rhcp011235 icon

Untitled

rhcp011235 | PRO | 02/05/26 04:18:08 AM UTC | 0 ⭐ | 17100 👁️ | Never ⏰ | []
Bash |

11.83 KB

|

None

|

0 👍

/

0 👎

#!/bin/bash
 
set -e
 
RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[1;33m'
CYAN='\033[0;36m'
NC='\033[0m'
 
echo "========================================"
echo "OGF InfoStealer Detection Script v4.0"
echo "========================================"
echo ""
echo "Based on: https://rentry.co/ogf_malware & rentry.co/ogf_malware_behavior"
echo ""
 
DETECTIONS=0
WARNINGS=0
 
echo "[1/12] Checking for known infected releases in Downloads..."
echo ""
 
DOWNLOADS_DIR="$HOME/Downloads"
 
KNOWN_MALICIOUS_HASHES="5f37ea4e9c38e3ab9b8ae9403dc92ed9|8c1ca9899a3850f0302f2b4c2b76237d|d7f8b30accdebbd343e0a63b05b2d527|ea795c69ff68af3ea67dbf5f841dac1a|5bf80ea3e65a3327504120d5833b3b6a|ac60b72617c8ce08931a4fd424ed4565|c30ad49debf39d1e73350ee06d370e59|bb300ba91a09ba23fbd7af43247ad4b3|d79d030e383eccaf3142e593b9ab074c|18590ff4d9eb846e9db01ab2cfd6537f"
 
KNOWN_MALICIOUS_NAMES="ParallelsDesktop|CleanMyMac|Adobe.*DC|Adobe.*Pro|Photoshop.*[0-9]|Premiere.*Pro|DaVinci.*Resolve|Final.*Cut.*Pro|PDF.*Expert|Capture.*One|Logic.*Pro|Office.*2024|Microsoft.*Office"
 
if [ -d "$DOWNLOADS_DIR" ]; then
    FOUND_INFECTED=""
 
    while IFS= read -r -d '' f; do
        NAME=$(basename "$f")
        SIZE=$(ls -lh "$f" 2>/dev/null | awk '{print $5}')
        MOD=$(stat -f "%Sm" -t "%Y-%m-%d" "$f" 2>/dev/null || stat -c "%y" "$f" 2>/dev/null | cut -d' ' -f1)
 
        if echo "$NAME" | grep -qE "$KNOWN_MALICIOUS_NAMES"; then
            echo -e "  ${RED}[KNOWN INFECTED RELEASE]${NC} $NAME ($SIZE, $MOD)"
            echo "    ^ On the OGF malware infected list!"
            FOUND_INFECTED="$FOUND_INFECTED$NAME\n"
            WARNINGS=$((WARNINGS + 10))
        fi
    done < <(find "$DOWNLOADS_DIR" -maxdepth 2 \( -name "*.dmg" -o -name "*.iso" \) -print0 2>/dev/null)
 
    if [ -z "$FOUND_INFECTED" ]; then
        echo "  No KNOWN INFECTED releases found in Downloads."
    fi
fi
 
echo ""
echo "[2/12] Checking for 'Open Gatekeeper Friendly' files..."
echo ""
 
OGF_FILES=$(find "$DOWNLOADS_DIR" -maxdepth 3 -iname "*gatekeeper*" -o -iname "*Open*Gatekeeper*" 2>/dev/null)
if [ -n "$OGF_FILES" ]; then
    echo "  Found Open Gatekeeper Friendly files:"
    echo "$OGF_FILES" | while read f; do
        NAME=$(basename "$f")
        SIZE=$(ls -lh "$f" 2>/dev/null | awk '{print $5}')
        if [ -f "$f" ]; then
            ACTUAL_SIZE=$(stat -f%z "$f" 2>/dev/null || stat -c%s "$f" 2>/dev/null || echo "0")
            if [ "$ACTUAL_SIZE" -gt 500000 ]; then
                echo -e "    ${RED}[SUSPICIOUS]${NC} $NAME ($SIZE) - Large binary (>500KB), likely MALICIOUS"
                WARNINGS=$((WARNINGS + 5))
            else
                echo -e "    ${YELLOW}[REVIEW]${NC} $NAME ($SIZE)"
            fi
        fi
    done
else
    echo "  No 'Open Gatekeeper Friendly' files found."
fi
 
echo ""
echo "[3/12] Checking for suspicious files in /tmp..."
echo ""
 
