GO TO DOXBIN.COM FOR THE FULL PASTE:
⠀⠀⠀⡎⢉⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⢈⣁⠆⡀⠀⠀⠀⠀⣄⠀⠀
⠀⠀⠀⢳⢹⠁⠀⠱⡀⠀⠀⢈⠆⠀
⠀⠀⠀⠠⢾⣆⠀⠞⠁⠀⣠⠮⡤⡀
⠀⠀⠀⠀⠐⠹⢦⡀⠀⠰⠁⡀⢰⡁
⠀⠀⠀⢔⠞⠛⠶⣟⣦⣀⠀⠀⠛⠀
⠀⠀⠀⠌⣤⡴⠀⠀⠀⠉⠳⡰⡡⠄
⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⡀⠹⡄⠀
⠀⠀⠀⠀⠀⠀⠀⠀⡇⢄⠙⢀⢷⢁
⠀⠀⠀⠀⣀⣄⡀⠀⠑⠀⠀⠊⣸⢰ ~ 𝙈𝙖𝙙𝙚 𝙗𝙮 𝙛𝙖𝙣𝙩𝙤𝙣𝙚𝙩𝙬𝙤𝙧𝙠
⠀⠀⠀⡔⠁⠠⠗⠀⠀⠀⠀⠀⡭⠄
⠀⠀⠀⢣⠀⠀⠲⣄⣀⣀⢤⡾⠁⠀
⠀⠀⠀⠀⠑⠢⠀⠀⢠⣴⣟⠍⠀⠀
⠐⠄⠄⠤⢐⡢⣀⡼⡾⠋⠀⠀⠀⠀
⠀⠀⢀⠔⣡⣞⠏⠀⠀⠀⠀⠀⠀⠀
⠀⠔⢡⠞⠁⡎⠀⠔⠒⡄⠀⠀⠀⠀
⡎⢰⠃⠀⠀⡗⠄⠁⣀⠆⠀⠀⠀⠀
⠀⠁⢀⠃⠀⠣⡀⠀⠀⠀⠀⣥⠀⠱
⠀⠀⡂⢧⡀⠐⢌⣀⠀⠀⢀⡠⢠⢀
⠀⠀⠂⠀⠁⠀⠀⢐⠩⣏⣋⡸⠗⠊
⠀⠀⠀⠀⠀⠈⠉⡆⢡⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠑⠤⠔⠁⣸⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠥⠃⠀⠀⠀⠀
╔══════════════════════════════════════════════════════════════════════════════════════╗
║ DOXBIN ARCHIVE // ENTRY: ROBLOX-PRORECREATION ║
║ [ CONFIDENTIAL LEAK ] ║
╚══════════════════════════════════════════════════════════════════════════════════════╝
┌─────────────────────────────────────────────────────────────────────────────────────┐
│ 0x01 [ SUBJECT PROFILE ] │
└─────────────────────────────────────────────────────────────────────────────────────┘
ALIAS: Ale De
HANDLE: ProRecreation (Roblox / X)
OTHER AKAS: Adele, Addie, Ale de
THEAT LEVEL: MODERATE (Social Engineering)
STATUS: ACTIVE / MONITORED
ANALYST NOTE:
The subject is a known "trust trader" who operates within Roblox development circles.
Unlike mass-phishing bots, this actor manually targets developers, building rapport
before deploying malicious payloads. The subject is classified as a "Script Kiddie"
due to poor OPSEC (no VPN) and reliance on pre-made malware tools.
┌─────────────────────────────────────────────────────────────────────────────────────┐
│ 0x02 [ INFRASTRUCTURE & GEO-LOCATION ] │
└─────────────────────────────────────────────────────────────────────────────────────┘
ISP: Optimum Online (Cablevision Systems Corp.)
ASN: AS6128
IP V4: 68.193.8.167
HOSTNAME: ool-44c108a7.dyn.optonline.net
CONNECTION: Dynamic Residential Cable (DOCSIS)
LOCATION DATA:
─────────────────────────────────────────────────────────────────────────────────────
Country: United States (US)
State: New York (NY)
City/Metro: Bronx / New York City Metro Area
Zip Code: [Estimated: 104xx Range]
Coordinates: 40.83° N, 73.86° W
Timezone: America/New_York (EST)
RISK ASSESSMENT:
The IP is a standard residential connection. No VPN, Proxy, or Datacenter hosting
is detected. This implies the subject operates from a home environment in the Bronx
area, likely a teenager or young adult using a family internet connection. This makes
identification via ISP subpoena trivial if legal action is pursued.
┌─────────────────────────────────────────────────────────────────────────────────────┐
│ 0x03 [ TACTICS, TECHNIQUES & PROCEDURES (TTPs) ] │
└─────────────────────────────────────────────────────────────────────────────────────┘
PRIMARY VECTOR: Social Engineering + Malware Distribution.
STAGE 1: INITIATION
─────────────────────────────────────────────────────────────────────────────────────
• Subject infiltrates Discord servers or follows target devs on Twitter/X.
• Initiates conversation regarding Lua scripting, building, or game mechanics.
• Establishes "credibility" by sharing basic code snippets or offering "help."
STAGE 2: THE HOOK
─────────────────────────────────────────────────────────────────────────────────────
• Proposes a collaboration or asks the victim to "test" a custom plugin/tool.
• Often claims the file is a "Roblox Studio Plugin" (.rbxm) or a texture pack.
• Uses urgency or flattery to lower victim defenses ("I need your expert opinion").
STAGE 3: EXECUTION
─────────────────────────────────────────────────────────────────────────────────────
• Delivers a file via Discord file transfer or a shady file host (e.g., Transfer.sh).
• File is typically an executable (.exe, .bat) or a script containing a webhook.
• Payload:
- Cookie Stealers (targets .ROBLOSECURITY file).
- Discord Token Grabbers.
- Generic Remote Access Trojans (RATs).
STAGE 4: EXFILTRATION
─────────────────────────────────────────────────────────────────────────────────────
• Victim executes file.
• Credentials are sent to the subject's Discord webhook or private server.
• Subject drains account (Robux, Limiteds) or locks the victim out.
┌─────────────────────────────────────────────────────────────────────────────────────┐
│ 0x04 [ PLATFORM PRESENCE ] │
└─────────────────────────────────────────────────────────────────────────────────────┘
Platform Username Notes
─────────────────────────────────────────────────────────────────────────────────────
Roblox ProRecreation Primary account used for scamming.
Twitter/X [Unknown] Likely used for DMing developers.
Discord [Varies] Changes IDs frequently to avoid bans.
═══════════════════════════════════════════════════════════════════════════════════════
// END OF LEAK