vx-underground
46.2K subscribers
3.96K photos
423 videos
84 files
1.45K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
It appears Microsoft accidentally published some dev code to prod. It unveiled Bing plans on soon implementing ChatGPT into their search engine. Microsoft has reverted the push, however Owen_Yin managed to take some images of the new search engine.

tl;dr Bing coming for Google
๐Ÿ”ฅ34๐Ÿฅด6๐Ÿคฉ3๐Ÿฆ„2
vx-underground
It appears Microsoft accidentally published some dev code to prod. It unveiled Bing plans on soon implementing ChatGPT into their search engine. Microsoft has reverted the push, however Owen_Yin managed to take some images of the new search engine. tl;drโ€ฆ
Reminder Microsoft laid off 10,000 people and invested $10,000,000,000 into ChatGPT just a few days later

tl;dr tl;dr Microsoft making power moves
๐Ÿคฃ46๐Ÿ”ฅ5๐Ÿฆ„2๐Ÿพ1
New vx-underground art by deinacrida_art
๐Ÿ”ฅ80โคโ€๐Ÿ”ฅ10๐Ÿ‘9โค6๐Ÿ–•2๐Ÿฆ„2๐Ÿคก1
This media is not supported in your browser
VIEW IN TELEGRAM
The United States Air Force has deployed a Lockheed Martin F-22 Raptor and shot down the Chinese spy balloon.

R.I.P Chinese spy balloon. Gone but not forgotten.

Footage via some random dude in South Carolina who has received no credit from CNN or Twitter
๐Ÿคฃ53๐Ÿซก21๐Ÿ‘4๐Ÿฆ„3
๐Ÿ•Š65๐Ÿซก36๐Ÿ˜9๐Ÿคช6๐Ÿ‘3๐Ÿคก2๐Ÿคฃ2๐Ÿฆ„2๐Ÿ˜ข1๐ŸŒš1
โค57๐Ÿคก13๐Ÿ˜4๐Ÿฆ„3๐Ÿ‘1๐Ÿ–•1
We are nearly finished with our second large scale project.

We have assigned a date-of-release to every paper in the vx-underground collection (with the exception of the Archive section). Ideally, this will be completed in the following week.

tl;dr you can see find newer papers
๐Ÿ”ฅ13๐Ÿ‘4๐Ÿฆ„1
๐Ÿ˜38๐Ÿคฃ17๐Ÿฆ„3๐Ÿ˜ข2
Julius Kivimรคki, a member of Lizard Squad, has been arrested (again). He was previously arrested in 2015 on 50,000 counts of computer crimes

He has been arrested in France and is soon to be extradited to Finland for extorting a therapist center in 2020

Intel via RecordedFuture
๐Ÿคก60โšก4๐Ÿ‘จโ€๐Ÿ’ป4๐Ÿ‘2๐Ÿฆ„2
The recently identified ESXiArgs ransomware group has infected hundreds of ESXi hosts across the globe with a CVE-2021-21974 spray-and-pray.

Numbers vary, but Shodan queries from various researchers show an est. 300 - 500 ransomed entities this weekend.

tl;dr TA like:
๐Ÿ‘14๐Ÿ˜6๐Ÿ˜2๐Ÿฆ„2๐Ÿ˜ฑ1
This media is not supported in your browser
VIEW IN TELEGRAM
"VXUG gives a voice to Threat Actors"

"VXUG has sold out, they charge for access to the MWDB"

"VXUG tweets too many memes"

"VXUG swears too much in their tweets, its unprofessional"

"VXUG made a Threat Intel feed, they're helping White Hats"
๐Ÿ”ฅ26๐Ÿคฃ19๐Ÿฆ„2
We would like to offer our deepest condolences to all of our friends and colleagues in Turkey who have been affected by the recent 7.8 magnitude earthquake.
๐Ÿ™77๐Ÿ‘6โค3๐Ÿคก1๐Ÿฆ„1
We've updated the vx-underground Windows malware paper collection

2023-01-23 - Exfiltrating data using Powershell and WAV files
2023-01-24 - Persistence via VSCode Profile Abuse
2023-02-03 - Windows Domain Controller NTDSUTIL activate instance abuse

https://www.vx-underground.org/windows.html
๐Ÿ”ฅ15๐Ÿ‘2๐Ÿคก1๐Ÿฆ„1
Turkey and Syria have been struck by 2 large earthquakes.

Thousands are suspected to be dead.

Thousands remain missing.

We encourage all individuals to donate to any humanitarian effort which can assist those affected by the earthquakes.

We have donated to Doctors w/o Borders.
โค99๐Ÿ™12๐Ÿ˜ข9๐Ÿ‘3๐Ÿ˜2๐Ÿฆ„2๐Ÿฅฑ1๐Ÿ—ฟ1
Google has announced they are creating a competitor to ChatGPT named "Bard". This comes shortly after Microsoft unveiled it is integrating ChatGPT into their Microsoft Bing search engine.

https://www.cnbc.com/2023/02/06/google-announces-bard-ai-in-response-to-chatgpt.html
๐Ÿคก38๐Ÿ‘5๐Ÿฆ„2๐Ÿคฎ1๐Ÿ‘€1
We've updated the vx-underground Windows malware paper collection

- 2021-05-12 - Breaking the WDAPT Rules with COM
- 2022-12-08 - Hooking System Calls in Windows 11 22H2 like Avast Antivirus
- 2023-02-06 - Diving Deeper Into Pre-created Computer Accounts

https://www.vx-underground.org/windows.html
๐Ÿ‘8๐Ÿคก2๐Ÿ˜ˆ1
On the Windows OS the data type BOOL is not the same as data type BOOLEAN
๐Ÿ˜ฑ29๐Ÿคก26๐Ÿ˜10๐Ÿ‘1๐Ÿ’ฏ1๐Ÿ˜ˆ1๐Ÿฆ„1
POV: You're at Microsoft and you describe a BOOL as having more than a TRUE/FALSE state ... or a BOOL as 0 or -1
๐Ÿคก47๐Ÿคฏ8๐Ÿ˜5๐Ÿคฃ2โคโ€๐Ÿ”ฅ1๐Ÿ‘1๐Ÿ˜ˆ1
If the function BindIoCompletionCallback fails you can use GetLastError to get extended information on why the function failed. The documentation states GetLastError will return an NTSTATUS error code and you should use RtlNtStatusToDosError to get the system error code.

???
๐Ÿคฏ18๐Ÿคฃ3โคโ€๐Ÿ”ฅ2๐Ÿ‘Ž1๐Ÿ‘1๐Ÿ˜ˆ1
mdyOzQThJn0TyX+LVlwEp8xdC+KiZb4dvJoJ4/U2FznS4AI7FI7L3ezZKUSxSGxeHXp4wsFPqWWKuVqgoUBdVxjBQy5hVFOa2GWTarURNoSwsPD4diuDf/N8l+vVhSnd4zQpMRMx/P43H2TOoJBQrUjtkjbsy3MbUBY+/baaDn4sAbK32Cr6RrngAghisvVukLwuA6uqxEbjW6cZRTtXfjKUvlzpPPqwBo9EnwPs/Y8=
๐Ÿค”22๐Ÿคฃ5๐Ÿ‘4๐ŸŽ‰2๐Ÿคก2๐Ÿ˜ˆ1