I stumbled across this on GitHub yesterday. It looks completely AI generated and the download URL seems to be a redirect link, although Google Chrome blocks the URL that the redirect leads to. Here is the GitHub article in question: https://github.com/Golly-Cellular-Automata-Simulator/
Let me know if I should remove the URL from this post and I will.
Is this a scam involving Golly?
Is this a scam involving Golly?
Puffer Suppressor
Would we be able to know when we know everything there is to know?
How would we know what we don’t know that we don’t know?
The (34,7)c/156 caterpillar is finished!!! You can download it here.
Would we be able to know when we know everything there is to know?
How would we know what we don’t know that we don’t know?
The (34,7)c/156 caterpillar is finished!!! You can download it here.
- I6_I6
- Posts: 999
- Joined: July 26th, 2025, 8:44 pm
- Location: Here, there, somewhere, anywhere, everywhere.
- Contact:
Re: Is this a scam involving Golly?
Yeah, it looks like an unauthorized copy.PC101 wrote: July 7th, 2026, 1:33 pm I stumbled across this on GitHub yesterday. It looks completely AI generated and the download URL seems to be a redirect link, although Google Chrome blocks the URL that the redirect leads to. Here is the GitHub article in question: https://github.com/Golly-Cellular-Automata-Simulator/
Let me know if I should remove the URL from this post and I will.
Code: Select all
#C [[ THEME Golly ]]
x = 27, y = 15, rule = LifeHistory
8.A$A6.A.A$3A4.BA2B.B2D$3.A4.2B.2B2DB$2.2A2.3B.6B2.3B$2.20B$4.19B$4.2B
C10BD4B$4.2B2C10BD4B$4.B2C11B2D3B$4.13B2D4B$5.12BD3B.B2A$6.13B3.BA.A$
6.3B.B3.B10.A$25.2A!
Re: Is this a scam involving Golly?
My ISP had issues with the site, so I downloaded it over a VPN. It redirects to a suspicious URL which doesn't even have a homepage (I'm not posting the domain here for obvious reasons, but the path was /2k2pyhygfuju/golly-cellular-automata-simulator.github.io/), and downloads a ~110 MB zip file.
The zip file contained the following:
The zip file contained the following:
- A potential GPL violation; the attached "Inn_License.txt" file was the "OPEN INNOVATION LICENSE", but since Golly is GPLv2, I believe this would be a violation if it is legitimate.
- A PNG which is just the GitHub logo named "giti_icon.png". (?)
- Four DLLs, named "database_driver.dll" (???), "ProfilerTools.dll" (??), "vsdebugeng.dll" (?????), and "webservices.dll" (???).
- A 23KB executable which doesn't even seem to call any of the aforementioned DLLs. VirusTotal identified it as vsdbg.exe, which is an official MS file. It also identified the other DLLs as legitimate and from MS. I have absolutely no idea what happened here.
User:PK22
Learning miscellaneous programming languages.
Learning miscellaneous programming languages.
Re: Is this a scam involving Golly?
I just did some more testing, as it turns out there are 2 redirect URLs which I will refer to as URL A and URL B.PK22 wrote: July 7th, 2026, 4:11 pm My ISP had issues with the site, so I downloaded it over a VPN. It redirects to a suspicious URL which doesn't even have a homepage (I'm not posting the domain here for obvious reasons, but the path was /2k2pyhygfuju/golly-cellular-automata-simulator.github.io/), and downloads a ~110 MB zip file.
The zip file contained the following:I have reported the user who contributed to the GitHub repository.
- A potential GPL violation; the attached "Inn_License.txt" file was the "OPEN INNOVATION LICENSE", but since Golly is GPLv2, I believe this would be a violation if it is legitimate.
- A PNG which is just the GitHub logo named "giti_icon.png". (?)
- Four DLLs, named "database_driver.dll" (???), "ProfilerTools.dll" (??), "vsdebugeng.dll" (?????), and "webservices.dll" (???).
- A 23KB executable which doesn't even seem to call any of the aforementioned DLLs. VirusTotal identified it as vsdbg.exe, which is an official MS file. It also identified the other DLLs as legitimate and from MS. I have absolutely no idea what happened here.
The first URL you can see by hovering over the "Download Installer" button and looking to the bottom left of Google Chrome (most browsers should display the URL in a hyperlink if you hover over the hyperlink element with your mouse). This URL is a .github.io URL. I will call this URL A.
When someone clicks on the "Download Installer" button, it redirects to URL A and then redirects to URL B almost immediately. URL B is also a .github.io URL where you see that webpage that lasts a few seconds that says "Validating Session.
After a few seconds, URL B redirects to URL C, which is a .com website. URL C is the URL that my Google Chrome automatically blocked with this error: ERR_SSL_PROTOCOL_ERROR
I'm hesitant to post the actual URLs because I don't think that's a good idea so that's why I referred to them as URL A, URL B, and URL C.
Since URL A and URL B are both .github.io URLs I decided to investigate the GitHub users behind them since most GitHub URLs are just username.github.io.
