40629
The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/
Chat, I keep getting invited to DEFCON. But, I don't want to talk to anyone and I feel like I'll be bored without computer to bonk malware.
I do NOT want to talk to people. I would kind of like to see some talks and get silly shirts though. What do you think?
Chat, I have to do a weird rant opinion thingy and I hope someone understand what I'm saying.
I've noticed a strange phenomena where people who grew up poor have this weird mentality like, they feel they're not good enough to not be poor? I was "poor" growing up, not poor-poor living in a shack, but money was definitely tight and sometimes dinner sucked.
Anyway, I've met TONS of people who come from lower class families and lives, and who act scared to try to pivot into cybersecurity, or computer-science in general.
I don't know if it's self-esteem, or some weird internal thingie on classism, I don't know.
Maybe I sound crazy. Maybe someone smarter than me can convey the idea better. But it 100% happens. I see genuinely intelligent people, definitely capable of performing the type of work I do, end up doing construction or working a dead-end job somewhere and struggling financially and hating their lives because they're not intellectually stimulated. They could do so much more ... but they don't.
1. It takes forever to fucking load
2. The auto-complete fucks up half the time, if you're doing a for loop it bugs the fuck out and can't auto-complete because it doesn't under conditional statements and expressions
3. It keeps bugging out previewing COM interfaces and COM methods
4. Everything is unnecessarily color coded and it looks like dog shit
5. It keeps asking me to use Copilot (fuck you Satya)
6. The search on Windows defaults to the Visual Studio installer, despite me telling it 10,000 fucking times to load the IDE
7. For some reason my pre-build and post-build events are fucked up, from an old-old projects with YARA I was doing
FUCKING PIECE OF SHIT
> be me
> open telegram
> new message
> look inside
It's been SEVEN AND A HALF YEARS and I STILL get emails like this.
It's far less frequent, but it still occurs
> check DMs
> 99+ message requests
> look inside
> malware or cat pictures
Chat, I am blessed. I love you all so much.
In regards to these files inside of "child porn folder", the files present inside all end in *.lnk (A Windows shortcut). This is a very common file masquerading technique to give the facade of a legitimate file, but it's actually malware (shortcut pulls a file that it detonates, or points to an actual malware payload).
However, there is a small chance this is not file masquerading and a legitimate child predator accidentally uploaded files which are flagged as malware due to them linking to an external domain... or something else.
Basically, there are a few things this could be
1. Legitimate CSAM (Child sexual abuse material)
2. Malware payload disguised as CSAM to target pedophiles
3. Malware naming itself something CSAM related to avoid analysis
Regardless, for legal reasons (and emotional), I won't even try to figure out.
I'm not sure if this is an anti-malware analysis technique, or legitimately child pornography. I don't want to find out.
If this is child pornography, shoot them in the head.
If this isn't child pornography, this is the most brazen anti-malware analysis technique I've ever seen.
> be me
> get dm
> "is this malware?"
> "windows defender went crazy when i tried this video game mod"
> download
> look inside
> not malware
There is a function in Windows you can invoke called "GetAsyncKeyState". In simplest terms, this function waits for user input on the keyboard. When a key is pressed down GetAsyncKeyState tells you what was pressed down.
GetAsyncKeyState is used frequently with video games. Using this function video games can determine ... what you're pressing. Likewise, GetAsyncKeyState can be used by legitimate software for when a user does a shortcut or something. There is a lot of legitimate use cases for this function.
However, GetAsyncKeyState is also abused because GetAsyncKeyState is tells you what key on the keyboard is pressed down, GetAsyncKeyState is used as a way to record what users are typing. Typically the data returned from GetAsyncKeyState is piped to a text file. Other times malware developers may use GetAsyncKeyState to store recorded key strokes in-memory and then send it out externally to a remote computer.
Regardless, this video game mod was invoking GetAsyncKeyState and filtering each key press to determine when the mod was triggered. In essence, it was scanning and waiting to determine if it is toggled on or off. Furthermore, after the mod was toggled on or off, it logged when it was turned off for debugging purposes.
From Windows Defenders perspective it saw an unsigned and unverified library being arbitrarily loaded into a video game and, once loaded, it was scanning user keys and subsequently writing something to a text file.
After bonking this video game mod with a stick we know it's not malware. However, this is a great example of false-positives in anti-malware services because, by all means, this mod does seemingly mimic something a malware payload would do.
