The initial .exe contains an embedded XOR encrypted .exe inside of it. It doesn't store the embedded .exe within a different executable section like malware traditionally has done, it stores it as text (sort of).
When the .exe runs it decrypts the embedded .exe and performs process hollowing. It creates a process but suspends it prior to execution. In other words, it basically hits the metaphorical pause button. It then "hollows" out the process and inserts the decrypted .exe it extracted from itself. It then clicks "play" (metaphorically speaking). This is a fancy form of process injection. To Windows this hollowed out .exe appears to be (as an example) calc.exe, but in actuality it is calc.exe hollowed out and replaced with malicious code.
The hollowed out process then extracts a .zip from itself. This .zip is inside a regular .exe section like you see with most malware. The .zip is base64 encoded however. Hence, it extracts the .zip, base64 decodes it, and then it's a regular .zip. Inside the .zip is another .exe. It extracts the .exe from the .zip. It is actually a .dll despite is being labeled .exe.
The hollowed out process then loads the DLL and executes it. The DLL loaded is PURE-RAT
tl;dr
a.exe extracts secret_b.exe from itself
a.exe makes calc.exe
a.exe rips out the code from calc.exe
a.exe puts secret_b.exe inside calc.exe
secret_b.exe has base64 encoded stuff_c.zip inside of it.
secret_b.exe base64 decodes stuff_c.zip
secret_b.exe extracts malware.dll from stuff_c.zip
secret_b.exe loads malware.dll
> be me
> get dm
> "is this malware?"
> "windows defender went crazy when i tried this video game mod"
> download
> look inside
> not malware
There is a function in Windows you can invoke called "GetAsyncKeyState". In simplest terms, this function waits for user input on the keyboard. When a key is pressed down GetAsyncKeyState tells you what was pressed down.
GetAsyncKeyState is used frequently with video games. Using this function video games can determine ... what you're pressing. Likewise, GetAsyncKeyState can be used by legitimate software for when a user does a shortcut or something. There is a lot of legitimate use cases for this function.
However, GetAsyncKeyState is also abused because GetAsyncKeyState is tells you what key on the keyboard is pressed down, GetAsyncKeyState is used as a way to record what users are typing. Typically the data returned from GetAsyncKeyState is piped to a text file. Other times malware developers may use GetAsyncKeyState to store recorded key strokes in-memory and then send it out externally to a remote computer.
Regardless, this video game mod was invoking GetAsyncKeyState and filtering each key press to determine when the mod was triggered. In essence, it was scanning and waiting to determine if it is toggled on or off. Furthermore, after the mod was toggled on or off, it logged when it was turned off for debugging purposes.
From Windows Defenders perspective it saw an unsigned and unverified library being arbitrarily loaded into a video game and, once loaded, it was scanning user keys and subsequently writing something to a text file.
After bonking this video game mod with a stick we know it's not malware. However, this is a great example of false-positives in anti-malware services because, by all means, this mod does seemingly mimic something a malware payload would do.
But it's not malware. It's just a silly video game mod for Baldurs Gate 3
> be pakistan government
> develop custom malware
> used to target high profile targets
> used against indian military and political ppl
> named SHEETCREEP
> send indian ppl file
> UAE-India Strategic Partnership Week
> malicious .lnk file
> .lnk executes malicious c sharp code
> does a bunch of stuff for persistence
> exfiltrates data to Google Sheets
> Google Sheets can be used to control victim pcs
> pakistan gov hardcodes google c2 sheet
> PAKISTAN GOV HARDCODES GOOGLE C2 SHEET
> embed access key in payload
> EMBED ACCESS KEY IN PAYLOAD
> malware nerds find it
> look inside
> find all targets from pakistan gov
> monitoring 91 ppl they think important
THEY STARTED SO STRONG. WHY DID YOU HARDCODE EVERYTHING. YOU BURNED YOUR OPERATION
https://t.co/PcCeV05cu3
This is an excellent example of AI training poisoning.
Microsoft's Forza Horizon series contains "Drivatars". These are bots which train off of your data. They learn how you drive and behave. They use your Xbox Live Gamertag. This technology exists to give single player and story-mode missions a more authentic feel.
Unbeknownst to Microsoft at the time, there is a player named "Bowie Knife99"
This player is incredibly aggressive, often times intentionally targets players, helps random other players, ... they basically don't follow the rules for anything. This player is incredibly chaotic.
Microsoft has been training off of this deranged persons behavior.
Recently Forza Horizon 6 players have encountered this AI Drivator. People have been angry online about it. This AI agent has been intentionally targeting players, crashing into them, intentionally crashing the entire race or ruining the race for everyone (including the other AI agents).
The chaos has gotten to such an extreme people are making meme compilations about this AI agent.
tldr some random guy named Bowie Knife99 is such a crazy player unironically their AI agent is ruining the Forza Horizon 6 experience. It's plays like an angry younger brother.
