VDB
GCVE-110-OSM-2026-8714
GCVE-110-OSM-2026-8714
Advisory PublishedCVSS 8.8/10
This package is a Telegram bot swarm tool designed for group flooding, chat takeover, and OSINT-based doxxing. This is a purpose-built Telegram abuse and doxxing toolkit published under a novelty anime theme to deflect scrutiny.
ENTRY
sankislayer/bot.py (console-script: "sankislayer=sankislayer.bot:main_run")
DESTINATION
- telegram-bot: 8670917633:AAHyYOvwq2J7KwP3m8UkG9jIWjY9V1suSLU (primary, plaintext) in sankislayer/bot.py
- telegram-bot: 8814064963:AAGBY_20bjJuEm6GMI1iz0WzzP9orUI4Qps (plaintext) in sankislayer/bot.py
- telegram-bot: 8856278072:AAEQLcRGPHMfxQoQpvVjB_5npBdJmgOU34g (plaintext) in sankislayer/bot.py
- telegram-bot: 8806837748:AAGsZiBuRF4P9jS7U-83DkCaS3NuRpeyPOg (plaintext) in sankislayer/bot.py
- telegram-bot: 8981300250:AAFtEgbpmxiT-5LF8HuQLvmi5Vf0bsja4Ag (plaintext) in sankislayer/bot.py
- telegram-bot: 8940953835:AAEK-9Ph5K8CEkDFzTYkhOGCPOmC4nTj96E (plaintext) in sankislayer/bot.py
- telegram-bot: 8992213913:AAGrwwfJlz1Sxb7g4U30aH6XamJ51wbMZp0 (plaintext) in sankislayer/bot.py
- telegram-bot: 8973071671:AAF1ErUkYkn3wEQLs7BgHRoicJ_W_tNL8D0 (plaintext) in sankislayer/bot.py
(+2 more)
OBFUSCATION
- Python Exec with Encoded Content in sankislayer/bot.py: "exec(base64.b64decode"
- Decoded Base64 Content in sankislayer/bot.py
- Base64 Encoded Payload in sankislayer/bot.py: ""IyEvdXNyL2Jpbi9lbnYgcHl0aG9uMwppbXBvcnQgYXN5bmNpbwppbXBvcnQganNvbgppbXBvcnQgb3M..."
- Deobfuscation Failed in sankislayer/bot.py
- recovered 9 urls, 10 domains, 1 paths from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Base64 Decoded Eval in sankislayer/bot.py: "exec(base64.b64decode"
- The entrypoint (`sankislayer/bot.py`) hardcodes 10 live Telegram bot tokens (e.g. `8670917633:AAHyYOvwq2J7KwP3m8UkG9jIWjY9V1suSLU`) and an OWNER_ID (`8756749479`), then uses `exec(base64.b64decode(PAYLOAD))` to load the full bot logic at runtime. The decoded payload implements coordinated spam loops (`/hinokamgi`, `/retsujitsu`, `/spam`) that use all 10 bots to flood Telegram groups at sub-10ms intervals, plus commands to promote bots to admin (`/promote`, `/hommie`), and OSINT lookups via attacker-controlled Workers.dev domains and `ft-osint-api.duckdns.org/api/numleak?key=freetill1` which leaks IMEI, MAC address, tower location, and identity data for Indian mobile numbers. The obfuscation layer (base64 exec) hides the full attack surface from static inspection.
PAYLOAD FILES
sankislayer/bot.py
INDICATORS (IOCs)
- domains: slayer.com, ig-adv.noobgamingv40.workers.dev, sc-avrg.noobgamingv40.workers.dev
- emails: sanki@slayer.com
- urls: https://ig-adv.noobgamingv40.workers.dev/info?username={username}, https://sc-avrg.noobgamingv40.workers.dev/info?user={username}, https://www.snapchat.com/add/{uname}, https://gh-avrg.noobgamingv40.workers.dev/info?user={username}, https://fb-adv.noobgamingv40.workers.dev/info?page={encoded_page} (+4 more)
- paths: /usr/bin/env
- payloadFileHash: 71f8f628b2cd8bcbf8e09cfd317bb5418499b7bec8fc3c019debcec1e457592d
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | sankislayer | all (affected) | — |
Aliases
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.