Games

Life and Nature isn't blessed, as claimed.

Założony przez mohammed2003 94 wpisy ostatni wpis 11 godzin temu Strona 5 z 5

#81

Ok Aiden.
I wish these people were bots though. Because the game is growing organically every week, just a few weeks ago there were about 100 players on a daily basis, now it's over 200 when there's literally nothing happening.
--
McOi

#82

He did, he did indeed drop the beloved number.
-- (rudolf):
did he just...
--

#83

no one cares about the player base if the game is bad. and its all bots

#84

mindblowing! I am overwhelmed.

#85

well yeah, I played STW since 2019 or 2018, then so 2022 to 2023 there was a phase where I quit playing it, to many bad memories, but 2024 to early 2025 i played a bit again.
404, Elten Signature not found.

#86

Was just reading through this thread and I am wondering what you found when running this thing on a vm. Could you give us a little more details on what you found besides cmd access?

-- (dennishelbig):
Hello there. Maybe I can clear a few things up here.

Yes, his name is Enes. I had several encounters with him, and in my opinion he has some pretty terrible ideals and has done some questionable things. Yeah, people always say not to judge someone by their past, but in this case, not enough time has passed for me to trust him again. No, just no.

I ran this game a few times inside a virtual machine while monitoring it with an inspection tool to see what it was actually doing. And honestly, that really freaked me out. There was the player data leak from real world in the past, and then there's the command prompt access... No thanks.

Actually, his payment scripts and mechanisms are very unsafe. You can simply enter the wrong player name, and it never gets verified, so you could end up paying for nothing just because of a typo.

Then he asked me on Telegram if I wanted to become a staff member, because a few years ago, back when I was in my "cloning" phase, I told him that I'd like to be an admin on one of his games someday. That was around four or five years ago. About six months ago, he asked me whether I was still interested. When I replied that maybe I would be someday, he actually offered to promote me if I paid him money first.

So, no. In my opinion, neither the game nor its developer are great, even today.

Yeah, I miss STW very much, but not enough to make me play random clones again. So yeah.
--
And that, is why you shouldn't do this.

