40629
The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/
extra silly points that the person who sent me the goop found it from a google ad lmfao
tl;dr no free robux, but free goop
> tell wife
> wife freaks out
> says I'll get rabies
> okay lol
> drive to ER
> tell them bit by bat
> they give me cool guy pass
> cut everyone in ER line
> haha suckers
> doctor sees me
> lol we gotta give you shots
> ok no big deal
> leaves
> comes back with 6 needles
> wtf
> "one in both shoulder"
> "one in both butt cheeks"
> "4 shots where bat bit you"
> needles fucking gigantic
> wtf
> get 8 shots
> body lumpy from shots
> tells me need to come back
> in 3 days, 7 days, 14 days
> wtf 6 more shots
Dawg, DO NOT become exposed to rabies. The shots HURT A LOT.
Chat, we're cooked.
Today I decided to review the malware collection. How much malware have I collected over the past 7.5 years? I've collected 42.13 TB
WHAT AM I DOING WITH ALL THIS GOOP
It turns out this goop someone sent me in a DM was state-sponsored malware designed to perform espionage on select groups on individuals in South America
This malware campaign was attributed to APT-C-36
Silly government written malware haha bonk bonk haha
Real ones know that this audio clip is from Dragon Ball Z: Broly the Legendary Super Saiyan, at the climatic ending when Goku was losing the fight to Broly, everyone was down and out, and Goku needed the energy from Trunks, Gohan, Piccolo, and Vegeta to defeat Broly once and for all before the comet destroyed the planet.
Totally unreasonable for them to show Planet Namek from the Frieza Saga
Vegeta was being a total bitch, refusing to give his energy to Goku, because Vegeta saw Goku as a lesser Saiyan and wasn't deserving of his royal energy (he is the Prince of all Saiyans). Eventually Vegeta concedes, gives Goku his energy, but tells him to "But Kakarot, finish him... finish him NOW!".
Instantly upon receiving the energy Goku hits a pseudo-SSJ2, terrifying Broly at Goku's newly acquired energy, even verbally saying out loud, "What?! Where is he getting all of this energy?!".
This accompanied by Haji's Kitchen "Lost" and "Day After Day".
I'm being so deadass, AI didn't even write this shit and I didn't even need to Google it, when this movie came out in the early 2000s me and middle school homies watched this fucking movie on repeat, we'd be rolling around the block on our bikes singing "Day After Day" and thinking about how Goku's Kamehameha wave didn't even scratch Broly when Goku was SSJ1
tl;dr United States government rules it may be legal to possess CSAM (Child Pornography) if it's AI generated
Dawg, last week the United States Seventh Circuit Court of Appeals made a decision which will unironically change the way CSAM (Child Pornography) is handled in the United States.
Under United States v. Anderegg, Anderegg was charged with distribution and possession of Child Pornography. Anderegg used Stable Diffusion AI to generate hyper-realistic depictions of children having sex.
While charged with CSAM, Anderegg appealed the decision and argued it was not possession of CSAM because the "children" in the images were not "real" children. Rather, Anderegg and his attorneys argued that it is not illegal to possess obscene material which does not harm anyone.
The courts official ruling: By 1969 ruling of Stanley v. Georgia, you are protected by the United States First Amendment to privately possess obscene material in one's home. Hence, because the images are completely computer generated, and no actual child was used to create the pornography, the United States government cannot constitutionally criminalize someone's private possession of those obscene images in their home under this statute
I also really hope no one in the government, or military, or whoever is in charge of this stuff, authorized IoT refrigerators...
Читать полностью…
> be me
> make post for Pasta People (italian government)
> Pasta People immediately message me
> wtf that was fast
> look inside
> angry message
> bad english
> "pasta lol we spaghetti people"
Having a physical dependency on Benzodiazepines (and playful psychological addiction) is not cool and is not badass.
