UPDATE #1
I was running ProcMon, API Monitor, Process Explorer, WinObjEx64 and IDA Pro and I sell a cheat for GamersClub. GCLauncher.exe finds USB drives and logs every single filename in the USB, traversing every directory, one by one, logging filenames. I noticed when they hit my LM source codes, they'd ping the server. They'd ping the server for other filenames too, but my the source code for LM would trigger a bunch of pings to the server.
After about thirty minutes GCLauncher.exe dropped the malware onto my machine and banned me from GC.
EDIT: Confirmed the malware is 100% DarkComet by the way.
EDIT #2: I caught and banned EMAC Lab staff members from my website on the 20th too. I know who they are, one is banned on -- for "Anti-Cheater" and another is still roaming free on --.
UPDATE #2
https://www.hybrid-analysis.com/samp...ironmentId=100
Here is a analysis of the malware sample via an automated tool.
UPDATE #3
Cool... fucking GamersClub...
UPDATE #4
Ohhh shooockerrrr.
monitor.emaclab.com no longer points to 179.183.89.214, it's been shut down and according to mxtoolbox it now points to 127.0.0.1. Ain't got the fuckin' nuts to keep your RAT live, EMAC Lab?
UPDATE #5
That's my IP. Hahahaha, that's literally my home fucking IP. What a bunch of smartass cunts...
EDIT: IP changed. Eat my dick, pussies. Your AC sucks cock.
UPDATE #6
http://en.gravatar.com/id/dudualfa
The alias dudualfa is tied to a Steam account called forest_x1, which traces back to this fellow here... [LINK TO OTHER SITE].
Him and AokiBR, a -- member who is banned from -- for "Anti-Cheater" are responsible for this crap.
UPDATE #7
Look for a fake GameOverlayUI.exe in your temporary files directory and an instance of cvtres.exe running. If cvtres.exe is running, terminate it. If you see GameOverlayUI.exe in your temporary files directory, delete it. Then run a Malwarebytes scan, it'll detect DarkComet if they've managed to get it's persistence functions executed.
Thanks for sharing this, this just confirms they infect more than just me. They infect other people too and it's clearly an anti-cheating measure... the scummiest one I've ever seen but it's one of them...
UPDATE #8
They just changed the IP to forward to a Google Crawlbot. The original IP is at the top of this thread in the OP.
UPDATE #9
So either being banned triggers the infection or they infect you when they suspect you of cheating and they use the RAT to find evidence.
Look for this file on your computer, seems you have an older version of their infection tool: C:\da5e79d724a1c3b426afcbf7681edfa6e8bbde857fbb4e1 1c8ae528d279a0093.exe
UPDATE #10
Well, if you're seeing SYN_WAIT then the malware is still active on your machine, it's trying to connect to the control server but since it's connecting to Google now instead of the DarkComet control server the connection is getting refused, hence SYN_WAIT.
https://www.malwarebytes.com/mwb-download/thankyou/
Go grab Malwarebytes Free AV and scan your machine, it detected lingering traces of DarkComet on my machine. I expect it'll completely detect and remove DarkComet from yours.
UPDATE #11
Yes, I'm keeping my plans for GC under wraps so they don't work to counter them but I'll say eSports journalists have been contacted as a part of the plans.
UPDATE #12
I'm setting up an RE environment on my friends honeypot network and will monitor GC for an undefined amount of time until I've discovered exactly what triggers the infection process. I'll post in this thread when/if I discover what triggers it or if at any time, monitor.emaclab.com starts pointing to the DarkComet control server again. But I don't recommend EMAC Lab re-route back to the DarkComet control server ever again, because they may peak the interest of the person who owns that honeypot network and that may have some unforeseen consequences.
UPDATE #13
I can confirm for you that at least two eSports journalists are currently researching the GamersClub malware discovery, one from Argentina and one a major eSports personality from Youtube.
UPDATE #14
What does FACEIT do? Sounds ominous, if they're in the same boat as GC you should make the public aware.
UPDATE #15
Thanks for that, forwarded to the journalist(s) so they can see GC telling bold faced lies about this situation.
Post(s) by Lord Tristan from a site that shall be unnamed.