- Joined
- Jul 5, 2013
- Messages
- 30,693 (7.10/day)
Easily understood.But it certainly hasn't been my favorite case either.
Easily understood.But it certainly hasn't been my favorite case either.
System Name | Starlifter :: Dragonfly |
---|---|
Processor | i7 2600k 4.4GHz :: i5 10400 |
Motherboard | ASUS P8P67 Pro :: ASUS Prime H570-Plus |
Cooling | Cryorig M9 :: Stock |
Memory | 4x4GB DDR3 2133 :: 2x8GB DDR4 2400 |
Video Card(s) | PNY GTX1070 :: Integrated UHD 630 |
Storage | Crucial MX500 1TB, 2x1TB Seagate RAID 0 :: Mushkin Enhanced 60GB SSD, 3x4TB Seagate HDD RAID5 |
Display(s) | Onn 165hz 1080p :: Acer 1080p |
Case | Antec SOHO 1030B :: Old White Full Tower |
Audio Device(s) | Creative X-Fi Titanium Fatal1ty Pro - Bose Companion 2 Series III :: None |
Power Supply | FSP Hydro GE 550w :: EVGA Supernova 550 |
Software | Windows 10 Pro - Plex Server on Dragonfly |
Benchmark Scores | >9000 |
System Name | Pioneer |
---|---|
Processor | Ryzen 9 9950X |
Motherboard | MSI MAG X670E Tomahawk Wifi |
Cooling | Noctua NH-D15 + A whole lotta Sunon, Phanteks and Corsair Maglev blower fans... |
Memory | 128GB (4x 32GB) G.Skill Flare X5 @ DDR5-4200(Running 1:1:1 w/FCLK) |
Video Card(s) | XFX RX 7900 XTX Speedster Merc 310 |
Storage | Intel 5800X Optane 800GB boot, +2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs, 1x 2TB Seagate Exos 3.5" |
Display(s) | 55" LG 55" B9 OLED 4K Display |
Case | Thermaltake Core X31 |
Audio Device(s) | TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED |
Power Supply | FSP Hydro Ti Pro 850W |
Mouse | Logitech G305 Lightspeed Wireless |
Keyboard | WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps |
Software | Gentoo Linux x64, other office machines run Windows 11 Enterprise |
Sounds like this guy went dark after the 2nd attack. I think I would do the same. Sounds like he reached out to have a "paper trail" of events too protect himself and his family. It looks like he had noticed this issues around or before March 2018; based on his post he shared at the beginning of this thread. I'll take a guess; but I don't think he will make contact again. I know I would not. I wouldn't have an issue moving too a remote location in the mountains or nice beach with white sand Beach, clear water and say f#%/ computers and modern conveniences. ...sounds great IMOP.....
Processor | Ryzen 9 3900X |
---|---|
Motherboard | Asus ROG Strix X370-F |
Cooling | Dark Rock 4, 3x Corsair ML140 front intake, 1x rear exhaust |
Memory | 2x8GB TridentZ RGB [3600Mhz CL16] |
Video Card(s) | EVGA 3060ti FTW3 Ultra Gaming |
Storage | 970 EVO 500GB nvme, 860 EVO 250GB SATA, Seagate Barracuda 1TB + 4TB HDDs |
Display(s) | 27" MSI G27C4 FHD 165hz |
Case | NZXT H710 |
Audio Device(s) | Modi Multibit, Vali 2, Shortest Way 51+ - LSR 305's, Focal Clear, HD6xx, HE5xx, LCD-2 Classic |
Power Supply | Corsair RM650x v2 |
Mouse | iunno whatever cheap crap logitech *clutches Xbox 360 controller security blanket* |
Keyboard | HyperX Alloy Pro |
Software | Windows 10 Pro |
Benchmark Scores | ask your mother |
System Name | Starlifter :: Dragonfly |
---|---|
Processor | i7 2600k 4.4GHz :: i5 10400 |
Motherboard | ASUS P8P67 Pro :: ASUS Prime H570-Plus |
Cooling | Cryorig M9 :: Stock |
Memory | 4x4GB DDR3 2133 :: 2x8GB DDR4 2400 |
Video Card(s) | PNY GTX1070 :: Integrated UHD 630 |
Storage | Crucial MX500 1TB, 2x1TB Seagate RAID 0 :: Mushkin Enhanced 60GB SSD, 3x4TB Seagate HDD RAID5 |
