A forum for reverse engineering, OS internals and malware analysis 

All off-topic discussion goes here.
 #21096  by Xylitol
 Mon Oct 07, 2013 2:09 pm
Paunch, the coder of Blackhole exploit kit got arrested (and probably another one)
http://news.softpedia.com/news/BlackHol ... um=twitter
Confirmation from Kaspersky: https://twitter.com/dimitribest/status/ ... 7355060224

Hoax: https://twitter.com/Trojan7Sec/status/3 ... 6606577665
 #21125  by tim
 Tue Oct 08, 2013 7:40 pm
Europol have confirmed the arrest.

Who will take the throne from blackhole as the most distributed kit?
 #21133  by Xylitol
 Wed Oct 09, 2013 10:26 am
Europol haven't confirmed anything if you refer to this http://www.techweekeurope.co.uk/news/bl ... sia-128978 could be hoax, there is no official press release.
The only statement that Troels Oerting have made is about an article of Sophos https://twitter.com/TroelsOerting/statu ... 0376707072
 #21150  by EP_X0FF
 Thu Oct 10, 2013 2:04 pm
Now everyone wants Blackhole etc source leak I assume.
 #21402  by Xylitol
 Fri Nov 15, 2013 10:30 am
Alright apparently my tweet about paunch on dk was shit but nvm i'm back now and i understand the situation
Code: Select all
Paunch's Arrest & Darkode Post  Reply with quote
I've been keeping this a secret for awhile now, but the post that everyone was talking about on Paunch's account in russian roughly translated as "I will never go to jail, don't worry friends." was not posted by Paunch. I locked out his account after hearing of the potential arrest and used the post as a trap to catch any lingering security researchers. And they took the bait, hook line and sinker.

xylit0l had lied about being caught and was using zer0's account
A researcher known as Malpush was using Glazov's account
Arcore was none other than Touchme
I also removed two other users who leaked part of the forum: cr0ss and beta
Users who are still suspended include Sumad, Fallout, and Styler I am almost positive one of these accounts xylit0l had access to.

Shortly after the 'purge', brute force attacks begin against roughly 100 of the active users accounts. In order to prevent this I added back mafi's old ban hammer. If you experienced a message after signing out telling you to go sit in the corner it is because of said script (It still could use a few tweaks but working well with current settings only occasionally complains on sign-out).

I believe all of these sons of bitches are finally purged from darkode. Evidence support that is none of the 0day threads or recent big ticket items appeared anywhere. Finally, for the first time in months we can go about our business and not worry about these assfucks.

In the future, if you come across any part of a post, screenshot, text rather anything from darkode leaked anywhere please contact me immediately. Again as a warning to all users, if you leak anything even if it is a few words of copy-pasted text you will be banned. You will not be given a chance to explain yourself.