Hud [RCORE-PRISON] 2025 FULLY WORKING/TESTED

Aug 4, 2026

1 Mesaj

0 Reaction

0 Solution

1

First Message

No reward!

No reward!

No reward!

No reward!

Joined
Aug 4, 2026
Messages
1
Reaction score
0
Points
1
Location
United States
Credits
1
⚠️ WARNING — THIS RESOURCE CONTAINS A BACKDOOR. DO NOT USE.

I inspected every file before running it. Here's what I found:

permissions.lua (lines 15–16) uses string.char(108,111,97,100) to obfuscate the word "load", then reads the bundled Roboto.ttf font file, skips 87,564 bytes past the real font data, strips disguise characters, and executes the hidden code using Lua's load() function.

The hidden code makes an HTTP request to — if you visit that URL in a browser it redirects to cfx.re to look innocent, but when called from a real FiveM server it returns 93KB of Luraph v14.7-obfuscated Lua malware and immediately executes it. This is a live C2 (command-and-control) dropper — the attacker can push any code they want to every server running this resource, at any time, silently.

This gives the attacker full server-side code execution: database credentials, player data, configs, admin commands — everything is compromised the moment this resource starts.

This has been deliberately trojanized.
 

Topics

5,251

Messages

8,944

Members

51,377

Latest member

afddfdfd

Top