bypass ZSZC AND MULTI CLIENT

09/02/2019 10:31 CountOPM#1
HELLO GUYS TODAY WE HAVE bypass ZSZC AND MULTI CLIENT

COPY TO FOLDER GAME AND START THE JAVA SCRIPT

AND ENJOY UNLIMT CHAR
09/02/2019 14:10 _SGA_#2
#Wrong Section!

Is this for the pvp server named ZSZC or for the old CSRO files.
09/02/2019 17:03 florian0#3
Java Script :lul: for sure.

[Only registered and activated users can see links. Click Here To Register...]
Ahh jeah, the good old "protected" JavaScript "Bypass"


Lame. Still that vjworm crapware.

[Only registered and activated users can see links. Click Here To Register...]


... updatefacebook my old friend ...
[Only registered and activated users can see links. Click Here To Register...]


did you know your crappy malware has a bug that lets me download files from your computer?

[Only registered and activated users can see links. Click Here To Register...]

Code:
08/06/18 09:00:20: infinst: Installing C:\Users\OnlyOne\AppData\Local\Temp\DX3579.tmp\xinput1_3_x64.inf [Install_Driver]
"Paypal Help" ... yeah sure.
Code:
{"account_id":"113396858731769581141","email":"[Only registered and activated users can see links. Click Here To Register...]","full_name":"PayPal Help","gaia":"113396858731769581141","given_name":"PayPal","
09/02/2019 22:32 #HB#4
LOL. I thought it was real from its title honestly, and also because ZSZC don't even have a protection against this that you can get all the formulas pseudo code.

But yeah... Wow, looks like you're straight looking for Paypal accounts. Unfortunately, the Windows Defender caught you.
09/03/2019 20:57 florian0#5
Quote:
Originally Posted by #HB View Post
But yeah... Wow, looks like you're straight looking for Paypal accounts. Unfortunately, the Windows Defender caught you.
He's not into Paypal accounts in particular. It's a multi stage process. This javascript crap is only a pre-step to get access to the PC. Once your PC is infected with this glorious piece of crapware, he uploads (a matching?) trojan, usually NJRat, manually to your computer. Not sure if that differs depending on OS or AV (since the crap javascript gathers all this information).
Once NJRat is installed, he starts searching your PC for files. All by hand. He also made screenshots of my desktop. I had quite some fun with him.
I drew a lovely image for him. He blantly closed MSPaint without saving, so I disabled the function to close programs. Then he tried to uninstall NJRat, so I removed that function aswell. Then he tried to destroy my VM, so I ended up removing all functions from NJRat, just leaving the screenshot function, forcing him to just sit there and watch.

My best guess that he turned of his PC after that because I couldnt get a connection for the next day and the IP didn't answer to ping in the meanwhile.


I'm not sure if his PC is a VM or something. I can download any file I want, i just need to know its path.
I got his username (OnlyOne) from logs on his PC and found Google Chrome. I downloaded the entire chrome profile but it seemed to be quite unused. History was empty and no passwords saved whatsoever. However I (we, some friends I asked for help) found his facebook profile.

I also stole his background image, the calc.exe (to verify the windows version) and some log files to look for more paths and files.

I also noticed uploading files does not produce an error. I don't know where uploaded files are stored so I can't confirm the files actually being stored. But at least I tried uploading some gachi music ;D.
09/03/2019 23:15 #HB#6
Quote:
Originally Posted by florian0 View Post
...
Aaah... Looks like he had a rough time...
09/04/2019 12:02 CountOPM#7
Quote:
Originally Posted by florian0 View Post
He's not into Paypal accounts in particular. It's a multi stage process. This javascript crap is only a pre-step to get access to the PC. Once your PC is infected with this glorious piece of crapware, he uploads (a matching?) trojan, usually NJRat, manually to your computer. Not sure if that differs depending on OS or AV (since the crap javascript gathers all this information).
Once NJRat is installed, he starts searching your PC for files. All by hand. He also made screenshots of my desktop. I had quite some fun with him.
I drew a lovely image for him. He blantly closed MSPaint without saving, so I disabled the function to close programs. Then he tried to uninstall NJRat, so I removed that function aswell. Then he tried to destroy my VM, so I ended up removing all functions from NJRat, just leaving the screenshot function, forcing him to just sit there and watch.

My best guess that he turned of his PC after that because I couldnt get a connection for the next day and the IP didn't answer to ping in the meanwhile.


I'm not sure if his PC is a VM or something. I can download any file I want, i just need to know its path.
I got his username (OnlyOne) from logs on his PC and found Google Chrome. I downloaded the entire chrome profile but it seemed to be quite unused. History was empty and no passwords saved whatsoever. However I (we, some friends I asked for help) found his facebook profile.

I also stole his background image, the calc.exe (to verify the windows version) and some log files to look for more paths and files.

I also noticed uploading files does not produce an error. I don't know where uploaded files are stored so I can't confirm the files actually being stored. But at least I tried uploading some gachi music ;D.
all your words is lie :)
09/04/2019 17:23 #HB#8
Quote:
Originally Posted by CountOPM View Post
all your words is lie :)
Your English is.
09/05/2019 16:09 Spidy.#9
#Closed
#content removed