Skip to content

Instantly share code, notes, and snippets.

View Gi7w0rm's full-sized avatar

Gi7w0rm

View GitHub Profile
@Gi7w0rm
Gi7w0rm / XXXBlyatRAT.osescript
Created February 26, 2026 15:14
ClearFake's XXXBylat Rat for MacOS
run script ""
set app_id to "xxxblyat"
-- Read file contents
on readFile(filePath)
try
set fileContents to read filePath
return fileContents
end try
return ""

This is a MEV (Maximal Extractable Value) bot contract designed to perform sandwich attacks and arbitrage on decentralized exchanges. Here's a breakdown of what it does:

Key Components:

Owner & Access Control

  • Owner: 0x6c8ec8f14be7c01672d31cfa5f2cefeab2562b50
  • Target DEX: 0x764c64b2a09b09acb100b80d8c505aa6a0302ef2 (likely a DEX router)
  • Token: 0xf65b5c5104c4fafd4b709d9d60a185eae063276c (token being traded)

Main Attack Functions:

@Gi7w0rm
Gi7w0rm / HookNMonitor.js
Created January 21, 2025 17:21
JavaScript code to use with chromes Dev console to hook certain functions in order to reveal what data is being processed.
(function() {
// Configuration object for monitoring
const MONITOR_CONFIG = {
// Enable/disable specific hooks
hooks: {
function: true,
atob: true,
decodeURI: true,
eval: false,
webSocket: true,

Keybase proof

I hereby claim:

  • I am gi7w0rm on github.
  • I am gi7w0rm (https://keybase.io/gi7w0rm) on keybase.
  • I have a public key ASCN5uI7A0CsviffsYfdPbAgN8s2bP0I85lxToaiqOGdBgo

To claim this, I am signing this object:

@Gi7w0rm
Gi7w0rm / additionalDomains.txt
Created November 16, 2024 17:09
CreditCard Scam via Email Spam
gokogift.com
gramagift.com
victory-wins.com
grsgoldpromo.com
grluckywin.com
surefireluck.com
verdeluck.com
getthatprize.com
grabthatprize.com
sexfamilygame.com
20.194.35.6:7904
103.153.182.247:6161
212.192.246.250:4480
194.5.98.46:1180
109.70.236.80:53166
65.21.3.192:1234
173.44.50.140:4550
8.208.27.150:4550
37.0.11.212:4444
37.0.10.19:5678
iroexjds.work.gd
kapobiko1.mooo.com
lesson.webredirect.org
abuhjil.com
sdfubuzoeoeiv.top
drippmedsot.mywire.org
cn-wh-plc-1.openfrp.top
adad3.casacam.net
actualizaciondedatosgrupoaval.net
5ra.webredirect.org
109.201.142.52:8080
138.201.196.90:443
149.248.3.194:443
153.92.222.162:4001
173.44.141.149:4001
185.236.232.20:445
185.73.124.42:4001
192.53.123.202:8080
193.233.21.140:4001
37.220.86.73:4001
@Gi7w0rm
Gi7w0rm / gist:a9f520f9eabc5fb7b0f20b7dc91e4fee
Created December 16, 2023 20:01
QakBot C2 Ips (unverified) as seen by drb-ra in the last 30 days (as of 16.12.2023):
1.221.179.74
100.2.41.26
102.113.158.156
102.113.169.213
102.113.31.13
102.113.71.59
102.156.106.202
102.156.45.163
102.157.101.136
102.157.15.16