Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
11,433
111,106
i would scan it when running
it collects fast , and deletes itself after usage ( what is in the bin file)
Hmm. I used a Sandbox to test and check, got no warnings etc. It also list every try to connect to the internet, etc. Gonna inform Sam.

WELL MOTHER FUCKER
Download the script if 10 minutes have passed since the first run
 

pitao

Member
May 18, 2023
267
279
bin folder is so the trojan can make a own path to get access to your files etc
I see, I actually Unzipped the game but didn't run it, so I tried to run it now and it created a bin folder with timestamp.txt file. Closed it right away, did a scan and didn't find anything with but yeah something is weird in all this. Guess I'll just delete the unzipped folder right away and wait for something more safe.
 
  • Like
Reactions: DragonsFear

moonshadow

Member
May 6, 2017
244
483
I only had one file in my bin folder, and that was a txt file called timestamps. But perhaps there was more files that somehow got automatically removed before I could check.
I know that the bin folder was created the second I booted up the game. I even deleted the folder the moment it got created while still booting up the game lol.

certainly helped me to see it right away by sorting the folder by 'date modified' so it pops up on top of the other 1029 folders I have in there lol.
 
  • Like
Reactions: DragonsFear

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
11,433
111,106
If the game didn't run for more than 10 minutes it didn't download shit.
# Download the script if 10 minutes have passed since the first run
 

Badjourasmix

Conversation Conqueror
Sep 22, 2017
6,958
15,581
After this stuff started happening I just use sandboxie to play all the game I download from here. You can make it so anything running inside the sandbox can't connect to the internet so even if you download an infected game, you should be fine because it can not download the malware.
 

DragonsFear

Member
Jan 8, 2022
146
154
After this stuff started happening I just use sandboxie to play all the game I download from here. You can make it so anything running inside the sandbox can't connect to the internet so even if you download an infected game, you should be fine because it can not download the malware.
thats what im going to do from now on
it happens to often ,and to bad (for now) it can't be detected easely
 

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
11,433
111,106
with me it actually responded in less than 1 minute, so woudn't count on the 10 minute rule imo
Its in the script though.
Actually it creates a timestamp file. (thats prob what your antivir detected)
Then if the the timestamp file exist after another 10 minutes it downloads stuff.
 
  • Thinking Face
Reactions: DragonsFear

DragonsFear

Member
Jan 8, 2022
146
154
Its in the script though.
Actually it creates a timestamp file. (thats prob what your antivir detected)
Then if the the timestamp file exist after another 10 minutes it downloads stuff.
casn it be counting up, so lets say multiple runs of 1 or 2 minutes that triggers it ? (after 10 minutes in total ? )
 

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
11,433
111,106
casn it be counting up, so lets say multiple runs of 1 or 2 minutes that triggers it ? (after 10 minutes in total ? )
10 minutes twice:

if datetime.now() - first_run < timedelta(minutes=10):
 

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
11,433
111,106
Which file has this script?
Maybe only R3 is affected? I played R1-R2
Yes only R3 was affected.
it was the leaked latest update for r3, you can safely download the old r3 version
The links are now fine I cleaned it up and reuploaded PC (that was the only version affected).

Also my compression is and was fine.
 

SonsOfLiberty

Post Pro
Compressor
Sep 3, 2022
20,808
171,863
Hmm. I used a Sandbox to test and check, got no warnings etc. It also list every try to connect to the internet, etc. Gonna inform Sam.

WELL MOTHER FUCKER
It can hide from VM"s and the like.

Trojan:Win32/Wacatac.H!ml can evade detection by performing checks to ensure it is not being executed in a debug environment, on a virtual machine, or in a banned country. While being present in nearly any malware, country checks are most commonly seen in malware that originates from ex-USSR countries.

Additionally, it establishes persistence in the attacked environment by creating a randomly named copy in a random directory in the AppData or LocalAppData folder of a user directory and adding a corresponding value to the Run entry of the system registry. By doing this, malware makes itself harder to stop and remove, ensuring that its execution will not be interrupted by restarts or file deletion.

Wacatac.H!ml is also a false positive in a lot of cases as well due to the nature of machine learning, it was the one that was going around during the last "big" outbreak and most, if not, all were false positives.

Machine Learning or Artificial Intelligence detection.

Machine Learning is a system at your antivirus developer that tries to identify features common to malware. It could be any kind of malware, could be a potentially unwanted program(ie. adware), could be a false positive.
 
  • Like
Reactions: pitao
4.30 star(s) 112 Votes