Difference between revisions of "Society X"
[unchecked revision] | [unchecked revision] |
Line 562: | Line 562: | ||
This link leads to https://www.societyx.net/09bc7b2dcc9a510f4ab3a40c47f7a4cb77954356, which has a download button. When the download button is clicked, the page goes to a mega.nz page for "scx.ova," which is 745 mb. The .ova extension signifies a virtual machine file. However, the file only opens in VMware, and not VirtualBox. | This link leads to https://www.societyx.net/09bc7b2dcc9a510f4ab3a40c47f7a4cb77954356, which has a download button. When the download button is clicked, the page goes to a mega.nz page for "scx.ova," which is 745 mb. The .ova extension signifies a virtual machine file. However, the file only opens in VMware, and not VirtualBox. | ||
+ | |||
+ | Within the .ova file Discord user faa8146 found the following picture: | ||
+ | |||
+ | [[File:GlitchX.jpg]] |
Revision as of 14:14, 7 November 2016
Main Page > List of Investigations > Society X
Society X | |
---|---|
You are not alone. | |
Type | [[List_of_Investigations#Independent|Independent]] |
Creator | Unknown |
Discovered | 2016-10-26 |
Contents
Timeline
Day 1
The Beginning
On October 26, 2016, at around 7PM EDT, a user (Prime) came into the GameDetectives Discord and said:
so i have a website, and it was getting DOSed (by one IP), I traced that ip and got to SocietyX.net, I looked through the source code and found a link to a password page. i posted it to the ohnickel discord, then while i was looking around at my sites files, i found "lol.html"https://itspri.me/ <<my website
http://societyx.net/ <<hacking site
https://itspri.me/lol.html <<the file i found
The Homepage
The homepage for the SOcietyX website shows the logo in ASCII art, with a video running in the background. Clicking on a specific character in the logo goes to a password page. The source of the password page shows this:
<!-- __ __ _ \ \ / / | | \ \_/ /__ _ _ __ _ _ __ ___ _ __ ___ | |_ \ / _ \| | | | / _` | '__/ _ \ | '_ \ / _ \| __| | | (_) | |_| | | (_| | | | __/ | | | | (_) | |_ |_|\___/ \__,_| \__,_|_| \___| |_| |_|\___/ \__| _ | | __ _| | ___ _ __ ___ / _` | |/ _ \| '_ \ / _ \ | (_| | | (_) | | | | __/_ \__,_|_|\___/|_| |_|\___(_) -->
The Password
The password is given as flashing letters and numbers in the background of the homepage: Z8L0N2G
After entering the password, another string appears: gk1qk
That string can be entered into the prompt, which gives:
Caw Caw, Tweet Tweet c: Together, but not together. 9a78211436f6d42~5ec38f5c4e02270801f3524f8
9a78211436f6d42~5ec38f5c4e02270801f3524f8 is a Sha1 hash for @9a78211436f6d42, which leads to a twitter account with one tweet:
u4sNeZB3ua.47425e4490d1548713efea3b8a6f5d778e4b1766 c: <3
47425e4490d1548713efea3b8a6f5d778e4b1766 is another Sha1 hash for "php". This leads to another page, titled "Love." The page slowly prints text, that reads:
~$ echo "I love SocietyX." I love SocietyX. ~$ echo "I love SocietyX." I love SocietyX. ~$ echo "I love SocietyX." I love SocietyX. ~$ echo "You are here, and we are here." You are here, and we are here. ~$ echo "I love SocietyX." I love SocietyX. ~$ echo "I love SocietyX." I love SocietyX. ~$ echo "I love SocietyX." I love SocietyX. ~$ echo "Your curiosity must get the better of you sometimes." Your curiosity must get the better of you sometimes. ~$ echo "I love SocietyX." I love SocietyX. ~$ echo "I love SocietyX." I love SocietyX. ~$ echo "I love SocietyX." I love SocietyX. ~$ echo "<a href="qut1eLkzbp.php">Sometimes, the answer is you.</a>" Sometimes, the answer is you.
