40629
The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/
SOMEONE CONTACT THE FTC IMMEDIATELY.
VX-UNDERGROUND MADE $500.
THEYRE DEFRAUDING EVERYONE FOR ASKING PEOPLE TO VOLUNTARILY DO A SURVEY
As many people know, there is a thing called the "Terrible Twos". It is called this because toddlers have big emotions, but are incapable of expressing their frustration or regulating their emotions. This is a more complex task their brains haven't fully formed yet.
Although it is called the "Terrible Twos", it isn't necessarily two years old, is ranges from slightly before being two years old, all the way to almost three years old.
I'm happy to share my son has had his first few tantrums. Just kidding, I'm not happy, it actually fucking sucks.
I told my son he couldn't play with his toy and he LOST HIS MIND. He was completely inconsolable. He threw himself to the floor, screaming at the top of lungs like he was being dismembered, didn't want us to hold him or touch him, refused his snacks or comfort food, bro LOST HIS MIND.
Then he slowly calmed down... and it stopped.
Dawg, toddler tantrums fucking suck ass so much omfg it's actually the worst and it's super stressful
Hello Little People Living Inside My Computer (LPLIMC),
Some place hit me up and asked if I'd share a survey. They're trying to understand hackers, or something, I don't know. It's a legitimate research institute from a fancy-shmancy place, it's all on something called "a research grant" (made up words), it's non-nerds trying to understand stinky nerds.
- No login required
- Doesn't log anything
- It's anonymous
There (apparently) might be questions you're uncomfortable with (I have no idea why), so they said if you're uncomfortable with any questions you can simply skip them.
If you feel like spending 15-20 minutes clicking on multiple choice thingies to help some research place understand nerds, feel free to do it. Or don't do it, whatever.
https://globalcyberstudy.limesurvey.net/115971?lang=en&newtest=Y
Kathy Hochul and Letitia James have the combined IQ of a fine plate of spaghetti with some freshly made meatballs.
Soon New York state will implement the SAFE for Kids Act.
Basically, you need to verify your identity to Instagram, TikTok, or any social media platform which is algorithmic (???).
They're doing this to protect children. They ARE NOT doing it to allow social media companies to aggregate your data and sell it to third parties (or worse).
You trust Instagram, TikTok, Facebook, X, SnapChat, YouTube, Reddit, LinkedIn, and Pinterest with your driver's license, right? Because to even view these websites you need to give them your driver's license. It is to protect children from algorithms.
Just give them your driver's license, bro. They said they'll delete it and they said they won't track you. Why would multi-billion dollar companies do something potentially unethical? You trust them, right? It's to protect kids, bro, you care about kids, right?
It's a well established fact parents are incapable of parenting and we must make tech companies and the government parent our children. Right?
The attached blog details the conclusion to his research and the self-propagation segment.
Part I and II (linked at the beginning of the attached article) detail the underlying mechanisms which some stinky nerds might appreciate. It discusses Copilot memory manipulation and AI abusing e-mail stuff.
I'm not an AI nerd, so I'm meh.
https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/
Hi
I've uploaded another 150,000 malwares to the internet. I haven't pushed the update file yet, but the malware is there for you to download and enjoy.
If you need anything please contact me secretary (homeless guy at the gas station)
Cheers,
Pic unrelated
Department of Homeland Security been REALLLLLLL quiet ever since they took down that anime streaming website.
What are you hiding?
Okay, maybe I'm a little annoyed, I'm sorry. Please excuse my language. I'm hungry and tired.
Читать полностью…
> check twitter
> account locked
> ???
> DMCA takedown request
> ???
