What's the rules on linking malware for research? I get hit up by sexy Indian dudes and Nigerians tryina get me to open malware, and I like to upload it to the cloud and open it with a VM to see what it looks like. I assume the answer is "nope" but thought I'd ask. This stuff just interests me and thought I'd share if others are interested.

Screenshot is an example. Sexy Indian dudes have been making the rounds with malware made to steal FB accounts so that they can run ads on your account under your CC. Some white woman reported losing $10k overnight after being dumb enough to run this shit on her PC. This one could just be a keylogger, but I haven't even looked at this one at all. I'm kinda bored with them, but I know some nerds here might like to look at the code. This one seems like a Word macro that probably downloads malware.


Krayon sexually assaulted his sister. https://i.rdrama.net/images/17118241526738973.webp https://i.rdrama.net/images/17118241426254768.webp https://i.rdrama.net/images/17156480765435808.webp

37
Jump in the discussion.

No email address required.

Is that even a word document or something hiding as one?

Jump in the discussion.

No email address required.

Good question. Probs an exe. I haven't opened it. Sundays are yuuuge for these people so I get contacted by them mostly on Sundays. They come in waves and usually they switch up their attack. Lately, they have been stealing FB accounts to charge on CCs. This could be something different to steal another account for all I know, but it's def malware.


Krayon sexually assaulted his sister. https://i.rdrama.net/images/17118241526738973.webp https://i.rdrama.net/images/17118241426254768.webp https://i.rdrama.net/images/17156480765435808.webp

Jump in the discussion.

No email address required.

oh I didn't know about tria.ge. I only look at the macros and don't use the exe. Do I need to extract it and get the malware file to upload to virusttotal or will it extract the rar file. I usually upload it to a cloud drive and extract it there from a VM off my network.


Krayon sexually assaulted his sister. https://i.rdrama.net/images/17118241526738973.webp https://i.rdrama.net/images/17118241426254768.webp https://i.rdrama.net/images/17156480765435808.webp

Jump in the discussion.

No email address required.

Thanks for the help. The platform pulled the file but I'll post a link and upload to virustotal next time. I just realized this is probably to steal creepto wallet keys based on the "job" that they wanted me to do.


Krayon sexually assaulted his sister. https://i.rdrama.net/images/17118241526738973.webp https://i.rdrama.net/images/17118241426254768.webp https://i.rdrama.net/images/17156480765435808.webp

Jump in the discussion.

No email address required.

I didn't download anything. Sorry! I will definitely do it next time. The platform where it was sent figured out it's malware and removed everything including the file. I will next time though!


Krayon sexually assaulted his sister. https://i.rdrama.net/images/17118241526738973.webp https://i.rdrama.net/images/17118241426254768.webp https://i.rdrama.net/images/17156480765435808.webp

Jump in the discussion.

No email address required.

Could be an actual word doc with some macros set to run on opening

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.