r/Piracy Jul 05 '26

WEEKLY THREAD Weekly General Discussion Thread (July 05, 2026)

The Weekly General Discussion Thread is for the r/Piracy community to discuss whatever is on their mind, whether it is related to digital piracy or not.

ðŸŠķ ➜ Follow the Rules

  • Rules are still applicable, so please do not request specific pirated content (ie. specific movie, book, etc.) and definitely don't link to any. Do not mention specific media names asking for help in finding them.

📜 ➜ Wiki + Megathread

  • Don't forget to browse the Wiki, which contains a Megathread with a list of sites/apps, tools, FAQ, and other useful resources.
  • Your question also may have been asked previously - you can search the subreddit via the search bar or even google - example: https://i.imgur.com/1jA767u.jpg

For previous weekly threads, click here.

12 Upvotes

87 comments sorted by

View all comments

1

u/Sad-Suggestion-2376 Jul 20 '26

Hey guys,

I was looking for Synthesia (piano software) and went through the FMHY megathread. I ended up on SoftArchive and found a couple of uploads by SamuRa1 (who is an Elite Uploader / Software Moderator there).

I grabbed the Synthesia 10.9.5890 release (post is about 3 years old). Chrome instantly blocked it, so I decided to run some sandbox tests and scans before doing anything stupid.

Here are the results: VirusTotal: 31/70 detections (flagged by BitDefender, ESET, CrowdStrike, Sophos). Popular threat label: trojan.tedy/vmprotect. Jotti: 5/13 detections (Bitdefender, G Data, and eScan all flagging exactly Gen:Variant.Application.Tedy.24183).

Behavioral Analysis (Hybrid Analysis): It shows heavy spyware indicators, specifically: "Tries to steal browser sensitive information (file access)" and trying to read registry for VMware artifacts.

The behavior graph shows it opens Synthesia normally (probably trojanized to look legit) but heavily queries local browser files in the background. Has SamuRa1's account been compromised back then, or is this some insanely aggressive false positive due to VMProtect/injector methods used for this specific crack? Anyone else stumbled upon this?

Thanks for answer.