There’s this weird github repository

https://github.com/OOOO00000000OOOO/OOOO00000000OOOO

I noticed there was someone attempting to proxy to this repository on my site, causing it to show up in the logs. It was detected as spam but this repo doesn’t look like it’s built by some normal spammy company. The owner has gone through great lengths to try to stay anonymous. And I can’t make out what the repo is or what it’s for. Does anyone know or have any ideas?

Thanks

      • urushitan 漆たん@kakera.kintsugi.moe
        link
        fedilink
        arrow-up
        4
        ·
        14 hours ago

        they actually didn’t when I grabbed them either but I kept them for posterity. Important to note some of these things are almost 10 years old, so there’s certainly the rot of not maintaining them, free services pruning, etc. That being said, it’s likely why they duplicate their 7GB backup repo all over the place

      • Their goal? Can’t say. They clearly have a drive to make art, especially mathematical fractal binary minimalist art. Whether they also are actually producing malware or are just trying to piggyback as many services as possible to archive and keep their stuff online is another question. The vast majority of what I saw in my quick recon of their online presence was mostly glitch art/unicode/ascii art, blender stuff, fractals, web based d3 animations, that sort of thing. That being said, as you said, they appear to have gone to great lengths to be anonymous, I’ve only found a couple of raw IPs in there that mirror their stuff.

        That being said, it seems they also clone their backups to anyone who hosts a free forgejo/gitea instance:

        OOOOOOOOOOOOOOOO\ꓨЯO.ꓨЯƎᗺƎᗡOϽ CODEBERG.ORG/OOOOOOOOOOOOOOOO
        OOOO\MOϽ.ᗺUHƧꓨAᗡ DAGSHUB.COM/OOOO
        OOOO\u\MOϽ.ƎᗡOϽƎᗡOHЯ.ƎᗡOϽ CODE.RHODECODE.COM/u/OOOO
        oooo∽\TH.ЯƧ.TIꓨ GIT.SR.HT/~oooo
        OOOO\ꓨЯO.ꓨUᗺATOИ NOTABUG.ORG/OOOO
        O\000Ԑ:მ4.111.78.ਟ81 185.87.111.46:3000/O
        O\HϽƎT.TƎꓨƎᗺ.MUTИƎꓨA.TIꓨ GIT.AGENTUM.BEGET.TECH/O
        O\ᗡI.Oꓨ.ᗺAꞰꓨИAᗡƎMUƧ.TIꓨ GIT.SUMEDANGKAB.GO.ID/O
        OOOO\ƎTIƧ.ƧƎOᒐƧIƧIHT.TIꓨ GIT.THISISJOES.SITE/OOOO
        O\UƎ.ЯƎꓨИIᒧᒧƎ.TIꓨ GIT.ELLINGER.EU/O
        O\HƧ.1ᗡIꟼ.AƎTIꓨ GITEA.PID1.SH/O
        O\ᒧИ.ИƎЯƎOᗺЯƎIVIᒧO.TIꓨ GIT.OLIVIERBOEREN.NL/O
        O\ƎM.YꓨOᒧOИYƧ.ꓨИOƎᒐꞰƎ.AƎTIꓨ GITEA.EKJEONG.SYNOLOGY.ME/O
        O\𑪽Ͻ.ϽƎVOЯOᗺꞰƎИƎᗡ𑪽.TIꓨ GIT.ZDENEKBOROVEC.CZ/O
        O\ꟼᒐ.ƧUᒧꟼTϽƎИИOϽ.TIꓨ GIT.CONNECTPLUS.JP/O
        O\YИAꟼMOϽ.ꞰᗺƎ.AƎTIꓨ GITEA.EBK.COMPANY/O
        O\MOϽ.ƧꟼOVƎᗡUAꞰA.AƎTIꓨ GITEA.AKAUDEVOPS.COM/O
        O\ZYX.VƎᗡƎᒧᗺATЯOꟼ.AƎTIꓨ GITEA.PORTABLEDEV.XYZ/O
        O\MOϽ.ƎꓨAMAIV.AƎTIꓨ GITEA.VIAMAGE.COM/O
        O\TƎИ.OTYЯϽ.TIꓨ GIT.CRYTO.NET/O
        O\VƎᗡ.ƧꟼAMO.TIꓨ GIT.OMAPS.DEV/O
        O\MOϽ.ИƎMMƎH-ИAV.TIꓨ GIT.VAN-HEMMEN.COM/O
        O\UƎ.ИƎVƧƎИ.TIꓨ GIT.NESVEN.EU/O
        O\MOϽ.ᗡAƎЯᗡHTꟻIꟻ.AƎTIꓨ GITEA.FIFTHDREAD.COM/O
        
