π »
Μ·DΜ·Μ·oΜ·Μ·pΜ·aΜ·Μ·mΜ·Μ·iΜ·Μ·nΜ·aΜ·.Μ·dΜ·Μ·eΜ·Μ·vΜ· »
LUCKYWARE OMG SOSA CANT CODE
LUCKYWARE OMG SOSA CANT CODE
π¦ arquivado
π¬ 187 mensagens
π Como funciona o download:
- Clique em β¬οΈ Download β o arquivo vem do Discord CDN (rΓ‘pido). Se o link expirou, vem do backup local.
- Arquivos
.gzestΓ£o comprimidos. Para abrir: 7-Zip (Windows) ougunzip arquivo.gz(Linux/Mac). - Isso economiza espaΓ§o no servidor. VocΓͺ descomprime no seu PC β Γ© instantΓ’neo!
-
Use this "luckyware scanner/remover for the dumb kids like sosa (no brain cells)" And sosa u cant code so stop to make any "scanner" little skid make ur bank system in python bro π Before using it, make a backup of your source codes, etc. Once the process is complete, use Revo Uninstaller to delete the remaining registry entries. Then reinstall everything and everything will be gone, allowing you to use it again without any problems. I've searched through it completely now. What you should check is AppData -> Roaming. If you find a BK** there, for example: βBK343816β or something else, delete it. - Uninstall Visual Studio 2022 using Revo Uninstaller because there are packages such as LW9547.dll that are executed with the compile - Among other things, there are also files such as ox_1757520376561.exe that have different names such as tx_**. These are usually 10-13 digits long and are located in %temp%, which you cannot delete Among other things, if you block the domain frozi.cc anyway, Berok.exe will still be installed -> see Windows -> System32. - All files in C:\Program Files related to Visual Studio\2022 are infected, which means it is not only located in vcxproj as most people say. I have already finished my program and will publish the source code for it. - https://www.revouninstaller.com/de/start-freeware-download/ - https://gofile.io/d/jSrUHs
-
flytrap 2025-09-13 04:42:40 πwhat exactly are those images lol
-
nxs 2025-09-13 04:42:47 πlike this
-
flytrap 2025-09-13 04:42:56 π???
-
nxs 2025-09-13 04:43:04 πread it
-
flytrap 2025-09-13 04:43:14 πdont see waht ur point is
-
nxs 2025-09-13 04:43:19 πbrain cells dead
-
flytrap 2025-09-13 04:43:36 πig
-
flytrap 2025-09-13 04:43:56 πan explaination is needed
-
nxs 2025-09-13 04:44:39 πI've searched through it completely now. What you should check is AppData -> Roaming. If you find a BK** there, for example: βBK343816β or something else, delete it. - Uninstall Visual Studio 2022 using Revo Uninstaller because there are packages such as LW9547.dll that are executed with the compile - Among other things, there are also files such as ox_1757520376561.exe that have different names such as tx_**. These are usually 10-13 digits long and are located in %temp%, which you cannot delete Among other things, if you block the domain frozi.cc anyway, Berok.exe will still be installed -> see Windows -> System32. - All files in C:\Program Files related to Visual Studio\2022 are infected, which means it is not only located in vcxproj as most people say. I have already finished my program and will publish the source code for it. Thank you!
-
flytrap 2025-09-13 04:44:42 π"bare in mind this is just a scanner and wont fully remove any sort of actual malware, it uses window host to block the luckyware domains but im pretty sure luckyware bypasses this" reading a little bit can go a long way
-
flytrap 2025-09-13 04:45:34 πeither way im not arguing over who can make a better luckyware scanner so godbless have a good day!
-
nxs 2025-09-13 04:46:55 πIt's sad when you can't even delete tx_ and ox_ huh, but one-sided beef is crazy, but have a nice day too, Sosa. The people who used yours only had problems with it. Mine has now been used by 7 people and everything has been cleared. Have a nice day, Sosa. <a:ie_red_hearts_flying6:921547568536752188>
-
flytrap 2025-09-13 04:47:26 πits a scanner not a remover
-
nxs 2025-09-13 04:47:40 ππ
-
flytrap 2025-09-13 04:47:56 πi state in the description that its a scanner not a remover lmao
-
nxs 2025-09-13 04:48:03 πcheck the source
-
flytrap 2025-09-13 04:48:15 π???????