Smart Little Butterflies
The last message from "Love" leads to another password prompt. The password is the user's IP.
Entering it gives the text Aren't you a smart little butterfly!
. Additionally, the following appears in the source code of the page:
!-- _--_ _--_ /#()# #\ 0 0 /# #()#\ |()## \#\_ \ / _/#/ ##()| |#()##-=###\_ \ / _/###=-##()#| \#()#-=## #\_ \ / _/# ##=-#()#/ |#()#--==### \_ \ / _/ ###==--#()#| |#()##--=# #\_ \!!!/ _/# #=--##()#| \#()##---===####\ O|O /####===---##()#/ |#()#____==#####\ / Y \ /#####==____#()#| \###______######|\/#\/|######______###/ ()#y#/ ##\_#_/## \#S#() ()#1#(__-===###/ _ \###===-__)#O#() ()#F#( # ###_(_|_)_### # )#C#() ()#K(---#__###/ (_|_) \###__#---)I#() ()#r#( / / ##/ (_|_) \## \ \ )#E#() ()##Y#\_/ #/ (_|_) \# \_/#T##() \)##SO#\ -) (_|_) (- /#OY##(/ )//##B.php| / | \ |*OOOX#\( |/_####_/ ( /X\ ) \_####_\| /X/ \__/ \___/ \__/ \X\ (#/ \#)-->
The text in the bottom right of the butterfly leads to y1FKrYSB.php. The page reads Well, that's it. You've won. Congrats.
The title of the page is 8utt3rfl1, which leads to another .php link. Upon visiting the page, it begins to draw a butterfly. The background fades to white, revealing the text I <3 SCX
. Viewing the page source shows this:
<!-- __ __ \ \ / / \ \_/ /__ _ _ __ _ _ __ ___ \ / _ \| | | | / _` | '__/ _ \ | | (_) | |_| | | (_| | | | __/ |_|\___/ \__,_| \__,_|_| \___| _ | | __ _| | ___ _ __ ___ / _` | |/ _ \| '_ \ / _ \ | (_| | | (_) | | | | __/_ \__,_|_|\___/|_| |_|\___(_) -->
I HATE SCX
The butterfly page leads to a link, I<3SCX.html. After about twenty minutes, the page started to change. At first, the page changed from fading to white to fading to red.
Eventually, the I <3 SCX
changed to I HATE SCX
.
The PM began to use the page to communicate:
YOU GUYS WERE QUICK, I WASN'T EXPECTING IT
MAYBE WE SHOULD WORK TOGETHER
OR MAYBE I'LL GIVE YOU A NEW CLUE
I KNOW YOU'RE FREAKING OUT, SPAMMING F5 LIKE THE LITTLE BUTTERFLY YOU ARE.
At this point, the Discord users began to try to attempt to learn if the PM was in Discord with them. Discord user Lucario posted you know it :wink:
, which was immediately posted on the page.
The PM began to post more messages:
I love you too Lucario
sorry my dad called me
, which was another quote from a Discord user.
get off my website
Finally, the text went blank, and was then replaced with:
See you tomorrrow? You guys might get a surprise tomorrow <3 :)
Day 2
␀
First discovered at 8AM EDT, the I<3SCX page had updated.
The comment now read v=ObU98LCo_Xs
, pointing to a youtube video.
A frame of the video contains a sha1 hash, ce91ec4cccd5ee41c080fa62d2bceb0b41a18445
, which reads "ihatex," leading to a page of the same name.
A garbled text-to-speech reads You're smart, and I was not expecting it. I know you all, you cute little bugs.
The metadata of the mp3 reads SMART LITTLE PUPPY ARENT YOU...
482bcddc8fe53ed1e68c77a95aab5f83
It contains an md5 hash for "discord," which leads to a page that redirects to an invite link to a server named "scx," with one channel, "#2-," with the description "you get two minutes."
