Or if you dislike all kinds of ads like me, you may also like the NewPipe fork Tubular, which provides SponsorBlock integration.
TLDR: I can't say for 100% sure, but there are multiple reasons to believe that this is malware.
Long version: I'm seeing multiple suspicious things here.
-
The IPs being connected to are part of some hoster and have some abuse reports: https://www.abuseipdb.com/check-block/217.20.58.98/29
-
The domain being resolved is qcloud[.]com, which belongs to Tencent Cloud and definitely not Microsoft.
-
Other domains in memory like counter-strike[.]com[.]ua are very new and definitely sound fishy.
-
A standalone version of 7zip is being run and extracts the created rar file with the password "infected". Real alarm bells here.
-
A lot of the registry actions look like anti-debugging, which does not sound like something an Illustrator Plugin would do.
Not only do I not mind you yoinking the text, I want to thank you for your contribution to the cause. If everyone who has signed could get one more person to sign, the initiative would succeed!
This link should be working.
Quoting from the OP tweet:
* Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago.
* Full disclosure happening in less than 2 weeks (as agreed with devs).
* Still no CVE assigned (there should be at least 3, possibly 4, ideally 6).
* Still no working fix.
* Canonical, RedHat and others have confirmed the severity, a 9.9, check screenshot.
* Devs are still arguing about whether or not some of the issues have a security impact.I've spent the last 3 weeks of my sabbatical working full time on this research, reporting, coordination and so on with the sole purpose of helping and pretty much only got patronized because the devs just can't accept that their code is crap - responsible disclosure: no more.
85°C is still fine. You wouldn't want your system running at those temps all the time but if those are only spikes during intensive tasks, you're good.
If you want your PC to run a bit cooler, check your airflow, set manual fan curves, or try out a mild undervolt.
Cannot complain.
Spotted the German.
The screenshot is getting crispy, time to get it out of the deep fryer
TLDR: Avoid Telegram and WhatsApp. Recommended messengers are Session, Signal, SimpleX and Threema. Honorable mention: Briar.
He wants all kinds of pets, rubs and scritches. Belly rubs too, but please without touching the belly.


PSA: The Syncthing fork repo has very recently been taken by a new maintainer without notice from the old one. However, the new maintainer seems to be in possession of the old PGP keys, which has made a lot of community members cautious/suspicious.
Related forum thread in the Syncthing forums