vx-underground
51.6K subscribers
4.53K photos
493 videos
84 files
1.57K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
"What if we used AI to turn source code into a binary?"
🀣324❀27πŸ₯°16😒9😎7😁3πŸ€“3πŸ‘2πŸŽ‰1πŸ™1
🀣191πŸ’―69❀20πŸ‘10😁5🫑4πŸ‘3πŸŽ‰2πŸ€“2❀‍πŸ”₯1😒1
❀156🀣96πŸ€”10πŸ₯°8❀‍πŸ”₯7πŸ’―6😁4πŸ€“2😒1
Lots of stuff happening with vx-underground at DEFCON

It's all very confusing though because I don't go to conferences, and many of the vx-underground things occurring I was not informed of, or made aware of, or I literally don't even know what it is

So it's just kind of weird when I'm chilling and I'm notified like, VXUNDERGROUND THING HAPPENING AT DEFCON and I just stare at my screen like ?????

Then people message me if I'm at DEFCON and I'm like "nah" and then they're like "omg thank you so much for the goop" and they send me a picture of something I've never seen before, or a picture of someone I've never met in my entire life

I don't care, I just do malware stuff and collect pictures of cats, but it's all very confusing and it hurts my little brain because I don't go outside but apparently I (or my crappy project) is doing many things that I myself didn't know existed

Anyway, yeah I have no idea what's going on, I'm not there, I'm sniffing around the internet looking for goop
❀101🀣44😁7πŸ€“2😱1😒1
Them: "Great meeting you at DEFCON! Thanks for the stuff!"
Then: *Sends picture of people and stuff*

Me:
- I'm not there
- I don't know who you are
- I didn't give you anything
- I don't know what you got
- I don't know the people in the photo

Me: "No problem, bro" (I don't know what's going on)
❀105🀣91😁12πŸŽ‰4πŸ€“2πŸ”₯1🫑1😘1😎1
> be me
> get email
> "smelly, is this malware?"
> look inside
> 23,000 line VBS file
😁125🀣56😱25❀7πŸ€“4πŸ€”3😒1
> be me
> get email
> "smelly, is this malware?"
> "someone sent this to our offices at work"
> "its trying to infect people at offices"
> ok cool
> get file
> download
> look inside
> 23,000 line vbs file
> lol ok
> xor encoded each individual character
> mildly annoying
> bonk bonk
> downloads file from enviamais-dot-store
> downloads "destenticador".py
> lol ok
> download
> look inside
> obfuscated python
> not very good obfuscation
> downloads .zip file
> "N3d5XpZbsd5juio".zip
> extracts .zip
> .zip contains .msi file
> lol ok
> download .zip, get .msi
> look inside
> all files inside installer stripped
> f1, f2, f3, f4, f5, f6
> lol ok
> check installer actions
> f6 is "winsqre".exe
> actually renamed autoit loader
> lol ok
> f6 (autoit) reads f4 (autoit scripts)
> look at f4
> obfuscated autoit
> takes a bunch of gunk to make another file
> chunk1, chunk2, etc
> add them together
> another autoit file
> ??? ok bro how far as we gonna go?
> look inside at new file
> autoit file scans machine for stuff
> looks stuff
> "FIBANK - Iniciar a sessΓ£o"
> "InternetBankingCAIXA"
> "GerenciadorCaixaGerenciadorFinanceiroCaixa"
> idk what this means
> if finds thingies, references other files inside msi
> ??? were looking back to the .msi installer ???
> autoit script loads f1
> RtlDecompressFragment
> o ok its a compressed .exe
> decompress file
> look inside
> DELPHI FILE
> look inside
> delphi does stuff
> delphi decrypts ANOTHER FILE and runs it
> ANOTHER DELPHI FILE

dude, what in the fuck is this shit?

.vbs -> .zip -> .msi (files 1 - 6)

.msi_file6 -> msi_file4

.msi_file4 -> autoitscript

autoitscript -> .exe

.exe -> msi_file5
πŸ€“98🀯47🀣27❀15πŸ”₯5πŸ‘1😒1
vx-underground
> be me > get email > "smelly, is this malware?" > "someone sent this to our offices at work" > "its trying to infect people at offices" > ok cool > get file > download > look inside > 23,000 line vbs file > lol ok > xor encoded each individual character >…
these nerds put in a significant amount of effort to make this as multi-staged and as convoluted as possible. this is 100% AI generated. they left the notes in place. however, based on everything i'm seeing, i think this person probably has a decent understanding of malware and understands how annoying this is

tl;dr not super sophisticated malware, but really fucking annoying
πŸ€”67😁24πŸ‘9❀5πŸ€“5😒1
vx-underground
> be me > get email > "smelly, is this malware?" > "someone sent this to our offices at work" > "its trying to infect people at offices" > ok cool > get file > download > look inside > 23,000 line vbs file > lol ok > xor encoded each individual character >…
oh, and the files arent on VT, for my colleagues who care about weird annoying goop

initial loader:
0a12cdc7d66a5a26a52b1a8baec6816fd25d847bd26c9ffe145ef6e59fbc1a7f

.msi
99fe40b0831f75d17e16db291d15f03e48c324754f3e999f4bea69b4006b85a7

initial autoit script
0fec75b0aec43e8661130a4c271a09681e773ee93423a8d12d5f9705531443a0