Discord
After about an hour, a user (scx#7056) began to speak in chat. A full log follows:
Brendan: echo "I love SocietyX." Brendan: I love SocietyX. Brendan: oh yeah tru you can't have non-tagged bots anymore Brendan: hm scx: I love SocietyX Brendan: I love SocietyX B.: I love SocietyX scx: I do too B.: Why do you love SocietyX scx: It is not that I love SocietyX, It is that SocietyX loves me. scx: It exists scx: And does not scx: We are it scx: And it is us holyhearted: so holyhearted: if it's a society holyhearted: who is part of it scx: It is a thing and it is not holyhearted: well that's just holyhearted: really weird scx: The world is weird holyhearted: no, just you Brendan: savage A4: what does "you get 2 minutes" mean? A4: and how do we proceed further scx: We are all it. scx: Everyone is a part of it now Brendan: spooopy scx: Everything Screams in my dreams tonight. Brendan: okay now we getting creepy scx: That is all you need to know.
“Everything screams in my dreams tonight”, is a quote from Suzanne Collins’s Mockingjay. It is unknown if that is relevant at this time.
After noon, SCX said something again:
TronLegacy1: wait... TronLegacy1: scx mentioned something TronLegacy1: it exists but it does not TronLegacy1: It's like the elder scrolls in the elder scrolls TronLegacy1: they have all ways existed but always never have scx: It is not that someone created it, but rather that an alternate meaning is present
Later, SCX posted another message, 7a3gh64m
. It leads to a page titled "It's Everywhere" containing a riddle:
What has no hands but grips you tight and squeezes out your grit? What whispers warnings in your ear and makes you lose all wit? What has no fangs yet bites down hard and causes valor’s bleed? What makes the indomitable spirit of man concede?
The answer to this riddle was "fear". Hashing this with sha1 lead to a new page with a hidden comment:
<!--Hey Babe, Wanna Chat at 5?-->
Hovering over the o in the A in fear gave a prompt: "They're Watching." Some users noticed the cheet module loaded on this page, without a call. However, this was quickly removed.
Anxiety
5 hours later, SCX came into #2- to chat.
scx: Hey babe. Lucario: hey hey scx: How was your day? Tron: Good, how are you scx: I'm good. Prime: Who is watching? scx: They are watching. Tron: Who is? scx: they are. Tron: Who are "they" scx: They. Lucario: Why are you doing this? scx: Why not. ¯\_(ツ)_/¯ scx: Who am I? I am you. Tron: Who is Society X? scx: SocietyX is a revolution. Lucario: what kind of revolution? scx: A Society Revolution. ICallHax: what is the next clue? scx: babe, if I dont respond right away, im browsing reddit btw whats the next clue? I don't know. Tron: K babe, but will we see you again? scx: I don't know. faa8146: https://www.reddit.com/r/gamedetectives/comments/59remz/hello/ scx: You're quick. Props. I must go now. Love you babe 😘
Discord user faa8146 found a reddit post by the PM that reads:
hi guys!!! YQ== I'm new, I was bg== wondering what this subeA==reddit is for?????? aQ==I'm new to reddit and dont know how to ZXQ= use it! help meQ==??!
There are snippets of Base64 in his post, which decode to a n x i et y
, which leads to another page titled "THEYRE AROUND ME," with text reading "THEY'RE ALL AROUND ME. HELP ME. HELP."
The page plays an audio file that contains a spectrogram that reads zUiAUtQ8
. This led to another page titled ".", with text only reading "Yes."
