Prom3th3uS, a trusted user on TPB, is uploading torrents bundled with RATs.

I'm going to copy my report from TPB forums/report a torrent forum.

"Start11/Stardock from their upload page dropped a trojan that used screenconnect to attempt to call out and exfiltrate data. I just finished cleaning this up, it was dialing out to edgeserv.ru. This malware sat on my PC for almost a year before attempting to dial out, installed in 2025. It didnt start to dial out until june 21 2026 thankfully and i was able to catch it right away but man this was a close one.

You have a TRUSTED user uploading cracks with trojans bundled into them. Do you have any idea how messed up it is that a trusted user is allowed to upload trojans for over a year with impunity?

How many others got infected because a trusted user decided to bundle malware into their legitimate uploads with a trusted account on your platform?

You guys need to take action on this, they're still uploading files as of today. Still trusted status. Download the stardock/start11 torrent and scan the executables in virustotal and check the behavior pages, you'll see the same things i saw. I would do it for you but i don't want to redownload malware on purpose.

Long term user, this is the only thing that has ever actually gotten me infected with a RAT. They need their trusted status stripped, hopefully banned, and their uploads removed from your database.

Here's some extra stuff:

  1. Network / C2 Infrastructure

    C2 Domain: Code: edgeserv.ru C2 Destination IP: Code: 95.214.234.238 C2 Port: Code: 8041 (TCP) Traffic Pattern: Regular outbound beaconing/handshake attempts every 30 to 60 minutes initiated by background client services.

  2. Dropped Binaries & Masqueraded Paths

    Malicious Install Directory: Code: C:\Program Files (x86)\Windows VC
    (masquerading as Microsoft Visual C++) Dropped Executables: Code: ScreenConnect.ClientService.exe Code: ScreenConnect.WindowsClient.exe Service Name / Masquerade: ScreenConnect Client registered under the guise of "Visual C++" to persist across reboots under Code: LocalSystem / Code: SYSTEM privileges.

  3. Bundled Installer & Heuristic Detections

    Patch Binary: Code: ...\Stardock\Start11\x64-patch.exe (Flags as Code: HackTool:Win32/Keygen ) Cached Installer Artifact: Code: C:\Windows\Installer[random].msi Threat Classification: Code: Trojan:Win32/Malgent!MTB / Code: PUA:Win32/ConnectWise Attack Method: Abuse of legitimate remote management software (ScreenConnect/ConnectWise Control). The repackaged installer quietly provisions a persistent background service pointing to unauthorized third-party infrastructure ( Code: edgeserv.ru / Code: 95.214.234.238 ) during the cracked software setup."

TL;DR a trusted user is uploading malware bundled with software cracks, the malware tries to dial out to the above details. I got hit from stardock/Start11, but there are multiple reports on reddit in the various subreddits of people getting RATs from their cracks.

They were trusted at one point, but does that really matter if they're now bundling malware into their cracks? Their seed statistics on their most seeded torrents also look incredibly sus, they go from 100 to 1xxx and they all sit at around the same seed count.

If i had to guess, the original guy sold his account or got hacked and people have continued to upload malware bundled into their cracks since then on the account to abuse the trusted status icon.

Stay away from anything this user uploads, hopefully the mods on the site can remove their status and torrents.

Edit: virustotal links/behavior, Main installer EXE- https://www.virustotal.com/gui/file/360455f3671b766a683b56dfc825fb3355b538cc1f1b8391a1b22e19f07d2f27/behavior

Secondary patch- https://www.virustotal.com/gui/file/ccbe694ce564c5c8bbcd6922693c7001dd774381ece53ca3f787ec652f32a64b/detection

Main installer is the infected one, you can see it under the behavior tab. You'll see edgeserv.ru as the C2 server, the patch is just included on my post to be thorough so im linking it here, too.

reddit.com
u/venatic — 6 days ago

My experience with Brixadi (Buprenorphine monthly shot) and the jump off of it

To give some background information, i started taking suboxone in 2013. It was intermittent at first but eventually evolved into daily use. In 2016 I started treatment (basically going from buying bupe on the street to getting an rx for it) and was put on 16mg daily.

I was on that 16mg daily until 2023, when i switched to brixadi because i had a wedding coming up and i didn't want to have to worry about tablets etc during it, like having to sneak off to let a tablet dissolve under my tongue. I stuck with the brixadi shot from 2023 until earlier this year.

Started at 128mg/month, worked my way down to 30mg/month which is about 1.5-2mg/day oral equivalent of tablets.

I have tried to quit multiple times over the years and it never stuck for more than a few weeks. It's been two months now and the worst withdrawal symptoms i noticed were general apathy/exhaustion. Two months later, i'm feeling pretty damn normal.

The reason I'm sharing this is because the brixadi shot is what allowed me to finally jump off completely. Getting rid of the tablet routine was a huge factor in all of this. When i've tried to quit in the past, there was almost a psychological compulsion to take the tablet out of routine. The monthly shot allowed me to end that routine.

For anyone looking to jump off of suboxone, i would highly recommend switching to the brixadi shot. Breaking the psychological routine of taking the tablets and having them linked to how you feel was key for me. The shot is flexible enough where you can get down to a sub 1mg daily dose of bupe over time while also removing the psychological component of the tablets.

I was expecting to be out of commission for weeks but it's been gentle af lol, the only thing i take occasionally is gabapentin, maybe 1/2 a 600mg every other day.

tl;dr if you're having a hard time quitting bupe, consider switching from tablets/films to the shot and reducing your dose gradually over months until you get to the point where the doctor is squirting 3/4 of the shot into the trash before they give you it. At that point, jumping off is mostly psychological. You also have the added bonus of the shot being its own taper. When you discontinue it, there's a depot of medicine in your arm still that slowly releases itself over a week or two and makes it more of a gradual drop vs dosing with tablets where your blood levels of buprenorphine will vary wildly on the taper throughout the day.