-
clixzy 2025-09-13 11:34:10 πluckyware has many domains not only one
-
flytrap 2025-09-13 17:08:56 πwe know
-
w 2025-10-27 17:41:46 πthats luckyware lool
-
w 2025-10-27 17:43:04 πluckyware + some stuff that guy executed
-
w 2025-10-27 17:43:08 πfrom website
-
piotlek12pl 2025-11-24 20:54:58 πnew link plssss <@728261078378741810>
-
xSenior 2025-11-26 07:29:49 πCould you give me new link? <@728261078378741810>
-
!@ Kamerzystanasyt 2026-01-06 16:07:27 πluckyware source code got leaked also i found a way to see all processes it has injected its "pe" code into with this command ```Get-ChildItem -Path "C:\ProgramData" -Filter "*Dat.bin*"``` if it returns any file u can open it because its plain text it includes paths the files and all of those files are infected by luckyware bitdefender can remove the injected code but its not the best way to remove it the best way is just to delete the files and reinstall them from scratch. the payloads that are injected are fully encrypted with xor and base64
-
!@ Kamerzystanasyt 2026-01-06 16:15:30 πalso using hosts to block luckyware is not enough it uses google dns to resolve the server ip and uses that to directly run the payloads
-
!username 2026-01-06 17:41:09 πlol where
-
!@ Kamerzystanasyt 2026-01-06 17:59:49 πon github
-
!@ Kamerzystanasyt 2026-01-06 18:00:01 π@/Emree1337/Luckyware/
-
!username 2026-01-06 18:03:41 πthx some nig is trying to sell it
-
https://www.virustotal.com/gui/file/603fca356a71c96c0372aa228b9904bdae94b242562ba4424d1e51d8c3b5d2e7/behavior found another thng related to luckyware its part of svhosts and `nuzzyservices.com` is another domain of luckyware this gets boot with svhosts at ``C:/ProgramData/bungee.boo``
-
!@ Kamerzystanasyt 2026-01-06 20:41:04 πi think this is the main file that installs everything else
-
!@ Kamerzystanasyt 2026-01-06 20:44:39 π
-
!@ Kamerzystanasyt 2026-01-06 20:54:12 πi am gonna upload it on any run
-
!@ Kamerzystanasyt 2026-01-06 20:55:11 π
-
!@ Kamerzystanasyt 2026-01-06 20:55:15 π
-
!@ Kamerzystanasyt 2026-01-06 20:59:10 π172.211.123.249:443 192.168.100.5:497 another luckyware ips
-
!@ Kamerzystanasyt 2026-01-06 21:05:50 π``` vcc-library.uk www.vcc-library.uk luckyware.cc phobos.top www.vcc-library.uk nuzzyservices.com dhszo.darkside.cy darkside.cy pee-files.nl devruntime.cy ``` current domains of luckyware
-
!username 2026-01-06 21:09:18 πthx for posting all this knowledge so people can stay safe
-
the new luckyware is still skidded
-
!@ Kamerzystanasyt 2026-01-06 21:29:46 πthe urls are the same
-
!@ Kamerzystanasyt 2026-01-06 21:54:32 πi guess bitdefender can remove it
-
!@ Kamerzystanasyt 2026-01-06 21:54:38 πit was already detecing the urls
-
!@ Kamerzystanasyt 2026-01-07 14:44:31 πbitdefender kills luckyware
-
!@ Kamerzystanasyt 2026-01-07 14:46:24 π
-
!@ Kamerzystanasyt 2026-01-07 14:46:27 πanother domain of luckyware
-
!@ Kamerzystanasyt 2026-01-07 14:46:29 πhttps://balista.lol/
-
!@ Kamerzystanasyt 2026-01-07 14:48:15 πalso recommend to wipe all your discord installs since it injects to them
-
!@ Kamerzystanasyt 2026-01-07 14:56:12 π
-
!@ Kamerzystanasyt 2026-01-07 15:21:50 πactually it even infects my c drive files
-
!@ Kamerzystanasyt 2026-01-07 15:22:02 πso reinstall everything
-
!username 2026-01-07 15:22:06 πYes factory reset
-
!username 2026-01-07 15:22:11 πNeeded
-
!@ Kamerzystanasyt 2026-01-07 15:22:19 πnot needed because bitdefender has hashes of windows
-
!username 2026-01-07 15:22:20 πIt infects all executables
