Skip to content

Commit e13579e

Browse files
author
lockness-Ko
committed
fix: add thanks
1 parent a4f2747 commit e13579e

17 files changed

+64
-60
lines changed
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
import{_ as r}from"./_page-f0d532c0.js";import{default as t}from"../components/pages/blog/_id_/_page.svelte-42a2a7e6.js";export{t as component,r as shared};
1+
import{_ as r}from"./_page-886adf02.js";import{default as t}from"../components/pages/blog/_id_/_page.svelte-42a2a7e6.js";export{t as component,r as shared};

docs/_app/immutable/chunks/_page-f0d532c0.js renamed to docs/_app/immutable/chunks/_page-886adf02.js

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

docs/_app/immutable/chunks/cs2_malware-26976645.js

Lines changed: 10 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

docs/_app/immutable/chunks/cs2_malware-4defdaa3.js

Lines changed: 0 additions & 8 deletions
This file was deleted.
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
import"../../../../chunks/preload-helper-9b728935.js";import{l}from"../../../../chunks/_page-f0d532c0.js";export{l as load};
1+
import"../../../../chunks/preload-helper-9b728935.js";import{l}from"../../../../chunks/_page-886adf02.js";export{l as load};

docs/_app/immutable/start-819b5f8f.js renamed to docs/_app/immutable/start-6517c1bc.js

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

docs/_app/version.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
{"version":"1730672550046"}
1+
{"version":"1730672604860"}

docs/about.html

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212

1313
<meta http-equiv="content-security-policy" content="">
1414
<link href="./_app/immutable/assets/_layout-6a01c3f4.css" rel="stylesheet">
15-
<link rel="modulepreload" href="./_app/immutable/start-819b5f8f.js">
15+
<link rel="modulepreload" href="./_app/immutable/start-6517c1bc.js">
1616
<link rel="modulepreload" href="./_app/immutable/chunks/index-104dd4d8.js">
1717
<link rel="modulepreload" href="./_app/immutable/chunks/singletons-9faa82f1.js">
1818
<link rel="modulepreload" href="./_app/immutable/chunks/preload-helper-9b728935.js">
@@ -41,7 +41,7 @@
4141

4242

4343
<script type="module" data-sveltekit-hydrate="uds5li">
44-
import { start } from "./_app/immutable/start-819b5f8f.js";
44+
import { start } from "./_app/immutable/start-6517c1bc.js";
4545

4646
start({
4747
env: {},
@@ -56,7 +56,7 @@
5656
},
5757
paths: {"base":"","assets":""},
5858
target: document.querySelector('[data-sveltekit-hydrate="uds5li"]').parentNode,
59-
version: "1730672550046"
59+
version: "1730672604860"
6060
});
6161
</script>
6262
</div>

docs/blog.html

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212

1313
<meta http-equiv="content-security-policy" content="">
1414
<link href="./_app/immutable/assets/_layout-6a01c3f4.css" rel="stylesheet">
15-
<link rel="modulepreload" href="./_app/immutable/start-819b5f8f.js">
15+
<link rel="modulepreload" href="./_app/immutable/start-6517c1bc.js">
1616
<link rel="modulepreload" href="./_app/immutable/chunks/index-104dd4d8.js">
1717
<link rel="modulepreload" href="./_app/immutable/chunks/singletons-9faa82f1.js">
1818
<link rel="modulepreload" href="./_app/immutable/chunks/preload-helper-9b728935.js">
@@ -57,7 +57,7 @@
5757

5858

5959
<script type="module" data-sveltekit-hydrate="rh4anq">
60-
import { start } from "./_app/immutable/start-819b5f8f.js";
60+
import { start } from "./_app/immutable/start-6517c1bc.js";
6161

6262
start({
6363
env: {},
@@ -72,7 +72,7 @@
7272
},
7373
paths: {"base":"","assets":""},
7474
target: document.querySelector('[data-sveltekit-hydrate="rh4anq"]').parentNode,
75-
version: "1730672550046"
75+
version: "1730672604860"
7676
});
7777
</script>
7878
<script type="application/json" data-sveltekit-fetched data-url="/api/posts">{"status":200,"statusText":"","headers":{},"body":"[{\"meta\":{\"title\":\"CS2 Malware Announcement\",\"date\":\"2024-11-03\"},\"path\":\"/blog/cs2_malware\"},{\"meta\":{\"title\":\"Malware madness\",\"date\":\"2023-4-24\"},\"path\":\"/blog/more_malware\"},{\"meta\":{\"title\":\"Malware analysis/Honepot stuff.\",\"date\":\"2022-5-5\"},\"path\":\"/blog/malware\"},{\"meta\":{\"title\":\"OP1 firmware reverse engineering\",\"date\":\"sometime\"},\"path\":\"/blog/op1\"}]"}</script></div>

