40629
The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/
If this were a meme made by someone in my age group it would be something like, "how I walk when I have hemorrhoids"
Читать полностью…
Literally every 3 or 4 months Satya Nadella serves us up a big slop pot of abusable features. He's a malware factory
Читать полностью…
Chat, big shenanigans are afoot. Zyaire Dontaevious Zamarion Wilkins, one of the individuals behind the "BlockBlasters" steam malware campaign, also social engineered people online by pretending to be a woman.
Wilkins, and a currently unlisted number of people, worked to spearphish people who owned cryptocurrency. They published a fake game on Steam named "BlockBlasters" which received international attention for crypto draining a terminally ill cancer patient.
It turns out Wilkins also impersonated a person named sibeleth
That girl who was flirting with you, asking about how much money you hold in crypto, was actually a 21 year old African American man
tldr you sending me malware is good, sometimes really interesting things happen. Thank you for sending me malware.
Also, I really want to note I didn't do any investigative work or whatever, I just reverse engineered it, explained how it works, noted some IPs or crypto wallets, nothing else. I'm just the malware guy. I'm nothing else. There were a lot of people who came together after BlockBlasters appeared that did really cool stuff and helped a lot of people. Lots of people shared information publicly which identified people. I'm just bonking stuff with sticks and looking at cats
> be UK
> post racism memes
> say schizo stuff
> 2 years in prison
> ransom critical infrastructure
> make millions from cybercrime
> 5 years prison
> eligible for release in 2 years
I don't understand the UK
They'll probably get out in two years. The United Kingdom is badass bro wtf ransomware is basically legal
Читать полностью…
Dawg, I'll tell you something right now though, if my son is like six, and he's like, "Dad, you're on beep boop machine a lot. Can you teach me how to malware?".
I'll say, "My son, my flesh and blood, my beautiful baby boy. Sit down. We begin now".
Then I will transfer everything I know about malware from my brain into his brain over several years. When he is a pre-teen he will possess all of my malware knowledge and he will inherit vx-underground when I die.
Or maybe he'll think malware is stinky nerd shit and instead want to play video games with his friends and do psychologically normal things. Only time will tell.
> be United States
> sanction VPN
> used for ransomware
> ransomware VPN uses Telegram
> Advertisement and customer support
> US Treasury publishes sanction thingie
> list VPNs Telegram channel
> Domain people see it
> See t.me/ransomwarethingie
> "OMG BLOCK T.ME!!!"
> Put global block on t.me
> Breaks Telegram URLs
> Telegram owner mad af
> Complains, says they can't read
> "hehe oops, me no think good"
> Resolved like, 24 hours later
Imagine waking up and being excited about helping Jimmy JumboToes remove malware from his computer. You unironically just send links to MalwareBytes, CCleaner, and hold their hand through the process. Then, once it's done, you decide to do it again, and for free.
Fucking schizo
It's very surreal. It doesn't feel like typical depression. I've been depressed. This is a different feeling. My logical state is normal, I can identify everything is fine. However, my emotional state is shot to shit. It's weird because like, one side of brain is normal, one side of brain is depressed, but it doesn't match, it is very strange and very confusing.
Because of this mismatch I can feel sad, then normal, then sad, then normal. It oscillates throughout the day, but it's not like mania or Bipolar disorder. It's like... Literally a random wave of depression that subsides seemingly randomly. It's really weird.
Overall I give this experience a 3/10. It's not terrible, but it is far from good.
Still thinking about that Python malware that targeted Steam
I kind of want to do it in C and make it painfully convoluted and unnecessarily obfuscated for literally no good reason other than a challenge
Conversely, I want to look at silly pictures of cats and watch esoteric videos on the the geography of the United States
I'm torn emotionally
Nah, I have to share some of my personal experiences for a second.
I saw a few newer people in information security share some code, or ideas they had, on social media. They retracted their posts, or code, because of criticism they received. This wasn't one singular person, to my surprise I saw like, five noobies sharing stuff.
Very cool.
Let me tell you something, stinky new people: yes, people online are mean. They are very mean. I have been BOILED ALIVE by stinky nerds online. I have been called every synonym for idiot you can imagine over the past ... uhhh, 21 years of doing malware related stuff.
And because this is the internet, and we're connected across the globe, I've had the pleasure of being called an idiot (or something similar) in English, Spanish, French, Russian, Mandarin, Hindi, Arabic, Portuguese, and more.