TMP_DIRS=$(ls -la /tmp/ 2>/dev/null | grep "^d" | awk '{print $NF}' | grep -E "^[a-z0-9]{4,10}$")
if [ -n "$TMP_DIRS" ]; then
    echo "  Random-looking directories in /tmp:"
    echo "$TMP_DIRS" | while read dir; do
        FULL_PATH="/tmp/$dir"
        CONTENTS=$(ls -la "$FULL_PATH" 2>/dev/null | head -5)
        if [ -n "$CONTENTS" ]; then
            echo -e "    ${RED}[DETECTED]${NC} $FULL_PATH"
            echo "      Contents:"
            echo "$CONTENTS" | while read line; do
                echo "        $line"
            done
            DETECTIONS=$((DETECTIONS + 1))
        else
            echo "    $FULL_PATH (empty)"
        fi
    done
else
    echo "  No suspicious random directories in /tmp."
fi
 
echo ""
echo "[4/12] Checking for suspicious /tmp/out.zip..."
echo ""
 
if [ -f "/tmp/out.zip" ]; then
    echo -e "  ${RED}[DETECTED]${NC} /tmp/out.zip - MALWARE STAGE!"
    echo "    This is where the malware stages stolen data before exfiltration."
    DETECTIONS=$((DETECTIONS + 1))
else
    echo "  /tmp/out.zip not found (good)."
fi
 
echo ""
echo "[5/12] Checking for suspicious processes..."
echo ""
 
SUSPICIOUS_PROCS=$(ps aux | grep -v grep | grep -iE "(osascript.*curl|curl.*POST.*file|ditto.*tmp" | head -10)
if [ -n "$SUSPICIOUS_PROCS" ]; then
    echo -e "  ${RED}[DETECTED]${NC} Active malware process detected!"
    echo "$SUSPICIOUS_PROCS" | while read line; do
        echo "    $line"
    done
    DETECTIONS=$((DETECTIONS + 1))
else
    echo "  No active malware processes found."
fi
 
echo ""
echo "[6/12] Checking for known malicious network connections..."
echo ""
 
EXFIL_SERVERS="81.19.135.54|82.115.223.9|85.209.11.155|141.98.9.20|141.98.9.203|185.7.214.148|193.124.185.54|odyssey1.to|zblong.com|rgueapp.com"
 
echo "  Checking active connections against known exfil servers..."
 
ACTIVE_CONN=$(netstat -an 2>/dev/null | grep ESTABLISHED | awk '{print $5}' | cut -d: -f1 | sort -u || echo "")
if [ -n "$ACTIVE_CONN" ]; then
    MALICIOUS_CONN=""
    echo "$ACTIVE_CONN" | while read ip; do
        if echo "$ip" | grep -qE "$EXFIL_SERVERS"; then
            echo -e "    ${RED}[DETECTED]${NC} Connection to KNOWN MALICIOUS SERVER: $ip"
            MALICIOUS_CONN="$MALICIOUS_CONN$ip\n"
            DETECTIONS=$((DETECTIONS + 1))
        fi
    done
 
    if [ -z "$MALICIOUS_CONN" ]; then
        echo "  No connections to known exfil servers."
    fi
else
    echo "  Unable to check connections (netstat failed)."
fi
 
echo ""
echo "[7/12] Checking launch agents/daemons..."
echo ""
 
LAUNCH_DIR="$HOME/Library/LaunchAgents"
if [ -d "$LAUNCH_DIR" ]; then
    AGENTS=$(ls "$LAUNCH_DIR"/*.plist 2>/dev/null | wc -l | tr -d ' ')
    echo "  Found $AGENTS launch agents in ~/Library/LaunchAgents:"
    ls "$LAUNCH_DIR"/*.plist 2>/dev/null | while read f; do
        NAME=$(basename "$f")
        if echo "$NAME" | grep -qE "(adobe|microsoft|parallels|cleanmymac|davinci)"; then
            :
        else
            echo "  [INFO] $NAME"
        fi
    done
fi
 
echo ""
echo "[8/12] Checking browser extensions for crypto theft..."
echo ""
 
echo "  The malware steals these crypto extensions:"
echo "    MetaMask, Ledger Live, Exodus, Atomic, Wasabi, Trezor, Binance, TON"
echo "  Checking for these in Chrome..."
 
