GO TO DOXBIN.COM FOR THE FULL PASTE: ╔══════════════════════════════════════════════════════════════════╗
║ DOX REPORT ║
╠══════════════════════════════════════════════════════════════════╣
║ made by: r00pa + whoisnee ║
║ Date: 2026-09-06 ║
║ Target IP: 24.129.233.210 ║
║ Report ID: 41e08efc-6459-41f6-ad7c-fd42337c8911 ║
╚══════════════════════════════════════════════════════════════════╝
┌─────────────────────────────────────────────────────────────────┐
│ PRIMARY TARGET IDENTIFICATION │
├─────────────────────────────────────────────────────────────────┤
│ IP Address : 24.129.233.210 │
│ Device User : plush │
│ HWID : 496E05A150779017EBDC85A9D5F1C6D2 │
│ Steam ID : 76561199808545839 │
│ Country : Canada (CA) │
│ OS : Windows 10 Home (10.0.19045) x64 │
│ Infection Path: C:\Users\plush\AppData\Local\Temp\...Tool.exe│
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ EMAIL FOOTPRINT (COMPLETE) │
├─────────────────────────────────────────────────────────────────┤
│ 1. 22plushroblox123@gmail.com │
│ 2. egapadow@email1.io │
│ 3. gogolgrisha@klemail.xyz │
│ 4. hotcoolw@gmail.com │
│ 5. java1x6x8x4@gmail.com │
│ 6. john6777wgt@gmail.com │
│ 7. johnw677gt@gmail.com │
│ 8. plushroblox123@gmai.com │
│ 9. sufyqlwdnq8rojbq@bt.pz5.r.rh (disposable) │
│ 10. johnw6777gt@gmail.com │
│ 11. m40n@gqphk.oq (disposable) │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ STEALER LOGS (3 VICTIM ENTRIES) │
├─────────────────────────────────────────────────────────────────┤
│ ENTRY 1 │
│ ├─ Log ID : 0e0525c9619c5c8f185d9513243982bb61ac2c0ab... │
│ ├─ Pwned At : 2024-12-22 00:24:00 UTC │
│ ├─ Indexed At: 2026-02-22 13:41:27 UTC │
│ ├─ Total Docs: 96 │
│ ├─ Services : github, roblox, steam, twitch (4) │
│ ├─ Infection : C:\Users\plush\AppData\Local\Temp\Rar$... │
│ └─ HWID : 496E05A150779017EBDC85A9D5F1C6D2 │
│ │
│ ENTRY 2 │
│ ├─ Log ID : 5eb1e23577b8df99ba2f0ec5a6601a1694477167b... │
│ ├─ Pwned At : 2024-12-11 14:27:41 UTC │
│ ├─ Indexed At: 2026-03-26 18:16:56 UTC │
│ ├─ Total Docs: 94 │
│ ├─ Services : github, roblox, steam, twitch (4) │
│ ├─ Infection : C:\Users\plush\Documents\v1.0.9\XenoB.exe │
│ └─ HWID : 496E05A150779017A056F87F09566454 │
│ │
│ ENTRY 3 │
│ ├─ Log ID : 5992bb352a1b72febf170bfe24427797c07f7eb6d... │
│ ├─ Pwned At : 2025-01-15 22:10:45 UTC │
│ ├─ Indexed At: 2026-02-09 19:14:05 UTC │
│ ├─ Total Docs: 175 │
│ ├─ Services : facebook, github, roblox, steam, twitch (5) │
│ ├─ Infection : C:\Users\plush\AppData\Local\Temp\Rar$... │
│ └─ HWID : 496E05A1507790179EF26D30D1BCE101 │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ GEOLOCATION & NETWORK │
├─────────────────────────────────────────────────────────────────┤
│ Country : Canada │
│ Region : British Columbia (BC) │
│ City : Oliver │
│ Postal Code : V0H │
│ Latitude : 49.1819 │
│ Longitude : -119.5451 │
│ Time Zone : America/Vancouver │
│ ISP : Persona Communications Inc. │
│ Organization : Oliver CPE │
│ AS Number : AS11260 EastLink │
│ Reverse DNS : host-24-129-233-210.public.eastlink.ca │
│ Proxy : No │
│ Hosting : No │
│ Mobile : No │
│ Currency : CAD (Canadian Dollar) │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ STEAM PROFILE INTELLIGENCE │
├─────────────────────────────────────────────────────────────────┤
│ Steam ID64 : 76561199808545839 │
│ Note : Full profile data not available via this scan│
│ Associated : Confirmed via stealer logs │
│ Linked Services: roblox, github, twitch, facebook │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ THREAT INTEL SUMMARY │
├─────────────────────────────────────────────────────────────────┤
│ Proxy/VPN : ❌ No │
│ Hosting/Cloud : ❌ No │
│ Mobile Network : ❌ No │
│ Known Breach : ✅ YES (multiple stealer logs) │
│ Steam Presence : ✅ Confirmed │
│ Email Valid : ✅ Confirmed (multiple) │
│ Device Compromised : ✅ Yes (XenoB.exe, BootstrapperV2.exe) │
│ Canada : ✅ Confirmed │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ POSSIBLE LEADS │
├─────────────────────────────────────────────────────────────────┤
│ 1. Primary Email : 22plushroblox123@gmail.com │
│ 2. Steam ID : 76561199808545839 │
│ 3. IP Geolocation: Oliver, British Columbia, Canada │
│ 4. ISP : EastLink (Persona Communications) │
│ 5. Device User : plush │
│ 6. Device OS : Windows 10 Home x64 │
│ 7. Infection Path: XenoB.exe, Tool.exe, BootstrapperV2.exe │
│ 8. Services : Roblox, Steam, Twitch, GitHub, Facebook │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ RECOMMENDED ACTIONS │
├─────────────────────────────────────────────────────────────────┤
│ 1. Cross-reference all emails against breach databases │
│ 2. Search Steam ID 76561199808545839 for profile details │
│ 3. Investigate IP range 24.129.233.0/24 for other victims │
│ 4. Check XenoB.exe/BootstrapperV2.exe signatures │
│ 5. Monitor plush@eastlink.ca for future activity │
│ 6. Search Roblox username "plush" for game activity │
│ 7. Check GitHub for repositories linked to these emails │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ RAW DATA REFERENCE │
├─────────────────────────────────────────────────────────────────┤
│ { │
│ "ip": "24.129.233.210", │
│ "device_user": "plush", │
│ "steam_id": "76561199808545839", │
│ "emails": [ │
│ "22plushroblox123@gmail.com", │
│ "egapadow@email1.io", │
│ "gogolgrisha@klemail.xyz", │
│ "hotcoolw@gmail.com", │
│ "java1x6x8x4@gmail.com", │
│ "john6777wgt@gmail.com", │
│ "johnw677gt@gmail.com", │
│ "plushroblox123@gmai.com" │
│ ], │
│ "country": "Canada", │
│ "city": "Oliver", │
│ "lat": 49.1819, │
│ "lon": -119.5451, │
│ "isp": "Persona Communications Inc.", │
│ "as": "AS11260 EastLink", │
│ "os": "Windows 10 Home (10.0.19045) x64", │
│ "services": ["github", "roblox", "steam", "twitch"], │
│ "logs": 3, │
│ "pwned_dates": ["2024-12-11", "2024-12-22", "2025-01-15"] │
│ } │
└──────────────────────────