docs/blog/cs2_malware.html

Lines changed: 9 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -13,16 +13,16 @@
1313
<meta http-equiv="content-security-policy" content="">
1414
<link href="../_app/immutable/assets/_layout-6a01c3f4.css" rel="stylesheet">
1515
<link href="../_app/immutable/assets/_page-cc4ed907.css" rel="stylesheet">
16-
<link rel="modulepreload" href="../_app/immutable/start-819b5f8f.js">
16+
<link rel="modulepreload" href="../_app/immutable/start-6517c1bc.js">
1717
<link rel="modulepreload" href="../_app/immutable/chunks/index-104dd4d8.js">
1818
<link rel="modulepreload" href="../_app/immutable/chunks/singletons-9faa82f1.js">
1919
<link rel="modulepreload" href="../_app/immutable/chunks/preload-helper-9b728935.js">
2020
<link rel="modulepreload" href="../_app/immutable/components/pages/_layout.svelte-85bcf2f0.js">
2121
<link rel="modulepreload" href="../_app/immutable/modules/pages/_layout.ts-b8ee4d7c.js">
2222
<link rel="modulepreload" href="../_app/immutable/chunks/_layout-1daba58d.js">
2323
<link rel="modulepreload" href="../_app/immutable/components/pages/blog/_id_/_page.svelte-42a2a7e6.js">
24-
<link rel="modulepreload" href="../_app/immutable/modules/pages/blog/_id_/_page.ts-1161bc9e.js">
25-
<link rel="modulepreload" href="../_app/immutable/chunks/_page-f0d532c0.js">
24+
<link rel="modulepreload" href="../_app/immutable/modules/pages/blog/_id_/_page.ts-9c2026a4.js">
25+
<link rel="modulepreload" href="../_app/immutable/chunks/_page-886adf02.js">
2626
</head>
2727
<body>
2828
<div style="display: contents">
@@ -44,7 +44,8 @@ <h2>UPDATE!!!</h2>
4444
<p>04/11
4545
We’ve discovered it persists in people’s Exodus wallets by using DLL Search-order hijacking.
4646
This DLL will be at <code>%LOCALAPPDATA%\exodus\app-24.41.6\profapi.dll</code>, or a similar <code>app-</code> directory.
47-
To remove the persistence, remove this file</p>
47+
To remove the persistence, remove this file
48+
<strong>Thanks to cayenne6561 for finding this!</strong></p>
4849
<h2>What we know</h2>
4950
<p><strong>Key Points</strong></p>
5051
<ul><li>The malware is an Exodus Wallet Stealer, <strong>which we are calling ExoTickler</strong>.</li>
@@ -87,8 +88,8 @@ <h2>FAQ</h2>
8788
</main>
8889

8990

90-
<script type="module" data-sveltekit-hydrate="re92r1">
91-
import { start } from "../_app/immutable/start-819b5f8f.js";
91+
<script type="module" data-sveltekit-hydrate="1nt1xr2">
92+
import { start } from "../_app/immutable/start-6517c1bc.js";
9293

9394
start({
9495
env: {},
@@ -102,8 +103,8 @@ <h2>FAQ</h2>
102103
form: null
103104
},
104105
paths: {"base":"","assets":""},
105-
target: document.querySelector('[data-sveltekit-hydrate="re92r1"]').parentNode,
106-
version: "1730672550046"
106+
target: document.querySelector('[data-sveltekit-hydrate="1nt1xr2"]').parentNode,
107+
version: "1730672604860"
107108
});
108109
</script>
109110
</div>