#87 Edytowano

Good evening everyone. Well, for the people who doubted whether the rumors about NBM were true or not, I share with you something that has been spread through a reputable Spanish-speaking group called Tiflojuegos. I say nothing, yet I say everything. What the fuck is this? A backdoor virus in an NBM game? Well. 4 years exposing these people, and now they have the definitive proof.
With this introduction, I'm not trying to disrespect anyone. It's simply a general message, and my indignation isn't directed at the community.
Thanks to x0 and their message, I realized that the beginning was a bit aggressive and quite inappropriate. However, it was just a general comment that I had written for other people who actually fit into this discussion because of how they reacted, but I simply hadn't edited the message earlier.
WHAT WAS LOOKED AT
This folder holds source code that was recovered (decompiled) from ln.exe, the Windows program for the online audio game Life in Nature, run by AudioWander and NBM Studios. The recovery tool's manifest says the exe had the SHA-256 fingerprint 3a1ea0c1edeffbf991f6cacf94ef8dcaa06b93057938d353986e41a7862bf8b3, was built with the NVGT game engine version 0.90.0-dev, and was compiled on 15 September 2026 on a computer set to Turkish time.
Every one of the 120 source files was read, including every command the game server can send to the game. The included browse.html page and the manifest were also checked. Nothing was run. No files in the folder were changed except for adding this report.
THE SHORT ANSWER
This is not a classic virus. I found no code that steals browser data, saved passwords from other programs, documents, Discord tokens or crypto wallets. It does not spread to other computers, does not mine crypto, and does not set itself to start with Windows.
However, the game contains a real backdoor. It also has several behaviours that are sneaky or harmful to the rest of your computer. The most important points are:
1. The game server can make your computer run any command it wants, silently.
2. The game hides a tracking ID in ten places on your computer plus the Windows registry. Several of these use fake names made to look like Microsoft, Microsoft Edge, DirectX and NVIDIA files, so the ID survives even if you uninstall the game.
3. It sends your Windows user name, computer name, install folder and hardware identifiers to the server.
4. It deletes files that belong to other programs.
5. It refuses to run inside a virtual machine, which is a common trick to make the program harder to inspect.
6. The connection to the game server is not encrypted, and in some situations your password is sent in plain text.
My overall judgement is to treat this as potentially unwanted software with a remote command backdoor. Do not run it on a computer you care about unless you fully trust whoever controls the game servers, and anyone who could impersonate them.
MOST SERIOUS FINDINGS
1. Remote command execution (backdoor). Severity: critical.
In functions_031.nvgt, around lines 538 and 552, there are two server commands, "batcode" and "restart". When the server sends either one, the game takes the rest of the message, saves it as a Windows batch file at %USERPROFILE%\temp.bat (normally C:\Users\YourName\temp.bat), and runs it through explorer.exe.
There is no prompt, no warning and no check of any kind. A batch file can do anything your Windows account can do: download and run other programs, delete files, change settings, and so on. The batch file is not deleted afterwards, so if it exists on your computer, it is evidence that this command was used.
Because the game connection is not encrypted (see point 7), the danger is not limited to the official server. Anyone who can sit between you and the server could also send this command. That includes the operator of any relay server you choose in the game, one of which is built in and located in Iran.
2. Collecting system information, probably through the backdoor. Severity: high.
Around line 525 of the same file there is a server command, "systeminfo". It reads a file called info.txt from your temp folder and sends its whole contents to the server along with your character name.
The game itself never creates info.txt. The only way within the game for that file to appear is a batch script sent through the backdoor above. This strongly suggests the two commands are meant to be used together: one command writes information about your computer into the file, and the next one collects it. That is an inference, but it is the only use the code allows for.
3. Hidden tracking ID disguised as system files. Severity: high.
In functions_032.nvgt, lines 173 to 470, the game makes a random 24-character ID and writes it to all of these places:
%APPDATA%\AudioWander\.lfsig
%APPDATA%\.lfsig
%APPDATA%\Microsoft_Sync_Telemetry.dat
%TEMP%\.lfsig
%TEMP%\dxcache.tmp
%LOCALAPPDATA%\.lfsig
%LOCALAPPDATA%\msedge_update_cache.bin
%USERPROFILE%\.lfsig
%PROGRAMDATA%\.lfsig
%PROGRAMDATA%\nvcache.dat
It also writes the ID to the registry at HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTelemetryCache, as a value named MachineCacheId. That key is not a real Windows key; it is named to look like one.
Each time the game starts, if any single copy still exists, it rewrites all the others. The names Microsoft_Sync_Telemetry, msedge_update_cache, dxcache, nvcache and WinTelemetryCache are chosen to look like files from Microsoft, Edge, DirectX and NVIDIA, so people will not delete them. To reach the registry, the code calls Windows functions directly (RegGetValueA, RegCreateKeyExA, RegSetValueExA and VirtualAlloc) instead of using normal game engine features. The clear purpose is a ban-evasion tracker that survives uninstalling the game and deleting its folders.
