╔══════════════════════════════════════════════════════════════════╗ ║ DOX REPORT ║ ╠══════════════════════════════════════════════════════════════════╣ ║ made by: r00pa + whoisnee ║ ║ Date: 2026-09-06 ║ ║ Target IP: 24.129.233.210 ║ ║ Report ID: 41e08efc-6459-41f6-ad7c-fd42337c8911 ║ ╚══════════════════════════════════════════════════════════════════╝ ┌─────────────────────────────────────────────────────────────────┐ │ PRIMARY TARGET IDENTIFICATION │ ├─────────────────────────────────────────────────────────────────┤ │ IP Address : 24.129.233.210 │ │ Device User : plush │ │ HWID : 496E05A150779017EBDC85A9D5F1C6D2 │ │ Steam ID : 76561199808545839 │ │ Country : Canada (CA) │ │ OS : Windows 10 Home (10.0.19045) x64 │ │ Infection Path: C:\Users\plush\AppData\Local\Temp\...Tool.exe│ └─────────────────────────────────────────────────────────────────┘ ┌─────────────────────────────────────────────────────────────────┐ │ EMAIL FOOTPRINT (COMPLETE) │ ├─────────────────────────────────────────────────────────────────┤ │ 1. 22plushroblox123@gmail.com │ │ 2. egapadow@email1.io │ │ 3. gogolgrisha@klemail.xyz │ │ 4. hotcoolw@gmail.com │ │ 5. java1x6x8x4@gmail.com │ │ 6. john6777wgt@gmail.com │ │ 7. johnw677gt@gmail.com │ │ 8. plushroblox123@gmai.com │ │ 9. sufyqlwdnq8rojbq@bt.pz5.r.rh (disposable) │ │ 10. johnw6777gt@gmail.com │ │ 11. m40n@gqphk.oq (disposable) │ └─────────────────────────────────────────────────────────────────┘ ┌─────────────────────────────────────────────────────────────────┐ │ STEALER LOGS (3 VICTIM ENTRIES) │ ├─────────────────────────────────────────────────────────────────┤ │ ENTRY 1 │ │ ├─ Log ID : 0e0525c9619c5c8f185d9513243982bb61ac2c0ab... │ │ ├─ Pwned At : 2024-12-22 00:24:00 UTC │ │ ├─ Indexed At: 2026-02-22 13:41:27 UTC │ │ ├─ Total Docs: 96 │ │ ├─ Services : github, roblox, steam, twitch (4) │ │ ├─ Infection : C:\Users\plush\AppData\Local\Temp\Rar$... │ │ └─ HWID : 496E05A150779017EBDC85A9D5F1C6D2 │ │ │ │ ENTRY 2 │ │ ├─ Log ID : 5eb1e23577b8df99ba2f0ec5a6601a1694477167b... │ │ ├─ Pwned At : 2024-12-11 14:27:41 UTC │ │ ├─ Indexed At: 2026-03-26 18:16:56 UTC │ │ ├─ Total Docs: 94 │ │ ├─ Services : github, roblox, steam, twitch (4) │ │ ├─ Infection : C:\Users\plush\Documents\v1.0.9\XenoB.exe │ │ └─ HWID : 496E05A150779017A056F87F09566454 │ │ │ │ ENTRY 3 │ │ ├─ Log ID : 5992bb352a1b72febf170bfe24427797c07f7eb6d... │ │ ├─ Pwned At : 2025-01-15 22:10:45 UTC │ │ ├─ Indexed At: 2026-02-09 19:14:05 UTC │ │ ├─ Total Docs: 175 │ │ ├─ Services : facebook, github, roblox, steam, twitch (5) │ │ ├─ Infection : C:\Users\plush\AppData\Local\Temp\Rar$... │ │ └─ HWID : 496E05A1507790179EF26D30D1BCE101 │ └─────────────────────────────────────────────────────────────────┘ ┌─────────────────────────────────────────────────────────────────┐ │ GEOLOCATION & NETWORK │ ├─────────────────────────────────────────────────────────────────┤ │ Country : Canada │ │ Region : British Columbia (BC) │ │ City : Oliver │ │ Postal Code : V0H │ │ Latitude : 49.1819 │ │ Longitude : -119.5451 │ │ Time Zone : America/Vancouver │ │ ISP : Persona Communications Inc. │ │ Organization : Oliver CPE │ │ AS Number : AS11260 EastLink │ │ Reverse DNS : host-24-129-233-210.public.eastlink.ca │ │ Proxy : No │ │ Hosting : No │ │ Mobile : No │ │ Currency : CAD (Canadian Dollar) │ └─────────────────────────────────────────────────────────────────┘ ┌─────────────────────────────────────────────────────────────────┐ │ STEAM PROFILE INTELLIGENCE │ ├─────────────────────────────────────────────────────────────────┤ │ Steam ID64 : 76561199808545839 │ │ Note : Full profile data not available via this scan│ │ Associated : Confirmed via stealer logs │ │ Linked Services: roblox, github, twitch, facebook │ └─────────────────────────────────────────────────────────────────┘ ┌─────────────────────────────────────────────────────────────────┐ │ THREAT INTEL SUMMARY │ ├─────────────────────────────────────────────────────────────────┤ │ Proxy/VPN : ❌ No │ │ Hosting/Cloud : ❌ No │ │ Mobile Network : ❌ No │ │ Known Breach : ✅ YES (multiple stealer logs) │ │ Steam Presence : ✅ Confirmed │ │ Email Valid : ✅ Confirmed (multiple) │ │ Device Compromised : ✅ Yes (XenoB.exe, BootstrapperV2.exe) │ │ Canada : ✅ Confirmed │ └─────────────────────────────────────────────────────────────────┘ ┌─────────────────────────────────────────────────────────────────┐ │ POSSIBLE LEADS │ ├─────────────────────────────────────────────────────────────────┤ │ 1. Primary Email : 22plushroblox123@gmail.com │ │ 2. Steam ID : 76561199808545839 │ │ 3. IP Geolocation: Oliver, British Columbia, Canada │ │ 4. ISP : EastLink (Persona Communications) │ │ 5. Device User : plush │ │ 6. Device OS : Windows 10 Home x64 │ │ 7. Infection Path: XenoB.exe, Tool.exe, BootstrapperV2.exe │ │ 8. Services : Roblox, Steam, Twitch, GitHub, Facebook │ └─────────────────────────────────────────────────────────────────┘ ┌─────────────────────────────────────────────────────────────────┐ │ RECOMMENDED ACTIONS │ ├─────────────────────────────────────────────────────────────────┤ │ 1. Cross-reference all emails against breach databases │ │ 2. Search Steam ID 76561199808545839 for profile details │ │ 3. Investigate IP range 24.129.233.0/24 for other victims │ │ 4. Check XenoB.exe/BootstrapperV2.exe signatures │ │ 5. Monitor plush@eastlink.ca for future activity │ │ 6. Search Roblox username "plush" for game activity │ │ 7. Check GitHub for repositories linked to these emails │ └─────────────────────────────────────────────────────────────────┘ ┌─────────────────────────────────────────────────────────────────┐ │ RAW DATA REFERENCE │ ├─────────────────────────────────────────────────────────────────┤ │ { │ │ "ip": "24.129.233.210", │ │ "device_user": "plush", │ │ "steam_id": "76561199808545839", │ │ "emails": [ │ │ "22plushroblox123@gmail.com", │ │ "egapadow@email1.io", │ │ "gogolgrisha@klemail.xyz", │ │ "hotcoolw@gmail.com", │ │ "java1x6x8x4@gmail.com", │ │ "john6777wgt@gmail.com", │ │ "johnw677gt@gmail.com", │ │ "plushroblox123@gmai.com" │ │ ], │ │ "country": "Canada", │ │ "city": "Oliver", │ │ "lat": 49.1819, │ │ "lon": -119.5451, │ │ "isp": "Persona Communications Inc.", │ │ "as": "AS11260 EastLink", │ │ "os": "Windows 10 Home (10.0.19045) x64", │ │ "services": ["github", "roblox", "steam", "twitch"], │ │ "logs": 3, │ │ "pwned_dates": ["2024-12-11", "2024-12-22", "2025-01-15"] │ │ } │ └──────────────────────────