<!--HeLp-->
Shortly after, scx came back into discord:
faa: scx, are you here? scx: i am here. B.: Would you like to talk scx: Why would I risk my anonymity. The Lone Mimikyu: How do you feel, @scx? scx: Lonely. Tron: Any good emotions? scx: No. PinkSkie1: Can we help you? scx: No. Mimikyu: Why don't you? scx: Why do I not what? Mimikyu: Feel any good emotions; scx: Sometimes, I feel as though I am two. Tron: The man with two souls. A ref to Doctor Jec and Mr Hide scx: 'Man.' Halke234: What are you? scx: I am neither. I am nothing. I am Emptyness. I am darkness. I am alone. I am fear and I am feared. Fear is everywhere. But that's okay. We all deal with it. Pink: We have nothing to fear but fear itself? scx: We have nothing to fear, but fear itself. Yes. But what is fear? Is it the inevitably of death? A misuse of imagination? Tron: Or is it Fear itself? scx: That is a loop. It just does not check out. Mimikyu: We are told to fear all our life. scx: I don't fear death. Pink: What do you fear? scx: I fear myself.
The Next One
Discord user ICallHax's version of societyx.net updated to show You're next
on the main page.
Shortly thereafter, it was discovered that Hax's website, fragstorm.net, also contains a "lol.html" page that mirrors Prime's.
On SCX's discord, both Prime and Hax have a role titled "Loved." Additionally, SCX has the role of "unloved."
Day 3
null.mp4
The video embedded in zUjAUtQ8 is called "null.mp4", and is 42 seconds long. Various words and phrases are in the video, and have different counts:
IAMDYING 1 hOLD 1+2 (Lonely?) Unhappy 1 Sad 1 dREAMING 1+2+4 hELL 1+1+3 Anger 1 Unhappy 1 Depressed 1 12481631 1 Kill 1+1+1 5 YEARS 5
In addition to this, a spectogram revealed "C," "JO," and "4" between the words.
This clue took a while to decipher, which made the PM impatient.
scx: I'M DONE T͡he̸ Mimikyu: With what? Prime: with what scx: I scx: AM scx: DONE. Fruitbread: no you’re scx T͡he̸ Mimikyu: What are you done with? TronLegacy1: @scx INSTRUCTIONS NOT CLEAR ICallHax: ? scx: I SWEAR Yeti: nice 1 bread scx: YOU GUYS ARE IMBICILS Fruitbread: thx @Yeti Prime: rood TronLegacy1: .... T͡he̸ Mimikyu: @scx I am truly sorry for the memes. TideSinger: Im offended TideSinger: My memes are dank CrystalShyps 💤: can’t even spell imbicile right, ironic scx: SHUT THE FUCK UP scx: SHUT Shypwreck: LMAO scx: THE FUCK UP TideSinger: Shhhhh guys T͡he̸ Mimikyu: I ruined this. scx: FIGURE IT OUT. !!"Ą͝͝ńǫ̶̕r̨a͏k̨̢͜": I like your stuff It looks cool too bad I cant change audio to something legible scx: THIS CLUE IS EASY faa8146: Are you dying? scx: FIGURE scx: IT scx: OUT. ... scx: I'm lonely. scx: and Sad. TronLegacy1: (EVERYONE SHUT UP) scx: I'm missing something. T͡he̸ Mimikyu: Its ok, @scx T͡he̸ Mimikyu: We all feel lonely. scx: You're missing something. TronLegacy1: I am missing a mind !!"Ą͝͝ńǫ̶̕r̨a͏k̨̢͜": C J0 4 scx: We're missing something.
On 29 Oct 2016, the source of zUjAUtQ8 was found to be different than the original non-HTML page, and it showed:
<body class="fade a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a "> <video playsinline autoplay loop poster="#000000" id="bgvid"> <source src="media/null.mp4" type="video/mp4"> </video> </body>
In addition to this, the word "Anxiety" was spelled out in different pieces throughout the code.
From this addition to the code, we were able to find the next clue, which was at the URL. This was found by combining the letters found in the spectrogram and the first letter of every word/phrase repeated in null.mp4.
The URL leads to a timer, which counts down to approximately 18:00:00 on 31 Oct 2016. However, for Prime, the countdown ends at 21:00:00 on 29 Oct 2016. It was thought that this was related to Prime's role of "loved" in the scx Discord server. However, ICallHax, who also has this role, saw that the countdown ends on 18:00:00 on the 31st as well, so does not seem to be related to the "loved" role.
