40629
The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/
It's been SEVEN AND A HALF YEARS and I STILL get emails like this.
It's far less frequent, but it still occurs
> check DMs
> 99+ message requests
> look inside
> malware or cat pictures
Chat, I am blessed. I love you all so much.
In regards to these files inside of "child porn folder", the files present inside all end in *.lnk (A Windows shortcut). This is a very common file masquerading technique to give the facade of a legitimate file, but it's actually malware (shortcut pulls a file that it detonates, or points to an actual malware payload).
However, there is a small chance this is not file masquerading and a legitimate child predator accidentally uploaded files which are flagged as malware due to them linking to an external domain... or something else.
Basically, there are a few things this could be
1. Legitimate CSAM (Child sexual abuse material)
2. Malware payload disguised as CSAM to target pedophiles
3. Malware naming itself something CSAM related to avoid analysis
Regardless, for legal reasons (and emotional), I won't even try to figure out.
I'm not sure if this is an anti-malware analysis technique, or legitimately child pornography. I don't want to find out.
If this is child pornography, shoot them in the head.
If this isn't child pornography, this is the most brazen anti-malware analysis technique I've ever seen.
> be me
> get dm
> "is this malware?"
> "windows defender went crazy when i tried this video game mod"
> download
> look inside
> not malware
There is a function in Windows you can invoke called "GetAsyncKeyState". In simplest terms, this function waits for user input on the keyboard. When a key is pressed down GetAsyncKeyState tells you what was pressed down.
GetAsyncKeyState is used frequently with video games. Using this function video games can determine ... what you're pressing. Likewise, GetAsyncKeyState can be used by legitimate software for when a user does a shortcut or something. There is a lot of legitimate use cases for this function.
However, GetAsyncKeyState is also abused because GetAsyncKeyState is tells you what key on the keyboard is pressed down, GetAsyncKeyState is used as a way to record what users are typing. Typically the data returned from GetAsyncKeyState is piped to a text file. Other times malware developers may use GetAsyncKeyState to store recorded key strokes in-memory and then send it out externally to a remote computer.
Regardless, this video game mod was invoking GetAsyncKeyState and filtering each key press to determine when the mod was triggered. In essence, it was scanning and waiting to determine if it is toggled on or off. Furthermore, after the mod was toggled on or off, it logged when it was turned off for debugging purposes.
From Windows Defenders perspective it saw an unsigned and unverified library being arbitrarily loaded into a video game and, once loaded, it was scanning user keys and subsequently writing something to a text file.
After bonking this video game mod with a stick we know it's not malware. However, this is a great example of false-positives in anti-malware services because, by all means, this mod does seemingly mimic something a malware payload would do.
But it's not malware. It's just a silly video game mod for Baldurs Gate 3
Dear people living in Brazil,
I have been invited to speak at some University there. It will be online. We are currently negotiating my extremely high compensation request ($20 for some pizza).
I will probably schizo rant about pill addiction, reverse engineering malware without using a VM, and my experiences with dealing with terrorists (I send them pictures of cats).
I'll share more details soon.
2/59 ?????????????
2/59 ??????????
https://www.virustotal.com/gui/file/1a3609e76ee85d9b0f4eb11e79d3dc0d1b401c1c967ad34825120ec267b2374e/detection
I want to give a big shoutout to "WatchBeam.exe". WatchBeam is the LOUDEST malware I've ever seen.
When I say "runs cmd.exe", I mean it creates a new process. So, in the list below, it is literally creating a new process each time. Does this sound suspicious to you?
> run .exe
> runs cmd.exe, checks if running as admin
> runs powershell, checks screen dimensions
> runs cmd.exe, checks screen dimensions (again)
> runs cmd.exe, checks video controller
> runs cmd.exe, checks disk type
> runs cmd.exe, checks if "VBOX" is present
> runs cmd.exe, checks if "VBOX__" is present
> runs cmd.exe, checks if "VBOX" in registry
> runs cmd.exe, checks if "VirtualBox" in registry
> runs cmd.exe, checks if "VBoxGuest" present
> runs cmd.exe, checks if "VmWare" in registry
> runs cmd.exe, checks if "vmmouse" in registry
> runs cmd.exe, checks if "KVM" in registry
> runs cmd.exe, checks computer model
> runs cmd.exe, checks computer name for "Xen"
> runs cmd.exe, checks computer name for "HyperV"
> runs cmd.exe, checks computer name for "Virtual"
> runs cmd.exe, checks computer serial number
> runs cmd.exe, checks mouse position
> runs cmd.exe, checks motherboard serial number
> runs cmd.exe, checks default drive letter
> runs cmd.exe, kills chrome
> runs cmd.exe, kills edge
> runs cmd.exe, kills brave
> runs cmd.exe, kills opera
> runs cmd.exe, kills vivaldi
> runs cmd.exe, kills yandex
> runs cmd.exe, kills orbitum
> runs cmd.exe, kills atom
> runs cmd.exe, kills kometa
> runs cmd.exe, kills torch
> runs cmd.exe, kills amigo
> runs cmd.exe, kills coccoc
> runs cmd.exe, kills uran
> runs cmd.exe, kills slimjet
> runs cmd.exe, kills ivaldi
> runs cmd.exe, kills firefox
> runs cmd.exe, checks computer serial number (again)
> runs cmd.exe, checks computer status
> runs cmd.exe, checks Windows type
> runs cmd.exe, checks if antivirus installed
> runs cmd.exe, checks if Windows Defender on
> runs cmd.exe, checks computer status (again)
> runs cmd.exe, checks if Kaspersky installed
> runs cmd.exe, checks if Norton installed
> runs cmd.exe, checks if McAfee installed
> runs cmd.exe, checks if BitDefender installed
> runs cmd.exe, checks if AVG installed
> runs cmd.exe, checks if Windows Defender on (again)
> if all tests pass, downloads malware
YOU CREATED A NEW CMD.EXE PROCESS 48 TIMES. WHAT THE FUCK ARE YOU DOING?
