vx-underground
47.7K subscribers
4.13K photos
441 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
We've updated the vx-underground Windows malware paper collection. We have a lot more papers in queue.

Read them.

Papers:
- 2024-08-31 - Finding open file handles in PS
- 2024-08-30 - Evil MSI A story about vulnerabilities in MSI Files
- 2024-08-26 - DLL Sideloading ith LicenseDiag.exe
- 2024-08-19 - DRMBIN - Prevent binaries from running on other machines
- 2024-08-15 - Offline SAM Editing
- 2024-08-14 - Tricks with Microsoft Word and Sandboxes
- 2024-08-13 - Abusing AVEDR Exclusions to Evade Detections
- 2024-06-09 - Bypassing EDR NTDSdit protection using BlueTeam tools
๐ŸŽ‰29โค11๐Ÿคฉ3๐Ÿค2๐Ÿ‘1๐Ÿ”ฅ1
Generally speaking, the ultimate goal of collecting malware is getting malware which offers intelligence in some capacity.

- Novel malware
- Stagers and/or chains (leading to malware)
- Active malware campaigns

There is a metric poop-ton of dead malware floating in cyber space which offers nothing of value. Collecting it simply allows you to add (yet another) SHA256 entry in your DB of known-bad files. It will do (probably) nothing except alter system files and be annoying.

Ideally, you'd like malware you can extract C2 information from, tie to a malware campaign, study for making detection rules, or study to learn new malware development techniques.

Old and dead malware does nothing except take up space. But, some vendors like it just to check it off as 'lol this bad fr'.

As an example: our malware ingestion can take it millions upon millions of "padodor", "berbew", "qukart", "vilsel", "zegost", or "vbclone" samples. Most of these don't even work on modern windows, drop like, 100+ copies of itself, and can't connect to anything.

tl;dr its dead
๐Ÿ”ฅ64๐Ÿ‘13๐Ÿ’ฏ7โค3๐Ÿ˜ข3๐Ÿค“3๐Ÿ‘1
Today we ingested 1,721,892 suspected malicious binaries.

Non-junk malware: less than 100,000, probably closer to 60,000
๐Ÿ”ฅ55๐Ÿคฃ11โค9๐Ÿ˜ข4๐Ÿค“2๐Ÿ‘1
lemon > rolex
๐Ÿ”ฅ100๐Ÿค“31โค10๐Ÿ‘8๐Ÿ‘5๐Ÿ˜ข1๐Ÿ’ฏ1
twitter algorithm ๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚
๐Ÿ˜126๐Ÿคฃ78๐Ÿ’ฏ21๐Ÿซก6๐Ÿ‘5๐Ÿค“5โค3๐Ÿ”ฅ3๐Ÿฅฐ1
This media is not supported in your browser
VIEW IN TELEGRAM
if you cringe you lose
๐Ÿ˜ฑ81๐Ÿ˜ข48๐Ÿคฃ32๐Ÿ˜12๐Ÿ”ฅ5๐Ÿ˜‡5๐Ÿค“3๐Ÿ™2โค1๐Ÿค1๐Ÿซก1
Saw XI: Internet Dweeb Edition:

Jigsaw voice: "Hello, internet pirate, want to play a game? One of these buttons is a real pirated version of Photoshop. The other three deliver Redline information stealer. Make your choice."
๐Ÿคฃ150๐Ÿ˜14โค9๐Ÿค“7๐Ÿ˜ข3๐Ÿซก3๐Ÿ‘1
Today reports surfaced on a cybersecurity incident impacting the London Transport Department

We can assert with a high degree of confidence that this 'incident' is of extreme severity. The immediate presence of the NCA and NCSC drives this point further.
๐Ÿ˜ฑ42๐Ÿ‘6๐Ÿ’ฏ6๐Ÿ˜5๐Ÿคฏ4๐Ÿค“2๐Ÿค1
Updates to vx-underground:

Papers:
- 2024-09-03 - Rundll32 and Phantom DLL lolbins
- 2024-08-17 - HookChain - A new perspective for Bypassing EDR Solutions
- 2024-08-11 - DriverJack
- 2024-08-11 - Blocking EDR drivers with HVCIDisallowedimage
- 2024-08-10 - ShimMe - Manipulating Shim and Office for Code Injection
- 2024-08-09 - Blocking EDR Drivers with WDAC policies
- 2024-08-08 - Abusing Windows Hello without a severed hand

Families:
- Android.BlankBot
- AteraAgent
- AtlantidaStealer
- Azorult
- BruteRatel
- CobaltStrike
- DCRat
- DonutLoader
- GCleaner
- Gh0stRAT
- GuLoader
- Lokibot
- LummaStealer
- Mirai
- Neshta
- NjRat
- Pony
- PureLogStealer
- RhadamanthysLoader
- Sliver
- Vidar
- XWorm
- ArcStealer
- AgentTesla
- Amadey
- Andromeda
- AsyncRAT
- AugustStealer
- CryptBot
- CyberGateRAT
- Danabot
- Formbook
- Latrodectus
- MicroClip
- Rakos
- Redline
- Remcos
- StealC
- XenoRAT

Note: someone said the artwork we use when pushing updates is scary, they requested we post something cute instead.
๐Ÿฅฐ53๐Ÿ”ฅ11๐Ÿ‘4๐Ÿ˜˜4๐Ÿ˜3โค1๐Ÿ˜ข1
September 3rd, Lara Trump (daughter-in-law of former U.S. President Donald Trump) and Tiffany Trump (daughter of former U.S. President Donald Trump) had their X accounts compromised.

