Quote:
Originally Posted by x3prototype
anyone know something about huisacheats?
|
Bit late but I saw someone claiming their loader dropped a RAT. I asked them for a copy of the loader and its an AutoIt crypter packing Nanocore pointing to a currently live C2 in some Eastern European datacentre.
Take this with a grain of salt as I have no proof it is their actual loader, just some random person sent it to me.
SHA256 of the "loader": c33846f5f0ad5582fad09c42230f594558198159eb8c91937d 0871f86d944c4b
(Also note it has an invalid digital signature cloned from teamspeak)
Never seen on VT and the nanocore stub was compiled 2/21/2019 10:31:32 PM.
Huge Disclaimer: I have not personally retrieved this from the website and so there is a high chance someone could have made this up to frame them.
KJHacks however, loooool angry ***** trying to scam children on the internet, dont waste your time with him.