But it's not malware. It's just a silly video game mod for Baldurs Gate 3
Dear people living in Brazil,
I have been invited to speak at some University there. It will be online. We are currently negotiating my extremely high compensation request ($20 for some pizza).
I will probably schizo rant about pill addiction, reverse engineering malware without using a VM, and my experiences with dealing with terrorists (I send them pictures of cats).
I'll share more details soon.
2/59 ?????????????
2/59 ??????????
https://www.virustotal.com/gui/file/1a3609e76ee85d9b0f4eb11e79d3dc0d1b401c1c967ad34825120ec267b2374e/detection
I want to give a big shoutout to "WatchBeam.exe". WatchBeam is the LOUDEST malware I've ever seen.
When I say "runs cmd.exe", I mean it creates a new process. So, in the list below, it is literally creating a new process each time. Does this sound suspicious to you?
> run .exe
> runs cmd.exe, checks if running as admin
> runs powershell, checks screen dimensions
> runs cmd.exe, checks screen dimensions (again)
> runs cmd.exe, checks video controller
> runs cmd.exe, checks disk type
> runs cmd.exe, checks if "VBOX" is present
> runs cmd.exe, checks if "VBOX__" is present
> runs cmd.exe, checks if "VBOX" in registry
> runs cmd.exe, checks if "VirtualBox" in registry
> runs cmd.exe, checks if "VBoxGuest" present
> runs cmd.exe, checks if "VmWare" in registry
> runs cmd.exe, checks if "vmmouse" in registry
> runs cmd.exe, checks if "KVM" in registry
> runs cmd.exe, checks computer model
> runs cmd.exe, checks computer name for "Xen"
> runs cmd.exe, checks computer name for "HyperV"
> runs cmd.exe, checks computer name for "Virtual"
> runs cmd.exe, checks computer serial number
> runs cmd.exe, checks mouse position
> runs cmd.exe, checks motherboard serial number
> runs cmd.exe, checks default drive letter
> runs cmd.exe, kills chrome
> runs cmd.exe, kills edge
> runs cmd.exe, kills brave
> runs cmd.exe, kills opera
> runs cmd.exe, kills vivaldi
> runs cmd.exe, kills yandex
> runs cmd.exe, kills orbitum
> runs cmd.exe, kills atom
> runs cmd.exe, kills kometa
> runs cmd.exe, kills torch
> runs cmd.exe, kills amigo
> runs cmd.exe, kills coccoc
> runs cmd.exe, kills uran
> runs cmd.exe, kills slimjet
> runs cmd.exe, kills ivaldi
> runs cmd.exe, kills firefox
> runs cmd.exe, checks computer serial number (again)
> runs cmd.exe, checks computer status
> runs cmd.exe, checks Windows type
> runs cmd.exe, checks if antivirus installed
> runs cmd.exe, checks if Windows Defender on
> runs cmd.exe, checks computer status (again)
> runs cmd.exe, checks if Kaspersky installed
> runs cmd.exe, checks if Norton installed
> runs cmd.exe, checks if McAfee installed
> runs cmd.exe, checks if BitDefender installed
> runs cmd.exe, checks if AVG installed
> runs cmd.exe, checks if Windows Defender on (again)
> if all tests pass, downloads malware
YOU CREATED A NEW CMD.EXE PROCESS 48 TIMES. WHAT THE FUCK ARE YOU DOING?
> check news
> see giant penis
> ???
> read news
> "The phallic forecast predicts a cluster of thunderstorms, hail and heavy windows could come through the Upper Midwest, before finishing in the central Great Plains"
wtf are meterologists actually degenerate nerds too?
> try to bond with young family members again
> want to be cool
> use slang
> gang, aura, slimed, chopped, huzz
> hehe ik the lingo
> "ew ACTUALLY dont talk like that, youre old"
WHY CANT I BE COOL. LET ME BE COOL
This is a meme, but this is dead ass how malware really works sometimes.
Читать полностью…
what the actual fuck is wrong with you nerds? im not a fucking cat. STOP CALLING ME A CAT
Читать полностью…
Visual Studio 2026 is such a fucking piece of shit
The things I want to say to Microsoft about the recent "additions" to Visual Studio would get me investigated the FBI.
My online alias is "smelly". It has slowly over the years mutated by people to be; "stinky", "smelly smellington", "crazy cat guy", "schnelli", "schmelly", etc. It is still mostly "smelly".