4. Hardware and personal identifiers sent to the server. Severity: medium to high.
Each time you log in or create a character, the game sends a bundle of identifiers. It contains:
a hardware node ID from the engine (on Windows this usually comes from a network card's MAC address)
the hidden tracking ID described above
your Windows user name
the name of your audio output device
The code also has functions that read your Windows MachineGuid from the registry and the serial number of your C drive. The spots where these should be added to the bundle came out blank in the decompiled code, so it is not certain they are actually sent. It is clear they were meant to be.
Separately, every time you enter the game (functions_036.nvgt, line 359), it sends a "compinfo" message with your Windows user name, your computer name, and the full folder path of the game (which usually contains your real name or user name). The "newplayer" message also sends that path and an engine-generated computer fingerprint.
5. Deleting files that belong to other programs. Severity: medium.
While you are in the game, once every second (functions_015.nvgt, lines 361 to 372), it deletes every file ending in .dmp from your temp folder. These are crash dumps and memory dumps, and they can belong to any program, not just this game. This is an anti-analysis measure: it stops people saving a copy of the game's memory to study it. It also destroys other programs' crash reports. In many menus and dialogs, the game also deletes a file called lf.dmp from your temp folder every few milliseconds.
At startup, and then every 5 seconds while playing, it checks for a folder called "Cheat Engine" inside your temp folder. If it finds one, it deletes the whole folder and its contents and closes the game. At startup it also lists your Program Files folder, looking for folder names containing "cheat" or "engine". In the decompiled code the result of that scan is not used for anything.
At startup, the non-beta version also deletes a file called GameEngine.dll from the game folder.
6. Refuses to run in a virtual machine. Severity: medium.
At startup the game checks whether it is inside a virtual machine. If it is, it says "this game can not run in virtual machines" and quits. Virtual machines are what security researchers use to examine suspicious programs safely, so this makes the game harder to inspect. The check is an engine function whose inner workings are not visible in this source.
7. Unencrypted connection and plain-text password. Severity: medium to high.
The game talks to its server at nbmstudios.com (IP 5.9.25.153, port 10001) using the NVGT network system, and I found no encryption on it.
The login first tries a safer method that sends hashed values. But if the server does not answer within 3 seconds, the game automatically falls back to sending your user name and password in plain text, together with all the identifiers from point 4 (functions_024.nvgt, lines 455 to 457 and 363). A slow connection, a malicious relay, or anyone intercepting the traffic can trigger this fallback simply by holding back the server's reply.
One of the two account creation routes in the code also sends the password in plain text along with your email address. Even the hashed login values travel unencrypted, so anyone who captures them can try to guess the password offline.
8. Relay servers. Severity: medium.
The game can connect through relay servers instead of directly. One relay is built in, labelled "Iran relay 1", at 5.160.197.212 port 32000. More relays are downloaded from https://audiowander.com/ln/relayservers.txt, and you can also type in any server yourself. A relay is only used if you choose it.
A relay operator can see all your traffic, including a plain-text password if the fallback in point 7 happens. A relay operator could also send the backdoor command from point 1. Just opening the server list connects to every listed relay to measure ping, which shows your IP address to each relay operator.
9. Automatic updates run downloaded programs without checking them. Severity: medium.
At startup the game checks https://nbmstudios.com/ln/version.txt (or the same path on audiowander.com). If there is a newer version, it shows a message saying to press Enter to download, with no option to decline. It then downloads ln.exe, saves it as lntemp.exe and runs it. Nothing checks a digital signature or a hash of the downloaded program. The download uses HTTPS, which helps, but whoever controls those web servers decides what program runs on your computer.
There is a second update path: when the server sends a "newupdate" message and you answer yes, the game runs lfupdater.exe. There is also leftover code: after you change the sound output device in the settings, the game runs a program called lf.exe from its own folder, whatever that file happens to be, and then quits.
OTHER THINGS THE SERVER CAN MAKE THE GAME DO
Change your clipboard: the "clip" and "clipraw" commands replace your clipboard contents without asking. The game only reads your clipboard when you paste into it yourself, and never sends clipboard contents anywhere.
Delete your settings: the "deleteconfig" command deletes the folder %APPDATA%\nbm-studios, including everything in it, and closes the game.
Create hidden marker folders: the "testban" command creates two folders named "windows2" and "system" inside %APPDATA%, then shows "you have been kicked from the game" and quits. The names look like Windows folders. Nothing in the game reads them, so they are probably markers for something else to look for later.