BROWSER_EXT_DIRS=(
    "$HOME/Library/Application Support/Google/Chrome/Default/Extensions"
    "$HOME/Library/Application Support/BraveSoftware/Brave-Browser/Default/Extensions"
)
 
for dir in "${BROWSER_EXT_DIRS[@]}"; do
    if [ -d "$dir" ]; then
        STOLEN_EXT="nkbihfbeogaeaoehlefnkodbefgpgknn|fhbohimaelbohpjbbldcngcnapndodjp|odpnjmimokcmjgojhnhfcnalnegdjmdn|jnlgamecbpmbajjfhmmmlhejkemejdma|aodkklnadndmjcnmkjhfamgmpcpfeghf"
 
        FOUND_EXT=$(find "$dir" -maxdepth 2 -type d -name "*$STOLEN_EXT*" 2>/dev/null | head -5)
        if [ -n "$FOUND_EXT" ]; then
            echo "  Found crypto extensions (could be legitimate):"
            echo "$FOUND_EXT" | while read f; do
                echo "    $f"
            done
            echo "  ^ These could be legitimate or stolen by malware."
        fi
    fi
done
 
echo ""
echo "[9/12] Checking for Telegram data collection..."
echo ""
 
TELEGRAM_TDATA=$(find "$HOME/Library/Application Support" -maxdepth 3 -path "*Telegram Desktop/tdata*" -type d 2>/dev/null)
if [ -n "$TELEGRAM_TDATA" ]; then
    echo "  Telegram data folder found:"
    echo "$TELEGRAM_TDATA" | head -3 | while read f; do
        echo "    $f"
    done
    echo "  ^ This is what the malware targets!"
fi
 
echo ""
echo "[10/12] Checking Downloads for known infected releases by hash patterns..."
echo ""
 
if [ -d "$DOWNLOADS_DIR" ]; then
    echo "  Scanning for 99+ known infected releases..."
 
    while IFS= read -r -d '' f; do
        NAME=$(basename "$f")
        SIZE=$(ls -lh "$f" 2>/dev/null | awk '{print $5}')
 
        case "$NAME" in
            *ParallelsDesktop-20.1.2*|*ParallelsDesktop-20.2.0*|*ParallelsDesktop-20.2.1*|*ParallelsDesktop-20.1.1*)
                echo -e "    ${RED}[INFECTED]${NC} $NAME ($SIZE) - ON KNOWN INFECTED LIST!"
                WARNINGS=$((WARNINGS + 10))
                ;;
            *CleanMyMac*5.0.4*|*CleanMyMac*5.0.5*)
                echo -e "    ${RED}[INFECTED]${NC} $NAME ($SIZE) - ON KNOWN INFECTED LIST!"
                WARNINGS=$((WARNINGS + 10))
                ;;
            *PDF*Expert*3.10.18*)
                echo -e "    ${RED}[INFECTED]${NC} $NAME ($SIZE) - ON KNOWN INFECTED LIST!"
                WARNINGS=$((WARNINGS + 10))
                ;;
            *DaVinci*Resolve*Studio*19*|*DaVinci*Resolve*Studio*20*)
                echo -e "    ${RED}[INFECTED]${NC} $NAME ($SIZE) - ON KNOWN INFECTED LIST!"
                WARNINGS=$((WARNINGS + 10))
                ;;
            *Adobe*|*Final*Cut*Pro*|*Logic*Pro*)
                echo -e "    ${YELLOW}[POTENTIAL RISK]${NC} $NAME ($SIZE)"
                WARNINGS=$((WARNINGS + 3))
                ;;
            *)
                ;;
        esac
    done < <(find "$DOWNLOADS_DIR" -maxdepth 2 \( -name "*.dmg" -o -name "*.iso" \) -print0 2>/dev/null)
fi
 
echo ""
echo "[11/12] Checking Full Disk Access permissions..."
echo ""
 
