Jump to content
Nytro

Darkode leak

Recommended Posts

Posted

[h=3]Darkode leak[/h]

And you can thanks Nassef.

Internal Revenue Service

I don't know if it's you who did this shit

upaskitv1.org

xylibox.biz

krebsonsecurity.biz

upaskitversion1.biz

stevenk.biz

briankrebs.biz

upaskit1.biz

researchsecurity.biz

securityresearch.biz

amatrosov.biz

But seems you are related to this so i gave a fuck.

Also i can thank you for this:

14-03-2013+22-13-34.png

Got your Builder from Darkode and made my keygen.

I also grabbed alot of other things but it's another story.

Nassef is also involved into POS sniffing.

15-03-2013+10-32-34.png

15-03-2013+10-34-04.png

15-03-2013+10-34-48.png

15-03-2013+10-35-53.png

15-03-2013+10-36-49.png

Trying to deal with carder shops:

15-03-2013+10-41-33.png

But i will not talk of Nassef here, but of 'darkode'

This forum is know to be a 'elite' community of black hats, there is alot of (in)famous actors inside.

Some are already jailled and some are still on business.

Darkode.login.GAY.png

Darkode login with a really gay captcha.

And about the captcha they added it due to me:

14-03-2013+20-24-15.png

I don't live in Lyon and i never walked with you, get a life man.

About the captcha something worry me:

14-03-2013+20-32-22.png

Seem he sniff passwords, i'm sure the login form is even backdoored to know passwords of his users.

Also this is not my bruteforce, when i bruteforce it's more hardcore than this shit.

Darkode, on a short period even asked a private SSL cert to avoid unauthorized people:

SSL+connection+error.png

They removed it for an unknown reason, (probably due to the skid wave end), admin of DK gived invite to everyone recently (i even received one without doing nothing, i'm not sure if it's black hat humor or if someone posed on dk and gived my mail)

Darkode+mail.PNG

Anyway i don't need this invitation.

Now, let's have a look on who's inside darkode...

symlink:

14-03-2013+12-57-19.png

Paunch:

14-03-2013+13-00-44.png

*******:

14-03-2013+13-01-58.png

bx1:

14-03-2013+13-04-21.png

BestAV:

14-03-2013+13-05-15.png

Severa:

14-03-2013+13-06-04.png

Exmanoize:

14-03-2013+13-25-08.png

alexudakov:

14-03-2013+13-26-03.png

Carberp

14-03-2013+13-26-58.png

J.P.MORGAN

14-03-2013+19-25-06.png

Even Slavik according to admin:

14-03-2013+13-19-26.png

Some members listed here are already jailed, e.g: bx1, *******.

A member who show off his money done with SpyEye ($11,404,34 USD):

paypalbalance.png

Another DK member who have launder 20k LR with members of this forum:

14-03-2013+22-57-18.png

14-03-2013+23-01-14.png

Sweet orange stats of a guys:

123.png

456.png

Coder of crimepack angry for the leak:

14-03-2013+18-51-01.png

Presentation of cr33k, coder of “Open Source Exploit Kit”

14-03-2013+18-57-07.png

"I skimmed Diebolds", "as a mule i cashed out WU payments with fake IDs"

There is some nice people on darkode...

Presentation of Egypack exploit kit:

14-03-2013+13-14-22.png

Business advice from a darkode admin:

14-03-2013+13-39-08.png

Now about darkode you will says "wow, this board is hardcore" but no... not really

Maybe this forum was cool in 2009 with Gribodemon and shit's but actually it's look like hackforums.

And about hackforums even admins are on it:

mafi (www.hackforums.net/member.php?action=profile&uid=82912)

Selling crimepack:

14-03-2013+19-46-16.png

sp3cial1st (hackforums.net/member.php?action=profile&uid=666599)

Recruiting hackforums people for darkode:

14-03-2013+20-12-19.png

Fubar (hackforums.net/member.php?action=profile&uid=83826)

HF Leet:

14-03-2013+20-16-41.png

(and they are all admins on darkode)

profile of mafi on malwareview (a kernelmode.info like but with idiots):

14-03-2013+19-59-29.png

oh wow they use even hackforums products and resell them.

14-03-2013+20-47-20.png

ngrbot, is this the scene ?

Also remember this ?

21-03-2013+20-49-31.png

Maybe in another post i will explain the dramascene between uNkn0wn and darkode...

At darkode they will probably calls 2,3 screenshots a 'leak'

so... i took around ~4500 screenshots:

14-03-2013+20-56-51.png

I know it can be hard for white hat to enter on community like darkode for do researchs.

So enjoy 763 Mb of screenshots, not a full dump but almost a full dump.

I have a full dump of course with each threads, pages fetched via wget but i keep this version for law enforcement guys (and some have already the darkode account and my regulars dump in hands since a long time, just saying..)

Anyway even with this 'public' screenshots dump anyone have enough to launch indictments and shit.

14-03-2013+21-15-24.png

Oh.. it's really fun dude.

Also took a screenshot of maza for the glory... (I must admit i miss malwares of 2010/2011)

maza.jpg

Gribo talk that Slavik is completely left from bussiness and he transfered everything related to Zeus 2.0 to Gribo, so he can continue work on this bot, including customers technical support. Slavik said to tell that he was happy to work with all the guys and other shit.

You can download the public dump here:

http://temari.fr/darkode.rar

http://trollkore.fr/darkode.rar

http://yandere.fr/darkode.rar

After 24 hours i will remove the archive from my server so fetch it fast.

Multiupload.nl - upload your files to multiple file hosting sites!

To conclude:

This post about darkode is exceptional i usualy leave these forums alone and don't blog about it.

I receive a lots of emails requesting me to give a fuck about theses boards, but since some days for an unknown reason some guys of darkode started to seriously annoy me (adding me on skype and mailling me with shits), this is just my response to them.

cb0f0ef62585ef7484d3582f3caf4ccf

Have a nice day and good advice: stay away of darkode if you don't want someone to knock at your door

Also don't ask me to do the same type of post about mazafaka, or other forums (i see already mails coming)

If you want some infs http://trojanforge.com/showthread.php?t=2391 is a good start, i will not help.

Posted by Steven K at 01:22

Sursa: XyliBox: Darkode leak

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...