Change your stored login: the "accountswitch", "newname" and "newpassword" commands replace the account name and password the game has saved.
Make the game send messages it did not write: the "echo", "echopacket", "sendcommand", "inv", "use", "itemtopla" and "usealt" commands make your game send back whatever text the server chooses. This means the server can make it look as if your client sent something.
Write language files: the "switchlang", "updatelang" and "langfileend" commands save a language file using a file name chosen by the server, without checking that name. A malicious server could use a name like ..\..\something to place a file outside the lang folder. The damage is limited: the name must end in .lng, cannot contain spaces, and the contents are scrambled before saving.
Other file and program actions:
"playerlog" writes a file called players.log in the game folder.
"update" relaunches the game.
"downloadsounds" opens https://soz-games.tk/tk/sounds.dat in your web browser.
"openurl" opens a web page, but only if it starts with https://audiowander.com/.
"storeopen" opens the AudioWander credit shop.
"killclient" closes the game.
"sapimessage" briefly saves a sound file with a random name in your temp folder, plays it and deletes it.
"upload" opens a menu of sound files from the game's upsounds folder; only the file you pick is sent.
"sndlen_q" asks the game how long certain game sounds are.
Pop-up prompts: commands such as "input", "repass", "addline", "editline" and "rename" open text boxes or password prompts at any moment, and send whatever you type. A text box opened by "input" can also be set to send its contents automatically, without you pressing Enter.
No server command turns on your microphone.
PRIVACY AND WEAK SECURITY (NOT MALICIOUS, BUT WORTH KNOWING)
Saved password: your account name and password are saved in %APPDATA%\AudioWander\config.dat. The file is encrypted, but the key is written in the program itself ("turkeyarepowerthanallcountryesAudioWander"), so anyone or any malware with a copy of the game can decrypt it. If you use the same password anywhere else, change it there.
Other keys built into the program: "regpacket32" and "bombedoclahoma1995" for the old license system, "voice_vol_key_123" for voice volume settings, and another fixed key for language files. The game proves it is the "original" client by sending the fixed text "iamoriginal1234567890", which anyone can copy.
Typing signals: while you are connected, every key you type in a game text box sends a small "typing sound" message to the server. This is on by default, and it includes in-game password change boxes. The letters are not sent, but the message does show when you type, how much, and whether each key was a space, a number or something else.
Old license code: there is leftover license code copied from another game called "The Killer" by IMS Productions, using the license server AudioWander.cf port 45530. Its "email this key" option sends your email address, name and license key over plain, unencrypted HTTP to http://breaker-originals.tk/lf/mail.php, a free .tk domain that has nothing to do with the game's main websites. The same code sends your computer name when it checks a license. The client also contains license admin commands (generate, list, ban and delete keys); whether the server checks who is allowed to use them cannot be seen here.
Old outside domains: when the game cannot reach its server in some menus, it fetches a message from breaker-originals.tk over plain HTTP and reads it to you. Free .tk domains are often abandoned and taken over by strangers, and whoever holds that domain now can show you any text and see your IP address. Unused code also points at soz-games.tk, ims-productions.com and two bare IP addresses, 91.224.23.174 and 2.59.117.88.
Voice chat: the microphone is only opened when voice chat is turned on. The setting that allows it is on by default. In the default toggle mode you press V to start, and the microphone then stays live, even when the game window is in the background, until you press V again. In push-to-talk mode, which you get by pressing Shift+V, it only records while V is held. If voice chat was on when you got disconnected, it turns back on automatically when you reconnect. Audio only goes to the game server or relay you are connected to.
Macro detector: if you press the arrow keys, T or I more than 15 times in a row, faster than 50 milliseconds apart, at an extremely regular rhythm, the game quietly reports "cheatengine" to the server. A very steady key repeat could in theory trigger it.
Music boxes: in-game music boxes stream audio over plain HTTP from nbmstudios.com port 7790.
Server code upload: the source contains a developer menu that uploads a replacement copy of the whole server program over the game connection. It cannot be reached in the released exe. If the server does not check who sends that upload, that is a hole on their side.
FILES AND SETTINGS THE GAME CREATES OUTSIDE ITS OWN FOLDER
The hidden tracking ID files and registry value listed under finding 3.
%USERPROFILE%\temp.bat, only if the server has used the backdoor command.
%APPDATA%\AudioWander, which holds config.dat (your settings and saved password), motdhash.dat and a few small settings files.
%APPDATA%\windows2 and %APPDATA%\system, only if the "testban" command was received.
Short-lived sound files named sapiMsg_ followed by random characters in %TEMP%.
Inside the game folder it may also create lang, sounds, logs and upsounds folders; sounds.dat and related download files; sndver.txt; voice_volumes.dat; and, only if you turn the matching options on, buffers.sav (saved chat history in plain text) and a few debug logs.
Oxidia Studios

