Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PUBG Cheat with keylogger implemented #88

Open
LoadingQ opened this issue Jul 2, 2024 · 2 comments
Open

PUBG Cheat with keylogger implemented #88

LoadingQ opened this issue Jul 2, 2024 · 2 comments

Comments

@LoadingQ
Copy link

LoadingQ commented Jul 2, 2024

A guy in a telegram group shared a weird file named 'bgmi shit.zip' which he claimed it to be a PUBG Mobile Cheat. I said this is malware since there was a weird .exe as well as .bin files. What also was there was a disassembled python file which I looked into. There started to look normal like as a cheat would be expected but I found a telegram sending function which I suspected of what it could be. I asked him and he starting calling me idiot, retard, Indian... Just to don't admit he messed up.

The file is too large (77MB) to be uploaded, here you have the mega.nz link:
https://mega.nz/file/Q7cxEKyA#RCsdC8EAkd2EF4p1tTw5jnL431t8KzngdiiFr3-a_Oo
SHA256: 56ccde41d04cf241c33674863c92e47f5a5488a2e237df4a48527c00c9514539
VT: https://www.virustotal.com/gui/file/56ccde41d04cf241c33674863c92e47f5a5488a2e237df4a48527c00c9514539

The part of the malware is in the line 93 of the decompiled.py file. Here's a screenshot:
image

Clearly in the image can be seen that there's a function that sends messages to a Telegram bot, and apparently it checks each key you type and sends them back to the telegram bot.

After that he continued calling me an idiot and said he's done with it, an administrator checked what I typed and then he got banned.

Enjoy this peace of malware and hope you liked the little story!

@SaadSaid158
Copy link

Wow, what a jerk!

Good to be careful, I know too many people who have fallen prone to such malware. Nice job and good reverse engineering skills, I can say, I do not have the best skills in malware reverse engineering.

@LoadingQ
Copy link
Author

Wow, what a jerk!

Good to be careful, I know too many people who have fallen prone to such malware. Nice job and good reverse engineering skills, I can say, I do not have the best skills in malware reverse engineering.

Thanks, it is true a lot of people have fallen on this but what hurts me more was that admins said it was clean as well as some other members which I later just tried to prove them wrong. This is just a compilation of all the proof I've posted there.
After that happened I just seen it interesting people is doing this new type of spreading method, which I think is only targeted for pubg since theres no background thread for it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants