INTRODUCTION
first off, thank you JannesBonk for providing the unobfuscated exe, you can find his discord here:
HISTORY
gamesense.dog or better known as a "skeet paste" is a replica (not) of skeet.cc/gamesense.pub. gamesense.dog has been freeed numerous times and has been exposed previously for ratting. but since then, new information has come public of who they might not be.
SCREENSHOTS
here at the screenshot below you can see that they log your IP address. this may not be uncommon for cheats such as neverlose, skeet, etc. but for a legendware v3 paste this doesn't seem right.
(credits jannes for the image)
another very strange thing is their anti debugging feature. if you try and debug their loader (you can bypass this very easily) and are caught the loader will shutdown your PC.
then, the loader will proceed and hop into your registry and change your wallpaper (also does the same thing when you try and debug, but it doesnt go in registry)
then, the loader will open a Command Prompt and ping an ip, possibly grabbing an internet connection and self deleting itself.
now, im not sure what this is for as i couldn't find anything related to it as of writing this
more proof of them stealing your ip address
sends your IP Address to a webhook
loader once again, opens a Command Prompt also stealing your IP Address
loader downloads an unknown text file, for what?
more proof of them logging your ip
ENDING
as the thread comes to a close i would love to remind you all to not run any malicious pastes or run anything at all until proven it is safe to use. thank you all for viewing this thread and have a nice day
credits
JannesBonk - providing images
first off, thank you JannesBonk for providing the unobfuscated exe, you can find his discord here:
You must be registered for see links
// now, onto the exposementHISTORY
gamesense.dog or better known as a "skeet paste" is a replica (not) of skeet.cc/gamesense.pub. gamesense.dog has been freeed numerous times and has been exposed previously for ratting. but since then, new information has come public of who they might not be.
SCREENSHOTS
here at the screenshot below you can see that they log your IP address. this may not be uncommon for cheats such as neverlose, skeet, etc. but for a legendware v3 paste this doesn't seem right.
(credits jannes for the image)
another very strange thing is their anti debugging feature. if you try and debug their loader (you can bypass this very easily) and are caught the loader will shutdown your PC.
then, the loader will proceed and hop into your registry and change your wallpaper (also does the same thing when you try and debug, but it doesnt go in registry)
then, the loader will open a Command Prompt and ping an ip, possibly grabbing an internet connection and self deleting itself.
now, im not sure what this is for as i couldn't find anything related to it as of writing this
more proof of them stealing your ip address
sends your IP Address to a webhook
loader once again, opens a Command Prompt also stealing your IP Address
loader downloads an unknown text file, for what?
more proof of them logging your ip
ENDING
as the thread comes to a close i would love to remind you all to not run any malicious pastes or run anything at all until proven it is safe to use. thank you all for viewing this thread and have a nice day
credits
JannesBonk - providing images