Python Forum
scammed through python keylogger
Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
scammed through python keylogger
#11
(Aug-29-2023, 09:25 AM)Gribouillis Wrote:
(Aug-29-2023, 08:46 AM)Noq Wrote: the .py file installed modules into my system. i only want to know if there is a possibility of removing it from my system
Can you identify what the program installed on your system? That is the main question. If it installed Python modules and you know these module names, they can easily be removed in principle, but a Python program can potentially install anything that you can install yourself as a user with the permissions it has when the program is launched. It could be Python modules, but it could as well be all sorts of files and executable programs that have nothing to do with Python. The Python program can download these files from the internet and install them on your computer.

I can not identify that, I thought maybe someone here could decompile it in a safe environment. Im not a computer guy, id do it myself if I had the knowledge.

that doesn't sound good.

these people required me to connect to a wallet with copy-paste my passphrase WHILE the program was running. its an application for crypto trading and they have 1000+ users, who can get scammed anytime now, too.
Reply
#12
I took a look it at this and did run it a sandbox.
So is of course all a scam from the obfuscation Betweensniper.py and there website(Domain age 1 week ago).
When run file it try to make a network connection to use Telegram messenger,then they can have control(Remote Desktop) over most of what you do as long the connection is up.
Quote:Even when Telegram is not installed or being used on target machines,
hackers can send malicious commands and operations remotely via the instant messaging app using a Telegram ‘bot’ embedded in the malware.
Recipients of the malware are subjected to:

• File system control (files and processes can be deleted/killed)
• Data leaks (data can be copied from the PC clipboard, or audio and video recorded via the PC’s microphone and camera)
It looks like when close connection from(Betweensniper.py) that no connection or service are running anmore,
but when the have control can install malware that can run later.
So what to do?
Not much as as the damage has already happened,i guess when network connection was closed is done.
You should maybe take it to someone to look over(network connetion,service,maleware),or search yourself how to check this.
Gribouillis likes this post
Reply
#13
(Aug-29-2023, 08:46 AM)Noq Wrote: i only want to know if there is a possibility of removing it from my system, or if i have to set up the system again

The sane thing to do after you get hacked is to completely set up the system anew again.
You can never be 100% sure there are no remnants otherwise. You can of course gamble.

If I were you, I would stop using cracked software, and boast about it online.
After 10 years of usage maybe you can give back to the developers and buy it.
Reply


Forum Jump:

User Panel Messages

Announcements
Announcement #1 8/1/2020
Announcement #2 8/2/2020
Announcement #3 8/6/2020