Categories > Etc > Disputes >
[Cw] Alezia Exploit | Skidding, Malicious Content
Posted
Ok So This Is Being Made More Or Less To Make People Aware Of The Suspiscious Things This Man Is Doing, I'm Not Much A Fan Of Participating In Cw's As I Was When I First Joined But It'd Be Nice To Rid The Community Of Some Scum. Their Thread Can Be Found Here (https://forum.wearedevs.net/t/31786)
Alezia Injector
1. Skidding
So To Begin I Did A Little Social Engineering And Managed To Get My Hand On A 'Premium' Version Of Their Executor Which They Are Selling For An Undisclosed Price.
So When First Throwing Into DnSpy I Notice This.
https://cdn.discordapp.com/attachments/1066452941294293044/1082484623268921395/image.png
https://cdn.discordapp.com/attachments/1066452941294293044/1082485493800910908/image.png
https://cdn.discordapp.com/attachments/1066452941294293044/1082486616855166996/image.png
Now This Is Nothing New I'm Aware Of Skids Attempting To Use These Classes That Are Found Here (https://github.com/Mecanik/Anti-DebugNET) To Attempt To Ig Stop People Like Me.
Now This Probably Isn't Technically Pasting But Whoever Made It Added These Structs/Enums And Probably Pasted Them In Having No Idea For Usage
https://cdn.discordapp.com/attachments/1066452941294293044/1082485927995256832/image.png
2. Suspicious Content
Keep In Mind It Requires Admin So Some Of The Things Below Will Work
https://cdn.discordapp.com/attachments/1066452941294293044/1082491187073650831/image.png
Now Immediately When Opening Any Of The Core Classes You'll Be Hit With These 2 Imports
https://cdn.discordapp.com/attachments/1066452941294293044/1082486848577876068/image.png
Now If You've Done Enough Research You'll Know Exactly What These Are Being Used For
https://cdn.discordapp.com/attachments/1066452941294293044/1082487724629565490/image.png
Another Weird Thing Is How These Are All The Same Classes Copy And Pasted With A Different Name Except For Hack Which Is The Pasted Lua Executor
https://cdn.discordapp.com/attachments/1066452941294293044/1082490657832177705/image.png
And Now For The Final Item
https://cdn.discordapp.com/attachments/1066452941294293044/1082490862895906947/image.png
This One Really Doesn't Need Explained
https://cdn.discordapp.com/attachments/1066452941294293044/1082490973101248603/image.png
https://cdn.discordapp.com/attachments/1066452941294293044/1082491025496486049/image.png
Source Code : https://cdn.discordapp.com/attachments/1066452941294293044/1082491174134231173/Alezia_Premium_Src.zip
Replied
yeah and not only that they're charging money for a wrd api exploit
Cancel
Post
"Questionable intellegence, but I like the mystery" - CubeFaces
https://cdn.discordapp.com/attachments/1136067487847415848/1138948596679589898/sig.png
Replied
If anyone is asking for where the thread went I deleted it so no more people can download it or use it
but yeah vouch
Cancel
Post
https://media.discordapp.net/attachments/1013939973671624917/1027279180192292944/unknown.png
https://media.discordapp.net/attachments/1010670716062007347/1108945330847883274/image.png
Join the Front-Page Club!
Replied
No wonder there was no VT or Any.run on his thread smh
Cancel
Post
nltr | Xaml & C# Developer | Former Fluxus Administrator
------------------------------------------------------------------------------------
💜 Developer of Kronos 💜
Senior Dev of Orbit
Replied
Here is his profile if anyone wants, it looks like he just made it in the past day and only had that one thread about his malware https://i.imgur.com/KoXnsdg.png
Cancel
Post
nltr | Xaml & C# Developer | Former Fluxus Administrator
------------------------------------------------------------------------------------
💜 Developer of Kronos 💜
Senior Dev of Orbit
Replied
Nice cw vouch
Cancel
Post
Replied
Vouch, i shall now reinstall windows because i downloaded his executor ðŸ˜
Cancel
Post
Replied
You dont even need to use a paid obfuscator but atleast use appfuscate if you already skid ;-;
Cancel
Post
Replied
Amazing cw, vouch
Cancel
Post
PLUTO_GUY FOR MODERATOR 2024!
---------------------------------
Reading this? Use charm.rest for the best gaming experience in your browser! It is unblocked at school and nice for gaming at home!
Replied
Pretty sure those functions require Admin Elevation, otherwise, nice CW!
Cancel
Post
hecker dude ngl i hecked 5 ips in 1 second also luaU_loadbiglongjuicythingy(rL);
Replied
it's funny how people still try to release viruses onto wrd forums thinking they could get away with it
Cancel
Post
Top 10 Poop Positions | Beginner's tutorial in making exploits
Xi Jinping Winnie the Pooh
Users viewing this thread:
( Members: 0, Guests: 1, Total: 1 )
Cancel
Post