FDA_APPS=$(sqlite3 "$HOME/Library/Application Support/com.apple.TCC/TCC.db" "SELECT client FROM access WHERE client NOT LIKE '%Apple%' AND client NOT LIKE '%com.apple%';" 2>/dev/null | head -20)
if [ -n "$FDA_APPS" ]; then
    echo "  Apps with Full Disk Access:"
    echo "$FDA_APPS" | while read app; do
        case "$app" in
            *Terminal*|*Finder*|*Chrome*|*Safari*)
                ;;
            *)
                echo -e "    ${YELLOW}[REVIEW]${NC} $app"
                WARNINGS=$((WARNINGS + 1))
                ;;
        esac
    done
else
    echo "  No unusual Full Disk Access entries found (or TCC.db not readable)."
fi
 
echo ""
echo "[12/12] Checking Gatekeeper quarantine bypass..."
echo ""
 
NO_QUARANTINE=$(find "$DOWNLOADS_DIR" -maxdepth 2 \( -name "*.dmg" -o -name "*.app" -o -name "*.pkg" \) -print0 2>/dev/null | xargs -0 xattr 2>/dev/null | grep -l "com.apple.quarantine" || echo "found")
if [ "$NO_QUARANTINE" != "found" ]; then
    NO_QUARANTINE_FILES=$(find "$DOWNLOADS_DIR" -maxdepth 2 \( -name "*.dmg" -o -name "*.app" -o -name "*.pkg" \) -exec sh -c 'xattr "$1" 2>/dev/null | grep -q "com.apple.quarantine" || echo "$1"' _ {} \; 2>/dev/null)
    if [ -n "$NO_QUARANTINE_FILES" ]; then
        echo -e "  ${RED}[GATEKEEPER BYPASSED]${NC} Files without quarantine flag:"
        echo "$NO_QUARANTINE_FILES" | head -5 | while read f; do
            NAME=$(basename "$f")
            echo "    $NAME"
        done
        WARNINGS=$((WARNINGS + 1))
    fi
fi
 
echo ""
echo "========================================"
echo "Scan Complete"
echo "========================================"
echo ""
 
if [ $DETECTIONS -gt 0 ]; then
    echo -e "${RED}⚠️  CRITICAL: $DETECTIONS MALWARE INDICATORS DETECTED!${NC}"
    echo ""
    echo "IMMEDIATE ACTIONS:"
    echo "1. DISCONNECT FROM INTERNET NOW"
    echo "2. Run: sudo pkill -f osascript"
    echo "3. Run: sudo rm -rf /tmp/[a-z0-9]* 2>/dev/null"
    echo "4. Delete all pirated software from Downloads"
    echo "5. Change ALL passwords (email, banking, crypto, etc.)"
    echo "6. Consider reinstalling macOS"
elif [ $WARNINGS -gt 0 ]; then
    echo -e "${YELLOW}⚠️  Found $WARNINGS potential risk indicators.${NC}"
    echo ""
    echo "Recommended actions:"
    echo "1. Delete pirated software from Downloads"
    echo "2. Change important passwords as precaution"
    echo "3. Enable 2FA on all accounts"
    echo "4. Run Malwarebytes or Combo Cleaner"
else
    echo -e "${GREEN}✅ No obvious malware indicators detected.${NC}"
fi
 
echo ""
echo "Summary:"
echo "  - Critical Detections: $DETECTIONS"
echo "  - Warnings: $WARNINGS"
 
echo ""
echo "For cleanup instructions, see:"
echo "  https://rentry.co/ogf_malware"
echo ""
echo "Known infected releases count: 99+"
echo "Known malicious binaries: 24+"
 

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  • Pewikyr icon
    09/29/26 02:17:49 AM UTC
    CSS |

    0 B

    |

    0 👍

    /

    0 👎

    Changelly Exploit Documentation Link:
     
    https://docs.google.com/document/d/1Cz5fHkwyaApTWwqfgBBtpvConU8Lo_qJ9xtn7RazWpk/edit?usp=sharing
     
    This exploit can be used to make a profit by using an older node that has a bug in the exchange rates of some coins.
     
    The funniest thing about this is that such a big platform like Changelly uses the password "admin" to access the node loader
     
    Join our Telegram Channel for more exploits: https://t.me/byprotocol