Lately I've been very stressed. My ears feel like they're on fire, my heart races, my legs shake, it feels like I have a weight on my chest, I feel like I can't breath, I get dizzy, my stomach hurts, ... all my from stress and anxiety.
Then I turn my head to my right, look at my night stand, and I see a bottle of Clonazepam I'm tapering off of.
I know that if I take a higher dose, if I take just a few pills, all my anxiety will disappear, all my physical symptoms will disappear, I'll feel euphoric, my bed will feel softer and warmer, and I'll be able to sleep for what feels like forever.
I haven't relapsed, but it is not cool and it is not badass.
Chat, do NOT get addicted to prescription medication.
Two individuals behind TeamPCP were apprehended today in Australia.
TeamPCP was the Threat Group responsible for a series of high-profile supply-chain attacks that shook the cybersecurity ecosystem and were indirectly responsible for two silly kitty cat memes ("I wake up, there's a supply chain attack").
This news comes as a shock to many researchers as, for many years now, people questioned whether or not Australia really existed.
Furthermore, the apprehension has caused some controversy and division online as one individual arrested is aurafarming while being arrested, yet law enforcement does nothing to stop it as he mogs. It is disgusting.
> be me
> get dm
> "smelly, someone sent our company an e-mail with an attachment that looks malicious. i work at a large company. what is it?"
> wtf i look mystery company goop
> download
> look inside
> "INT-Number.20260821152655.IMG"
> disc image
> ok
> open with 7z
> two files inside
> "INT-Number.20260821152655.exe"
> "hdp.dll"
> INT-Number.20260821152655.exe SHA256 is harmless, well known file
> ok
> hdp.dll flagged as malware
> open hdp.dll in IDA
> ida implodes
> big ass fuck off stack frame
> intentionally poisons ida
haha this is v v silly goop
I made some typos, I meant to say "more technical for nerds", and when I copied the C2 addresses for ILSpy I messed up the formatting.
This was actually a kind of annoying payload to reverse because everything was so absurdly bloated and filled with junk.
Anyway, that's what the GTA VI "leak" does. It'll steal your passwords, allow some nerd remote access to your machine, and disables a bunch of stuff.
If you're going to distribute malware, at least have the common courtesy to do it in a manner which allows EVERYONE to get the malware.
Last time on Dragon Ball Z: I got over 9,000 DMs about a GTA VI video game leak circulating on torrent sites. Truthfully, I'm not up to date on the Take-Two and/or Rockstar Games Leeky boi lore, however I know the base game has NOT been leaked. Hence, we can conclude this is NOT the real GTA VI and this is almost certainly malware.
Unfortunately, this "totally legit" GTA VI "game" is an artificially inflated .ISO file, it is 133GB and only has five seeders. It would take me ages to download this file. I'm not going to try to download this .ISO file, patiently wait, watch it stall 56 times, and then get bummed out when it dies.