docs/blog/malware.html

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -13,16 +13,16 @@
1313
<meta http-equiv="content-security-policy" content="">
1414
<link href="../_app/immutable/assets/_layout-6a01c3f4.css" rel="stylesheet">
1515
<link href="../_app/immutable/assets/_page-cc4ed907.css" rel="stylesheet">
16-
<link rel="modulepreload" href="../_app/immutable/start-819b5f8f.js">
16+
<link rel="modulepreload" href="../_app/immutable/start-6517c1bc.js">
1717
<link rel="modulepreload" href="../_app/immutable/chunks/index-104dd4d8.js">
1818
<link rel="modulepreload" href="../_app/immutable/chunks/singletons-9faa82f1.js">
1919
<link rel="modulepreload" href="../_app/immutable/chunks/preload-helper-9b728935.js">
2020
<link rel="modulepreload" href="../_app/immutable/components/pages/_layout.svelte-85bcf2f0.js">
2121
<link rel="modulepreload" href="../_app/immutable/modules/pages/_layout.ts-b8ee4d7c.js">
2222
<link rel="modulepreload" href="../_app/immutable/chunks/_layout-1daba58d.js">
2323
<link rel="modulepreload" href="../_app/immutable/components/pages/blog/_id_/_page.svelte-42a2a7e6.js">
24-
<link rel="modulepreload" href="../_app/immutable/modules/pages/blog/_id_/_page.ts-1161bc9e.js">
25-
<link rel="modulepreload" href="../_app/immutable/chunks/_page-f0d532c0.js">
24+
<link rel="modulepreload" href="../_app/immutable/modules/pages/blog/_id_/_page.ts-9c2026a4.js">
25+
<link rel="modulepreload" href="../_app/immutable/chunks/_page-886adf02.js">
2626
</head>
2727
<body>
2828
<div style="display: contents">
@@ -67,7 +67,7 @@ <h2>&gt; Mirai sample - 5/5/22</h2>
6767

6868

6969
<script type="module" data-sveltekit-hydrate="14vnhgt">
70-
import { start } from "../_app/immutable/start-819b5f8f.js";
70+
import { start } from "../_app/immutable/start-6517c1bc.js";
7171

7272
start({
7373
env: {},
@@ -82,7 +82,7 @@ <h2>&gt; Mirai sample - 5/5/22</h2>
8282
},
8383
paths: {"base":"","assets":""},
8484
target: document.querySelector('[data-sveltekit-hydrate="14vnhgt"]').parentNode,
85-
version: "1730672550046"
85+
version: "1730672604860"
8686
});
8787
</script>
8888
</div>

docs/blog/more_malware.html

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -13,16 +13,16 @@
1313
<meta http-equiv="content-security-policy" content="">
1414
<link href="../_app/immutable/assets/_layout-6a01c3f4.css" rel="stylesheet">
1515
<link href="../_app/immutable/assets/_page-cc4ed907.css" rel="stylesheet">
16-
<link rel="modulepreload" href="../_app/immutable/start-819b5f8f.js">
16+
<link rel="modulepreload" href="../_app/immutable/start-6517c1bc.js">
1717
<link rel="modulepreload" href="../_app/immutable/chunks/index-104dd4d8.js">
1818
<link rel="modulepreload" href="../_app/immutable/chunks/singletons-9faa82f1.js">
1919
<link rel="modulepreload" href="../_app/immutable/chunks/preload-helper-9b728935.js">
2020
<link rel="modulepreload" href="../_app/immutable/components/pages/_layout.svelte-85bcf2f0.js">
2121
<link rel="modulepreload" href="../_app/immutable/modules/pages/_layout.ts-b8ee4d7c.js">
2222
<link rel="modulepreload" href="../_app/immutable/chunks/_layout-1daba58d.js">
2323
<link rel="modulepreload" href="../_app/immutable/components/pages/blog/_id_/_page.svelte-42a2a7e6.js">
24-
<link rel="modulepreload" href="../_app/immutable/modules/pages/blog/_id_/_page.ts-1161bc9e.js">
25-
<link rel="modulepreload" href="../_app/immutable/chunks/_page-f0d532c0.js">
24+
<link rel="modulepreload" href="../_app/immutable/modules/pages/blog/_id_/_page.ts-9c2026a4.js">
25+
<link rel="modulepreload" href="../_app/immutable/chunks/_page-886adf02.js">
2626
</head>
2727
<body>
2828
<div style="display: contents">
@@ -91,7 +91,7 @@ <h2>Tor Shenanigans</h2>
9191

9292

9393
<script type="module" data-sveltekit-hydrate="13i6clz">
94-
import { start } from "../_app/immutable/start-819b5f8f.js";
94+
import { start } from "../_app/immutable/start-6517c1bc.js";
9595