Display(s) | Onn 165hz 1080p :: Acer 1080p |
Case | Antec SOHO 1030B :: Old White Full Tower |
Audio Device(s) | Creative X-Fi Titanium Fatal1ty Pro - Bose Companion 2 Series III :: None |
Power Supply | FSP Hydro GE 550w :: EVGA Supernova 550 |
Software | Windows 10 Pro - Plex Server on Dragonfly |
Benchmark Scores | >9000 |
System Name | Overkill! |
---|---|
Processor | i7-8700k |
Motherboard | Asus Prime Z370-A |
Cooling | Corsair H100i v2 |
Memory | 32GB DDR4@2400Mhz |
Video Card(s) | Evga 980ti FTW |
Storage | Samsung Evo 500GB |
Power Supply | Evga 1000W G2 |
Software | Win 10 Pro |
I don't seem to be on anyone dangerous's radar right now at least. But it certainly hasn't been my favorite case either.
I'll admit it has me wondering as well, what I can do to tighten things down. It'd be nice if there was some sort of guide somewhere... but anything I can find usually falls basics like changing your default router password and putting a password on your wifi, to doing more, less effective things like a mac filter, hiding the SSID, etc... all of which are easily sidestepped by anyone who would be trying to hack you, anyway.
System Name | Overkill! |
---|---|
Processor | i7-8700k |
Motherboard | Asus Prime Z370-A |
Cooling | Corsair H100i v2 |
Memory | 32GB DDR4@2400Mhz |
Video Card(s) | Evga 980ti FTW |
Storage | Samsung Evo 500GB |
Power Supply | Evga 1000W G2 |
Software | Win 10 Pro |
Yep, and at a resume and job seminar the head of HR of a company said to make sure you don't post anything you don't want anyone to see, even if it's private because ALL companies HR have back doors to see EVERYTHING. And this is just HR depts--your friendly gov will have much more ability to see stuff.I mean, think about it; what a concept. Millions of people voluntarily post everything about their lives with 100's of pictures and locations for almost everyone
to see. then share who thier family members are, where they live, where their from, who they hang around currently (and previously)where they go to school, where they hang out...ect...
As far as the "average Joe"; I doubt the NSA has to collect anything on us. We submit it for them.
System Name | Overkill! |
---|---|
Processor | i7-8700k |
Motherboard | Asus Prime Z370-A |
Cooling | Corsair H100i v2 |
Memory | 32GB DDR4@2400Mhz |
Video Card(s) | Evga 980ti FTW |
Storage | Samsung Evo 500GB |
Power Supply | Evga 1000W G2 |
Software | Win 10 Pro |
Yes, of course your'e correct; Windows can be tamed, and Ad blocks can be installed. I should have stated that by defuult alot of programs
and OS's have to be tweaked. The user has to go out of his way to remove cookies, empty browser cache, turn off reletive ads in windows setting
(Of which seems to change all the time, and I still can't remember where stuff is!!!!) and install a good 3rd party adblocker/remover.
https://www.businessinsider.com/facebook-gets-top-fine-ico-cambridge-analytica-data-breach-2018-10
lol...this is good. I have never liked Facebook anyways.
But its probably only a spank on the hand; they have DEEEP pockets; I have always thought that have ties to GOV.
I mean, think about it; what a concept. Millions of people voluntarily post everything about their lives with 100's of pictures and locations for almost everyone
to see. then share who thier family members are, where they live, where their from, who they hang around currently (and previously)where they go to school, where they hang out...ect...
