vxunderground | Unsorted

Telegram-канал vxunderground - vx-underground

14367

The largest collection of malware source, samples, and papers on the internet. Password: infected Website: https://www.vx-underground.org/ vx-underground Telegram chatroom link: https://t.me/+njfLzUrqos01ZWNh

Subscribe to a channel

vx-underground

Internet web designer drama today.

Advanced Custom Fields, a WordPress plugin that allows people to modify pages easier, and offers a paid version, has been usurped by WordPress itself.

WordPress pretty much told them to piss off, causing a massive shitstorm

Читать полностью…

vx-underground

Hello,

tl;dr im sick, be patient, giveaways in december, hdds soon (maybe), vxdb ideas?, be patient (again).

1. I'm still sick. I've been sick for over a week now. My sinus infection is semi-persistent and it's being a total pain in the ass. My health has improved, but I'm not quite 100% recovered yet. I feel like I've got a giant booger in my right nostril that I can't get out. Ugh.

2. We still haven't gotten around to the swag giveaway. It's on my todo list, but I need to sync with the crew to check out the submissions and select a few winners. We haven't found a time in the past week where we're all online at the same time and can really sit and down and review the critter pictures. That's my bad, it's on the todo list.

3. This year, as we did last year, we're going to try to do a bunch of Christmas giveaways. Last December we gave away over $45,000 in educational material. We're trying to make this an annual tradition. Let's see how it goes this year.

4. A ton of people have messaged me about harddrive sales. We've got some that are ready to clone, but I haven't sat down and began. I've been distracted by tons of stuff and cloning the drives can be kind of annoying. I'll probably start cloning drives again in the next couple of weeks.

5. We're trying to find a way to fuse our malware database with vx-underground. We had this idea where people can easy move between virus-exchange and vx-underground and download individual samples way faster. We're not sure how we're going to do it, but it's on the chopping block.

6. Despite the huge boost in hardware, thanks to all the people to helped us with our hardware fundraiser, ingestion 1,000,000+ malware samples a day is really hard and expensive. A more realistic number is closer to 100,000 - 400,000 a day, but even that is challenging unless we get a sudden surge in funding. I'm not sure why I'm so set on collecting all this malware and pushing the crew to continue the malware collection, but it's what's happening.

7. Adding papers can be hard. We try to actively monitor social media for new and cool malware-related research. Usually once we've got a bunch bookmarked somewhere, or saved as a PDF, we double check to see if we already have the paper on vx-underground, we sync it with a local backup and our remote backup, and then push to prod. Finding fresh material and doing all these extra steps is a pain in the ass, especially when we review them and try to classify them as best as possible. Stop bugging us on why we're not adding more papers — we've got like, 60,000 papers and it's not as easy as ctrl-c + ctrl-v. Because of the size of our malware collection, nothing is simple anymore, especially because we try to do everything right the first time.

Thanks for reading. Enjoy your weekend.
- smelly

Читать полностью…

vx-underground

Massive Pokemon leak today.

- Partial Black/White v2 dev builds & source patch files
- Pokemon Bank source code
- Pokémon HeartGold and SoulSilver source code
- Famicom tech demo from 2004
- Black/White Git
- Platinum full SVN

Читать полностью…

vx-underground

We've made a ground breaking discovery.

When regular internet dweebs learned the Internet Archive got defaced they were under the impression that someone deleted over 100PB's of data within the time span it takes to click refresh on their web browser.

The panic and terror makes much more sense now.

We too would be terrified if someone discovered a way to zero-fill 100PB of data (without detonating an incendiary device) across a data warehouse in the blink of an eye, because this is no regular data-wiper payload, this is unironically spooky wizard galaxy brain time magic (only logical explanation).

Pic attached is an image from the Internet Archive. Imagine zero-filling all these computer thingies in .03 seconds.

Читать полностью…

vx-underground

333,100 followers and we're getting BIG money from it on social media. Don't even try to talk to us unless you've got stacks like us.

Читать полностью…

vx-underground

Seriously? What the hell are we going to do with it? We don't analyze it (we do sync it with some vendors), we only reverse maybe 0.00000001% of the samples.

What the hell are we doing? Why hasn't someone said something? We literally just have terabytes of malware hangin' around

Читать полностью…

vx-underground

Not a big deal, the disk is okay and we still got ((2,147,483,648 * 3) - 17,216) good sectors left.

Читать полностью…

vx-underground

Unfortunately, as we grow in size we continue to see less tech-savy individuals who do not understand the malware nomenclature.

Moving forward we will make translations.

Translation:

Sad we getting big but dumb mfers come here mad as hell and now we gotta use littler words

Читать полностью…

vx-underground

Thank you to everyone for the kind words and for defending us.

Truthfully, we aren't upset by these remarks. The post was made in our typical fashion and was directed toward our target audience. Whenever something we post escapes the information security ecosystem, information tends to bend and warp. It isn't surprising non-technical people who are unfamiliar with our work would misconstrue our commentary.

Some people who made the hateful remarks have apologized, others continued to criticize us saying our post was intentionally (or unintentionally) misleading. We personally did not believe this is something which could mislead people as we were directly quoting the wording in the compromise. However, it is evident we were painfully wrong.

We are sure things will calm down soon. The internet moves very fast and people outside the information security ecosystem will drift back into their circles of interest.

There is also a joke to be made somewhere regarding the hateful comments directed toward us on October 10th, World Mental Health Day, probably. We'll let someone more creative than us make the memes.

Anyway, back to work.

Have a nice day

Читать полностью…

vx-underground

We're not entirely sure what is happening right now, but we suspect this person thinks we are responsible for the attacks against The Internet Archive.

It also has 94,000 likes and 1.8M views

Читать полностью…

vx-underground

Note:

Final update and confirmations:

The compromise has been confirmed via BleepinComputer and TroyHunt. 31,000,000 users impacted. There is no confirmed information on how the site was compromised. No Threat Actor(s) have been attributed to the compromise. More information is available on their respective social media platforms. More information will probably become available in the following hours or days.

Unrelated to the defacement and compromise, Sn_darkmeta claims to have been DDoSing Internet Archive. They state they're DDoSing the website because the United States government supports Israel and The Internet Archive belongs (?) to the United States.

Читать полностью…

vx-underground

Craziest compromise of 2024 (thus far) possibly going to this person(s). This is wild

Читать полностью…

vx-underground

> be fall season
> get chilly outside
> turn off air conditioning
> get on pc
> compress 150gb blobs of malware
> office becomes inescapable fiery hell
> turn ac back on
> entire house freezing cold
> office still burning hot

¯\_(ツ)_/¯

Читать полностью…

vx-underground

Yesterday someone wrote that Lockbit ransomware group is making a training course. Is this true?

tl;dr no

1. LockbitSupp a/k/a Dimitry Yuryevich Khoroshev is a Russian national who has stolen an estimated $400,000,000 via ransomware. Does he need money by producing and selling a training course? Probably not.

2. According to the United States Federal Bureau of Investigation and United Kingdom National Crime Agency, Lockbit ransomware group had affiliates who were members of EvilCorp, an infamous Russian-based malware crime family who the family is estimated to have made hundreds of millions of dollars. EvilCorp is believed to have ties to the Russian FSB. Does he need money by producing and selling a training course? Probably not.

3. LockbitSupp does not speak English well. Why would he write a course in English? (in the photo shared it was written in English, native English with virtually no typos or funky spelling)

4. The photo shared mentioned Breached. LockbitSupp is not associated with Breached. He is a Russian national, does not speak English well, and does not traditionally trust foreigners (or anyone really, except maybe his most esteemed ransomware affiliates). His primary forum platforms for communication and recruitment has been Exploit and RAMP

5. We asked Lockbit if he was making a training course, he said no. Note his native English (sarcasm, a native English speaker would write, "no, why do you ask?")

Читать полностью…

vx-underground

We love hearing that students, the morbidly curious, and independent researchers use our website.

We don't like watching your multi-million dollar company scrape our malware collection for their 'AI' training set.

Читать полностью…

vx-underground

"smelly why are you always so sick?"

In the spirit of full-disclosure, I've got a kind of, sort of, rare disease-thing. I'm immuno-compromised. The medicine which fixes my disease thingy requires injecting drugs which essentially toggle my immune system offline.

This fixes my disease thing, but it makes me susceptible to illness, and in the event that I do get sick, it takes me much longer to recover from it.

If in the event I don't take injections which toggle my immune system offline, my body is in crippling pain all day, everyday, and it hurts to live because my immune system thinks my body is a giant infection and it tries to kill me.

Читать полностью…

vx-underground

Nintendo executives right now (they're going to sue everyone into nothingness)

Читать полностью…

vx-underground

Good morning, evening, or night.

We still haven't selected winners to the swag giveaway. Relax — you can stop sending us DMs. We'll do it later today, or tomorrow, whatever.

Okay, going back to bed now. Talk to you later.

Love you,

Читать полностью…

vx-underground

Our social media stats from the past 28 days

tl;dr 8m - 16m impressions == $109

Читать полностью…

vx-underground

Good morning,

- We've got a bunch of papers in queue, no idea when we'll push them to prod
- Estimated daily malware ingestion is 450,000 samples
- Winners for the swag giveaway will be selected throughout the weekend. We wanted to let people continue posting critters

Thanks,

Читать полностью…

vx-underground

There is literally no reason why we should possess 30,335,219 malwares (growing as this is being written).

This 'collecting' thing is getting out-of-hand.

Читать полностью…

vx-underground

Apologies — we failed to use a comma and we fear our translation may be misleading to some.

Translation:

my bad lol i forgot the , in the sentence, i dont want mfers thinkin we sad that we blowin up lol, fr we blessed

Читать полностью…

vx-underground

Thank you, it's appreciated.

(no idea what this means, or why they blocked us after the message)

Читать полностью…

vx-underground

> go online
> see internet archive defaced
> comment on the ddos / compromise
> give more information in follow up post
> non-nerds find post
> blame us

Читать полностью…

vx-underground

We woke up to hate mail.

Some people believe we're responsible for DDoS and/or compromise of The Internet Archive. We did not DDoS and/or compromise The Internet Archive

Regardless, thanks for calling us mentally handicapped and saying we should commit suicide.

Читать полностью…

vx-underground

The website has returned to normal. We suspect this person(s) defaced the site to make a point. However, this is just speculative. If this were a financially motivated TA they could have done much more damage or made a horrific defacement.

tl;dr kind of classy?

Читать полностью…

vx-underground

The wayback machine has been compromised.

See you all in HIBP!

Читать полностью…

vx-underground

In summary: the person who claimed Lockbit ransomware group was making a training course was doing it as a publicity stunt (probably) to attract people to their training course (crime focused?).

We give it a 7/10. It fooled some people.

Читать полностью…

vx-underground

Malware Ingestion statistics, August 2024:

2024-08-01: 15,604
2024-08-02: 13,593
2024-08-03: 12,354
2024-08-04: 12,679
2024-08-05: 12,245
2024-08-06: 12,914
2024-08-07: 14,432
2024-08-08: 15,054
2024-08-09: 13,625
2024-08-10: 20,955
2024-08-11: 23,064
2024-08-12: 22,850
2024-08-13: 19,464
2024-08-14: 15,219
2024-08-15: 114,050
2024-08 -16: 70,162
2024-08-17: 93,572
2024-08-18: 138,520
2024-08-19: 178,314
2024-08-20: 87,425
2024-08-21: 146,435
2024-08-22: 306,526
2024-08-23: 208,720
2024-08-24: 133,827
2024-08-25: 7,533
2024-08-26: 19,108
2024-08-27: 18,980
2024-08-28: 21,085
2024-08-29: 16,032
2024-08-30: 17,327
2024-08-31: 17,620

Total: 1,821,596
Size: 230GB (7z Ultra compressed)

Читать полностью…

vx-underground

We are considering implementing a clause where companies with a specific amount of revenue must pay for the right to download malware from us.

It's irritating seeing multi-million or multi-billion dollar companies profit off our work

tl;dr becoming a villain

Читать полностью…
Subscribe to a channel