Please, if you're going to masquerade as GTA VI, make the malware easier to download. I am NOT waiting 42 hours for your malware payload
Dear Scammers Located Outside the United States,
If you want to social engineer someone, do not use the word "kindly". We've told you this like, a bajillion schmschmillion times, but seriously, when we read, "Do the needful, kindly open the application", it fucking STINKS of scam especially when you sign it something like, "Sincerely, Robert McNeal, Houston Texas"
Dawg, there is no stinky Texan, burning alive in the summer heat, drunk driving in a lifted truck with a "Jesus Saves" tattoo, named Robert McNeal saying "Do the needful, kindly do ____"
Just use ChatGPT bro, I don't know man, but it stinks and it's not fooling anyone
Pic possibly related
> be me
> get dm
> "smelly i found goop"
> wtf i love goop (malware)
> fake cloudflare download page
> tries to convince roblox nerds its robux
> haha_classic.gif
> look inside
> downloads powershell script
> curl file
> redirects, fails a bunch
> curl file again, but ask to not redirect
> goop download successful
> goop strategy so far is lots of staging
> .ps1 -> .exe -> .exe downloads more .exe
> ok
> curl next .exe
> fails, redirects again
> omfg bro
> curl file again, but ask to not redirect
> works
> look inside
> .exe with manually written COM for custom .NET
> tl;dr manual .NET loader
> whoa neato
> bonk with stick
> manually strip out .net code from .exe
> goop strategy thus far
> .ps1 -> .exe -> .exe -> .exe custom load csharp .exe
> look inside
> heavily obfuscated c# .exe
> evades emulation
> hehe silly goop
> decompile with ILSPY
> follow code execution manually
> checks system environment (fingerprinting)
> checks to see if .exe is in russia (lmfao)
> kills itself if its russian IP address (lmfao)
> checks gpu, cpu, ram, etc
> connects to spoopy IP address (tries to be sneaky)
> 158.94.208.92:61120
> tells 158.94.208.92:61120 what kind of PC its on
> 158.94.208.92:61120 asks what files are on PC
> gives 158.94.208.92:61120 file listing of PC
> csharp .exe waits for 158.94.208.92:61120
> 158.94.208.92:61120 may deliver more goop later
haha silly goop, this is v v silly
stage 1: cloudenterprisenew(.)com
stage 2: 8758aa166281eca53eecf11d167bf069ac3c3c07490b16f2efa687fd514081e8
stage 3: 1e0a8824261e3edb36d12fd5ce659cbb3989d4470809d2310cc56cd47da53555
stage 4: 6c14ea6f34a3a8f6a5eaa576e95c191326a2c4d58f9c19a0faf8ad139970a713
Stage 2 and Stage 4 weren't on VT
pic unrelated
> be me
> outside
> hehe sun feel good
> weird thingie on tree
> looks like fuzzy frog
> wtf frogs are cool
> approach fuzzy frog
> fuzzy frog flies off tree
> bites me
> scream
> "ah wtf, you fucking bitch"
> slap fuzzy frog hard af
> fuzzy frog on ground twitching
> finger has two tiny marks
> bleeding a little
> look down at fuzzy frog
> not fuzzy frog
> bat
Governments are funny and make funny goop
https://www.levelblue.com/blogs/spiderlabs-blog/still-circling-blind-eagles-toolkit-keeps-evolving
NEVER FEAR, NEVER HEAR, NEVER HOPE, NEVER TALK, NEVER EVER HAVING A THING, NEVER FEEL, NEVER WILL, I NEVER CRY, I NEVER DIE, I WON'T DIE MISSING YOU
https://www.youtube.com/watch?v=uJYI2hnc2SA
For more details and the full court ruling you can read it here:
https://media.ca7.uscourts.gov/cgi-bin/OpinionsWeb/processWebInputExternal.pl?Submit=Display&Path=Y2026/D08-25/C:25-1354:J:Lee:aut:T:fnOp:N:3597567:S:0
I was some really stupid AI video online. It's like, ... A really buff Pigeon? And he whispers when he talks, but it's loud like a speaking voice.
The Pigeon buff guy was talking about special pee pee poo poo sauce and for some reason jazz always plays when the video starts. Then the Pigeon guy has two sons and tells them one is going to be a hood Pigeon and the other a business Pigeon?
What the fuck am I looking at and why is it so stupid and funny? What is it called?
On social media today I've seen various United States military personnel (or individuals who known military personnel) discussing problems with refrigeration units on military bases.
For those outside the United States, the United States government has military bases which act as housing for soldiers, as well as veterans, and are basically like... mini cities, kind of. You drive there, a guard is at post, they ask to see your military badge or some sort of identification to prove you're military, then they let you on base.
These military bases have homes, gas stations, restaurants, grocery stores, and they're usually exempt from tax (I don't know to what degree, I'm not in the military).
