Poll

Which theria is your favorite?

Aetheria
30 (34.1%)
Etheria
58 (65.9%)

Total Members Voted: 88

Author Topic: Etheria & Aetheria  (Read 30266 times)


wtf is that
the fancy mystery solving clue things
like the mura thing

An alternate reality game.

It means OP is leaving a trail of encoded bread crumbs for us to follow. One puzzle leads to the next and so on.

i knew it would be an arg!!

List of ultimatum directories
http://i.imgur.com/xxxxxx.gif

Quote
P 4 i a B 3 R
6 A f Y o s X
C s x 5 o H l
G f l O 6 b
B l 4 O 5 s
5 a f l 1 a r
V r 9 5 R l r
« Last Edit: January 02, 2015, 09:37:29 PM by Darksaber2213 »

http://i.imgur.com/GflO6b.gif (only one that works dont bother trying the rest)

OP is just having an advertising campaign for MoviePack.
« Last Edit: January 02, 2015, 09:43:58 PM by Swat 3 »

Virustotal of the exe shows 4/56 results being a trojan. I aint runnin that stuff.
« Last Edit: January 02, 2015, 09:55:56 PM by Ipquarx »

I do have to say, this ARG was well timed. If this was done earlier last year people would just ignore it.

http://i.imgur.com/GflO6b.gif (only one that works dont bother trying the rest)

OP is just having an advertising campaign for MoviePack.
maybe the password is moviepack

EDIT: yeah, i'm getting no luck with this program he linked. it's just crashing when you type "You are not worthy." but anything else gives you an "incorrect password" thing

EDIT x2: wait, it's one word. anything with two words or more crashes the program
« Last Edit: January 02, 2015, 10:27:59 PM by Flame »

« Last Edit: January 03, 2015, 01:03:32 AM by Badspot »

OH stuff GUYS WAIT. Maybe it just closes without an "incorrect password" thing because it hid a text or image file on your computer!

OH stuff GUYS WAIT. Maybe it just closes without an "incorrect password" thing because it hid a text or image file on your computer!
Well, the virustotal of the exe file the readme links to is here: https://www.virustotal.com/en/file/a8ff1e82b45d5a0048e75be255eebbdc73b463bcd8d201ae1cb197539be1eb5a/brown townysis/1420253104/

It creates two files
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\ytmp\tmp33507.bat (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\ytmp\tmp95157.exe (successful)

and then runs them.

So yeah, no, i'm not running this stuff.


ff108Br77xx01

try it

EDIT: yep, it's the password.

It creates two files
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\ytmp\tmp33507.bat (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\ytmp\tmp95157.exe (successful)

and then runs them.

i opened the .bat in Notepad++ and stole the password from there (which probably isn't the legit way of doing so but oops) but hey it werks, no clue what the .exe is though. using the password and then the program on the "password.mdft" file decrypts it and writes a new file called "passwordDecrypted.mdft" containing this:

Quote from: passwordDecrypted.mdft
50617373776F72643A204266386D69397830306638

unfortunately, this is not the password to the file in the included songs.rar.

i don't think this is a virus, though.
« Last Edit: January 02, 2015, 10:47:02 PM by Flame »

Well, the virustotal of the exe file the readme links to is here: https://www.virustotal.com/en/file/a8ff1e82b45d5a0048e75be255eebbdc73b463bcd8d201ae1cb197539be1eb5a/brown townysis/1420253104/

It creates two files
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\ytmp\tmp33507.bat (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\ytmp\tmp95157.exe (successful)

and then runs them.

So yeah, no, i'm not running this stuff.
inb4 ARG is RAT.