9696
start({
9797
env: {},
@@ -106,7 +106,7 @@ <h2>Tor Shenanigans</h2>
106106
},
107107
paths: {"base":"","assets":""},
108108
target: document.querySelector('[data-sveltekit-hydrate="13i6clz"]').parentNode,
109-
version: "1730672550046"
109+
version: "1730672604860"
110110
});
111111
</script>
112112
</div>

docs/blog/op1.html

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -13,16 +13,16 @@
1313
<meta http-equiv="content-security-policy" content="">
1414
<link href="../_app/immutable/assets/_layout-6a01c3f4.css" rel="stylesheet">
1515
<link href="../_app/immutable/assets/_page-cc4ed907.css" rel="stylesheet">
16-
<link rel="modulepreload" href="../_app/immutable/start-819b5f8f.js">
16+
<link rel="modulepreload" href="../_app/immutable/start-6517c1bc.js">
1717
<link rel="modulepreload" href="../_app/immutable/chunks/index-104dd4d8.js">
1818
<link rel="modulepreload" href="../_app/immutable/chunks/singletons-9faa82f1.js">
1919
<link rel="modulepreload" href="../_app/immutable/chunks/preload-helper-9b728935.js">
2020
<link rel="modulepreload" href="../_app/immutable/components/pages/_layout.svelte-85bcf2f0.js">
2121
<link rel="modulepreload" href="../_app/immutable/modules/pages/_layout.ts-b8ee4d7c.js">
2222
<link rel="modulepreload" href="../_app/immutable/chunks/_layout-1daba58d.js">
2323
<link rel="modulepreload" href="../_app/immutable/components/pages/blog/_id_/_page.svelte-42a2a7e6.js">
24-
<link rel="modulepreload" href="../_app/immutable/modules/pages/blog/_id_/_page.ts-1161bc9e.js">
25-
<link rel="modulepreload" href="../_app/immutable/chunks/_page-f0d532c0.js">
24+
<link rel="modulepreload" href="../_app/immutable/modules/pages/blog/_id_/_page.ts-9c2026a4.js">
25+
<link rel="modulepreload" href="../_app/immutable/chunks/_page-886adf02.js">
2626
</head>
2727
<body>
2828
<div style="display: contents">
@@ -74,7 +74,7 @@ <h3>&gt; random interesting things</h3>
7474

7575

7676
<script type="module" data-sveltekit-hydrate="torf3j">
77-
import { start } from "../_app/immutable/start-819b5f8f.js";
77+
import { start } from "../_app/immutable/start-6517c1bc.js";
7878

7979
start({
8080
env: {},
@@ -89,7 +89,7 @@ <h3>&gt; random interesting things</h3>
8989
},
9090
paths: {"base":"","assets":""},
9191
target: document.querySelector('[data-sveltekit-hydrate="torf3j"]').parentNode,
92-
version: "1730672550046"
92+
version: "1730672604860"
9393
});
9494
</script>
9595
</div>

docs/contact.html

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212

1313
<meta http-equiv="content-security-policy" content="">
1414
<link href="./_app/immutable/assets/_layout-6a01c3f4.css" rel="stylesheet">
15-
<link rel="modulepreload" href="./_app/immutable/start-819b5f8f.js">
15+
<link rel="modulepreload" href="./_app/immutable/start-6517c1bc.js">
1616
<link rel="modulepreload" href="./_app/immutable/chunks/index-104dd4d8.js">
1717
<link rel="modulepreload" href="./_app/immutable/chunks/singletons-9faa82f1.js">
1818
<link rel="modulepreload" href="./_app/immutable/chunks/preload-helper-9b728935.js">
@@ -46,7 +46,7 @@
4646

4747

4848
<script type="module" data-sveltekit-hydrate="1qzjl2b">
49-
import { start } from "./_app/immutable/start-819b5f8f.js";
49+
import { start } from "./_app/immutable/start-6517c1bc.js";
5050

5151
start({
5252
env: {},
@@ -61,7 +61,7 @@
6161
},
6262
paths: {"base":"","assets":""},
6363
target: document.querySelector('[data-sveltekit-hydrate="1qzjl2b"]').parentNode,
64-
version: "1730672550046"
64+
version: "1730672604860"
6565
});
6666
</script>
6767
</div>

docs/index.html

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212

1313
<meta http-equiv="content-security-policy" content="">
1414
<link href="./_app/immutable/assets/_layout-6a01c3f4.css" rel="stylesheet">
15-
<link rel="modulepreload" href="./_app/immutable/start-819b5f8f.js">
15+
<link rel="modulepreload" href="./_app/immutable/start-6517c1bc.js">
1616
<link rel="modulepreload" href="./_app/immutable/chunks/index-104dd4d8.js">
1717
<link rel="modulepreload" href="./_app/immutable/chunks/singletons-9faa82f1.js">
1818
<link rel="modulepreload" href="./_app/immutable/chunks/preload-helper-9b728935.js">
@@ -46,7 +46,7 @@ <h2>Facts about this website:</h2>
4646