Anyway, people on base are sharing images of the on-base military grocery stores having their refrigerators compromised. These refrigerators are used to hold ice cream, meat, dairy products, eggs, etc. Some soldiers have said they've heard nine military bases have had this issue.
This is not outside the realm of possibility if these refrigerators are IoT (Internet of Thing) devices, meaning they're connected to the internet and can be managed remotely. It is totally possible a Threat Actor was able to access the refrigerator control panel and disable them, which would destroy the food products.
It is extremely important however that I note this is all speculative. While it is possible they were compromised, and some military bases are having problems, this could all be rumors circulating around military bases and online. In other words, this is what soldiers are saying, but that doesn't necessarily make it true. We have no concrete evidence or official statement from the United States government.
I've easily cut my Clonezepam (Klonopin) dosage down 75%. However, this last 25% is a fucking NIGHTMARE. It is AWFUL. I am so fucked up from it. My body and mind are SCREAMING at me for more mystery goo (I have no idea how Klonopin is produced, I assume it's mystery goo).
My first 75% went back super super fast. This last 25% will take me a long, long, long time. I have no idea how long. If I had to guess, maybe 6 months or more. It fucking sucks.
Then these goofy ass doctors who specialize in addiction are trying to be helpful and be like, "Well, if you're feeling a little tense, have an Apple, or go for a walk".
You fucking stupid bitch I'M LOSING MY MIND. You think an Apple is going to take the edge off? A walk? Are you fucking nuts? Haha, I'm teasing (kind of), she is a super nice lady, she means well, but seriously though, it is really hard. I don't recommend it.
That's my prescription addiction lore update for nerds who asked.
Okay, have a nice day. I love you. Xoxo
All my peers and colleagues are being all serious and shit discussing the apprehension of TeamPCP members, discussing their OPSEC mistakes, the impact of the cyberattacks, an analysis on their malware payload, and I'm over here spreading 2006 Flat Earth Society conspiracy theories and commenting on the dudes very fancy jeans.
I've got nothing in the tank, big dawg. I'm just spewing bullshit. More news at 11 (I'll post pictures of cats).
Cheers,
> fbi red flag pops up
> man in atlanta, georgia
> username is unusual
> "MrChildPorn"
> go to his house
> take laptop
> password to laptop?
> "I FUK KIDZ"
> unlock computer
> look inside
> find child porn
Mannnn, I had hoped this would be good goop. I got all excited.
I decided to emulate this piece of shit to see what it does. The silly .dll that poisons IDA just runs a bunch of CMD.exe commands and drops a .vbs script.
The VBS script is vibe coded, all the AI agent notes are left in place. The VBS pulls a .zip from a jank ass URL and executes it using Powershell
The .zip has a fucking has ManageEngine and it does a silent install of the remote desktop software
I had high hopes. I thought you would be cool and badass. Instead it was AI slop and a goofy ass payload.
The Hastebin link with the VBS payload the .DLL drops. Look at that vibe coded slop. It is disgusting.
https://hastebin.ianhon.com/8aa5
Everyone and their Grandmother has been HOUNDING ME about this "GTA VI leak" which is circulating on torrent websites. I also saw TONS of terrible, absolutely atrocious, "reverse engineering" write-ups which are 100% AI slop or people who have no idea how to bonk goop with a stick.
Thankfully, stinky nerds came to my rescue and torrented the fake GTA VI so I could bonk it with a stick. Previous "write-ups" on social media ARE WRONG.
> gta vi "leak"
> download from ChlorideCull
> look inside
> tons of files
> junks DOI files
> "compress.libs"
> decoy file, Rockstar Games launcher
> other random junk
> setup.libs
> SHA256: 370efaa710945ece0e8b3b30a26b97ba8e56f0812d5014f512cab71c074a2e62
> password protected SFX installer
> lolwtf?
> "SetupGTAVI.exe"
> 1.05gb
> SHA256: 23a7d2ccfa91c2bb48eec6487a71f87b961d4c86f400cd60b1a9babcbe38849a
> artificially inflated with junk
> self-packed encapsulated payload
> jumps to payload far af away from base
> extracts VB6 DLL
> runs secondary stage VB6 DLL in-memory
> VB6 DLL runs various LOLBIN stuff
> executes setup.libs with super-secret password
> "pro defend 6"
> password somewhere in the 1gb file
> found by EricParker having to emulate 1gb file
> RIP da homie Eric fr
> setup.libs is tertiary payload
> setup.libs drops a bunch of files
> drops stage 4 binary, c.vbs
> drops stage 5 binary, c.bat
> both heavily obfuscated
> copies files to C:\Intel directory (fake directory)
> does over 9000 LOLBIN commands
> tries to kill any known AV known to man
> changes power settings so PC cant enter sleep mode
> disables telemetry on the computer
> disables copilot
> ??? wtf is bro doing lmfao
> disables phishing filter
> disables AI analysis
> disables windows suggestions
> ??? are they trying to help me now?
> disables error reporting
> disables more windows features
> extracts stage 6 payload, s.rar
> SHA256: 95930b47664a923a7317f7291a7678d01cdb392b78145fbcda6cd90c8f1b3a44
> super secret password: xUxVtsFFYjX7gL57LESCCBSfNsy5zqoT1fjf8iDFpdjEvjipPJzVNmhsWQ
> tired of following this binary down execution stack
> stage 7 binary, stage 8 binary doing stuff
> really tired of this payload
> another password for some other archive: dXbmLPhGBoZ0JIDsfsEG9u05nV3rPPLgDuO4lQQSAEfPd4UjObQnBj
> stage 9 payload
> Quasar RAT
> SHA256: e87b8c1997a8fca26dd408ccd7f186748821c49a3cb508984c7b46759cf2f592
> bonk with stick
C2s:
s21(.)my03(.)com:23140
s22(.)zzux(.)com:23140
strawenlike(.)mrbasic(.)com:23140 oldbooksdbkts(.)my03(.)com:23140
wormbookhgs(.)duckdns(.)org:23140 tencntsrv(.)cbu(.)net:23140
More technical for non-nerds: multi-staged payload, goes through 9 or 10 stages, to ultimately deliver QuasarRAT. It begins from an inflated binary which self-extracts a LZMA compressed VB6 DLL (stage 2). The VB6 in-memory modules launches a tertiary stager present with the masqueraded leak (setup.libs). The Tertiary stager is an SFX installer, password protected, which relies on a successfully IPC from the VB6 DLL secondary stager to pass "pro defend 6". The SFX installer copies data to a masqueraded Intel directory and executes a heavily obfuscated .VBS, which executes a heavily obfuscated .BAT, which performs a series of commands which extract from various .rar files present inside the SFX tertiary payload. The .rar files are additional stages responsible for disabling anti-malware software, disabling Windows telemetry, and anything which could tamper with the final payload. The final payload is a password protected .rar file which contains an artificially inflated .NET binary (QuasarRAT) which exfiltrates sensitive binaries to multiple C2 addresses and allows remote access to the machine.
When you have malware on your computer, and you let your anti-virus remove it, this is who you're hurting. Happy now? Don't remove the malware. Malware is good
Читать полностью…
I mean, it was kind of interesting for a second? He's using ESENT, the Microsoft database thingie, I haven't seen that in awhile, people usually use like SQLite or a goofy text file. He pulls update query stuff from his TMOG domain, updates are from a shrimple JSON file listing
I see his licensing stuff with Ed25519 verification and the fields for it... I see the update functionality, the speed test functionality...
Nothing really sticks out. I see the usage of COM for AUMID stuff... and a shit load of C++ goop.
Nothing in it really sticks out. It isn't malware. It isn't anything super-duper crazy. It does exactly as described.
Okay, now I must go back to other goop