It is not a cool or badass alias. However, the name was assigned to me from my wife. Ages ago my wife called me her "smelly man". She would walk into my office when I was working and, because room was small, poorly ventilated, and the door was closed, the room would get incredibly hot. I would get stinky from body odor.
She would come in, kiss me on the cheek, call me her "smelly man", and give me a snack or something. I would then resume work. She has always been extremely supportive of my malware collecting, writing, reversing, etc.
Hence, when I made vx-underground in 2019, and decided to start the journey of malware collecting and stuff, I said, "I need a cool name that is tough and everyone will think I'm totally awesome and badass". Then I remembered my wife called me "smelly"... so I went with that.
For the first like ... four years of the existence of vx-underground, people kept memeing, "What's the password?" because it was asked so often.
Memes never die, I guess, I don't know
"Can your next post have two cat pictures instead of one? I feel like you're not posting enough cats, so two of them will be (p)awesome" — Snailter
Yeah, I got you dawg, don't even trip.
> get dm
> "smelly, my dads old pc has a keygen on it. it plays really loud annoying music. was our old home pc infected with malware for many years?"
> download key gen
> look inside
> not malware
unfathomably based dad knew how to get legit warez
"if it's labeled child porn they won't even try to download it to reverse it"
That is correct.
Yesterday two different people contacted me about two different projects on GitHub.
"Tito" DMd me about someone making a comment on GitHub claiming to have a patch for "synara" (Image 1)
"Robert Z" emailed about something similar on a different GitHub project (image 2).
Interesting.
Upon further investigation it turns out this exact file has been discovered online named:
- hb_patch_v1112
- registry_patch_v0.1.7
- rep_fix_v1.zip
- sodium_fix_v1
- log_fix_patch
blah blah blah (image 3)
Basically, someone is creating accounts on GitHub, going to open issues, and leaving a comment saying they've found a patch (it's likely automated, but whatever). The patch is malware.
It appears this campaign began around July 7th (yesterday) and is making its rounds pretty quickly.
When you look inside (hehe silly reference) it's a program written in Go. When the binary detonates it queries a remote host which resolves to ... Telegram. The Telegram channel description specifies a website. The website in the Telegram description is where the payload exfiltrates code too.
They're doing it this way because they can quickly change the Telegram channel description if the website they specify is taken down. It's basically a bootleg DNS resolver (image 4).
Anyway, this is StealC (based on YARA identifiers). This is (probably) a new malware campaign by someone using StealC. I like it. Very cool usage of GitHub spam combined with a bootleg ass DNS resolver on Telegram. It probably helps because I doubt Telegram is quick to take action with takedown requests.
> read court affidavit on ransomware operator
> ransoms multi-billion dollar company
> does it while running Windows 11
> logs into Facebook from that computer
> uses Microsoft Edge
> make post making fun of malware
> get message
> look inside
> "Drop dead, you fucking idiot"
My Brother in Christ, your attempt at being stealthy unironically made your malware super loud. Your shit is not fooling ANYONE. Scrap this whole thing dawg, start over, because this shit is fucked up. I'm actually laughing at how absurd this payload is.
48 TIMES BRO
Tiny people living inside my computer,
I have synced the malware to prod. It is roughly 75,000 malware. Please download the malware. If you do not download malware this cat with a loaded revolver will shoot something (or someone).
https://vx-underground.org/Updates
Cheers,
-smelly
Good news for people who like malware: I have more malware coming soon
Bad news for people who HATE malware: I have more malware coming soon
What does this mean? It means I'm adding another 75,000 malwares and like, 50 papers on malware reverse engineering tonight.
> be me
> vxug admin
> 500,000 followers across social media
> crazy malware cat guy
> talk at unis
> millions of malwares
> unis use my website
> students use my website
> companies use my website
> governments use my website
> be mentioned by famous youtubers
> in tons of news article
> feel super cool and badass
> try to bond with younger family members
> "hey, you like someordinarygamer and moistcritical. they talked about me. thats pretty cool huh?"
> they roll eyes
> "they dont know that youre actually old and cringe"
> kills me inside
> talk to wife
> "hey fbi most wanted guy gave me an autograph!"
> she sighs
> "thats nice, but can you please just take out the trash?"
> kills me inside
> talk to young family member again
> "hey my self published book is trending top seller on amazon. thats cool huh?"
> rolls eyes
> "i guess, its not like its at barnes and noble or something"
> kill me inside