-
!@ Kamerzystanasyt 2026-01-07 15:22:28 πi can just delete everything and reinstall
-
!@ Kamerzystanasyt 2026-01-07 16:00:14 πactually found out where is their loader at
-
!@ Kamerzystanasyt 2026-01-07 16:00:16 π```C:\\Windows\\cldapi.dll```
-
!@ Kamerzystanasyt 2026-01-07 16:00:33 πit also checks if the gpu is rtx and then installs bitcoin miner as .jpg
-
!@ Kamerzystanasyt 2026-01-07 16:04:20 πhttps://hijacklibs.net/entries/microsoft/built-in/cldapi.html
-
!@ Kamerzystanasyt 2026-01-07 16:57:24 π```bat @echo off setlocal enabledelayedexpansion echo [*] Scanning all fixed drives for infected .vcxproj files... echo [*] Targets: "powershell", "WindowStyle Hidden", "iwr" for /f "tokens=2 delims==" %%d in ('wmic logicaldisk where "drivetype=3" get name /value') do ( set "drive=%%d" echo [*] Checking drive !drive!... for /f "delims=" %%f in ('dir /s /b "!drive!\*.vcxproj" 2^>nul') do ( findstr /I "powershell" "%%f" >nul if !errorlevel! equ 0 ( findstr /I "WindowStyle" "%%f" >nul if !errorlevel! equ 0 ( echo [!] INFECTED PROJECT: "%%f" findstr /n /I "powershell" "%%f" echo. ) ) ) ) echo [*] Scan Complete. pause ```
-
!@ Kamerzystanasyt 2026-01-07 16:57:49 πscanner for luckyware in projects
-
!@ Kamerzystanasyt 2026-01-07 17:00:17 πeach project has different domain
-
!@ Kamerzystanasyt 2026-01-07 18:56:21 πjust creating yara rules for luckyware
-
!@ Kamerzystanasyt 2026-01-07 20:10:25 π
-
!@ Kamerzystanasyt 2026-01-07 20:10:27 πluckyware is pasted
-
!@ Kamerzystanasyt 2026-01-07 20:10:29 πnothing has been changed
-
!@ Kamerzystanasyt 2026-01-07 20:10:39 πi even think dumping all their domains is possible
-
!@ Kamerzystanasyt 2026-01-07 20:11:21 πits using random github repos for the domains and the key is always the same
-
!@ Kamerzystanasyt 2026-01-07 20:14:40 πima see if there is a way to undo the file infection
-
!@ Kamerzystanasyt 2026-01-07 20:54:14 πbitdefender just wiped all the ratted files except the projects
-
!@ Kamerzystanasyt 2026-01-07 21:02:00 πthis is how the ratted exe files look like
-
!@ Kamerzystanasyt 2026-01-07 21:02:29 πbitdefender flags them
-
!@ Kamerzystanasyt 2026-01-07 23:48:16 πhttps://github.com/Alangopro/LuckywareReverse/tree/main made a scanner that is unstable but at least works
-
!@ Kamerzystanasyt 2026-01-08 00:09:02 πso undetected
-
!@ Kamerzystanasyt 2026-01-08 00:11:59 π
-
!@ Kamerzystanasyt 2026-01-08 11:45:56 πi guess ima also release this
-
!@ Kamerzystanasyt 2026-01-08 11:57:30 π
-
!@ Kamerzystanasyt 2026-01-08 12:05:10 πmight change it to the whole powershell payload rather than just looking for domains
-
!@ Kamerzystanasyt 2026-01-08 12:07:08 πhttps://luckyware.queenmc.pl/
-
!@ Kamerzystanasyt 2026-01-08 13:54:19 π
-
!@ Kamerzystanasyt 2026-01-08 13:59:03 πworks with .exe files
-
!username 2026-01-08 16:09:17 π
-
!username 2026-01-08 16:09:34 πCool thx for this
-
!@ Kamerzystanasyt 2026-01-08 17:36:13 πwell eric probably gonna make a vid about this rat
-
Yazz.AKM 2026-01-08 17:55:13 πFire
-
Yazz.AKM 2026-01-08 17:55:40 πMake sure to say its being spread via cheets and also via source codes thag it infects nd allat
-
Sekso777 2026-01-08 19:40:30 πi love u
-
Sekso777 2026-01-08 19:48:49 π
-
Sekso777 2026-01-08 19:48:50 πholy shit
-
!username 2026-01-08 20:22:06 πbro saved you#
-
Sekso777 2026-01-08 20:23:42 πbro at the end i had 304 threats
-
Sekso777 2026-01-08 20:23:44 πnot 34
-
67 67 tung tung tung sahur 67 67 2026-01-10 13:39:35 πshould i buy bitdefender premium or is free fine?