While these people are not nice, I very sincerely recommend filtering out the negative verbiage and focusing on the underlying message (if applicable). It is a skill that you'll need to adapt and grow in this field. In the "hacker" sphere, intellectuality is like, the thingie people value the most (or at least claim to).
Hence, if you share something it will be heavily critiqued. When you share something, whether you explicitly say it or not, you're inviting your peers for feedback. You WILL receive feedback, good or bad, and you will have to learn to handle it, process it, or learn from it.
Someone say your code is trash? Good. That is an opportunity to improve.
Someone criticize you for leaning heavily on AI? Good. Use AI as a tool to learn and stop using it as much.
Someone misunderstood what you said and called you a bad name? Good. Use that as an opportunity to practice improving your phrasing and writing.
Someone say your idea is repetitive and has been done before? Good, you discovered an idea for yourself, learned about an existing idea, and now you know how to find more ideas.
"Hey smelly, I work for (company), we had a threat actor phish an employee and use ScreenConnect to get access to their computer. The Threat Actor then dropped a .exe on the computer. Our AV/EDR stopped it, but we don't know what it is. Do you want to see?"
> yes, absolutely, give me goopies
> give malware
> download
> look inside
> position independent c code
> points to section of memory
> xor'd several times
> un-xor's thingie in memory
> creates process of random thingie
> pauses process of random thinie
> hollows out process
> puts goopies it extracted from itself into it
> resumes process
> lol process hollowing from embedded payload
> payload not in .exe section
> payload in .rdata mixed with other stuff
> omg w/e fine, make me work
> run the goopie
> bonk with stick
> find thingie it hollowed out
> grab the magic goop from it
> yay
> look inside
> another .exe
> ok, .exe has .exe hidden inside, runs random .exe and puts secret .exe inside it
> look at secret .exe thingie
> c#.net .exe
> ok lol
> look inside
> has hidden .exe inside it
> omfg why bro are you doing this to me
> pull .exe out of hidden .exe (im on secret .exe two now)
> dies
> base64 encoded the .exe internally
> omfg why bro
> base64 decode second secret .exe internally
> get the goopies
> second .exe is actually .dll
> heavily obfuscated c#.net
> really annoying me now
> check virustotal
> second mystery .exe (actually .dll) never seen before
> look inside more
> sniff sniff
> sniff sniff
> PURE-RAT
> attributed to suspected Vietnamese Threat Actor group
> matches known tactics, techniques, and procedures of group
> matches details from Trellix and Huntress
> group still evolving
> went from noobs to doing p good malware
My Brother in Christ, your organization is (probably) being targeted by a known Vietnamese Threat Group
The kids are making anti government surveillance memes and I love it.
Читать полностью…
Was laying in bed this morning thinking of Satya Nadella (CEO of Microsoft).
He makes me feel warm and fuzzy inside.
I'm so excited to hear about the new additions to Windows next quarter. It's going to be more features we can use for malware. I'm so excited. He's awesome
> x ad revenue sharing?
> down.
> monthly vx-underground donors?
> losing more.
> vx-underground sponsors?
> lost more.
> pictures of silly cats?
> up 8000%
Maybe a year ago, I don't remember, a game appeared on Steam called BlockBlasters. BlockBlasters was actually malware, and it gained recognition primarily because it was used to crypto drain a terminally ill cancer patient.
I was the first person (to the best of my knowledge) to reverse engineer BlockBlasters after people began notifying me about the game on Steam potentially being malware.
It ended up being a huge deal, primarily because BlockBlasters was used for targeted crypto draining campaigns.
Anyway, the FBI has begun arresting the people. The first person arrested was 21 year old Zyaire Dontaevious Zamarion Wilkins, based out of Florida. I assume more arrests are coming.
This person specifically made $220,000 from the malware campaign, with $32,000 coming from a terminally ill (now deceased) cancer patient.
The FBI after I keep sending them e-mails with pictures of cats for literally no reason (they hate my guts)
Читать полностью…
After receiving an e-mail from the FBI, or EUROPOL, or whatever, about Operation Leak, I decided to establish a line of communication with the FBI.
I am now Super Top Secret (STS) FBI Agent Smelly Smellington, in charge of silly cat picture collection intelligence
HOLY.
