What's new

Welcome to HvH Forum!

SignUp Now! Download Free HvH CS:GO Cheats, CFG, LUA/JS Scripts, And More!


SignUp Now!

Info gamesense.dog exposed | ratting, editing registry, shutting down pcs, etc

supremacy
Moderator
User ID
2180
Messages
272
Reactions
308
Level
32
INTRODUCTION
first off, thank you JannesBonk for providing the unobfuscated exe, you can find his discord here: // now, onto the exposement


HISTORY
gamesense.dog or better known as a "skeet paste" is a replica (not) of skeet.cc/gamesense.pub. gamesense.dog has been freeed numerous times and has been exposed previously for ratting. but since then, new information has come public of who they might not be.


SCREENSHOTS
here at the screenshot below you can see that they log your IP address. this may not be uncommon for cheats such as neverlose, skeet, etc. but for a legendware v3 paste this doesn't seem right.
(credits jannes for the image)
1689782264178.png

another very strange thing is their anti debugging feature. if you try and debug their loader (you can bypass this very easily) and are caught the loader will shutdown your PC.

1689782344420.png

then, the loader will proceed and hop into your registry and change your wallpaper (also does the same thing when you try and debug, but it doesnt go in registry)
1689782500850.png

then, the loader will open a Command Prompt and ping an ip, possibly grabbing an internet connection and self deleting itself.
1689782675674.png

now, im not sure what this is for as i couldn't find anything related to it as of writing this
1689782802523.png

more proof of them stealing your ip address
1689782875552.png
1689782904436.png

sends your IP Address to a webhook
1689782955688.png

loader once again, opens a Command Prompt also stealing your IP Address
1689783034291.png

loader downloads an unknown text file, for what?
1689783329923.png

more proof of them logging your ip
1689783380205.png



ENDING
as the thread comes to a close i would love to remind you all to not run any malicious pastes or run anything at all until proven it is safe to use. thank you all for viewing this thread and have a nice day

credits
JannesBonk - providing images
 

Password for .zip file is hvh.net

  • 1689783321072.png
    1689783321072.png
    3.9 KB · Views: 59
Newbie HvHer
User ID
45234
Messages
13
Reactions
2
Level
2
the text file says "false" in it, thats all, it could of been a base64 malware that autodownloads, but its just false for some reason, so what some cheats do is take ur ip address for anti debugging purposes, but this is merely way too far to pull a ip for security reasons, theres not alot of proof of ratting exactly, you cannot do alot with a ip address, but i still wouldnt trust them with it, and also, in alot of cheats it will shut down ur pc for debugging, neverlose BSODS ur pc when u fail a debugging check in the 2nd stage, u can find the file "NeverloseBSOD" dropped in ur pc. (also the dll, ive seen used for discord shit to disply info that ur on the cheat etc)
 
Newbie HvHer
User ID
63007
Messages
6
Reactions
1
Level
0
Holy shit a paid software logging an ip WHAT, AND ANTI free FEATURES NO WAY, you're retarded
 
supremacy
Moderator
User ID
2180
Messages
272
Reactions
308
Level
32
the text file says "false" in it, thats all, it could of been a base64 malware that autodownloads, but its just false for some reason, so what some cheats do is take ur ip address for anti debugging purposes, but this is merely way too far to pull a ip for security reasons, theres not alot of proof of ratting exactly, you cannot do alot with a ip address, but i still wouldnt trust them with it, and also, in alot of cheats it will shut down ur pc for debugging, neverlose BSODS ur pc when u fail a debugging check in the 2nd stage, u can find the file "NeverloseBSOD" dropped in ur pc.
you can find the unobfuscated exe, dll, and webhooks here:

funny meme:
1689784326195.png
 
supremacy
Moderator
User ID
2180
Messages
272
Reactions
308
Level
32
its a authentication handshake, when ur verified on their server (to login), it sends status and keep alive and auths you
and i know what it is, its just funny how they did it
 
Newbie HvHer
User ID
63007
Messages
6
Reactions
1
Level
0
Almost every cheat logs an ip so I dont see why its an issue when they do it.
Every loader has some protection from a debugger, i cant wait for you to find out about packed loaders.
HOLY SHIT IT CHANGES YOUR WALLPAPER lock this man up.
again why is it an issue that they're taking an ip? its a loader
The text file just says false lol you should of looked into that before posting.
To sum it up, you're retarded stop posting thanks, delete your account + delete that fade paste you call "detroit" or some bullshit like that
 
Newbie HvHer
User ID
7052
Messages
3
Reactions
0
Level
1
Almost every cheat logs an ip so I dont see why its an issue when they do it.
Every loader has some protection from a debugger, i cant wait for you to find out about packed loaders.
HOLY SHIT IT CHANGES YOUR WALLPAPER lock this man up.
again why is it an issue that they're taking an ip? its a loader
The text file just says false lol you should of looked into that before posting.
To sum it up, you're retarded stop posting thanks, delete your account + delete that fade paste you call "detroit" or some bullshit like that
relax dude
 
Newbie HvHer
User ID
45234
Messages
13
Reactions
2
Level
2
Almost every cheat logs an ip so I dont see why its an issue when they do it.
Every loader has some protection from a debugger, i cant wait for you to find out about packed loaders.
HOLY SHIT IT CHANGES YOUR WALLPAPER lock this man up.
again why is it an issue that they're taking an ip? its a loader
The text file just says false lol you should of looked into that before posting.
To sum it up, you're retarded stop posting thanks, delete your account + delete that fade paste you call "detroit" or some bullshit like that
bro is heated
 

dFL

$$$ aguero $$$
User ID
17560
Messages
134
Reactions
4,085
Level
49
INTRODUCTION
first off, thank you JannesBonk for providing the unobfuscated exe, you can find his discord here: // now, onto the exposement


HISTORY
gamesense.dog or better known as a "skeet paste" is a replica (not) of skeet.cc/gamesense.pub. gamesense.dog has been freeed numerous times and has been exposed previously for ratting. but since then, new information has come public of who they might not be.


SCREENSHOTS
here at the screenshot below you can see that they log your IP address. this may not be uncommon for cheats such as neverlose, skeet, etc. but for a legendware v3 paste this doesn't seem right.
(credits jannes for the image)
View attachment 5001

another very strange thing is their anti debugging feature. if you try and debug their loader (you can bypass this very easily) and are caught the loader will shutdown your PC.

View attachment 5002

then, the loader will proceed and hop into your registry and change your wallpaper (also does the same thing when you try and debug, but it doesnt go in registry)
View attachment 5003

then, the loader will open a Command Prompt and ping an ip, possibly grabbing an internet connection and self deleting itself.
View attachment 5004

now, im not sure what this is for as i couldn't find anything related to it as of writing this
View attachment 5005

more proof of them stealing your ip address
View attachment 5006
View attachment 5007

sends your IP Address to a webhook
View attachment 5008

loader once again, opens a Command Prompt also stealing your IP Address
View attachment 5009

loader downloads an unknown text file, for what?
View attachment 5011

more proof of them logging your ip
View attachment 5012



ENDING
as the thread comes to a close i would love to remind you all to not run any malicious pastes or run anything at all until proven it is safe to use. thank you all for viewing this thread and have a nice day

credits
JannesBonk - providing images
real (i know iv3tka and hes such of a fucking paster)
 
Newbie HvHer
User ID
61988
Messages
4
Reactions
0
Level
1
Yo guys so i'm here to tell u gs.dog isn't rat

1. At all this ,,RATTING" what the hell u mean by RATTING show me how we are ratting?
Also this picture is only about software what is doing when start. (label hide) that's all..

String about ip? yeah it's saving ip and sending through webhooks that i have.
Im using to know who is sharing account and who doesn't that's normal. not a rat XD
1690114425809.png

2. How is this picture malware? ... don't be stupid and posting shit about GS.DOG IS RAT or smth else.. it isn't ofc.

explain -> this is debugger which means if u try debug in software called ida64 or smth else like dnspy it says

Shutdown WINDOWS, and CHANGE WALLPAPER that's all what it did if u try debug..
1690114529533.png



3. DiscordMessenger is dll in visualstudio u can install it's for Webhook sending in ur discord channel by WEBHOOKS..
And Costura it means Costura.Fody when u try build project and u have some dlls added in project it will automatically not working if u doesn't connect it and make it in EXE

so if u use Costura.Fody it will make all dlls in 1.exe that's why EXE is sometimes BIGGER then themself
1690114608527.png


4. This Downloadstring(" ") -> it's string which checking ur ip so when u login with keyauth logins it will automatically send WEBHOOKS ip included in.

What it says in webhooks?

probably -> USERNAME
PASSWORD
HWID
IP

also this CMD if u have eyes and know coding it probably means when VERSION isn't 2.4 then THIS CODE WILL START..
-> Process.Start(new ProcessStartinfo("cmd.exe", bla bla bla") it's code to automatically delete old loader which is diff version then 2.4
1690114757625.png

5. Yeah this is KEYAUTHAPI and it shows what they can use in loader or in webhooks stop be dumb and thinking that we are freeing any IP or any shit..

EVERY SITE USING UR IP, and can PUBLISH IT.. -> Neverlose.cc, Gamesense.pub, Nixware.cc, Aimware.net Every site have for example DATABASE, and other shit. bcs i was know c# i did loader through keyauth and upgrade it to better administration for me..

SO i can see who is sharing, who is freeing, etc.
1690114968455.png

Have a nice day :)
 
Last edited:
supremacy
Moderator
User ID
2180
Messages
272
Reactions
308
Level
32
Yo guys so i'm here to tell u gs.dog isn't rat

1. At all this ,,RATTING" what the hell u mean by RATTING show me how they ratting?
Also this picture is only about software what is doing when start. (label hide) that's all..

String about ip? yeah it's saving ip and sending through webhooks that he have.
i asked him why he using it, he told me to know who is sharing account and who doesn't that's normal. not a rat XD
View attachment 5024

2. How is this picture malware? ... don't be stupid and posting shit about GS.DOG IS RAT or smth else.. it isn't ofc.

explain -> this is debugger which means if u try debug in software called ida64 or smth else like dnspy it says

Shutdown WINDOWS, and CHANGE WALLPAPER that's all what it did if u try debug..
View attachment 5025



3. DiscordMessenger is dll in visualstudio u can install it's for Webhook sending in ur discord channel by WEBHOOKS..
And Costura it means Costura.Fody when u try build project and u have some dlls added in project it will automatically not working if u doesn't connect it and make it in EXE

so if u use Costura.Fody it will make all dlls in 1.exe that's why EXE is sometimes BIGGER then themself
View attachment 5026


4. This Downloadstring(" ") -> it's string which checking ur ip so when u login with keyauth logins it will automatically send WEBHOOKS ip included in.

What it says in webhooks?

probably -> USERNAME
PASSWORD
HWID
IP

also this CMD if u have eyes and know coding it probably means when VERSION isn't 2.4 then THIS CODE WILL START..
-> Process.Start(new ProcessStartinfo("cmd.exe", bla bla bla") it's code to automatically delete old loader which is diff version then 2.4
View attachment 5027

5. Yeah this is KEYAUTHAPI and it shows what they can use in loader or in webhooks stop be dumb and thinking they are freeing any IP or any shit..

EVERY SITE USING UR IP, and can PUBLISH IT.. -> Neverlose.cc, Gamesense.pub, Nixware.cc, Aimware.net Every site have for example DATABASE, and other shit. bcs he is pasting and smth doing by himself probably not.. so he made webhooks for me it's normally code.
View attachment 5028
defending a paid paste is WILD

how much anyone wanna bet this nigga a staff member or its the owner themself?
 
supremacy
Moderator
User ID
2180
Messages
272
Reactions
308
Level
32
Yo guys so i'm here to tell u gs.dog isn't rat

1. At all this ,,RATTING" what the hell u mean by RATTING show me how we are ratting?
Also this picture is only about software what is doing when start. (label hide) that's all..

String about ip? yeah it's saving ip and sending through webhooks that i have.
Im using to know who is sharing account and who doesn't that's normal. not a rat XD
View attachment 5024

2. How is this picture malware? ... don't be stupid and posting shit about GS.DOG IS RAT or smth else.. it isn't ofc.

explain -> this is debugger which means if u try debug in software called ida64 or smth else like dnspy it says

Shutdown WINDOWS, and CHANGE WALLPAPER that's all what it did if u try debug..
View attachment 5025



3. DiscordMessenger is dll in visualstudio u can install it's for Webhook sending in ur discord channel by WEBHOOKS..
And Costura it means Costura.Fody when u try build project and u have some dlls added in project it will automatically not working if u doesn't connect it and make it in EXE

so if u use Costura.Fody it will make all dlls in 1.exe that's why EXE is sometimes BIGGER then themself
View attachment 5026


4. This Downloadstring(" ") -> it's string which checking ur ip so when u login with keyauth logins it will automatically send WEBHOOKS ip included in.

What it says in webhooks?

probably -> USERNAME
PASSWORD
HWID
IP

also this CMD if u have eyes and know coding it probably means when VERSION isn't 2.4 then THIS CODE WILL START..
-> Process.Start(new ProcessStartinfo("cmd.exe", bla bla bla") it's code to automatically delete old loader which is diff version then 2.4
View attachment 5027

5. Yeah this is KEYAUTHAPI and it shows what they can use in loader or in webhooks stop be dumb and thinking that we are freeing any IP or any shit..

EVERY SITE USING UR IP, and can PUBLISH IT.. -> Neverlose.cc, Gamesense.pub, Nixware.cc, Aimware.net Every site have for example DATABASE, and other shit. bcs i was know c# i did loader through keyauth and upgrade it to better administration for me..

SO i can see who is sharing, who is freeing, etc.
View attachment 5028

Have a nice day :)

"Have a nice day :)"
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Top