        • mark@programming.devOP
          link
          fedilink
          arrow-up
          2
          ·
          edit-2
          19 hours ago

          Yeah. Just found that they’re using this email address: OOOOOOOOOOOOOO@MURENA.IO. murena.io gives them 1GB of storage for free. Like you said, they appear to be attempting to keep a backup of a lot of data using third-party services, I’m guessing so that, in theory, even after their death, this data will be available… forever?

          • lad@programming.dev
            link
            fedilink
            English
            arrow-up
            1
            ·
            17 hours ago

            Their repositories are really something, and the commits seem to only happen in bursts, I expected them to do a few commits every day, instead it’s like 10 days a year with 1700+ commits total.

            But I wouldn’t assume they are conventionally malicious, more like a paperclip storage optimiser

            • urushitan 漆たん@kakera.kintsugi.moe
              link
              fedilink
              arrow-up
              3
              ·
              17 hours ago

              Agreed, leads me to think they have some kind of script that rewrites filenames and directory names to be symbolic/symmetric and they run it manually rather than on some automated schedule. Then by storing it as a git repo they can find open git hosting and just mirror it there (the lastest copy I saw was like 7 or 8 GB so definitely not tiny, but also not enough to take down your average self hosting project)

    • felsiq@piefed.zip
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      I don’t know what their vibe is but I love it, we need more people like this in the world

  • ludrol@programming.dev
    link
    fedilink
    arrow-up
    38
    ·
    edit-2
    2 days ago

    At first glance there is a lot of noise that look like an ARG but there is just too much random stuff. There are some binary blobs that are marked as executable. They might be malware.

    Edit:

    Found blender screenshots, firefox screenshots with some firefox extension config files, SVGs and PNGs, links to alternative 4chans, solidworks tutorials and blender VK groups

    They are crazy for using VERY heavily riced windows that is ultra-minimalist white.

    Russian hacker for sure. Might or might not have developed malware. I am more inclined for this to be a cloud backup hosted on github.

    Edit2: The Filepath is crazy

    • mark@programming.devOP
      link
      fedilink
      arrow-up
      12
      ·
      edit-2
      2 days ago

      It’s insane, right? I was looking through the files and trying to find anything that made sense. None of it does. I thought it was some foreign or custom encoded programming language or something.

      • ludrol@programming.dev
        link
        fedilink
        arrow-up
        24
        ·
        edit-2
        2 days ago

        It makes sense in Terry A. Davis/Temple OS sense. Someone mentally ill needs everything to be symmetrical. They substitute o with Ⓞ in www.gⓄⓄgle.com I think they use fancy unicode to have a bearable symmetrical font; And someday they found that they can upload stuff to github and they upload what they made.

    • mark@programming.devOP
      link
      fedilink
      arrow-up
      13
      ·
      2 days ago

      Good idea. I didn’t report it before because I wasn’t quite sure of whether or not it was malicious or just someone testing something out. But it’s clear this person isn’t just testing or debugging something. I’ll report. Thanks!

  • talkingpumpkin@lemmy.world
    link
    fedilink
    arrow-up
    9
    ·
    2 days ago

    No idea, but it’s certainly not the intended use of github.

    Have you already reported the user (look at their other repos) or should I?

    • theherk@lemmy.world
      link
      fedilink
      arrow-up
      7
      ·
      1 day ago

      Several such repositories very similar. I’m thinking some strange encoding for using it as remote storage of some sort.

    • mark@programming.devOP
      link
      fedilink
      arrow-up
      5
      ·
      2 days ago

      Just reported. Wasn’t sure if I should at first. But the more people who report it, the better, right? ;) Thanks