> click see post
> rockstar games compromise post
> shows GTA 6 testing footage
> 8:51 AM · Sep 19, 2022
you fucking assholes hit me with a DMCA takedown request on a video from 2022? seriously?
fr tho bro, if youre going to commit crime, launder money, whatever, dont show ur face on discord calls or flex bro, cmon man
Читать полностью…
I know I probably shouldn't tell someone who committed a felony to relax, but let's be real here, bro. FBI agents are paid like shit and they're dealing with serious problems, Schlunko McSchmeeSchmee isn't even on their radar. They probably don't even feel like doing the paperwork, some agent probably saw it, said "heh", and went back to some case where someone is laundering $10,000,000 of Bitcoin
How much money was stolen? What? Like $700? The FBI doesn't even look at you until you've done somewhere between $100,000 - $1,000,000. It costs them $200/hr for the attorneys alone, not to mention the man hours to talk to Steam, do the court paperwork, subpoena people, determine which field office is going to handle.
I don't know bro, whatever
Also, apparently Meccha Chameleon people follow me on Telegram.
Hello MecchaChameleon malware people living inside my computer,
I think overall your strategy of using a malicious custom map thingie was cool and probably yielded moderate success. I don't think your intention was being like, 100,000 infected machines, but I suspect you got enough infected machines to be happy. People wrote you were using PureRAT, whether or not that is true, I don't know, YARA rules for flagging can be iffy.
But, when I was reverse engineering your C# payload (which I think you attempted to obfuscate?) I saw the weird dependency you used for remote access to machines. I can't remember what it was now, I deleted your goopies off my machine, but I saw it as an embedded resource next to PAYLOAD_ULTRA_MEGA_FUCK_OFF.zip which you decrypted and loaded as a raw assembly. Maybe that raw assembly you loaded was PureRAT? Or was it the stager? I don't know.
Obviously we've been this a million times before with other video games (malicious mods), but seeing it in something obscure was a nice surprise. Your advertisement, or demo, or whatever, you showed was not an RCE. An RCE would require ... remote code execution. This is really fancy payload smuggling.
Anyway, it's obvious your staging was vibe coded. It was pretty easy to reverse engineer. I think you had the right idea on how to go about things, but between the segments being in order (1 - 66), the obvious embedded payload in the 2nd stager, and the really loud BATCH files, it wasn't going to go very far.
Thanks for the goopies though, it was chill.
Cheers,
(pic unrelated)
The reason many of you are seeing me discuss malware reverse engineering lately is because I've temporarily shifted my focus to malware defense, rather offense.
A majority of my life, and goop with malware, has been malware development. I love writing malware. However, the past couple of months-ish I felt kind of bored with malware development. I was just kind of burned out.
From the recommendations of the people living inside my computer, I decided to shift to malware defense. If anyone remembers, I spent awhile studying the internals of YARA and built my own YARA scanner thingie.
Anyway, it's been a lot of fun bonking malware with a stick. It's given me better perspective on what does, and what does not, work offensively.
Thank you everyone for giving me malware you find in the wild. It is better to bonk random malware, versus malware already bonked, because there is no "cheat sheet" of someone else's research or notes. I'm going in completely blind and it's fun.
> get dm
> "hey smelly look at this"
> sends link
> look inside
> torrent website
> The Odyssey 2160pHD (2026) ENGSubs EZTV
> look closer
> "The Odyssey 2160pHD (2026) ENGSubs EZTV.exe"
> 147 seeds
bro knows ball, this is a 2002 limewire classic
I was indeed paid to post this, although not very much. I liked the core concept of what they wanted to do. I think the people behind it are chill. My monies was given to me because I have stinky nerd street cred.
This university research place which is trying to understand "hackers", or whatever, got monies from some place to study stinky nerds.
These non-nerds were like, "well, they do crime, surely hackers and stuff have a similar psychology to other criminals". They quickly learned however that cyber criminals are FAR more paranoid than regular criminals.
With regular criminals, like a drug dealer or something, you can usually approach them and try to talk. It makes it easier because you can physically see them. With cyber criminals on the other hand, it is extremely difficult to approach them because they're (usually) hyper-paranoid and (usually) have extreme anti-government and/or anti-authority beliefs.
