40629
The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/
Wait, no, that is incorrect. That is instructions on how to make booze in prison.
Читать полностью…
Update on building the new vx-underground backend server: things are getting weird
Читать полностью…
Today Elon Musk announced Twitter (X?) will be removing the ability to block people.
Читать полностью…
We are excited to announce a new project in collaboration with our friend pancak3lullz
We will be making a collection of artwork using AI, inspired by malware and Threat Actors.
Check it out here: https://art.vx-underground.org
Basssterlord (also known as AL3xL7 on Twitter), is an internationally wanted cyber criminal, known Lockbit ransomware group affiliate, and leader of the infamous "National Hazard Agency" group (a subgroup of Lockbit).
He is publicly offering to pentest companies.
Leaked footage of FBI agents celebrating the indictment of ransomware actors
Читать полностью…
AnonFiles, the anonymous file upload and sharing website, has decided to call it a quits today. When attempting to visit their website you are greeted with a farewell message.
Thank you for your service, AnonFiles. It was a helluva website.
Information via g0njxa
When you become a Lockbit ransomware affiliate this is what the affiliate panel looks like.
- StealBit
- LockBit RED
- LockBit GREEN
- LockBit BLACK
- Linux/ESXi
- Chat generation
Chinese authorities have pledged to “publicly disclose a highly secretive global reconnaissance system” operated by the U.S. government following an investigation into the alleged hacking of earthquake monitoring equipment in Wuhan.
https://therecord.media/china-accuses-us-global-reconnaissance-system-wuhan
We've updated the vx-underground paper collection
- 2023-07-14 - Oh-No a Vulnerability & PoC demonstration in a popular Anticheat tool
- 2023-07-31 - Intel Redirect Protection Internals
- 2023-08-02 - Using Call Frequency to Identify API Functions
https://www.vx-underground.org/
This morning ALPHV ransomware group released over 1TB of data from a Catholic university in Illinois.
On the front page of the ransom announcement for the school they display a photo of an alleged HR sexual harassment complaint. It shows a male receiving a fellatio from a woman.
Life goals:
- Get an autograph from Anatoliy Sergeyevich Kovalev
- Get an autograph from Maksim Viktorovich Yakubets
- Visit Pyongyang (without being kidnapped)
- Visit Russia to meet Mikhail Pavlovich Matveev and ALPHV administrative staff (without being kidnapped)
The final two goals have a high risk of being kidnapped or being sent to labour camps. So it's more of a pipe dream
Some nerd called in a bomb threat to Caesars forum at DEFCON. They had to clear out the place.
Some nerds are reporting someone detonated fireworks
Hello.
It is nice seeing so many photos of people wearing our merchandise. It is a surreal feeling knowing that so many people genuinely care about our goofy little website with its bad HTML and edgy images.
Thank you for the love
P.S. More nerd photos attached
Over the past 24 hours we have received dozens of e-mails from compromised government e-mail addresses.
This is a clear illustration of how easy it is for Threat Actors to get access to legitimate e-mails to social engineer people (or corporations).
New vx-underground backend is up.
The issue was resolved using 96 fl oz of grape juice, half a cup of pure cane sugar, and .40 oz of Fleischmann's RapidRise Yeast.
We are currently building the new vx-underground backend servers
Читать полностью…
ALPHV ransomware group administrative staff calling Microsoft Threat Intelligence 'slowpokes' for discovering their new ransomware variant 6 MONTHS LATER.
Читать полностью…
8base ransomware group used the now defunct AnonFiles as a backup mirror for all of their stolen (or ransomed) data from victims. Due to the site going down 8base has admitted they are now encountering problems.
Читать полностью…
We've updated the vx-underground malware sample collection.
We've added Win32.4943GeopBytes.Bomb. This zip bomb, when opened, it extracts to 4,943 Geopbytes
- Byte
- Megabyte
- Gigabyte
- Terabyte
- Petabyte
- Exabyte
- Zettabyte
- Yottabyte
- Brontobyte
- Geopbyte 🥵🥵
Although this is relatively benign compared to the other malware in our repo, this is a fun reminder of child like pranks in the early days of computers =D
File courtesy of the nerds at /g/
We completed a long term project. Our entire APT collection is now named appropriately. It will improve legibility and improve search results when using the search bar.
Special thanks to _BradleyVX and f0wlsec
https://www.vx-underground.org/
And when you build the binary through the panel this is the output:
Читать полностью…
Some dork on TikTok claims to uncovered an NSA (or CIA) plot about the "those muthafuckers are not real" airplane girl. As proof, he posts a traceroute from his computer to her website. He 100% believes the traceroute is proof that this viral video is being covered up because she discovered aliens.
Her website is hosted on HostGator and uses a WordPress install. It is shared hosting.
He 100% believes the United States government can only buy servers in the Washington DC metropolitan area. (???)
https://twitter.com/xInFiNiTe1x/status/1690909158793433088
Today Raccoon Stealer announced their return.
The Raccoon Stealer team informed us that the individual from their team arrested in October, 2022 was responsible for infrastructure. Following his arrest they decided to rebuild the entire infrastructure from scratch.
Ransomware is bad - but if the HOA was ransomed we would celebrate.
That's all.
We've updated the vx-underground malware sample collection
- Arechclient2
- CobaltStrike
- Emotet
- IcedId
- LockBitRansomware
- NetSupportRAT
- NSIS
- Paradies
- PoweRAT
- QakBot
- RedCap
- RedLine
- RoyalRansomware
- SpyNote
- Xdr33
Check it out here: https://www.vx-underground.org/
We've updated the vx-underground paper collection
- 2022-12-04 - SilentMoonWalk - Demonstrating call stack spoofing
- 2022-12-30 - Code Execution against Windows HVCI
- 2023-07-27 - Kerberos UAC Bypass - Abusing Kerberos Tickets for UAC Bypasses
https://www.vx-underground.org/
Thank you to our amazing friend and colleague LaurieWired for the mysterious floppy and cool Pokemon card.
However, it is 2023 and we do not have anything to view this....
A new combatant has entered the arena.
This individual e-mailed us from a compromised United States government e-mail. They also wanted to provide to message to the other individuals e-mailing us.
Image 1 & 2 is e-mail
Image 3 is headers for nerds screaming spoof at us
Someone else ran into this nerd again. We have no idea who he is, but we can assert with some degree of confidence he has not changed his shirt in over 2 days.
Читать полностью…