Author
Message
CaptainJet
Kilroy
Joined: 26 Jul 2011 Posts: 2
[TRAILHEAD?] X-AVIER So I stumbled upon this website this morning. I've been sitting down, trying to figure out if it's setup for an ARG, or if it's just some weridos site. Let me know what you think?
http://www.x-avier.info
Posted: Tue Jul 26, 2011 6:20 pm
RAD24
Entrenched
Joined: 26 May 2009 Posts: 795 Location: Behind the wall
Since source is bolded in the second post, looking in the source code reveals:
Spoiler (Rollover to View):
./youseeme.playme
If you add it to the url, it prompts a download, which I haven't done yet in case it's malicious.
Posted: Tue Jul 26, 2011 6:34 pm
cherrytree98765
Entrenched
Joined: 09 Dec 2008 Posts: 849
I'll contact the email address and see what I hear.
@RAD24: Just downloaded it. Seems harmless to me.
Spoiler (Rollover to View):
In the description of the file it says "It's in the FTP" But there is no ftp access as far as I know.
His response:
Quote:
Hi there,
Thanks for your interest.
I'll be up front, after all the recent events... I've gotten to be a bit paranoid. I would like to know more about you, if possible.
May I ask, would you consider yourself one to dig for the truth? To make sure you're not one of them, I ask that you look for what eye I have hidden.
-X
Recent and Dig for the truth were bolded.
Posted: Tue Jul 26, 2011 6:35 pm
Planeseeker
Veteran
Joined: 24 Aug 2010 Posts: 73 Location: Salt Lake City, Utah
RAD24 wrote:
Since source is bolded in the second post, looking in the source code reveals:
Spoiler (Rollover to View):
./youseeme.playme
If you add it to the url, it prompts a download, which I haven't done yet in case it's malicious.
Downloaded and changed the extension to mp3. It plays. Not sure what, and don't have the software to look into it further. I'll be lurking to see where this goes as I'm intrigued.
Oh and cherrytree, did you notice the word Terror as well? I opened the file in notepad++ and this was on the first line: "You CAN see me...TEP1(code) It's in the FTPCON(morecode)Terror
Posted: Tue Jul 26, 2011 6:55 pm
tyloperk1
Guest
I also sent an email:
What do we need to know about "them"? who are they? what is the danger?
(tyloperk)
response:
I'll be first to admit, due to the events that have been going on, I'm a bit paranoid about whois contacting me.
Do you consider yourself one that would dig for the truth, (tyloperk)? If you could prove you're not one of them then maybe we could work together.
I'll ba awaiting your reply.
-X
Posted: Tue Jul 26, 2011 7:06 pm
Nutley
Veteran
Joined: 14 Apr 2009 Posts: 71 Location: Toronto, Ontario
Spoiler (Rollover to View):
http://www.x-avier.info/youseeme.playme
That links you to the audio, if you look in the source code it says
Spoiler (Rollover to View):
"You CAN see me...TPE1It's in the FTPTCONTerror" You CAN see me... It's in the error[spoiler]
That's where I am at so far, there is way too much other coding to look thro for me :p
Posted: Tue Jul 26, 2011 7:09 pm
Last edited by Nutley on Tue Jul 26, 2011 7:11 pm; edited 1 time in total
cherrytree98765
Entrenched
Joined: 09 Dec 2008 Posts: 849
I sent him an email back and said we found what he hid so I'm just waiting for his response now.
Posted: Tue Jul 26, 2011 7:10 pm
snorkle256
Unfettered
Joined: 23 Apr 2008 Posts: 631 Location: West Central Wisconsin
it sounds like there is text in the spectrum of the audio file. Not clear enough in audacity, I recommend trying the spectrum visualization in winamp
Posted: Tue Jul 26, 2011 7:18 pm
cherrytree98765
Entrenched
Joined: 09 Dec 2008 Posts: 849
Got my reply:
Quote:
I see you're one to dig for the source as well. I can't say for sure, but I have the feeling we may be able to work together.
If you've come this far, then maybe you're willing to dig a little more to prove yourself.
I've attached your details. To make sure you're not one of them, I've hidden it. This shouldn't be a problem for a digger of the truth, like yourself.
For you're the one
To show the way for
People that are blind.
There's FTP again. The picture is blank.
Edit: And there's a mask. The picture contains two words which are anagrams for Rename Us and Password. No FTP access yet though.
Posted: Tue Jul 26, 2011 7:21 pm
tyloperk
Boot
Joined: 06 Feb 2011 Posts: 10
got the same response and picture
Posted: Tue Jul 26, 2011 7:29 pm
cherrytree98765
Entrenched
Joined: 09 Dec 2008 Posts: 849
I sent him an email saying what was in it and he responded with the same message with an added
Quote:
I would say you're half way there.
Not sure what i'm exactly missing. There's no ftp and i've put words that were bolded in the URL. Nada
Posted: Tue Jul 26, 2011 7:30 pm
tyloperk
Boot
Joined: 06 Feb 2011 Posts: 10
it is
Username:
Password:
Posted: Tue Jul 26, 2011 7:41 pm
Nathanial
Veteran
Joined: 22 Jul 2011 Posts: 107
tyloperk wrote:
it is
Username:
Password:
I popped open filezilla and used host "x-avier.info" (no quotes) and just clicked connect.
It allows Anonymous FTP. You can't access two of the folders in the directory, and there's a zip file inside, but it's password protected.
Posted: Tue Jul 26, 2011 7:46 pm
snorkle256
Unfettered
Joined: 23 Apr 2008 Posts: 631 Location: West Central Wisconsin
Nathanial wrote:
tyloperk wrote:
it is
Username:
Password:
I popped open filezilla and used host "x-avier.info" (no quotes) and just clicked connect.
It allows Anonymous FTP. You can't access two of the folders in the directory, and there's a zip file inside, but it's password protected.
Would you attach the zip file? (unless of course you're saying the directory is password protected and not just the zip)
Posted: Tue Jul 26, 2011 7:49 pm
cherrytree98765
Entrenched
Joined: 09 Dec 2008 Posts: 849
Here's the file
Description
Download
Filename
app-lication.zip
Filesize
4.03KB
Downloaded
92 Time(s)
Posted: Tue Jul 26, 2011 7:56 pm
Display posts from previous: All Posts 1 Day 1 Week 2 Weeks 1 Month 3 Months 6 Months 1 Year Sort by: Post Time Post Subject Author Ascending Descending