As far as the "average Joe"; I doubt the NSA has to collect anything on us. We submit it for them
System Name | Pioneer |
---|---|
Processor | Ryzen 9 9950X |
Motherboard | MSI MAG X670E Tomahawk Wifi |
Cooling | Noctua NH-D15 + A whole lotta Sunon, Phanteks and Corsair Maglev blower fans... |
Memory | 128GB (4x 32GB) G.Skill Flare X5 @ DDR5-4200(Running 1:1:1 w/FCLK) |
Video Card(s) | XFX RX 7900 XTX Speedster Merc 310 |
Storage | Intel 5800X Optane 800GB boot, +2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs, 1x 2TB Seagate Exos 3.5" |
Display(s) | 55" LG 55" B9 OLED 4K Display |
Case | Thermaltake Core X31 |
Audio Device(s) | TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED |
Power Supply | FSP Hydro Ti Pro 850W |
Mouse | Logitech G305 Lightspeed Wireless |
Keyboard | WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps |
Software | Gentoo Linux x64, other office machines run Windows 11 Enterprise |
System Name | Starlifter :: Dragonfly |
---|---|
Processor | i7 2600k 4.4GHz :: i5 10400 |
Motherboard | ASUS P8P67 Pro :: ASUS Prime H570-Plus |
Cooling | Cryorig M9 :: Stock |
Memory | 4x4GB DDR3 2133 :: 2x8GB DDR4 2400 |
Video Card(s) | PNY GTX1070 :: Integrated UHD 630 |
Storage | Crucial MX500 1TB, 2x1TB Seagate RAID 0 :: Mushkin Enhanced 60GB SSD, 3x4TB Seagate HDD RAID5 |
Display(s) | Onn 165hz 1080p :: Acer 1080p |
Case | Antec SOHO 1030B :: Old White Full Tower |
Audio Device(s) | Creative X-Fi Titanium Fatal1ty Pro - Bose Companion 2 Series III :: None |
Power Supply | FSP Hydro GE 550w :: EVGA Supernova 550 |
Software | Windows 10 Pro - Plex Server on Dragonfly |
Benchmark Scores | >9000 |
Thanks, let us know any updates when/if you hear...I'm not really following this thread right now but I thought everyone would like to know my client is alive and well. He got in touch with me just tonight after setting up a honeypot of sorts with a wireshark monitor. He's hoping the net capture trafic will help his case with the FBI. I'm probably going to be sending him his things soon for said case. But at any rate, he wasn't eliminated or anything horrible, he just was taking some time letting his system do a "userfree run" for which to capture a lot of what this malware is doing.
As for him not logging in since whenever May, he told me that a few of you here scare him frankly and he doesn't trust the place as a whole. I'd hope he's humorously referring to mailman with that comment, but keep in mind he's understandably a little paranoid given his situation.
Hopefully it works out for him, but I'm largely uninvolved now. Thank you for everyones advice and lets hope something good comes of this whole saga.