I hope this helps someone out there, i wish i would've been aware of the shot earlier because it's a literal game changer for addiction treatment.

reddit.com
u/venatic — 1 month ago

Another Talisman theory

After sitting down and taking a good look at the talismans, i think it's staring us in the face. The meaning isn't that deep at all. When you look at it, what do you see? A circular barricade of runic-looking symbols, then something representing the sun/moon/some form of cycle like that. Then, right in the middle, you have two people. who look like they could be sleeping.

So, what does this mean? Let's look at this literally. The runic symbols are forming a ring around the center symbols, with a daytime-nighttime cycle set at the next level inwards, then finally you have two people who are splayed out.

This, to me, appears to be saying "this protects humans at night" or, "humans are safe within a boundary at night with this talisman hung up". We know the talismans rely on a physical boundary like a door or window, i think it's literal.

u/venatic — 2 months ago

AC Valhalla crackfix for windows 11, DODI/EMPRESS repack fix

I spent the last 2 hours trying to figure out how to launch this game on a modern system, tried everything. all the normal suspects. nothing. I ended up finding a link to a google drive with a replacement dll file. I dragged and dropped it and it worked and i don't want this to be lost to future generations.

Symptoms- When you launch the game exe as admin, you get the splash screen for a second then it vanishes with no error

Solution- Drop this dll over the existing one.

Windows 11 d3dcompiler_47.dll, replace the existing d3dcompiler_47.dll with the new one and launch as administrator.

I'm pretty sure this is the same file dodi had on his site under >Windows 11 24H2 Crackfix skystar

The link on his site no longer works, this is a mirror of that one.

https://drive.google.com/file/d/1kvDmAH70LEfKStTXLLXpzfNacTPm6Hdi/view?usp=sharing

Hope this helps someone down the line!

reddit.com
u/venatic — 2 months ago

Got billed triple my monthly payment by mistake and the customer service rep hung up on me. WTF?

I've used spectrum for 2 years and i've had 0 issues until today. I woke up, got ready, went to get groceries, and got to the store and tried to pay out of my checking account only for it to get DECLINED IN THE STORE. I had to go through my banking app to figure out where my money went.

Turns out spectrum billed me for a in house visit that never took place, they had no record of me calling, nothing, but i still got billed triple my monthly payment. Now the reps are telling me it's gonna take 7-10 days to return the money spectrum literally stole from me.

How can this even happen? How can my account get billed when i never authorized anything? Isn't this the entire reason we have PINs when we call in?

For real, spectrum, what the f??? You left me sitting there at the checkout with my dick swinging in the wind and a cart full of groceries i couldn't pay for.

Can SOMEONE PLEASE CONTACT ME FROM YOUR SUPPORT TEAM? I never thought i'd have to get customer service from a subreddit, but here we are..

This is ridiculous. How are you going to take my literal lunch money, then make me wait 7-10 days because YOU GUYS SCREWED UP?? AND HOW WAS THIS POSSIBLE?? I REITERATE, I WAS NEVER ASKED FOR MY PIN FOR THE CHARGE. Y'all just slapped it on my account.

reddit.com
u/venatic — 2 months ago
▲ 226 r/diablo4

I've been running some pits after finishing the new campaign and the mob density is 1/2 what it was last season. Probably less. It definitely feels like less. What used to be 2-3 minute pit runs are now 3-5 for no reason other than you have to spend more time hunting mobs to kill to fill the bar up.

It's not just one map, it's every last map available. Why was everything else this season a big step forward but this was two steps back? Does blizzard think we enjoy backtracking and spending more time to do the same content as last season?

This is a big L, which is contrasted by all the W's blizz has had with this season's launch. Whoever suggested this change needs to get yeeted out of a 10th floor office window.

All i want to do in my ARPG demon slaying game is slay demons. I don't want to spend 10 seconds hunting down every pack, i don't want to backtrack because i got sent down some path with 2 packs on it, I WANT TO SMASH. WHY BLIZZARD NO LET SMASH?

reddit.com
u/venatic — 4 months ago
▲ 30 r/LilyGO

I was lucky enough to be able to get my hands on one of these thanks to the lilygo team and I've had around a week to play with the hardware. This is my take so far on the unit.

  • The form factor is amazing for EDC.
  • The solar panel is great, this thing sips power so expect your battery to last 5+ days.
  • The OLED screen is a very nice addition to what are typically headless units in this form factor.
  • The IP66 rating means you don't have to worry if it starts to drizzle on you while hiking. The assembly is very solid, they use a gasket when assembling the unit that is still waterproof after pulling it apart and putting it back together.
  • The magnetic usb connector requires you to carry a specialized USB cable with you while out in the field. Having to carry around a special cable for something meant for an EDC/ruggedized unit seems like an oversight. There are USB-C waterproof connectors with covers on them that would be a better alternative imo.

Overall, for what it is, it's a very impressive little piece of hardware. I cannot wait for meshtastic to roll out some firmware for this device. This is something you can clip on your backpack and go camping for a weekend and never worry about getting lost or it dying on you or getting fried due to some morning dew.

If we're comparing it to similar form factor units, the biggest upgrade over existing ones is the integration of solar and a (tiny) OLED. You'll be able to read your meshtastic messages without having to pair over BLE. That means you can grab it off your backpack and read the screen instead of having to go through another device to read a message.

8/10 hardware. The nrf based architecture consumes so much less power than an esp32 based unit. If this thing had a standardized USB connection I'd raise that to a 9/10.

u/venatic — 4 months ago