> check news
> see giant penis
> ???
> read news
> "The phallic forecast predicts a cluster of thunderstorms, hail and heavy windows could come through the Upper Midwest, before finishing in the central Great Plains"
wtf are meterologists actually degenerate nerds too?
> try to bond with young family members again
> want to be cool
> use slang
> gang, aura, slimed, chopped, huzz
> hehe ik the lingo
> "ew ACTUALLY dont talk like that, youre old"
WHY CANT I BE COOL. LET ME BE COOL
But for real, I had sooooo many DMs of people telling me about their dependency on anxiety medications. People seemed scared to discuss it? Dawg, EVERYONE knows SOMEONE with dependency and/or addiction problems (alcohol, pain killers, benzos, whatever).
It isn't anything to be ashamed of.
In my experience thus far though, some people are kind of weird like ... "just quit cold turkey bro, just drink this cleansing tonic from my favorite Instagram Influencer for $15.99 per bottle" ... just BAD medical advice and kind of superstitious thinking? I don't know. I think everyone wants to help, or offer support, but sometimes their support or opinion isn't very good... but whatever bro, we ballin', fuck it
The fact the United States Department of Homeland Security took down an anime streaming website, and arrested the websites administrators, can only mean one thing.
Weebs pose a serious threat to the United States government. They're dangerous. They must be contained.
I only have one question though... This malware kills itself if it detects the following strings:
- sandbox
- sand box
- malware
- virus
- maltest
- peter wilson (??????)
- paul jones (??????)
who THE FUCK is peter wilson and paul jones???
Chat, today is a good day.
Look at this "Grand Theft Auto 6 BETA for FREE" advertisement that fell onto my lap. It delivers a .rar that has a .exe inside.
I am so happy. I am elated. It is free malware.
The United States is 250 years old.
To celebrate this occasion, we will be giving everyone two hundred and fifty (250) malwares.
God Bless
"Can your next post have two cat pictures instead of one? I feel like you're not posting enough cats, so two of them will be (p)awesome" — Snailter
Yeah, I got you dawg, don't even trip.
> get dm
> "smelly, my dads old pc has a keygen on it. it plays really loud annoying music. was our old home pc infected with malware for many years?"
> download key gen
> look inside
> not malware
unfathomably based dad knew how to get legit warez
"if it's labeled child porn they won't even try to download it to reverse it"
That is correct.
Yesterday two different people contacted me about two different projects on GitHub.
"Tito" DMd me about someone making a comment on GitHub claiming to have a patch for "synara" (Image 1)
"Robert Z" emailed about something similar on a different GitHub project (image 2).
Interesting.
Upon further investigation it turns out this exact file has been discovered online named:
- hb_patch_v1112
- registry_patch_v0.1.7
- rep_fix_v1.zip
- sodium_fix_v1
- log_fix_patch
blah blah blah (image 3)
Basically, someone is creating accounts on GitHub, going to open issues, and leaving a comment saying they've found a patch (it's likely automated, but whatever). The patch is malware.
It appears this campaign began around July 7th (yesterday) and is making its rounds pretty quickly.
When you look inside (hehe silly reference) it's a program written in Go. When the binary detonates it queries a remote host which resolves to ... Telegram. The Telegram channel description specifies a website. The website in the Telegram description is where the payload exfiltrates code too.
They're doing it this way because they can quickly change the Telegram channel description if the website they specify is taken down. It's basically a bootleg DNS resolver (image 4).
Anyway, this is StealC (based on YARA identifiers). This is (probably) a new malware campaign by someone using StealC. I like it. Very cool usage of GitHub spam combined with a bootleg ass DNS resolver on Telegram. It probably helps because I doubt Telegram is quick to take action with takedown requests.
> read court affidavit on ransomware operator
> ransoms multi-billion dollar company
> does it while running Windows 11
> logs into Facebook from that computer
> uses Microsoft Edge
> make post making fun of malware
> get message
> look inside
> "Drop dead, you fucking idiot"
My Brother in Christ, your attempt at being stealthy unironically made your malware super loud. Your shit is not fooling ANYONE. Scrap this whole thing dawg, start over, because this shit is fucked up. I'm actually laughing at how absurd this payload is.
48 TIMES BRO
Tiny people living inside my computer,
I have synced the malware to prod. It is roughly 75,000 malware. Please download the malware. If you do not download malware this cat with a loaded revolver will shoot something (or someone).
https://vx-underground.org/Updates
Cheers,
-smelly
Good news for people who like malware: I have more malware coming soon
Bad news for people who HATE malware: I have more malware coming soon
What does this mean? It means I'm adding another 75,000 malwares and like, 50 papers on malware reverse engineering tonight.
> be me
> vxug admin
> 500,000 followers across social media
> crazy malware cat guy
> talk at unis
> millions of malwares
> unis use my website
> students use my website
> companies use my website
> governments use my website
> be mentioned by famous youtubers
> in tons of news article
> feel super cool and badass
> try to bond with younger family members
> "hey, you like someordinarygamer and moistcritical. they talked about me. thats pretty cool huh?"
> they roll eyes
> "they dont know that youre actually old and cringe"
> kills me inside
> talk to wife
> "hey fbi most wanted guy gave me an autograph!"
> she sighs
> "thats nice, but can you please just take out the trash?"
> kills me inside
> talk to young family member again
> "hey my self published book is trending top seller on amazon. thats cool huh?"
> rolls eyes
> "i guess, its not like its at barnes and noble or something"
> kill me inside
Last time on Dragon Ball Z: I made a long ass post discussing my Benzodiazepine dependency. Lots of people sent me DMs, or left comments, calling me "brave", or something (is addiction and/or dependency taboo or something?). People also DMd me saying they also have Benzodiazepine dependency but were too scared to try to taper due to how dangerous the drug can be.
Behind the scenes I've basically been a test dummy for some people. Let me share with all of you how cool and badass my taper has been
> be me
> on benzos for 14 years
> not supposed to do more than 90 days
> everyone like "wtf bro"
> decide to do 25% reduction in dosage
> people call me crazy
> withdrawals start after two days, or something
> day two arrives
> insanely high anxiety
> heart sometimes races
> sometimes feel really hot
> sometimes legs feel like jelly
> sometimes really grumpy
> weird withdrawals arent nonstop
> comes in waves seemingly randomly
> sometimes better, sometimes worse
> not too bad, honestly
> really, really, really bad insomnia tho
> day five
> every clams down
> shrimple, not too bad
> consult with addiction specialist to help insomnia
> give me sleeping pills (trazadone)
> "go to hospital if you get dangerous erection"
> okay?
> hold previous 25% cut for a few weeks
> decide to aggressively taper again
> another 25% cut
> total reduction would be 50%
> start
> day two arrives
> feel really sad
> doesnt feel like depression
> feel "blue", just low energy and kind of mopey
> everything in my life great
> no reason to be sad
> legs sometimes feel like jello
> anxiety back
> heart race sometimes
> heart sometimes beat really hard
> mostly really sad
The sadness feels like I'm a 14 year old boy in math class whos crush (Susie Bananas, straight A student, champion of the Spelling Bee) recently told you in secret she has a crush on Joseph FastFeet (fastest kid in school), and now you're sad and have to listen to really emo music in your bedroom while your parents make you pancakes for dinner. It's not crippling depression, but you just feel kind of emotional.
The weird heart beat thingie is like, you'll be laying in bed and it's like your heart turned the bass up to fuck off level. I'm in bed and it feels like my heart is punching the mattress through my back. It's interesting.
Overall the taper hasn't been too bad.
Pic related: what my anxiety feels like during taper (just cat crushing the planet).
I'm on the weird part of the internet reading about Termite microbiomes
Now I'm frustrated scientists haven't conducted more research into biotechnologies that allow humans to extract nutrition from woody stuff like lignin
tldr why science man no let us eat wood wtf
Literally shaking, screaming, crying, THROWING UP.
The .exe is bundled with BUN (some Javascript bullshit). I deobfuscated the main goop inside of it, found the C2 configuration (where it downloads cool malware from), and ... it's dead.
Cloudflare KILLED THEIR C2. THE MALWARE IS DEAD. THEY KILLED THE MALWARE CAMPAIGN.
How are we supposed to get malware from fake Grand Theft Auto 6 advertisements if Cloudflare KILLS their infrastructure???
RIP NWHStealer campaign ID 202fdde5193b.
RIP NWHStealer c2 unauth-amper(.)cc
We're slowly convincing the youth to autismmax via silly pictures of cats.
Читать полностью…
You can read about it yourself here on page 12 (or page 8 of affidavit), then page 33 and down (page 29 of affidavit)
https://www.justice.gov/usao-ndil/media/1450651/dl?inline