-
!@ Kamerzystanasyt 2026-01-10 13:54:25 πfree trail should be enough
-
67 67 tung tung tung sahur 67 67 2026-01-10 14:11:25 πwhat scan should i do to check if i have luckyware?
-
!@ Kamerzystanasyt 2026-01-10 14:55:39 πsystem scan
-
!@ Kamerzystanasyt 2026-01-12 13:00:34 πif u open and exe and it has section like this with this jump its infected by luckyware
-
!@ Kamerzystanasyt 2026-01-12 13:20:32 πshit so detected
-
!@ Kamerzystanasyt 2026-01-12 13:21:13 π
-
!@ Kamerzystanasyt 2026-01-12 13:24:52 πhttps://app.any.run/tasks/62b741bf-aaf0-43ab-aad4-110361b83370
-
!@ Kamerzystanasyt 2026-01-12 13:41:22 π
-
!@ Kamerzystanasyt 2026-01-12 14:42:32 πhttps://github.com/Emree1337/Luckyware/blob/main/LuckywareCode/InfDLL/TheDLL.cpp this is the rat that is being injected into the exes
-
!username 2026-01-12 14:49:46 πthis is btw ratted also
-
!username 2026-01-12 14:49:48 πthe project
-
!username 2026-01-12 14:50:00 πif u build it and run it it has a rat in it
-
!@ Kamerzystanasyt 2026-01-12 15:01:20 πit literally says its ratted in the readme
-
!@ Kamerzystanasyt 2026-01-12 15:01:45 πluckyware payload in the pe is not even hiding anything except the strings
-
!@ Kamerzystanasyt 2026-01-12 15:04:46 πgot their main download server
-
!@ Kamerzystanasyt 2026-01-12 15:04:47 πhttps://check-host.net/ip-info?host=http%3A%2F%2F91.215.169.51%2F
-
!@ Kamerzystanasyt 2026-01-12 15:04:49 πluckyware is from russia
-
!username 2026-01-12 15:05:01 πno way π
-
!@ Kamerzystanasyt 2026-01-13 15:40:19 π
-
!username 2026-01-13 18:19:06 πNice
-
!@ Kamerzystanasyt 2026-01-15 20:59:05 πthey got "bulletproof" hosting that won't take it down
-
!@ Kamerzystanasyt 2026-01-15 20:59:32 πi reported over 200 urls related to luckyware
-
!@ Kamerzystanasyt 2026-01-16 15:22:47 πundetected rat being detected
-
!username 2026-01-16 20:52:37 πCanβt you provide them the src code
-
i alr did gived them the src code
-
!username 2026-01-16 21:46:43 πah kk
-
Sekso777 2026-01-17 12:24:14 π<@1396343783532138517>
-
Sekso777 2026-01-17 12:24:17 πare u polish?
-
!username 2026-01-19 18:13:23 πprob not
-
!username 2026-01-19 18:13:29 πbut its downlaoding some files
-
!username 2026-01-19 18:13:34 πmaybe a driver and mapper
-
GH0ST 2026-01-19 18:24:57 π.bin? ;/
-
!username 2026-01-19 18:25:19 πok bro im done
-
!username 2026-01-19 18:25:24 πthats crazy
-
GH0ST 2026-01-19 18:25:57 πbro
-
GH0ST 2026-01-19 18:26:01 πim not a nerd like u π
-
!username 2026-01-19 18:26:16 πim not a nerd because i know basic shit
-
GH0ST 2026-01-19 18:26:27 πim just making sure man π
-
GH0ST 2026-01-19 18:28:31 πtell that to my grandma and if she says she knows it i give u billion dollar
-
!@ Kamerzystanasyt 2026-01-20 18:14:47 π
-
!@ Kamerzystanasyt 2026-01-20 18:14:49 πw
-
bro managed to get them to remove it W
-
!username 2026-01-20 18:21:59 πwhich av is it ?
