vx-underground
51.6K subscribers
4.53K photos
493 videos
84 files
1.57K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
vx-underground
Hello, So uh, a long time ago I said I was giving away tickets to DEFCON for free. A lot of people have DM'd me about it. I can't go into too much detail about. I don't want to diss anyone, or throw shade at anyone, because I myself don't even know what…
I really don't want to throw shade at anyone, but it's super confusing, because we had a giant pile of cash from sponsors. We said, "Hello, we would like to use this giant pile of cash". They pretty much said, "Okay, cool, one moment" ... then kind of radio silence.

I assume DEFCON likes money, so I don't know what happened.
😒67❀9🀣7😱1πŸŽ‰1
> get dm
> "smelly, is this goop?" (malware)
> "i found it on x"
> links GitHub
> download
> look inside
> .net goop
> didnt strip metadata
> internally refers to itself as FunkyStar
> internally does "ProcessAlpha", "ProcessBeta", etc

Not only is this shit slop malware, the author of this malware is larping to themselves as like, some sort of military operation. My brother in Christ, I'm happy you're feeling peppy about your slop malware, but you ARE NOT writing state-sponsored malware.
😁93🀣27πŸ₯°8❀7😒2πŸ”₯1
I like writing malware because, instead of making useful and productive software, you spend an absurd amount of time writing a really over complicated and convoluted way to create a file.

A simple line or two of code becomes like 50 lines.

It's fun, I don't know why
❀88πŸ₯°32πŸ’―12😒1
This media is not supported in your browser
VIEW IN TELEGRAM
> get dm
> "someone defaced health institute for czech republic"
> look at website
> indeed they did
> they leave a telegram handle
> dm them
> say hello
> "haha check this out bro"
> adds "smelly" to website
> lists "smelly" as a "crew member"

chat, we are cooked
😁165🀣124🫑20πŸ₯°8❀5😒5πŸŽ‰3πŸ”₯1
vx-underground
> get dm > "someone defaced health institute for czech republic" > look at website > indeed they did > they leave a telegram handle > dm them > say hello > "haha check this out bro" > adds "smelly" to website > lists "smelly" as a "crew member" chat, we are…
o ok, thank god they removed it, i was afraid the knedliky police were gonna come to my house and beat me to death with knedliky

close one
❀106🀣46πŸ₯°14😁8😒4πŸŽ‰3
Oh yeah? You're a "hacker"? Prove it.

Show me your $600 entry ticket for Slermie Doop 16 and massive collection of cybersecurity vendor merchandise you either received for free or purchased.

You're not a real hacker until you're a walking billboard for tech companies
🀣93❀24😁8😒5πŸ€“2❀‍πŸ”₯1πŸ’―1
vx-underground
Oh yeah? You're a "hacker"? Prove it. Show me your $600 entry ticket for Slermie Doop 16 and massive collection of cybersecurity vendor merchandise you either received for free or purchased. You're not a real hacker until you're a walking billboard for tech…
Hahahahaha. What? You can't afford a ticket to Slermie Doop??? Sounds like you're POOR. Sorry, kid. We're HACKERS. We fucking HATE poor people.

Next thing you're going to do is say you can't afford the $2,000 Schmeemee certificate, proving you're a real hacker.
🀣130❀22πŸ₯°6😁5😒3πŸ€“2❀‍πŸ”₯1πŸ’―1
It makes me very happy receiving DMs of malware and people asking "is this goop?".

There is a real-world chance that we can fundamentally corrupt people to begin referring to malware as "goop", and making our entire industry look like a fucking joke

That's so badass omg
❀173πŸ₯°38❀‍πŸ”₯12🀣11😎7πŸ€“4😁3🀯3πŸ™2🀝2😒1
Chat, I'm unironically a big fan of AI now

I don't vibe code, or whatever, but it's ability to generate me slop Python scripts for reverse engineering, or it's ability to help me troubleshoot Linux gunk, is absolutely incredible.

I'll say, "Hey ChatGPT, I've got this goop that is doing X, Y, Z. Can you make me a Python script that handles it?".

My Python is trash, but ChatGPT is like, "I got you, big dawg", and gives me the thingie I need in just a few seconds, saving me tons of time browsing StackOverflow or screaming at my IDE about syntax issues.

Thank you, OpenAI, for giving me ultra mega slop Python maker 9000. It is incredibly helpful to me.

Oh, and I've never had OpenAI give me any warnings and stuff about potential violations or whatever. Anthropic complained all the time. I'm not verified by OpenAI as a cybersecurity professional, ... I just ask for slop Python and it produces magic. I don't know how it works, but it's cool and badass
❀155🀣63πŸ€”15😒14πŸ’―6🀯5πŸ”₯4😍4😎4πŸ‘3πŸ₯°3
❀145🀣87😁12😍7πŸ’―5πŸ€“5❀‍πŸ”₯4😒2πŸŽ‰1
This media is not supported in your browser
VIEW IN TELEGRAM
Someone is DDoSing vx-underground.

This is terrible news. I was going to work on the website, but now all I can do is spend time with my family and enjoy a beautiful summer day

Terrible, this is just plain terrible

Welp, do your thing big dawg, hit me up when you're done
❀245🀣123😒18πŸ₯°10😁6😱6πŸ”₯5πŸŽ‰2πŸ€“2🫑1
Hi

More malware has been uploaded to VXUG. It's like, 150,000 malwares, or something. I also uploaded more malware analysis papers.

Show it to your parents, they'll be proud of you.
❀95πŸ₯°15😁12🫑8🀣6❀‍πŸ”₯2πŸ‘2πŸ”₯1😒1πŸ€“1
This media is not supported in your browser
VIEW IN TELEGRAM
I am filled with disappointment.

Last time on Dragon Ball Z, I announced my boredom with malware development, hence I decided to pivot to malware defense. I began by taking apart YARA to understand how it works, and making my own little silly YARA scanner. Whatever.

I then began reviewing the malware people discovered in the wild. I have reviewed hundreds of malwares, and many also non-malwares.

Unfortunately, I am at the point where I am no longer finding original goop. It is the same malware campaigns, different person sending it, different compromised webhosts, or slightly tweaked SHA256 hashes.

I now feel the existential dread my blue team colleagues feel. It is the same gunk everyday. The gunk is persistent. The gunk is infinite and vast. The gunk is like an ocean of gunk.
😒166❀27🀣21🀯3πŸ’―3πŸ€“3πŸ‘2😁2πŸŽ‰1
"What if we used AI to turn source code into a binary?"
🀣324❀27πŸ₯°16😒9😎7😁3πŸ€“3πŸ‘2πŸŽ‰1πŸ™1
🀣191πŸ’―69❀20πŸ‘10😁5🫑4πŸ‘3πŸŽ‰2πŸ€“2❀‍πŸ”₯1😒1
❀156🀣96πŸ€”10πŸ₯°8❀‍πŸ”₯7πŸ’―6😁4πŸ€“2😒1
Lots of stuff happening with vx-underground at DEFCON

It's all very confusing though because I don't go to conferences, and many of the vx-underground things occurring I was not informed of, or made aware of, or I literally don't even know what it is

So it's just kind of weird when I'm chilling and I'm notified like, VXUNDERGROUND THING HAPPENING AT DEFCON and I just stare at my screen like ?????

Then people message me if I'm at DEFCON and I'm like "nah" and then they're like "omg thank you so much for the goop" and they send me a picture of something I've never seen before, or a picture of someone I've never met in my entire life

I don't care, I just do malware stuff and collect pictures of cats, but it's all very confusing and it hurts my little brain because I don't go outside but apparently I (or my crappy project) is doing many things that I myself didn't know existed

Anyway, yeah I have no idea what's going on, I'm not there, I'm sniffing around the internet looking for goop
❀101🀣44😁7πŸ€“2😱1😒1
Them: "Great meeting you at DEFCON! Thanks for the stuff!"
Then: *Sends picture of people and stuff*

Me:
- I'm not there
- I don't know who you are
- I didn't give you anything
- I don't know what you got
- I don't know the people in the photo

Me: "No problem, bro" (I don't know what's going on)
❀105🀣91😁12πŸŽ‰4πŸ€“2πŸ”₯1🫑1😘1
> be me
> get email
> "smelly, is this malware?"
> look inside
> 23,000 line VBS file
😁124🀣56😱25❀7πŸ€“4πŸ€”3😒1
> be me
> get email
> "smelly, is this malware?"
> "someone sent this to our offices at work"
> "its trying to infect people at offices"
> ok cool
> get file
> download
> look inside
> 23,000 line vbs file
> lol ok
> xor encoded each individual character
> mildly annoying
> bonk bonk
> downloads file from enviamais-dot-store
> downloads "destenticador".py
> lol ok
> download
> look inside
> obfuscated python
> not very good obfuscation
> downloads .zip file
> "N3d5XpZbsd5juio".zip
> extracts .zip
> .zip contains .msi file
> lol ok
> download .zip, get .msi
> look inside
> all files inside installer stripped
> f1, f2, f3, f4, f5, f6
> lol ok
> check installer actions
> f6 is "winsqre".exe
> actually renamed autoit loader
> lol ok
> f6 (autoit) reads f4 (autoit scripts)
> look at f4
> obfuscated autoit
> takes a bunch of gunk to make another file
> chunk1, chunk2, etc
> add them together
> another autoit file
> ??? ok bro how far as we gonna go?
> look inside at new file
> autoit file scans machine for stuff
> looks stuff
> "FIBANK - Iniciar a sessΓ£o"
> "InternetBankingCAIXA"
> "GerenciadorCaixaGerenciadorFinanceiroCaixa"
> idk what this means
> if finds thingies, references other files inside msi
> ??? were looking back to the .msi installer ???
> autoit script loads f1
> RtlDecompressFragment
> o ok its a compressed .exe
> decompress file
> look inside
> DELPHI FILE
> look inside
> delphi does stuff
> delphi decrypts ANOTHER FILE and runs it
> ANOTHER DELPHI FILE

dude, what in the fuck is this shit?

.vbs -> .zip -> .msi (files 1 - 6)

.msi_file6 -> msi_file4

.msi_file4 -> autoitscript

autoitscript -> .exe

.exe -> msi_file5
πŸ€“98🀯47🀣27❀15πŸ”₯5πŸ‘1😒1