The two nerds from Scattered Spider got FIVE YEARS for profiting millions from ransomware and, most notably, ransoming critical infrastructure in the United Kingdom.
Dawg, move to the UK and do cyber crime. It's basically legal there. They don't even extradite you
> wake up
> take a shit
> get out of bed
> check email
> email from fbi
> not spoofed
> something something leakbase
> "On behalf of the International Law Enforcement Operation Leak"
> "Law enforcement takes this type of crime extremely seriously and will not hesitate to act against offenders"
> think
> "did i make a leakbase account?"
> flash back
> made account to check out website
> spoke with admin briefly
> unironically sent him pictures of cats
> now fbi and europol sending me mean emails
> is sending cats a crime?
Chat, my entire life I've hated going outside. I like being on beep boop machine and doing malware stuff.
However, my son is 16 months old and, despite everything, I have been extremely happy and fulfilled spending time with my son and extended family outside.
For the first time in my life I do not hate outside because my son is happy outside. He plays in the dirt, farts, and says "Dad?" while pointing at stuff.
It is cool and badass. Being a Dad is super cool and super badass.
Anyway, I see your malwares you've sent me. I plan on getting to it. I have lots of stuff planned. However, it is low priority for me at the moment because my son and I are busy (playing in the dirt, farting, etc).
Overall I'd rate having children a 10/10. Having a little dude call you "Dad" makes you feel good inside in a way nothing else can
The darkest time in my life was the 3 months following my son's birth.
It's not because of my son.
It's because people online recommended I watch anime. I watched anime basically every single day for 90 days straight.
My mind has never been the same.
I found some dork online who talks about being a malware enthusiast, or something.
He dedicates basically every second of his free time to helping people remove malware from their computers for free. He provides step-by-step instructions on how to install an anti-virus and provides useful links to software tool suites that can help clean your computer
Y'know, God bless him, but that seems like such a terminally bleak existence. If you told me this man was Jesus Christ in the flesh, I might believe you. I've never met someone who does Helpdesk support for the love of the game.
Lots of people asked me to be their Benzodiazepine test dummy and kind of document my taper and stuff. Many people seemed nervous trying to quit. Here is the current state. Unfortunately it is not good.
> be me
> on Benzodiazepines
> 14 years
> not good
> decide to stop
> cut by 25%
> not too bad
> people say be careful
> can be hard
> no big deal
> cut another 25%
> hehe 50% reduction
> shrimple
> day 5 arrives of 50% cut
> feel weird
> whatever
> day 6 feel weirder
> day 8 arrives
> deep unfathomable depression
> feel empty, unable to even malware
Holy cannoli, Chat. This will pass, but you have GOT to be prepared when doing big tapers with Klonopin or Benzodiazepines. I know tons of people told me, but the first aggressive 25% cut wasn't bad.
My brains GABA thingies are screaming at me and it feels like my soul is being crushed. It is a deep hollow emptiness and wave after wave of anxiety.
Here is a silly picture depicting how I currently feel inside. Klonopin is not cool and it is not badass. It fucks you up
Also, you'll notice some people are extremely quick to criticize others but do not share anything. You'll notice quickly many people kind of sit around idly and don't share stuff they've done or what they're learning. It is because:
1. They're not doing anything, genuinely.
2. They're aware they will be criticized and are afraid of it
3. Something, something, something, NDAs, but I think people exaggerate it and it's sometimes BS. They're being goofy
Original SHA256:
8698fd9c5a64bb4bcc550b73441d119b6e77c266b6ef8a6987a70c6285838fc0
Secondary payload (in-memory CSharp loader):
0ec474c62146820aa5f2a9f4ba1bd2148b91a52c1fb9ff74da6480e3c5aec3ae
Tertiary payload (encoded, likely PURE-RAT)
77512e1591c014bb6ca3bc2a92fc03b4e3e2a200fba3c07ea632874c903cc12a
Tertiary payload (decoded, likely PURE-RAT)
b23087939109c73a09f21cafb5097c0389d61795c426b5098a52f40182ed0f0f
Shout-out to Threat Actor "LoneNone" for writing this triple-staged malware. It was cool. I had fun.
> malware
> tries to run as admin
> fails
> already running as admin
> didn't check privileges before
> self terminates because thinks isn't admin
This is why you should run every application as Admin, for the 1/1,000,000 chance a malware payload forgets to check it's privilege