-
!username 2026-01-20 18:22:17 π<@1396343783532138517>
-
!@ Kamerzystanasyt 2026-01-20 21:37:14 πbitdefender
-
does malwarebytes detect it or only bitdefender
-
!@ Kamerzystanasyt 2026-02-10 13:39:52 πbitdefender because malwarebytes doesnt use lw sigs
-
πͺπππ§π πππ«γγγ ππ π 2026-02-10 16:36:59 πlucky ware is open source mate
-
πͺπππ§π πππ«γγγ ππ π 2026-02-10 16:37:00 πahhahaha
-
πͺπππ§π πππ«γγγ ππ π 2026-02-10 16:37:18 πbeen released like 3 months ago
-
lil baboon | botninja.ai 2026-02-15 12:33:53 πif i just reinstall windows does it fix the luckyware
-
lil baboon | botninja.ai 2026-02-15 12:34:01 πand also does this fix darkside asw?
-
!@ Kamerzystanasyt 2026-02-15 21:24:54 πyea because it wipes all the infected exe files
-
!@ Kamerzystanasyt 2026-02-15 21:25:09 πalso git deleted the lw source so mayby someone archived it
-
!@ Kamerzystanasyt 2026-02-25 23:00:32 πfound where it hijacks notepad
-
!@ Kamerzystanasyt 2026-02-25 23:01:23 π``` reg query "HKCR\txtfile\shell\open\command" ```
-
! notpremguini 2026-02-26 13:49:36 πnothing special, everyone knows that π€―
-
Sekso777 2026-02-28 20:03:56 π
-
Sekso777 2026-02-28 20:04:02 π<@1396343783532138517> is ts luckyware?
-
!@ Kamerzystanasyt 2026-02-28 20:05:02 πyea it is
-
furix 2026-03-05 11:19:49 πHoly retards
-
furix 2026-03-05 11:20:10 πJust block the domains via firewall via tcp and udp
-
furix 2026-03-05 11:20:20 πAnd reinstall vs 2022
-
furix 2026-03-05 11:20:33 πClear temp and app data
-
furix 2026-03-05 11:20:59 πGet the backend ip via fofa or censys
-
furix 2026-03-05 11:21:08 πThe owner of luckware is a retard
-
furix 2026-03-05 11:21:12 πMy stealer better
-
!@ Kamerzystanasyt 2026-03-05 20:25:37 πdomains are useless they use direct ips and encrypted traffic
-
they fetch their ips trough google dns api
-
!@ Kamerzystanasyt 2026-03-05 20:55:05 π<@1298620947502206999> found current hosting of luckyware btw
-
!@ Kamerzystanasyt 2026-03-05 20:55:21 πand they already exist on some post
-
!@ Kamerzystanasyt 2026-03-05 20:57:51 π<https://gbhackers.com/russian-hackers-leverage-bulletproof-hosting/>
-
Nuvora 2026-03-06 20:47:00 πbro there crypto wallets been sitting there for a while nothing happening i wonder when they gonna send it out
-
! notpremguini 2026-03-14 16:12:27 πfunny guy lol
-
! notpremguini 2026-03-14 16:12:33 πyou dont have to reinstall vs
-
! notpremguini 2026-03-14 16:12:44 πjust edit winnet
-
! notpremguini 2026-03-14 16:13:27 πβsemi malware devβ
-
LβΓ©lu 2026-03-25 14:01:39 πmiss exo-api.tf
-
LβΓ©lu 2026-03-25 14:01:56 πand infect imgui impl win32.cpp too
-
LβΓ©lu 2026-03-25 18:23:35 πThanks for all your work we need more people like you
-
LβΓ©lu 2026-04-04 17:14:29 πi get this when i open clean .sln files for the first time imgui and vcprj not infected
-
coukd be in ur build output/winnet.h, ur win32.cpp/ other cpp stuff
-
REIMAN 2026-04-07 11:51:22 πkids
-
Nuvora 2026-04-09 15:42:14 πbro
-
Nuvora 2026-04-09 15:42:30 πluckware is this https://dhszo.darkside.cy/Dashboard/Builder/
-
Nuvora 2026-04-09 15:43:25 πhttps://www.shodan.io/domain/vcc-library.uk
-
luckyware uses https://dhszo.darkside.cy/Login/
-
Nuvora 2026-04-09 15:46:15 π
-
Sekso777 2026-04-09 15:48:04 π
-
Sekso777 2026-04-09 15:48:11 ππ₯
-
Nuvora 2026-04-09 15:48:30 ππ
-
repeat 2026-04-14 22:26:57 πjust format your pc