Processor | Ryzen 9 3900X |
---|---|
Motherboard | Asus ROG Strix X370-F |
Cooling | Dark Rock 4, 3x Corsair ML140 front intake, 1x rear exhaust |
Memory | 2x8GB TridentZ RGB [3600Mhz CL16] |
Video Card(s) | EVGA 3060ti FTW3 Ultra Gaming |
Storage | 970 EVO 500GB nvme, 860 EVO 250GB SATA, Seagate Barracuda 1TB + 4TB HDDs |
Display(s) | 27" MSI G27C4 FHD 165hz |
Case | NZXT H710 |
Audio Device(s) | Modi Multibit, Vali 2, Shortest Way 51+ - LSR 305's, Focal Clear, HD6xx, HE5xx, LCD-2 Classic |
Power Supply | Corsair RM650x v2 |
Mouse | iunno whatever cheap crap logitech *clutches Xbox 360 controller security blanket* |
Keyboard | HyperX Alloy Pro |
Software | Windows 10 Pro |
Benchmark Scores | ask your mother |
Honestly, given his situation... ...that's just a generally prudent way to operate. When this all started he had to know something was distinctly unusual, but he probably didn't anticipate the FBI investigation and everything else that has followed. I know if I had crap like that to deal with, I wouldn't even be talking to too many people I actually know about it, let alone strangers on the internet. Why expose yourself if you can avoid it? I mean... ...blabbing to people you don't know about a big problem with an unknown source is just... ...for me it wouldn't be a matter of paranoia or necessarily trust, just principle. It's not about whether anyone here even could have anything to do with anything. That would be a little silly. It's the idea of it. Not the best time to go putting yourself out there for no reason... ...not when you're already in a vulnerable position.As for him not logging in since whenever May, he told me that a few of you here scare him frankly and he doesn't trust the place as a whole. I'd hope he's humorously referring to mailman with that comment, but keep in mind he's understandably a little paranoid given his situation.
Sorry, if something really that sophisticated has attacked your computer, you'll just have to buy everything new again...
System Name | BOX |
---|---|
Processor | Core i7 6950X @ 4,26GHz (1,28V) |
Motherboard | X99 SOC Champion (BIOS F23c + bifurcation mod) |
Cooling | Thermalright Venomous-X + 2x Delta 38mm PWM (Push-Pull) |
Memory | Patriot Viper Steel 4000MHz CL16 4x8GB (@3240MHz CL12.12.12.24 CR2T @ 1,48V) |
Video Card(s) | Titan V (~1650MHz @ 0.77V, HBM2 1GHz, Forced P2 state [OFF]) |
Storage | WD SN850X 2TB + Samsung EVO 2TB (SATA) + Seagate Exos X20 20TB (4Kn mode) |
Display(s) | LG 27GP950-B |
Case | Fractal Design Meshify 2 XL |
Audio Device(s) | Motu M4 (audio interface) + ATH-A900Z + Behringer C-1 |
Power Supply | Seasonic X-760 (760W) |
Mouse | Logitech RX-250 |
Keyboard | HP KB-9970 |
Software | Windows 10 Pro x64 |
System Name | Pioneer |
---|---|
Processor | Ryzen 9 9950X |
Motherboard | MSI MAG X670E Tomahawk Wifi |
Cooling | Noctua NH-D15 + A whole lotta Sunon, Phanteks and Corsair Maglev blower fans... |
Memory | 128GB (4x 32GB) G.Skill Flare X5 @ DDR5-4200(Running 1:1:1 w/FCLK) |
Video Card(s) | XFX RX 7900 XTX Speedster Merc 310 |
Storage | Intel 5800X Optane 800GB boot, +2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs, 1x 2TB Seagate Exos 3.5" |
Display(s) | 55" LG 55" B9 OLED 4K Display |
Case | Thermaltake Core X31 |
Audio Device(s) | TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED |
Power Supply | FSP Hydro Ti Pro 850W |
Mouse | Logitech G305 Lightspeed Wireless |
Keyboard | WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps |
Software | Gentoo Linux x64, other office machines run Windows 11 Enterprise |
Side question : Can this malware work on PC that doesn't support virtualisation or/and has non-UEFI MB (ie. Pentium 4 Prescott-1M [E0] or 1-st gen Core i7 with legacy BIOS) ?
I have been dealing with a similar malware infection for several months... While i can actually flash the vbios and mb bios, or atleast i can go through the process which reports success.. But it does zero good. Ultimately what we are seeeing is not a piece of malware but a framework like metasploit for kali linux, only this is pieced together using many legitimate tools and files that have been repurposed. My extensive reading of logs, config files as well as plain text data located in many of the corrupt .dlls indicate something that is actively being developed, i wont go into the entire craziness that i have witnessed as this basically ate a brand new highend desktop and laptop as well as a handfull of old junk boxes i used to research and study. At the end of the day the reason it seems undefeatable is because it has corrupted the spi flash memory.. And therefore is god. The uefi bios is most likely being loaded from a repository thats been created in reported bad clusters on the hdds.. Which gives it space that isnt even looked at by anything, beyond that it runs a fuse file system on the hdds ensuring you will likely never access the real root directory... And in my case my os installs. are basically being virtualized... Turning my systwm into a vm ...