4747

4848
<script type="module" data-sveltekit-hydrate="fhbj5c">
49-
import { start } from "./_app/immutable/start-819b5f8f.js";
49+
import { start } from "./_app/immutable/start-6517c1bc.js";
5050

5151
start({
5252
env: {},
@@ -61,7 +61,7 @@ <h2>Facts about this website:</h2>
6161
},
6262
paths: {"base":"","assets":""},
6363
target: document.querySelector('[data-sveltekit-hydrate="fhbj5c"]').parentNode,
64-
version: "1730672550046"
64+
version: "1730672604860"
6565
});
6666
</script>
6767
</div>

docs/vite-manifest.json

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"node_modules/@sveltejs/kit/src/runtime/client/start.js": {
3-
"file": "_app/immutable/start-819b5f8f.js",
3+
"file": "_app/immutable/start-6517c1bc.js",
44
"src": "node_modules/@sveltejs/kit/src/runtime/client/start.js",
55
"isEntry": true,
66
"imports": [
@@ -98,12 +98,12 @@
9898
]
9999
},
100100
"src/routes/blog/[id]/+page.ts": {
101-
"file": "_app/immutable/modules/pages/blog/_id_/_page.ts-1161bc9e.js",
101+
"file": "_app/immutable/modules/pages/blog/_id_/_page.ts-9c2026a4.js",
102102
"src": "src/routes/blog/[id]/+page.ts",
103103
"isEntry": true,
104104
"imports": [
105105
"_preload-helper-9b728935.js",
106-
"__page-f0d532c0.js"
106+
"__page-886adf02.js"
107107
]
108108
},
109109
"_singletons-9faa82f1.js": {
@@ -124,8 +124,8 @@
124124
"__page-69b2005d.js": {
125125
"file": "_app/immutable/chunks/_page-69b2005d.js"
126126
},
127-
"__page-f0d532c0.js": {
128-
"file": "_app/immutable/chunks/_page-f0d532c0.js",
127+
"__page-886adf02.js": {
128+
"file": "_app/immutable/chunks/_page-886adf02.js",
129129
"imports": [
130130
"_preload-helper-9b728935.js"
131131
],
@@ -179,11 +179,11 @@
179179
]
180180
},
181181
".svelte-kit/generated/nodes/5.js": {
182-
"file": "_app/immutable/chunks/5-b5fa75c5.js",
182+
"file": "_app/immutable/chunks/5-06233c3b.js",
183183
"src": ".svelte-kit/generated/nodes/5.js",
184184
"isDynamicEntry": true,
185185
"imports": [
186-
"__page-f0d532c0.js",
186+
"__page-886adf02.js",
187187
"src/routes/blog/[id]/+page.svelte"
188188
]
189189
},
@@ -196,7 +196,7 @@
196196
]
197197
},
198198
"src/routes/blog/cs2_malware.md": {
199-
"file": "_app/immutable/chunks/cs2_malware-4defdaa3.js",
199+
"file": "_app/immutable/chunks/cs2_malware-26976645.js",
200200
"src": "src/routes/blog/cs2_malware.md",
201201
"isDynamicEntry": true,
202202
"imports": [
@@ -227,12 +227,12 @@
227227
"_index-104dd4d8.js"
228228
]
229229
},
230-
"src/routes/blog/[id]/+page.css": {
231-
"file": "_app/immutable/assets/_page-cc4ed907.css",
232-
"src": "src/routes/blog/[id]/+page.css"
233-
},
234230
"src/routes/+layout.css": {
235231
"file": "_app/immutable/assets/_layout-6a01c3f4.css",
236232
"src": "src/routes/+layout.css"
233+
},
234+
"src/routes/blog/[id]/+page.css": {
235+
"file": "_app/immutable/assets/_page-cc4ed907.css",
236+
"src": "src/routes/blog/[id]/+page.css"
237237
}
238238
}

src/routes/blog/cs2_malware.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@ date: "2024-11-03"
1313
We've discovered it persists in people's Exodus wallets by using DLL Search-order hijacking.
1414
This DLL will be at `%LOCALAPPDATA%\exodus\app-24.41.6\profapi.dll`, or a similar `app-` directory.
1515
To remove the persistence, remove this file
16+
**Thanks to cayenne6561 for finding this!**
1617

1718
## What we know
1819

0 commit comments

Comments
 (0)