secondary autoit file
8e57bbbdbccb3bf13069e02f0209a69fca2b6c3cc7d224cb94a1f342f23968b6

compressed delphi loader
4c8fdac932ee465bbcbb292c1570350284e46bd258fd961ea9c3bf69ccd65ee1

delphi loader
1b2c3e80347b35fb5811619f3aeae75f05dd4e635ffef7620141be7ed3041eb3

file6 (weird delphi thingie)
38c1d2f4888852b23c540ffdff38be2ab24cb14c4bed86ae762f532377772319
❀65πŸ€“4πŸ”₯3😒1
This media is not supported in your browser
VIEW IN TELEGRAM
"Bro look! That cybersecurity company is using CAT MEMES as advertisements! Isn't that awesome?"
😁91❀13πŸ”₯5πŸ€“2😒1
This media is not supported in your browser
VIEW IN TELEGRAM
❀73😱25😁15🀣8πŸ₯°4😒4πŸ€“3
> computer nerds talking about stuff
> discussing some kind of mod
> video game stuff
> people say might be malware
> scroll down
πŸ₯°142πŸ€“27🀣9πŸ”₯8😁7❀6πŸ‘3🀯1😒1
Had a dream last night about malware

Outside doing family stuff, daydreaming of my malware idea. Super excited to sit down on computer and bonk malware.

God I love malware so much
πŸ’―101πŸ€“31❀22πŸ₯°9πŸ‘2😁1😒1
I've had so many people talk to me about looking for entry level material for malware, I've decided to give writing a book another try.

I'm going to call it "Malware for Noobs" and just schizo rant a bunch on my blog until I think it's enough for a book
❀125🀣31πŸ”₯9πŸ₯°5😁3πŸ™2🫑2😒1
vx-underground
I've had so many people talk to me about looking for entry level material for malware, I've decided to give writing a book another try. I'm going to call it "Malware for Noobs" and just schizo rant a bunch on my blog until I think it's enough for a book
Maybe someone will pick it up and I can have it published at a fancy place like Barnes and Noble, then I can be called cool and badass and people can make fun of me
πŸ€“86🀣24πŸ”₯12❀8😁4πŸŽ‰3❀‍πŸ”₯2πŸ₯°2😒1
Some dork on Instagram is accusing me of being behind the whole Mecca Chameleon steam malware thingie and says @IntCyberDigest labeled me the criminal, or something, I don't know.

I'm not even mad they called me a criminal, I'm mad they would accuse me of making weak malware.

I've got a family now, I'm basically a born again Christian, I drive the speed limit, wear socks with sandals, and tuck my shirt into my cargo shorts. I don't do anything even close to illegal.

However, if I was going to switch it up and become a full fledged Threat Actor, I am NOT going to do something half-baked like this Mecca Chameleon thing, I'm going to develop an information stealer, partially AI generated, written in like five different programming languages, and storing the payload on something goofy like a Billie Eilish instagram comment. Then I am going to sell it online on some place like Tier1 and deal strictly in XMR.

I am insulted you would think I would stoop so low to do something like a malicious Steam game (or hijack).
πŸ₯°139😁44🀣42❀11πŸ‘11πŸ”₯5πŸ’―4❀‍πŸ”₯3😒2
vx-underground
Some dork on Instagram is accusing me of being behind the whole Mecca Chameleon steam malware thingie and says @IntCyberDigest labeled me the criminal, or something, I don't know. I'm not even mad they called me a criminal, I'm mad they would accuse me of…
Nah, but bro said, "vx-underground is an educational website about malware; everything they use or test is done for ethical purposes. It is important to get informed before looking for someone to blame."

tinchoocabrera is the homie wtf i love him
πŸ₯°210❀28❀‍πŸ”₯14🫑10😁4😒2πŸŽ‰2
I sat down and did some schizo ranting for my attempt at a book I might name "Malware 4 Noobs" (no idea yet).

Here is my introduction segment, part zero (no reforms or changes made yet).

If you're noob, please read and give feedback.

https://malwaresourcecode.com/home/my-projects/write-ups/part-i-malware-4-noobs-version-0
❀147😱15πŸ”₯10πŸ‘7🫑4❀‍πŸ”₯2😒1
me when ive never done any sort of hacking ever in my life so i need to do it as obnoxiously as possible and also my brain has been replaced by a can of peas
🀣204πŸ€“17❀11πŸ‘5😁2😱2😒2❀‍πŸ”₯1πŸ’―1
I'm about to crash out

You're a fucking bum if you use AI to write your research papers. If I see one more "WHY THIS MATTERS" I'm going to lose my fucking shit bro

You're a fucking bum who can't do research, you depend on a subscription model to think for you, and your bum ass can't even comprehend what happened so you need to spend more money to have it "write".

Then I see all these corny ass replies, people larping like they've read the "write-up", when anyone with a shred of self-respect, integrity, and critical-thinking skills, know it's a big stinky sloppy pile of pig shit

HOW DO YOU INTEND ON GETTING A JOB IF YOU DON'T KNOW ANYTHING?

Okay, I'm done screaming at my computer monitor. I'm going to go eat dinner, tonight we're having pizza. I am excited because I like pizza and it makes me happy.

Mwah, kissies, love you all lots
❀208πŸ’―49πŸ‘8πŸ”₯7❀‍πŸ”₯3πŸ‘3🀣2🀯1😒1