haven't switched again by now. when i tracked your friend Trojan coming off the tor node in minneapolis his ip was like 202. something

Wow, so wait you tracked tor? I think 150 governments around the world just hired you lol!

If you had any idea how tor works you would say that lol!
i get it, you got a penchant for the scifi... you're a dumb motherfucker if you think tor is intraceable.
hero member
Activity: 686
Merit: 504
always the student, never the master.
July 18, 2013, 08:19:00 PM
you think im talking to tradefortress?

 Cheesy

tradefortress is like Agent Smith from the matrix. that's exactly who he reminds me of
hero member
Activity: 686
Merit: 504
always the student, never the master.
July 18, 2013, 08:15:20 PM
hm.... here's the old one 76.190.237.222

doubt you haven't switched again by now. when i tracked your friend Trojan coming off the tor node in minneapolis his ip was like 202. something IIRC. if i cared at all i probably would have wrote it down, but i don't so i didn't.
full member
Activity: 182
Merit: 100
Hodl regularly and often!
July 18, 2013, 08:14:11 PM
if i were you id stop using a certain vpn

If I were you I'd know to shut up about now. You think I already didn't know about that? you think I'm actually still using that VPN? lolplz
if i was cayce franklin id.
full member
Activity: 182
Merit: 100
Hodl regularly and often!
July 18, 2013, 08:12:58 PM
you think thats me lol

Look at the bitcoin address you set on your bitcointalk profile and the one in your last tweet idiot!

Your only a kid so I'm not threatening you or anything, but I'm letting you know your not anonymous online.
still clueless
full member
Activity: 182
Merit: 100
Hodl regularly and often!
July 18, 2013, 08:11:34 PM
if i were you id stop using a certain vpn
full member
Activity: 182
Merit: 100
Hodl regularly and often!
July 18, 2013, 08:09:02 PM
BAM!

https://twitter.com/caycefranklin

Honeypots? eh? lulz.

Offer still stands, 10BTC sent immediately for the first 3 digits of IP, if you get it wrong you have to agree to stfu.
you think thats me lol
full member
Activity: 182
Merit: 100
Hodl regularly and often!
July 18, 2013, 08:07:57 PM
having info is much more useful than disclosing Cheesy

148 is one
full member
Activity: 182
Merit: 100
Hodl regularly and often!
July 18, 2013, 08:04:47 PM
btw ty for using honeypots.
full member
Activity: 182
Merit: 100
Hodl regularly and often!
July 18, 2013, 08:01:35 PM
btw if youre going to do a web whois use https not plaintext
Pages:
Jump to: