vxunderground | Unsorted

Telegram-канал vxunderground - vx-underground

40629

The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/

Subscribe to a channel

vx-underground

I was some really stupid AI video online. It's like, ... A really buff Pigeon? And he whispers when he talks, but it's loud like a speaking voice.

The Pigeon buff guy was talking about special pee pee poo poo sauce and for some reason jazz always plays when the video starts. Then the Pigeon guy has two sons and tells them one is going to be a hood Pigeon and the other a business Pigeon?

What the fuck am I looking at and why is it so stupid and funny? What is it called?

Читать полностью…

vx-underground

On social media today I've seen various United States military personnel (or individuals who known military personnel) discussing problems with refrigeration units on military bases.

For those outside the United States, the United States government has military bases which act as housing for soldiers, as well as veterans, and are basically like... mini cities, kind of. You drive there, a guard is at post, they ask to see your military badge or some sort of identification to prove you're military, then they let you on base.

These military bases have homes, gas stations, restaurants, grocery stores, and they're usually exempt from tax (I don't know to what degree, I'm not in the military).

Anyway, people on base are sharing images of the on-base military grocery stores having their refrigerators compromised. These refrigerators are used to hold ice cream, meat, dairy products, eggs, etc. Some soldiers have said they've heard nine military bases have had this issue.

This is not outside the realm of possibility if these refrigerators are IoT (Internet of Thing) devices, meaning they're connected to the internet and can be managed remotely. It is totally possible a Threat Actor was able to access the refrigerator control panel and disable them, which would destroy the food products.

It is extremely important however that I note this is all speculative. While it is possible they were compromised, and some military bases are having problems, this could all be rumors circulating around military bases and online. In other words, this is what soldiers are saying, but that doesn't necessarily make it true. We have no concrete evidence or official statement from the United States government.

Читать полностью…

vx-underground

I've easily cut my Clonezepam (Klonopin) dosage down 75%. However, this last 25% is a fucking NIGHTMARE. It is AWFUL. I am so fucked up from it. My body and mind are SCREAMING at me for more mystery goo (I have no idea how Klonopin is produced, I assume it's mystery goo).

My first 75% went back super super fast. This last 25% will take me a long, long, long time. I have no idea how long. If I had to guess, maybe 6 months or more. It fucking sucks.

Then these goofy ass doctors who specialize in addiction are trying to be helpful and be like, "Well, if you're feeling a little tense, have an Apple, or go for a walk".

You fucking stupid bitch I'M LOSING MY MIND. You think an Apple is going to take the edge off? A walk? Are you fucking nuts? Haha, I'm teasing (kind of), she is a super nice lady, she means well, but seriously though, it is really hard. I don't recommend it.

That's my prescription addiction lore update for nerds who asked.

Okay, have a nice day. I love you. Xoxo

Читать полностью…

vx-underground

All my peers and colleagues are being all serious and shit discussing the apprehension of TeamPCP members, discussing their OPSEC mistakes, the impact of the cyberattacks, an analysis on their malware payload, and I'm over here spreading 2006 Flat Earth Society conspiracy theories and commenting on the dudes very fancy jeans.

I've got nothing in the tank, big dawg. I'm just spewing bullshit. More news at 11 (I'll post pictures of cats).

Cheers,

Читать полностью…

vx-underground

> fbi red flag pops up
> man in atlanta, georgia
> username is unusual
> "MrChildPorn"
> go to his house
> take laptop
> password to laptop?
> "I FUK KIDZ"
> unlock computer
> look inside
> find child porn

Читать полностью…

vx-underground

Mannnn, I had hoped this would be good goop. I got all excited.

I decided to emulate this piece of shit to see what it does. The silly .dll that poisons IDA just runs a bunch of CMD.exe commands and drops a .vbs script.

The VBS script is vibe coded, all the AI agent notes are left in place. The VBS pulls a .zip from a jank ass URL and executes it using Powershell

The .zip has a fucking has ManageEngine and it does a silent install of the remote desktop software

I had high hopes. I thought you would be cool and badass. Instead it was AI slop and a goofy ass payload.

The Hastebin link with the VBS payload the .DLL drops. Look at that vibe coded slop. It is disgusting.

https://hastebin.ianhon.com/8aa5

Читать полностью…

vx-underground

DOLLY PARTON DIED

NOOOOOO

Читать полностью…

vx-underground

Everyone and their Grandmother has been HOUNDING ME about this "GTA VI leak" which is circulating on torrent websites. I also saw TONS of terrible, absolutely atrocious, "reverse engineering" write-ups which are 100% AI slop or people who have no idea how to bonk goop with a stick.

Thankfully, stinky nerds came to my rescue and torrented the fake GTA VI so I could bonk it with a stick. Previous "write-ups" on social media ARE WRONG.

> gta vi "leak"
> download from ChlorideCull
> look inside
> tons of files
> junks DOI files
> "compress.libs"
> decoy file, Rockstar Games launcher
> other random junk
> setup.libs
> SHA256: 370efaa710945ece0e8b3b30a26b97ba8e56f0812d5014f512cab71c074a2e62
> password protected SFX installer
> lolwtf?
> "SetupGTAVI.exe"
> 1.05gb
> SHA256: 23a7d2ccfa91c2bb48eec6487a71f87b961d4c86f400cd60b1a9babcbe38849a
> artificially inflated with junk
> self-packed encapsulated payload
> jumps to payload far af away from base
> extracts VB6 DLL
> runs secondary stage VB6 DLL in-memory
> VB6 DLL runs various LOLBIN stuff
> executes setup.libs with super-secret password
> "pro defend 6"
> password somewhere in the 1gb file
> found by EricParker having to emulate 1gb file
> RIP da homie Eric fr
> setup.libs is tertiary payload
> setup.libs drops a bunch of files
> drops stage 4 binary, c.vbs
> drops stage 5 binary, c.bat
> both heavily obfuscated
> copies files to C:\Intel directory (fake directory)
> does over 9000 LOLBIN commands
> tries to kill any known AV known to man
> changes power settings so PC cant enter sleep mode
> disables telemetry on the computer
> disables copilot
> ??? wtf is bro doing lmfao
> disables phishing filter
> disables AI analysis
> disables windows suggestions
> ??? are they trying to help me now?
> disables error reporting
> disables more windows features
> extracts stage 6 payload, s.rar
> SHA256: 95930b47664a923a7317f7291a7678d01cdb392b78145fbcda6cd90c8f1b3a44
> super secret password: xUxVtsFFYjX7gL57LESCCBSfNsy5zqoT1fjf8iDFpdjEvjipPJzVNmhsWQ
> tired of following this binary down execution stack
> stage 7 binary, stage 8 binary doing stuff
> really tired of this payload
> another password for some other archive: dXbmLPhGBoZ0JIDsfsEG9u05nV3rPPLgDuO4lQQSAEfPd4UjObQnBj
> stage 9 payload
> Quasar RAT
> SHA256: e87b8c1997a8fca26dd408ccd7f186748821c49a3cb508984c7b46759cf2f592
> bonk with stick

C2s:
s21(.)my03(.)com:23140
s22(.)zzux(.)com:23140
strawenlike(.)mrbasic(.)com:23140 oldbooksdbkts(.)my03(.)com:23140
wormbookhgs(.)duckdns(.)org:23140 tencntsrv(.)cbu(.)net:23140

More technical for non-nerds: multi-staged payload, goes through 9 or 10 stages, to ultimately deliver QuasarRAT. It begins from an inflated binary which self-extracts a LZMA compressed VB6 DLL (stage 2). The VB6 in-memory modules launches a tertiary stager present with the masqueraded leak (setup.libs). The Tertiary stager is an SFX installer, password protected, which relies on a successfully IPC from the VB6 DLL secondary stager to pass "pro defend 6". The SFX installer copies data to a masqueraded Intel directory and executes a heavily obfuscated .VBS, which executes a heavily obfuscated .BAT, which performs a series of commands which extract from various .rar files present inside the SFX tertiary payload. The .rar files are additional stages responsible for disabling anti-malware software, disabling Windows telemetry, and anything which could tamper with the final payload. The final payload is a password protected .rar file which contains an artificially inflated .NET binary (QuasarRAT) which exfiltrates sensitive binaries to multiple C2 addresses and allows remote access to the machine.

Читать полностью…

vx-underground

When you have malware on your computer, and you let your anti-virus remove it, this is who you're hurting. Happy now? Don't remove the malware. Malware is good

Читать полностью…

vx-underground

I mean, it was kind of interesting for a second? He's using ESENT, the Microsoft database thingie, I haven't seen that in awhile, people usually use like SQLite or a goofy text file. He pulls update query stuff from his TMOG domain, updates are from a shrimple JSON file listing

I see his licensing stuff with Ed25519 verification and the fields for it... I see the update functionality, the speed test functionality...

Nothing really sticks out. I see the usage of COM for AUMID stuff... and a shit load of C++ goop.

Nothing in it really sticks out. It isn't malware. It isn't anything super-duper crazy. It does exactly as described.

Okay, now I must go back to other goop

Читать полностью…

vx-underground

this goes unbelievably hard wtf

Читать полностью…

vx-underground

Thank you to everyone who has sent me the magnet link for what they suspect to be a masqueraded GTA VI malware payload.

I won't have time today to bonk it with a stick. It is Saturday. I will primarily be outside with my family doing things. I am currently sitting in a parking lot while my family fights for food in the wilderness (the grocery store, it's super busy for some reason).

Later this evening, realistically like, 10pm or later EST, I will take a look at it and see what it's doing, unless one of my peers decides to bonk it with a stick first.

I would like to note however that this isn't a surprising malware idea. Threat Actors are quick to weaponize anything which is trendy or will grab attention. Malware frequently masquerades as video game leaks, movie releases, music releases, political news, ... basically anything that people in large quantities would be interested in.

Anyway, smell ya later NERDS

Читать полностью…

vx-underground

Nah this is a real image circulating online from Facebook. The Albany, Georgia Police Department did actually post this asking for the publics assistance.

But, it's so stupid it's worth memeing. It unironically costs the Police Department more money to even make this post on social media and do an investigation than simply saying "sorry dawg" to whoever dropped $30 out of their pocket.

I'll literally give the police department $30 so they fuck off and leave this old guy alone. Who hasn't found money on the ground and said "oh whoa cool" and went on about their business?

Fucking goofy bro lmfao

Читать полностью…

vx-underground

What the fuck is this

Читать полностью…

vx-underground

> How can you tell it was vibe coded?

Читать полностью…

vx-underground

I also really hope no one in the government, or military, or whoever is in charge of this stuff, authorized IoT refrigerators...

Читать полностью…

vx-underground

> be me
> make post for Pasta People (italian government)
> Pasta People immediately message me
> wtf that was fast
> look inside
> angry message
> bad english
> "pasta lol we spaghetti people"

Читать полностью…

vx-underground

Having a physical dependency on Benzodiazepines (and playful psychological addiction) is not cool and is not badass.

Lately I've been very stressed. My ears feel like they're on fire, my heart races, my legs shake, it feels like I have a weight on my chest, I feel like I can't breath, I get dizzy, my stomach hurts, ... all my from stress and anxiety.

Then I turn my head to my right, look at my night stand, and I see a bottle of Clonazepam I'm tapering off of.

I know that if I take a higher dose, if I take just a few pills, all my anxiety will disappear, all my physical symptoms will disappear, I'll feel euphoric, my bed will feel softer and warmer, and I'll be able to sleep for what feels like forever.

I haven't relapsed, but it is not cool and it is not badass.

Chat, do NOT get addicted to prescription medication.

Читать полностью…

vx-underground

Two individuals behind TeamPCP were apprehended today in Australia.

TeamPCP was the Threat Group responsible for a series of high-profile supply-chain attacks that shook the cybersecurity ecosystem and were indirectly responsible for two silly kitty cat memes ("I wake up, there's a supply chain attack").

This news comes as a shock to many researchers as, for many years now, people questioned whether or not Australia really existed.

Furthermore, the apprehension has caused some controversy and division online as one individual arrested is aurafarming while being arrested, yet law enforcement does nothing to stop it as he mogs. It is disgusting.

Читать полностью…

vx-underground

TIM CURRY DIED

NOOOO

Читать полностью…

vx-underground

> be me
> get dm
> "smelly, someone sent our company an e-mail with an attachment that looks malicious. i work at a large company. what is it?"
> wtf i look mystery company goop
> download
> look inside
> "INT-Number.20260821152655.IMG"
> disc image
> ok
> open with 7z
> two files inside
> "INT-Number.20260821152655.exe"
> "hdp.dll"
> INT-Number.20260821152655.exe SHA256 is harmless, well known file
> ok
> hdp.dll flagged as malware
> open hdp.dll in IDA
> ida implodes
> big ass fuck off stack frame
> intentionally poisons ida

haha this is v v silly goop

Читать полностью…

vx-underground

I made some typos, I meant to say "more technical for nerds", and when I copied the C2 addresses for ILSpy I messed up the formatting.

This was actually a kind of annoying payload to reverse because everything was so absurdly bloated and filled with junk.

Anyway, that's what the GTA VI "leak" does. It'll steal your passwords, allow some nerd remote access to your machine, and disables a bunch of stuff.

Читать полностью…

vx-underground

If you're going to distribute malware, at least have the common courtesy to do it in a manner which allows EVERYONE to get the malware.

Last time on Dragon Ball Z: I got over 9,000 DMs about a GTA VI video game leak circulating on torrent sites. Truthfully, I'm not up to date on the Take-Two and/or Rockstar Games Leeky boi lore, however I know the base game has NOT been leaked. Hence, we can conclude this is NOT the real GTA VI and this is almost certainly malware.

Unfortunately, this "totally legit" GTA VI "game" is an artificially inflated .ISO file, it is 133GB and only has five seeders. It would take me ages to download this file. I'm not going to try to download this .ISO file, patiently wait, watch it stall 56 times, and then get bummed out when it dies.

Please, if you're going to masquerade as GTA VI, make the malware easier to download. I am NOT waiting 42 hours for your malware payload

Читать полностью…

vx-underground

Dear Scammers Located Outside the United States,

If you want to social engineer someone, do not use the word "kindly". We've told you this like, a bajillion schmschmillion times, but seriously, when we read, "Do the needful, kindly open the application", it fucking STINKS of scam especially when you sign it something like, "Sincerely, Robert McNeal, Houston Texas"

Dawg, there is no stinky Texan, burning alive in the summer heat, drunk driving in a lifted truck with a "Jesus Saves" tattoo, named Robert McNeal saying "Do the needful, kindly do ____"

Just use ChatGPT bro, I don't know man, but it stinks and it's not fooling anyone

Pic possibly related

Читать полностью…

vx-underground

> SCHMEEELY LOOK AT DAVE PLUMMERS TASK MANAGER TMOG
> sort of free time
> ok
> download
> look inside
> not malware

Читать полностью…

vx-underground

> be me
> off beep boop machine for a bit
> get back on beep boop machine
> check news
> leaks, extortion, crypto theft
> cybercrime rampant
> internet drama all over the place
> 22% DECREASE in silly pictures of cats

Читать полностью…

vx-underground

Some group told people I have the GTA VI game, or something, and told people to DM me for a chance to get GTA VI? I think?

They also said I was their business partner?

I don't understand what's going on.

But I am receiving a lot of DMs online about it.

I'm not sure if this is a troll, or meme, or a coordinated harassment campaign, but this is a very odd start to my Saturday. I am extremely confused.

Читать полностью…

vx-underground

BREAKING🚨

AN ELDERLY MAN FOUND $30 ON THE GROUND AND DID NOT RETURN IT.

HE IS EXTREMELY DANGEROUS.

THE POLICE OF THE ALBANY GEORGIA POLICE DEPARTMENT ARE WARNING THE PUBLIC OF THIS DANGEROUS CRIMINAL

THEY WILL SPEND THOUSANDS OF TAX DOLLARS TO GET THAT $30 BACK

Читать полностью…

vx-underground

Setting up a malware stand on the side of the road.

Windows Malware for ¢25
Linux Malware for ¢50
Cat picture ¢35

Читать полностью…

vx-underground

I have lots of stuff cooking, but when I will have the opportunity to do more is difficult to determine***

Proof I don't use stupid sissy AI, I make dumb typos and look brain dead like a CHAD (please don't bully me)

Читать полностью…
Subscribe to a channel