It was creating virtual raid array and utilizing gpu memory as a virtual hd in the array.
The motherboard will need to be rma'd and the spi reflashed along with the uefi bios, thwn fresh hd fresh install media and periphrials. The card SHOULD BE OK AT THAT POINT so says asus. Good luck.
I would love to expand. All I can say without his permission is that the second attack was a sophisticated network based attack, using his modem as the bridge. And no matter what modem we replaced it with, it would happen again. It would then proceed to infect home devices. (We know this from a firewall netlog showing them contacting malware ips).
He basically shoveled money at this problem with no end in site. I don't think he'd disagree with that statement. It's part of why I couldn't work for him anymore: I couldn't take his money and gurantee success; he needed someone better skilled at network issues and able to "do the job right." I'm a firmware guy, it left that turf.
It was almost as if his home was cursed. I could remove devices from the premise, cure them via a hardware flash, and they'd remain fine. Put them back in his home and they'd not last 2 nights. Of course it wasn't cursed, it was just a repeatedly infected modem/router. I almost wonder if the cable end was compromised at the ISP's side... that's basically why I told him "call the FBI."
I haven't heard from him in over a month, which sucks because I want to send things of his to Symantec/other AV groups/the FBI but don't know if I have his permission. Some of the evidence consists of complete, untampered with drives, so I don't feel comfortable sending them without client permission since they contain a lot of his personal stuff surely.
Advice there appreciated, actually.
Plus, it's odd having a box of SSDs and thumb drives on the mantle labeled "INFECTED - DO NOT USE." It's not a good conversation piece when you can't say much: I'd be glad to be rid of it.
System Name | WorkInProgress |
---|---|
Processor | AMD 7800X3D |
Motherboard | MSI X670E GAMING PLUS |
Cooling | Thermalright AM5 Contact Frame + Phantom Spirit 120SE |
Memory | 2x32GB G.Skill Trident Z5 NEO DDR5 6000 CL32 |
Video Card(s) | Asus Dual Radeon™ RX 6700 XT OC Edition |
Storage | WD SN770 1TB (Boot)|1x WD SN850X 8TB (Gaming)| 2x2TB WD SN770| 2x2TB+2x4TB Crucial BX500 |
Display(s) | LG GP850-B |
Case | Corsair 760T (White) {1xCorsair ML120 Pro|5xML140 Pro} |
Audio Device(s) | Yamaha RX-V573|Speakers: JBL Control One|Auna 300-CN|Wharfedale Diamond SW150 |
Power Supply | Seasonic Focus GX-850 80+ GOLD |
Mouse | Logitech G502 X |
Keyboard | Cherry G80-3000N (TKL) |
Software | Windows 11 Home |
Benchmark Scores | ლ(ಠ益ಠ)ლ |
I'm not really following this thread right now but I thought everyone would like to know my client is alive and well. He got in touch with me just tonight after setting up a honeypot of sorts with a wireshark monitor. He's hoping the net capture trafic will help his case with the FBI. I'm probably going to be sending him his things soon for said case. But at any rate, he wasn't eliminated or anything horrible, he just was taking some time letting his system do a "userfree run" for which to capture a lot of what this malware is doing.
As for him not logging in since whenever May, he told me that a few of you here scare him frankly and he doesn't trust the place as a whole. I'd hope he's humorously referring to mailman with that comment, but keep in mind he's understandably a little paranoid given his situation.
Hopefully it works out for him, but I'm largely uninvolved now. Thank you for everyones advice and lets hope something good comes of this whole saga.