99% Sure One Just Attempted to Infect me
Dinners out though.
Will post proof / explanation in 15 minutes when i'm done eating.
Be wary of his FUD crypting service.
http://runegear.net/showthread.php?tid=60966
Warning, images are big as fuck.
Server size multiplied by four.
When the file he sent me was ran in sandbox it displayed a function that wouldn't not terminate, and when it was tried to terminate, it came back. For those of you familiar with RAT's you will recognize this as persistence installation.
The file he sent me also did not infect me on my own RAT when ran in sanboxie.
However, when I ran the original it did.
Also, I received this PM, which immediately made me suspicious. He didn't show up on my RAT (happy to confirm with any admin/owner on TV or skype). But he wanted my TV info which made me think he wanted to try and run it on me/make sure I ran it myself.
Dinners out though.
Will post proof / explanation in 15 minutes when i'm done eating.
Be wary of his FUD crypting service.
http://runegear.net/showthread.php?tid=60966
Warning, images are big as fuck.
Server size multiplied by four.


However, when I ran the original it did.

Also, I received this PM, which immediately made me suspicious. He didn't show up on my RAT (happy to confirm with any admin/owner on TV or skype). But he wanted my TV info which made me think he wanted to try and run it on me/make sure I ran it myself.