Death
During the two days before the countdown ended, the PM, SCX, did not show up to talk to us at 17:00:00 PST.
After the timer was finished, the page updated to be titled sorry i'm late
with a new string of sha1 hashes:
8e3b005ff3fb5cab6fff6a93b36ac8faaca621f6 becce3c77d0792aebddc03d75f3c591d8c1c46d1 43c310799fa753f8a43bf826ebce5e765c3ca804
The hashes decode to read:
Remaining strong Till the day That the faith is gone
They are lyrics from a song by Arts the Beatdoctor & Bless of SHAHMAN, titled "Part of the Crow." The song's lyrics primarily deal with death. Discord user Shadow Spade found the link to the next page by encrypting the word "death" using sha1. This leads to a page with a massive button that says "download death," leading to societyx.png. When societyx.png is manipulated, there is a string of data at the very top of the image:
When this section of the image is cropped and saved as a bitmap file, the string of binary is easily readable:
This binary translates to:
3c363836cf4e16666669a25da280a1865c2d2874 0cc175b9c0f1b6a831c399e269772661 7a1b96563495a2286ab79687369c07b3 8254c329a92850f6d539dd376f4816ee2764517da5e0235514af433164480d7a a87d8f7ff9267bad515057f7a7f772c469d2536b70f1e8e770f9a5581922b986520a3d7 1d952f30593bcfa2318bfeb0d 4992A157B9ECC2A7D2066FEFF64967D3 5335f048bddebe600ae6edb89b36da3a2d7c18bc53b83e2fa577cc9a4f262fc1c3741830955303a0158e7d48be7965f8 2c1ee68372215b1ce064426b5cdbd4ef2581ace0dd3b21fa2be27f364827242e83f68b68be03f5b3e24be5d1b4315f98a0a96d19713fb3a19dc455fb6adc3431 415ab40ae9b7cc4e66d6769cb2c08106e8293b48
This passage uses multiple different encryption methods, including sha1,md5, md4, NTLM, and some others. Instead of continuing to translate this passage, Discord user Lexicon found the link, which is a sha1 of the word "darkness." This page shows a video called "Crow.mp4." In the metadata for this video, there is a strange string:
Discord user A4 found that the string is part of a URL for an unlisted YouTube video, called "..................................," found at this URL. The text in the description of the video (7e6f31cfc162d6c21b116b6b0e1e3eb5718a6841) leads to another page on the SocietyX website. There is no content in the page, but the page itself is titled "soon," implying that we have to wait once again.
Day 12
STILL HERE
On November 4, Discord user Anorak discovered that the "soon" (https://www.societyx.net/7e6f31cfc162d6c21b116b6b0e1e3eb5718a6841) page had changed again. In it, a video is now embedded, on which flash the words "STILL HERE" and the date "11/6/16," implying that something will happen on November 6.
Your Turn
On November 6th, at around 20:51:00, SCX came on again, after a week long absence, for 4 minutes.
Towards the end of the conversation, SCX said "I miss you," but deleted it very quickly afterwards.
As of November 7, the Soon page changed yet again, into a prompt asking for a username and password. Thanks to Discord user faa8146 and the usage of SQL injection, the credentials were found to be:
Username: SocietyX Password: ' OR '1=1
Once this is done correctly, the text below displays at the top of the page:
Welcome User: SocietyX Your next order of business is: 09bc7b2dcc9a510f4ab3a40c47f7a4cb77954356
This link leads to https://www.societyx.net/09bc7b2dcc9a510f4ab3a40c47f7a4cb77954356, which has a download button. When the download button is clicked, the page goes to a mega.nz page for "scx.ova," which is 745 mb. The .ova extension signifies a virtual machine file. However, the file only opens in VMware, and not VirtualBox.
Within the .ova file Discord user faa8146 found the following picture: