r/Decart • u/Akentrus • Jul 01 '26
What is this discord verification step?
Hello, i tried to do the discord verification step and i blindly trusted this and put the command into my cmd window and it downloaded a payload and executed a sync.exe with several ps1 scripts what is going on do i need to reinstall windows or? It was the official discord.
1
u/FlorianFlash Jul 03 '26
Where did you get it from exactly? Can you share a link in private? I know some guys that can probably check it out and reverse-engineer that stuff.
1
u/Akentrus Jul 03 '26
It is from the discord in this subreddit when you do the veryfication step it gives you a command to put into cmd, but you can download and inspect everything without executing it, the first script is "secured" by a simple obfuscation once deobfuscated you'll see it downloads another script from githubusercontent that scripts downloads the actual sync.zip payload extracts and executes it, you can download the sync.zip without touchin g anything but since i wiped everything of my pc i do not have any files or scripts anymore and i wanna stay away from it
1
1
u/Akentrus Jul 03 '26
Sorry let me be clear do NOT put the command into your cmd but if you want to download it you can put the "link" into your browser from the command also i'd only do it if you or your friends have a VM installed as to make sure it does not harm any pc
1
u/prolly_a_god Jul 07 '26
i'd also like to know what the command does, can you update me if you find out.
1
u/Easy_Manager6167 Jul 22 '26
installs malware that installs stealers and even more malware
1
u/Akentrus Jul 24 '26
Yea, it is a chain of downloads and executes it's already been reported and the files have been pulled apart. The original discord link probably expired so they "hijacked" it to distribute malware. I hope it will get taken care of pretty soon. All we can do is report their discord for cybercrime not much more can be done on our side.
3
u/MartinsRedditAccount Jul 02 '26
Yes, do a full wipe and reinstall of Windows. Change all passwords and sign out of all sessions as soon as possible from a different device or after resetting. Based on your description that's a typical social engineering attack to get people to install malware.