Their accounts briefly shilled some sort of crypto stuff. X locked the accounts within minutes.
๐Ÿคฃ78โค10๐Ÿค”8๐Ÿ‘3๐Ÿ˜1๐Ÿ˜ข1
vx-underground
September 3rd, Lara Trump (daughter-in-law of former U.S. President Donald Trump) and Tiffany Trump (daughter of former U.S. President Donald Trump) had their X accounts compromised. Their accounts briefly shilled some sort of crypto stuff. X locked the accountsโ€ฆ
> compromise high profile social media accounts tied to powerful american political figures
> can do catastrophic damage
> shills crypto
๐Ÿ’ฏ86๐Ÿคฃ64๐Ÿ˜7๐Ÿ‘3๐Ÿ˜ข1
pizza topping must be a valid email address
๐Ÿ’ฏ111๐Ÿคฃ27๐Ÿค“21๐Ÿ˜14๐Ÿคฏ8โค2๐Ÿ‘1๐Ÿ˜ข1
vx-underground
pizza topping must be a valid email address
pepperoni_is_ok_i_guess_im_not_picky@gmail
๐Ÿคฃ130โค10๐Ÿ’ฏ6๐ŸŽ‰3๐Ÿ˜2๐Ÿค“1
RansomHub ransomware group claims to have ransomed Planned Parenthood
๐Ÿคฃ85๐Ÿ˜ข52๐Ÿ”ฅ14๐Ÿค”11๐ŸŽ‰6๐Ÿ™6โคโ€๐Ÿ”ฅ4๐Ÿ‘4โค2๐Ÿคฉ2๐Ÿ’ฏ1
We have performed a colossal oopsie doopsie.

Our malware ingestion system prepended 'file=' to every file being sent to VirusTotal, thus impacting AV vendors down stream. Sent vendors hundreds of thousands of botched malware samples
๐Ÿคฃ147๐Ÿ˜ฑ27๐Ÿ”ฅ12๐Ÿ˜‡8๐Ÿ‘6๐Ÿซก6โค5๐Ÿค“4๐Ÿ˜3๐Ÿ˜ข2๐Ÿ‘1
vx-underground
We have performed a colossal oopsie doopsie. Our malware ingestion system prepended 'file=' to every file being sent to VirusTotal, thus impacting AV vendors down stream. Sent vendors hundreds of thousands of botched malware samples
We were made aware of the issue when AV companies contacted us regarding our VirusTotal account and the files being corrupted.

tl;dr my bad yall (its free, so fuck you, but seriously were sorry were fixing it)
โค90๐Ÿคฃ39๐Ÿค“16๐Ÿ˜ข4๐Ÿ‘3๐Ÿ”ฅ1๐Ÿ˜1๐Ÿค”1
Improving the homelab today โ€” decided to run some cables through the wall to be fancy.
๐Ÿคฃ123๐Ÿ”ฅ14โค8๐Ÿ‘5๐Ÿ˜3๐Ÿ˜ข3๐Ÿค2๐ŸŽ‰1
Today the United States Department of Justice indicted Russian nationals Elena Afanasyeva and Kostiantyn Kalashnikov for violations of the Foreign Agents Registration Act (FARA), and conspiracy to commit money laundering.

Afanasyeva and Kalashnikov remain at large as of September 4th.

Afanasyeva and Kalashnikov are accused of laundering money to covertly fund as much as $10,000,000 to English-speaking social media companies (listed as U.S. Company-1) to sway content in favor of the Russian government.

Interestingly, the indictment states the company which received the funds is described as, "a network of heterodox commentators that focus on Western political and cultural issues". Journalists and researchers have tied this to Tennessee-based company Tenet Media ... because ... it has the exact same message on their homepage verbatim.

This media company employees conservative media commentators Lauren Southern, Tim Pool, Tayler Hansen, Matt Christiansen, Dave Rubin, and Benny Johnson.

The indictment is interesting, discusses the money laundering techniques, disinformation campaigns, and their chat communication medium ... on Discord.

Image 1 is U.S. Company-1 per the indictment. Image 2 is Tenet Media.

More information: https://www.justice.gov/opa/pr/two-rt-employees-indicted-covertly-funding-and-directing-us-company-published-thousands
๐Ÿคฃ58๐Ÿ‘21โค6๐Ÿ˜ข6๐Ÿ”ฅ4๐ŸŽ‰3๐Ÿซก3๐Ÿ˜2๐Ÿ˜ฑ2๐Ÿคฏ1
๐Ÿคฃ243๐Ÿ˜34โค11๐Ÿค5๐Ÿ”ฅ4๐Ÿคฉ4๐Ÿ™4๐Ÿซก4๐Ÿฅฐ2๐Ÿ˜‡2๐ŸŽ‰1