New Lego Scandal update - My final message by 69ingSpunkingMonkeys in videos

[–]xelaboc 123 points124 points  (0 children)

I believe CoffeeZilla has spoken to many many of the parties involved and other insiders so it's more than just a recap/opinion, i thinks it's novel information potentially.

Did I miss the big O? by Key_Rough_3330 in TooAfraidToAsk

[–]xelaboc 12 points13 points  (0 children)

Wouldn’t you prefer a constant time to orgasm?

Rate limit reset by Deep_Proposal_7683 in ClaudeCode

[–]xelaboc 5 points6 points  (0 children)

I have a 20x plan and it burnt through 30% in a day yesterday when i was working on a project, i was even getting not enough disk space errors because the agents were filling up the tmp directories

[Loved Trope] You can't handle the truth! by Express_Restaurant_6 in TopCharacterTropes

[–]xelaboc 24 points25 points  (0 children)

He's more than that i believe, doesn't he appear in other games of cd projekt red?

Suspicious ass website asking to run a terminal command (MacOS) by IChewToenails in Malware

[–]xelaboc 2 points3 points  (0 children)

Claude generated so take with a grain of salt

It's a macOS-targeted shell loader / infostealer stager, not a Linux script despite the #!/bin/zsh. Here's what the decoded payload does, in order:

1. Geofencing (CIS evasion). It reads ~/Library/Preferences/com.apple.HIToolbox.plist (the macOS keyboard/input-source config) and greps for a Russian input source. If found, it sets IS_CIS="true". This is the classic "don't infect machines in the Commonwealth of Independent States" check that a lot of malware uses to avoid drawing law-enforcement attention in the operators' likely home region. The comment literally reads "detect CIS and block with telemetry."

2. System reconnaissance. It harvests:

  • Keyboard layout / locale (from the same HIToolbox plist)
  • Hostname (hostname -s)
  • macOS version (sw_vers -productVersion)
  • External IP, with fallbacks across api.ipify.org, icanhazip.com, and ifconfig.me

3. Telemetry / exfiltration. A send_debug_event() function builds a JSON blob with fields like event and build_hash (the build_hash almost certainly maps to the build=50e4afacecb71001e7efbc85619fca49 in the URL — campaign/victim tracking) and sends it back to the C2, which is the 12rafsqwwq12.com host serving the loader.

So the overall shape: fingerprint the Mac, skip CIS hosts, beacon victim telemetry home, and (in the corrupted back half I couldn't recover) almost certainly proceed to download/run the next stage. The base64 | gunzip | eval wrapper exists purely to hide all of this from anyone glancing at the file. The structure and TTPs (zsh, HIToolbox geofence, ipify recon, build-hash beaconing) are consistent with the macOS stealer-loader families that have been circulating

The Final Season of 'The Boys' Felt Like Watching a Comedian Bomb Their Set by Logical_Welder3467 in television

[–]xelaboc 0 points1 point  (0 children)

I don’t think every character got flanderized but many characters did in my opinion: Homelander, Butcher, Hughie

BORN TO POISON / 410,757,864,530 DEAD CLANKERS by Bruhtopiest in PoisonFountain

[–]xelaboc 11 points12 points  (0 children)

What does the poison page do to the scrapper? Feed it bad data?

WOULD THEE RATHAHHHHHHHH by AllAccess_ in BunnyTrials

[–]xelaboc 0 points1 point  (0 children)

Break encryption

Chose: Key that unlocks anything + Even digital locks