vx-underground
46K subscribers
3.95K photos
420 videos
83 files
1.44K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Cloudflare is cool and badass
πŸ€“91πŸ”₯13🀣12❀‍πŸ”₯4🀯4πŸ₯°3πŸ‘2😒2πŸ€”1
If you don't have a Valentine for Valentine's Day, we'll be your Valentine.
❀124🀣30❀‍πŸ”₯11😘6πŸ‘5πŸ₯°1
We've updated the vx-underground Malware Analysis collection. We've added 86 new papers.

Thanks to our friends over at @malpedia for helping us stay up-to-date every month.

Check it out here: https://vx-underground.org/Papers/Malware%20Defense/Malware%20Analysis
❀‍πŸ”₯14πŸ₯°4
We apologize if you visit vx-underground and you're greeted with a Cloudflare waiting room (queue system).

We've been getting DDoS'd for the past 7 hours+, the longest we've ever been DDoS'd

tl;dr toothbrush's all across the globe have begun attacking us
🀣187πŸ€“17❀‍πŸ”₯5😁5πŸ‘2πŸ”₯2🀯2😱2❀1
Some nerd is visiting vx-underground, with a wilderness background, to bamboozle us into believing they're outside.

We should have known Apple Vision Pro nerds wouldn't go outside 😑
🀣122πŸ€“13😎7πŸ”₯5😁3πŸ‘2❀1πŸ‘1
Hello,

As is tradition, we accidentally did an oopsie. Our search function is botched and downloads on files aren't working. We pushed some code to prod without actually testing if the file download part worked.

Testing code before pushing to prod is for nerds

Thanks,
πŸ‘84πŸ€“44🫑17πŸ‘6πŸ’―6❀5🀣3πŸ”₯1
The new Windows 11 sudo.exe is displaying something strange in IDA πŸ€”πŸ€”πŸ€” what could it mean
🀣103πŸ€”13πŸ”₯8🀯7😱5πŸ₯°2❀1πŸ‘1
Today James Forshaw (tiraniddo) did a quick assessment on the new Windows 11 Sudo.exe.

Despite his quick assessment, the blog post is wonderful. It is an excellent read. We recommend it:)

tl;dr fancier ShellExecute 😭

https://www.tiraniddo.dev/2024/02/sudo-on-windows-quick-rundown.html
🀣47πŸ‘12
We've updated our Windows malware paper collection

- 2023-11-22 - ETW internals for security research & forensics
- 2024-02-08 - Bypassing ApplyOnce limitation in GPO with key removal
- 2024-02-08 - Executing CSharp Assemblies from C code
- 2024-02-09 - Sudo On Windows
πŸ‘33❀13😁12πŸ”₯9🀝1
🀣127😁25πŸ‘11πŸ€“5πŸ”₯2❀1
Chainalysis' report indicates ransomware *payments exceeded $1,100,000,000 in 2023.

*Payments which are confirmed to be attributed to ransomware attacks, more attacks may not have been identified

More information: https://www.chainalysis.com/blog/ransomware-2024/
😱45❀13😎10πŸ‘6πŸ₯°4😁2❀‍πŸ”₯1😒1🀝1
We've uploaded more malware samples to vx-underground.

InTheWild && Bazaar && VirusSign

It is over 100,000 new samples.

Please download them, they're very lonely and scared.
❀44πŸ₯°13😒5🀣2
🀣143πŸ€“20😒8πŸ‘5😁5❀2πŸ”₯1
We have begun archiving SEC Form 8K filings related to cyber-crime.

Archives are from the SECurityTr8Ker feed.

https://vx-underground.org/Archive/SEC%20Form%208K
❀23πŸ‘6❀‍πŸ”₯3😁2
We've updated the vx-underground Windows malware paper collection

- 2019-02-15 - Understanding Windows x64 ASM
- 2023-12-31 - Compression using undocumented RDP APIs
- 2024-02-08 - Disabling System Event Logs with IDataCollectorSet

https://vx-underground.org/Papers/Windows
πŸ€”17πŸ”₯7❀6πŸ‘4😒4❀‍πŸ”₯2πŸ€“2
Namecheap is currently experiencing a rather significant DDoS attack.

This attack is not impacting their products. It is effecting their primary domain and customer support.
😒46πŸ‘13πŸ€”4
October 24th, 2022 an account on Doxbin operating under the alias "pedohunters" released a lengthy article on an individual operating under the alias "Rabid" a/k/a "Rabid7997".

February 8th, 2024 the identity of "Rabid" was confirmed - the United States Department of Justice arrested Richard Anthony Reyna Densmore of Kaleva, Michigan.

The United States Department of Justice unveiled details of this individuals sadism - he forced children to perform acts of self-harm on Discord for sexual gratification.

Due to the severity of his crimes he is currently facing life in prison.

More information: https://www.justice.gov/usao-wdmi/pr/2024_0208_R_Densmore_Indictment
πŸ‘64πŸ‘41πŸŽ‰11😱10🫑8❀‍πŸ”₯3😁3❀2🀩2🀣2
February 9th, 2024 the United States Department of Justice announced the arrest of two individuals behind WarzoneRAT.

- Daniel Meli, 27, of Zabbar, Malta
- Prince Onyeoziri Odinakachi, 31, of Nigeria

They are being charged with conspiracy, obtaining authorized access to protected computers to obtain information, illegally selling an interception device, and illegally advertising an interception device.

They are facing up to 20 years in prison.

More information: https://www.justice.gov/opa/pr/international-cybercrime-malware-service-dismantled-federal-authorities-key-malware-sales
🀯34🫑13😁9😒3😱2πŸ‘1🀣1