

I can’t sleep :(


I can’t sleep :(


Typosquat domain for sure! In a sandbox I’m seeing that all the download links point to the same HTML page on a .ink domain that cloudflare is now refusing to serve.
But our buddy joe already got a copy for us so we can at least view that report for fun: https://www.joesandbox.com/analysis/1763244/1/html
Edit: It pulls down an MSI installer or something it runs with msiexec but disguised with a PDF file extension. It seems to want a copy of cmd.exe to exist in an AutoIT installation (SearchPathW vs “C:\Program Files (x86)\AutoIt3\cmd.exe”) as well as pointing toward the multilanguage (.exe.mui) and other cmd variants. I suspect we’re one step away from a real payload with this report and that’s what we’d see the “Invoke-Obfuscation” powershell the sandbox spotted used for (if that wasn’t a false positive due to the base64 offset string).
You deserve your meds, and a treat for taking your meds.
If you microdose a breakdown by crying in a closet afterwards you get extra cooldown reduction.


DID I HEAR A ROCK AND STONE???


deleted by creator
It seems disproven, or perhaps only useful to some subset of people they haven’t pinpointed.
https://www.sciencedirect.com/science/article/pii/S0001691824001811
Honestly though if it helps someone they should ride that placebo as far as it takes them!
I genuinely think that being ranted at by my principal engineer early in my career and having to defend my ideas did more for my understanding and problem solving than any amount of explanation could have. Good faith disagreement is like a mirror that lets you see from perspectives you’d never have access to alone.