CVE-2026-31431 a/k/a CopyFail
> Linux LPE
> Description sounds like AI slop
> Exploit is legit
> Impacts every Linux kernel from 2017 - Now
> Proof-of-concept released
> It's Wednesday?
https://t.co/FXgjWW7lOV
Another zero day exploit released by some nerd (can't remember name right now) because they're annoyed with Microsoft. It's been confirmed by other nerds. It is yet another legit zero day. Whew.
https://t.co/Zllhns1ztn
Yeah, so pretty much that whole Windows 11 Notepad RCE thing was ridiculously stupid. Like, it was so dumb it kind of hurts.
Windows 11 Notepad, with the fancy Copilot AI slop, now possesses the ability to handle mark up, or markdown, ... It's mark something, the stuff used in ReadMes. Whatever.
Anyway, a security researcher realized that if you used markup in Notepad and instead of a hyperlink to a website with https:// you put file:// (the protocol on Windows for files, like in file explorer), it will arbitrarily execute it. It won't prompt you.
Furthermore, he realized you could specify a remote host to execute it from using a different Microsoft specific protocol used for app installation. In other words, if you user clicked the hyperlink in Notepad it would download and run a program from any website ... without alerting the user.
Normally, any sort of hyperlink that leads to a different domain, or tries to execute a file, is supposed to prompt you with an alert message, ... or something. However, Microsoft software engineers seemingly forgot to implement this notification Window.
With this attack vector which has been present for AT LEAST 9 months, a malicious actor could send a .txt file and if the user clicked the link inside the .txt file it would automatically execute and run anything specified in the hyperlink.
Even more silly, forensically under the hood, the logs on Windows, or to an anti malware service, it would look like Notepad was downloading something and then running a program. This is a very unique scenario which (to the best of my knowledge) no security product has encountered before. This could hypothetically result in files being downloaded and executed and being completely ignored by anti malware services because Notepad is a known and trusted program. Why would an anti malware service question Notepad?
Basically, the point I'm trying to get to here is that I don't understand why Microsoft has introduced so many new features into Notepad. With new features means a new attack landscape (more stuff to abuse).
Whatever man
> Epstein writes down email and password
> FBI finds it
> Stores as evidence
> Doesn't censor
> Released
> Nerds find Epstein password
> No MFA
> I wonder if anyone logged in?
> Look inside
Chat, we've solved the mystery of the Ubisoft Rainbow Six Siege incident. Unfortunately, I cannot go too deep into details (yet), but it is very silly.
Okay, we have FIVE GROUPS of people now.
GROUP ONE - Responsible for the Rainbow Six Siege incident, they gave away $339,000,000,000 worth of in-game currency and caused chaos. They're now sort of laying low.
GROUP TWO - Claims to have Ubisoft source code. They claimed it was from MongoBleed. This has been proven to be A LIE. However, they DO have internal things from Ubisoft. They lied how they achieved it (read more, GROUP FIVE)
GROUP THREE - Has been lying on Telegram claiming to have compromised Ubisoft. They're using fake data to try to intimidate Ubisoft, and Ubisoft customers, to pay them money. They're all lying.
GROUP FOUR - Very critical of GROUP TWO, calls GROUP TWO LIARS. GROUP FOUR says GROUP TWO is trying to bamboozle GROUP ONE
GROUP FIVE - GROUP FIVE appeared today and presented a comprehensive breakdown on the Ubisoft Rainbow Six Siege (and other) conflicts. GROUP FIVE illustrated step by step how all actions were performed. GROUP FIVE unveiled exactly how GROUP TWO managed to get access to Ubisoft internals (with photographic evidence). GROUP FIVE also provided code demonstrating how GROUP ONE did many things as well other things not reported. GROUP FIVE has a big swinging dick and isn't fucking around. GROUP FIVE is pretty hardcore, not even memeing. They're very intelligent and calculated in what they say and do. GROUP FIVE (probably) make and sell cheats for Ubisoft soft games and are very talented reverse engineers.
Ubisoft is well aware of GROUP ONE, GROUP TWO, GROUP FOUR, and GROUP FIVE. GROUP FIVE also provided a comprehensive breakdown on how Ubisoft knows things.
All of the groups listed, except GROUP THREE, know each other and operate loosely together, in some capacity, it's basically a hardcore community of gaming Ubisoft nerds.
Don't worry, Ubisoft, I'll keep your secrets safe. You and I (your company) probably understand what I'm referencing in this post.
GROUP FIVE has promised to do a write-up and technical breakdown at a later time which I can share publicly. However, they will not do it yet because of some stuff happening between GROUP ONE and GROUP TWO.
The anime saga has concluded.
I'm not a forensics expert. I couldn't forensic my way out of a forensics thing.
However, this cyber weapon thingy leaked from the Iranian government has a program debug file thingy and it contains a debug file path
What could it mean?