#88 2 polubienia

Some routine things and some not so much things. I'm going to comment on some of these, do not take me as defending them, because I'm not.
The idea of storing persistent identifiers on your machine in response to a ban command was IIRC originated with STW and some other games, called hardban. Machine IDs are used in banning systems, which any audiogame uses in some form, including SBYW.
The ability to set the contents of the clipboard via a packet is used when copying anything the server knows. SBYW, of course, uses this for the output of rawmap. It's possible this packet is actually used by builders. I would be more concerned if you found a packet to *read* the clipboard.
The echo commands are not harmful on their own. They mostly serve as a shortcut to avoid code duplication when packet handlers are organized in known ways. SBYW has them and uses them for some of its commands and menus, and their lineage goes back to ultrapower at least.
As for sending passwords across, it's stupid that they do so over an unencrypted channel, are you actually saying they figured out a system to not do so? You can never send a hash to the server, because the server has to authenticate it! You could send a session token though, or use a challenge response system. If they're using one of those, that would put them somewhat unique among most BGT and NVGT games. Storing your username and password in an encrypted config file is unfortunately the price you pay for keeping credentials on someone's machine, and those change account info packets are almost certainly to deal with password resets and the like to nicely fix your config for you, just like SBYW does.
Also I'm almost certain that SAPI packet to the temp folder is for their equivalent of TTS chat.
Now the rest. I proved the TK lineage some time ago via the distinct signature of vehicle packets for a system I designed, which someone posted in a message earlier in this thread. vespawning, vestart, vepitch, vestop, veunspawn, lowfuel, vehicle_lowfuel.ogg, goodfuel, etc. Especially in that order, possibly with vesiren, that's my actual vehicle system in a game that doesn't have vehicles. Ims-productions.com left in the game code is perhaps the most blatant admition, and I swear i've seen the string bombedoclahoma1995 somewhere in Ivan's code for registration.
And. Arbitrary batch files? Really? That is definitely unique. Those genuinely could run anything, including shunting to PowerShell when they need more power to download programs or whatever. Shit happens all the time. Also, deleting files that other programs may have written? Crash dumps saved by Windows and who knows what else? Literally refusing to run if cheat engine is *installed*, not even being used? NVGT has the capability to detect its usage, sort of, and they could have obfuscated important variables besides!
I wouldn't trust them either, the fact that someone put in the capability to run arbitrary commands compounding with the fact that they feel free to just delete who knows what, have clearly leftover domains that could be used to distribute malware to their players, and that the developer is an actual liar. He didn't just use an unauthorized code fork. He claimed he wrote it all from scratch, a blatant lie.
I also have nothing to say about any of their history and how trustworthy they've proven from that, as I wasn't involved or even knew about any of it.
Just my two cents. Not everything you see is proof of malice, which is why I commented on some of the first bits. But that doesn't make the totality not suspicious. I just think your outrage should be directed at the right things and not turned on the rest of us when you realize that we happen to use some of the same patterns listed above for legitimate reasons.


This mesage has been approved by x0.

#89 Edytowano

I agree with the first points mentioned, but the other is, to say the least, strange. I simply decided it was good to talk about this, since these things affect the entire community.
I find this particularly worrying.
Oxidia Studios

#90

oh. Holy. Crap. They did all this? Storing passwords, in plane text? Good luck getting back all that info now. Just goes to show how much of a scumbag that arnold (smith/enes?) Can be sometimes with this... Glad I never downloaded LN. Did they do something like this in reelworld? What did they do in that game / what commands could they send? And at this point this guy isn't even trying to hide the fact that this game is susspicious, because you can't run it in a VM, I even remember being able to run ultimate life on windows frickin 7!! Are you serious... I wouldn't be surprised if they send passwords from any other characters you have saved in the game, as well as not only your main chat history. But also your PM's, the say thing that is like the sapi, and put all that stuff in a log... What other things could this idiot do with your CMD?
signed, Mayowa Arogundade

#91

They do log and read your pms, yes. I got a warning due to a pm as it contained a link.
Signed by Muhammad.

#92

getting a warning just because of a link? Really? Remember kids, don't play clones that are a virus and can hack your computer. This is Mayowa and I aprove this Message
signed, Mayowa Arogundade

#93

Actually the warning was valid, as links are disallowed as per their rules. The thing is, I didn't post a game, I was posting an office course for someone who wanted to learn this summer. They pmed me and told me they don't want to allow links as they fear viruses. If they allowed mine, they'll need to allow others. Later, they have a filter that checks for links.
Signed by Muhammad.

#94 3 polubienia

Hahahahaha the irony is insane.