The users behind URL A and URL B both have 1 repository each called ".github", which is responsible for hosting the URLs via GitHub pages.
Both repositories have 2 files: a 404.html file and a README.md file. Normally a website is supposed to have index.html as it's home page/main page.
The 404.html in the code of URL A contains code that redirects to URL B. The code in URL B contains code that I don't really understand, but I know that when a user visits the website in URL B they eventually get redirected to URL C (the .com website).
If any Golly developers want I can send you the URLs via direct message if it will help investigate this.
Puffer Suppressor
Would we be able to know when we know everything there is to know?
How would we know what we don’t know that we don’t know?
The (34,7)c/156 caterpillar is finished!!! You can download it here.
Would we be able to know when we know everything there is to know?
How would we know what we don’t know that we don’t know?
The (34,7)c/156 caterpillar is finished!!! You can download it here.
- NNlk05
- Posts: 602
- Joined: January 14th, 2026, 8:42 pm
- Location: Exploring in the Jungle of the INT Rulespace
- Contact:
Re: Is this a scam involving Golly?
The thing is, many FOSS projects are getting attacked by LLM websites scams, including 2 projects in a-hem my other field of expertise.
I can name the names if you PM me...
What I did it:
EDIT:
EDIT2:
Output of strings:
The site wrote: Not affiliated with [REDACTED]. This is an independent site providing documentation, guides and links to the official project repositories. For official releases visit GitHub
I will not name any names (or URLs). I'm just going to say that we had a good laugh over this.I wrote: !! WARNING !!: DO NOT TRUST [REDACTED].COM!!! IT IS A VIBECODED, COOKIE CUTTER, GARBAGE QUALITY, SCAMSITE, WITH SEO STUFFING!!!! I WILL NOT BE SURPRISED IF THE AUTHOR CHANGE THE DOWNLOAD LINK TO MALWARE!!!! D-O-N-T-U-S-E-I-T!!!!!!
I can name the names if you PM me...
What I did it:
- Warned the author of the tool.
- Reported the site to Google because keyword stuffing.
- Reported the Github user and repo.
I'll take a look at the ZIP next using a decompiler./j6az9yojhnhg/golly-cellular-automata-simulator.github.io/ wrote: Golly Cellular Automata Simulator
Content package for golly-cellular-automata-simulator.github.io
...
Authorized Access
...
VirusTotal Approved
...
EDIT:
The ZIP wrote: giti_icon.png (GitHub logo.)
golly-cellular-automata-simulator-github-io-3.97.3.exe (???)
Inn_Agreement.txt
Inn_License.txt
*DLLs*
Inn_Agreement.txt wrote: DYNAMIC COMMONS AGREEMENT
THIS LICENSED MATERIAL IS FURNISHED SUBJECT TO THE PROVISIONS OF THIS DYNAMIC COMMONS AGREEMENT ("DCA"). ANY HANDLING OF THE LICENSED MATERIAL, INCLUDING BUT NOT LIMITED TO OPERATION, REPRODUCTION, OR REDISTRIBUTION, CONSTITUTES THE RECIPIENT'S COMPLETE AND UNCONDITIONAL ACCEPTANCE OF ALL DCA TERMS, REGARDLESS OF WHETHER THE RECIPIENT HAS EXAMINED THEM. THE TERMS "LICENSED MATERIAL" AND "RECIPIENT" ARE DESCRIBED IN SUBSEQUENT SECTIONS.
This is really weird, 100% GPL violation.LLM (I don't read Legalese) wrote: The text you provided is the introductory paragraph of the Dynamic Commons Agreement (DCA).
The DCA is a specialized, open-source-style public license typically used for sharing, operating, and distributing technical or digital assets (such as software, data, or specialized hardware designs). It functions similarly to more famous public licenses like Creative Commons (CC) or the GNU General Public License (GPL) by establishing an automatic, legally binding contract with anyone who interacts with the licensed material. [1]
## Key Aspects of the DCA License:
* Adhesion Contract: It uses "shrink-wrap" or "click-wrap" logic. Simply handling, operating, replicating, or redistributing the material acts as your complete, unconditional signature—even if you never read the text.
* Licensed Material: This refers to the specific software, data, or technical content provided under this agreement.
* Recipient: This applies to any third party who downloads, receives, or interacts with the material.
EDIT2:
Output of strings:
Code: Select all
!This program cannot be run in DOS mode.
