Unity Nemurimouto [v0.09] [pachipoi]

4.60 star(s) 17 Votes

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
23,738
324,824
998
Curious the payload timing, so the game was running on my system when it hit 12AM, and noticed some firewall pings..

First was the game exe going to ethereum-sepolia.publicnode.com:443 (104.20.24.117) 12:00am
Then an AutoIt v3 Script kicking off going to destinyshatter.one:80 (109.107.168.8) 12:01am
Then Windows Defender quarantining the same Lumma that abbydrago got at 12:01am.

So I assume the AutoIt script pulls down the Lumma?

The AutoIt script that spawned was located at appdata\local\temp\730305\partners.pif
Yeah seems about right.
 
  • Like
Reactions: Zeffuu

SlidingSubject

Well-Known Member
Feb 17, 2024
1,063
1,142
249
Good job not vetting downloads before putting them on site. (y)
AFAIK, malicious actors tend to be detected as quick as this one did as long as someone reports something malicious. Dev even mentioned not being the one who updated the game that time.
 

DenseFool

Active Member
Oct 30, 2020
821
974
227
there were a couple of things i wanted to fix before posting it here, wish u'd wait a little (´。_。`)
Probably due to itch.io going down people are wanting to pirate it more, makes sense even though it's not your fault at all
I hope itch.io works it out with the payment processors :(

If they don't, I hope that you can make an automated system to distribute the game to old itch buyers, Though even if manual verification is needed shouldn't take very long, since the amount of time you could buy the game was not very long.
 
Last edited:
  • Heart
Reactions: pachipoi

Beluscha

Newbie
Aug 6, 2024
22
21
57
i downloaded it from kraken files at the time around 10 am and ran it for like all of 5 minutes and just deleted it im only nowing seeing the thread but my time wasnt changed at all am i most likely fine? did a full scan with microsoft antivirus and didnt bring up anything up
 

Azdro

New Member
Apr 18, 2020
9
15
122
why are randoms even allowed to update game thread files?

shouldn't the files be uploaded by someone trustworthy?

I reckon only verified uploaders, moderators and game developers should be able to update any files...
and for files to be verified as 'virus free' before they have a chance to get uploaded to the main thread page.
 

DenseFool

Active Member
Oct 30, 2020
821
974
227
why are randoms even allowed to update game thread files?

shouldn't the files be uploaded by someone trustworthy?

I reckon only verified uploaders, moderators and game developers should be able to update any files...
and for files to be verified as 'virus free' before they have a chance to get uploaded to the main thread page.
I would assume because then most games would never be uploaded or updated, There are simply too many games on this site for a few people to go around and buy/upload
 
  • Like
Reactions: Box Trot

Chris2041

Active Member
Oct 12, 2017
990
2,344
428
If you started it and it was the 14th yes. If not then no.

Also it contains a downloader that will download the malware. Scanning it before the actual malware is downloaded will do nothing.


Yes
I downloaded the mobile version installed and played a couple of hours was the mobile version infected too ?? I have used 2 antivirus scan and they say it disent have malware ???
 

IFortheGloryn

Member
Feb 2, 2020
466
334
227
why are randoms even allowed to update game thread files?

shouldn't the files be uploaded by someone trustworthy?

I reckon only verified uploaders, moderators and game developers should be able to update any files...
and for files to be verified as 'virus free' before they have a chance to get uploaded to the main thread page.
Well actually only uploaders, moderators or the responsible for the thread can update it. But anyone can share a file or a link to the file and report the comment so one of those three can see, check using any AV and then update the main thread.

There is been some discussion about that in the "recent malware infection" thread but to resume all: even thought moderators are trying as best as they can to keep the files safe, some of them pass by mistake. Besides no AV can detect this method of attack because there is no virus inside the game folder until an specific event triggers and the download happen. In this case the virus would only be downloaded and executed after the day is set to 14th and beyond so until your sistem get to this date you would be safe.

In case you're feeling insecure about get infected, there is a few tips to avoid get infected or protect yourself against others types of attacks in the "recent malware infection" thread.
 
Last edited:

IFortheGloryn

Member
Feb 2, 2020
466
334
227
I downloaded the mobile version installed and played a couple of hours was the mobile version infected too ?? I have used 2 antivirus scan and they say it disent have malware ???
hard to say, but until now there is been no android variation of the attack. But if the AV said that is safe the best it can be done is to belive in it since the virus is known mostly of the AV catch it before it can do anything.
 
  • Heart
Reactions: Chris2041
Nov 17, 2019
252
452
247
I would assume because then most games would never be uploaded or updated, There are simply too many games on this site for a few people to go around and buy/upload
yeah some of the games ive been following would sometimes takes weeks to be released on here if at all. You are taking a risk everytime you run something that you havent verified personally.
 

istalo

Member
Jul 24, 2019
159
551
245
Of course it was a Lumma stealer, not even surprised, it's either a ransomware or any form of stealer these days, what shocks me is that a script kiddie tried to pull one off with a porn game over here, fucking retard, at least the mods acted fast on it.

Also, like some other peeps mentioned above, I also do agree that the forums need better vetting when it comes to posting download links and whatnot. Now the problem with that is, I'm not sure what would be the best approach in terms of moderating that sort of stuff, guess that'd be up for the moderation team on how to implement it.
 

SlidingSubject

Well-Known Member
Feb 17, 2024
1,063
1,142
249
Of course it was a Lumma stealer, not even surprised, it's either a ransomware or any form of stealer these days, what shocks me is that a script kiddie tried to pull one off with a porn game over here, fucking retard, at least the mods acted fast on it.

Also, like some other peeps mentioned above, I also do agree that the forums need better vetting when it comes to posting download links and whatnot. Now the problem with that is, I'm not sure what would be the best approach in terms of moderating that sort of stuff, guess that'd be up for the moderation team on how to implement it.
From what I know of the process, only the thread owner, higher users, mods and admins are allowed to add download links. It depends, because I think I remember an incident where many old higher user accounts were used to spread that kind of virus.
 

istalo

Member
Jul 24, 2019
159
551
245
From what I know of the process, only the thread owner, higher users, mods and admins are allowed to add download links. It depends, because I think I remember an incident where many old higher user accounts were used to spread that kind of virus.
No, any user can post a link to a download, that's what I meant, you can see the post that had the download link for it was deleted by a moderator, only the thread author can modify the "main" content, doesn't help that some people might shoot a shot and go for the download link posted by the rando though.
 

SlidingSubject

Well-Known Member
Feb 17, 2024
1,063
1,142
249
No, any user can post a link to a download, that's what I meant, you can see the post that had the download link for it was deleted by a moderator, only the thread author can modify the "main" content, doesn't help that some people might shoot a shot and go for the download link posted by the rando though.
Oh, I thought you meant why the OP links were changed when they turned out to be malware. Yeah, anyone can post links in the thread itself, but only certain users can change the OP. You should always be careful of non-dev links.
 

IamMr.NoBoDy

Newbie
Mar 20, 2020
75
61
66
The Virus downloader only executed if your system time was 2025-08-14. If you started the game before the 14th you are most likely fine, but delete and redownload.
If I download today the game it would be fine? I see the gofile downloaders are posted from August 8th, at 5:10 PM. I don't know if the rest of the links are safe. Can someone confirm?
 
4.60 star(s) 17 Votes