Rich
.text
`.rdata
@.data
.pdata
@.rsrc
@.reloc
UVWH
D$8H
T$0A
|$01u
f9l$2u
x8E3
L$8H3
\$pH
@_^]
t!eH
uxHc
uTL+
J
L;
\$@H
t$HH
t$ WH
ntel
ineI
Genu
t(=`
t!=p
w$H
D$ $
D$ "
D$ "
D$ H
\$(3
l$0H
t$8H
u0HcH<
;csm
\$03
H3E
\$PH
\$0H
\$0H
RSDS
D:\a\_work\1\s\bin\Release\CoreDebugger\x64\vsdbg-exe.pdb
GCTL
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.gfids
.rdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.idata$2
.idata$3
.idata$4
.idata$6
.data
.bss
.pdata
.rsrc$01
.rsrc$02
__C_specific_handler
__current_exception
__current_exception_context
VCRUNTIME140.dll
free
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
__setusermatherr
_configure_wide_argv
_initialize_wide_environment
_get_initial_wide_environment
_initterm
_initterm_e
exit
_exit
_set_fmode
__p___argc
__p___wargv
_c_exit
_register_thread_local_exe_atexit_callback
_configthreadlocale
_set_new_mode
__p__commode
terminate
api-ms-win-crt-heap-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
SetErrorMode
GetEnvironmentVariableW
IsDebuggerPresent
Sleep
SetUnhandledExceptionFilter
GetModuleHandleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
KERNEL32.dll
Initialize
InitializeSession
RunMainLoop
ShutdownSession
Shutdown
vsdbg.dll
memcpy
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1"><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS></application></compatibility></assembly>
N0L0
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 20110
250619182137Z
260617182137Z0t1
Washington1
Redmond1
Microsoft Corporation1
Microsoft Corporation0
JHur
SA|Q8
$W$-
u|^P
1jcNd
:081
Microsoft Corporation1
230012+5053590
M0K0I
Chttp://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
U0S0Q
Ehttp://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
.,Lv\
'.=NN
)Yk|
@]5b
8%Y0
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20110
110708205909Z
260708210909Z0~1
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 20110
nd5x
!t%_
'(8%
!K>R
x X,
S0Q0O
Ihttp://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^
R0P0N
Bhttp://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0
3http://www.microsoft.com/pkiops/docs/primarycps.htm0@
e_.,>
D=xz#
*?*kXIc
QEX82q'
,: i
WqVNHE
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 2011
4;BGbT
http://www.microsoft.com0
GPl:
*-p
20260309165254.883Z0
Washington1
Redmond1
Microsoft Corporation1%0#
Microsoft America Operations1'0%
nShield TSS ESN:3703-05E0-D9471%0#
Microsoft Time-Stamp Service
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
250130194257Z
260422194257Z0
Washington1
Redmond1
Microsoft Corporation1%0#
Microsoft America Operations1'0%
nShield TSS ESN:3703-05E0-D9471%0#
Microsoft Time-Stamp Service0
N705
`k@H5
F3}$
SC_P
X0V0T
Nhttp://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l
`0^0\
Phttp://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0
DyD!
0[P%0
&@Dj
<y[g
Pz+)
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20100
210930182225Z
300930183225Z0|1
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
`}jR
q\Q17
&S|9a
0\O,
s=CN
!]_0t
\RQ]
<F5)
U0S0Q
0A0?
3http://www.microsoft.com/pkiops/Docs/Repository.htm0
O0M0K
Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
N0L0J
>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
>NGdx
fg:SM
xSu$W
as.,k{n?,
J>f;O
ctH,
WITd
!TkjE
Af=i
AI~~
$5g+
'B=%
tt[j
pcSM
Washington1
Redmond1
Microsoft Corporation1%0#
Microsoft America Operations1'0%
nShield TSS ESN:3703-05E0-D9471%0#
Microsoft Time-Stamp Service
~0|1
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
20260309091101Z
20260310091101Z0t0:
1,0*0
1(0&0
#vF=
86n`
~&V54QC{
,A=_M
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
~0|1
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
<8z0
3)H@
Feci quod potui, faciant meliora potentes.
https://nnlk05.github.io
=3
Code: Select all
x = 10, y = 3, rule = B34twz/S23
b2o4b2o$obo4bobo$2bo4bo!
[[ AUTOSTART AUTOHIDEGUI TRACK 0 -47/270 ZOOM 4 GPS 45 STEP 3 THEME BOOK ]]
=3
Re: Is this a scam involving Golly?
Hey it looks like the URL no longer exists. I just tested it right now and it returns a 404 error, so it looks like reporting it worked.
That being said, I still have the URLs I mentioned before. They both contain GitHub URLs and the users behind them still exist. Like I said earlier, I can still DM them to relevant people if they want me to because:
1. I don't want the URLs to be gone if I delete them. If these same users try something else, they will still be accessible here.
2. I'm not sure if putting the URLs on this post is a good idea even though the URLs I saved are only on GitHub.
That being said, I still have the URLs I mentioned before. They both contain GitHub URLs and the users behind them still exist. Like I said earlier, I can still DM them to relevant people if they want me to because:
1. I don't want the URLs to be gone if I delete them. If these same users try something else, they will still be accessible here.
2. I'm not sure if putting the URLs on this post is a good idea even though the URLs I saved are only on GitHub.
Puffer Suppressor
Would we be able to know when we know everything there is to know?
How would we know what we don’t know that we don’t know?
The (34,7)c/156 caterpillar is finished!!! You can download it here.
Would we be able to know when we know everything there is to know?
How would we know what we don’t know that we don’t know?
The (34,7)c/156 caterpillar is finished!!! You can download it here.