Additionally, unlike a majority of criminals, cyber-criminals place great importance on intellectualism and meritocracy. When this university place tried to approach hackers, they were coming in as anonymous nobodies who had no merit and no background in anything technical.
As the many nerds who follow this social media profile know, people who put out work, produce work, or do SOMETHING are (usually) treated well (or better) or given respect. It is kind of like, stinky nerd street cred.
Anyway, they found vx-underground and asked for my help to push the study. They ascertained I had stinky nerd street cred and hoped I could help them. Whenever they tried on their own they were called racial slurs, told to fuck off, were ignored, or called feds (or all of these combined).
tl;dr stinky internet nerds not think like like criminals, have different philosophies on stuff
Oh, I'm going through it now, they're trying to understand the psychology of Threat Actors versus non-Threat Actors
Neat
I'm doing that thing again where I crash out over government surveillance and tech companies needing more identification under the guise of protecting children
Читать полностью…
Y'know, peace and love to my fellow stinky nerds, but someone really needs to sit down and explain to people what exact RCE means. The acronym Remote Code Execution implies code (the beep boop stuff) is remotely (far away) executed (ran on the computer).
Hence, beep boop stuff that is far away runs on a computer.
Historically an RCE is like, your computer is running Soup Goop server, and Soup Goop server fails to properly parse data it receives, allowing specially crafted input to trick Soup Goop server to execute code.
So, you could like, use Python 3.11 to send some dumb slop to a remote computer address and it'll execute your bad stuff.
In this instance (and many other from Steam and malicious mods in general), the idea is that someone operates or possesses a server which, and when a player joins, the video game server syncs data to the newly connected host which pushes a payload to it.
In simple language, and as a hypothetical example, I operate Stinky Minecraft server, and if you join Stinky Minecraft server, my Stinky Minecraft server automatically pushes mods to your computer. Stinky Minecraft server does this because it automatically ensures you're compatible with Stinky Minecraft server and we can all play and have fun. However, one day Stinky Minecraft server says, "you need Goop Texture Pack Mod 0.2.1.1 and ... INFORMATION STEALING MALWARE HEHEHEHEHE" and that malware is automatically pushed to your machine (also with Goop Texture Pack Mod 0.2.1.1).
Things like this doesn't really fit the category of Remote Code Execution because nothing is being executed remotely as a vulnerability, it requires a victim machine to connect to a malicious host which syncs the payload to the machine. This is closer in terminology to arbitrary code loading, malicious plugin loading, remote installation of untrusted code ... something, I don't know, but it's not an RCE.
Overall, this is more or less a fundamental flaw in the design of video game mods because they're not appropriately sandboxed.
Yesterday Håkon Måløy, a stinky AI security researcher, unveiled several vulnerabilities with Microsoft Copilot which could hypothetically allow an AI-like worm in Microsoft Office documents.
the tl;dr-ish is that if you insert carefully worded instructions, as white-text thus making it invisible to the user, at the end of Microsoft Office documents, Microsoft Copilot will follow the instructions given to it.
The problem with this method (as is tradition), is that the text is still visible in the document if highlighted by the user. Hence, doing something as simple as CTRL+A would render the text visible to the user.
Regardless, Håkon Måløy successfully appended white text to a Microsoft Office document that halved the values of company data presented in the document. In simple words, the appended white text manipulated company data in the Microsoft Word file.
His second proof-of-concept demonstrated appended white texting propagating the appended white text to other Microsoft Office documents, thus making it worm-like (self-propagating).
This is an interesting idea and it is an excellent proof-of-concept. However, like many AI vulnerabilities, this relies heavily on social engineering (kind of) where as text is still present in the document, and like many AI vulnerabilities, results may not be consistent depending on how the AI interprets the data.
This isn't a diss to Mr. Måløy, I think this is really interesting, unique, and creative, and could potentially have some real world abuse. Simple tricks have proven to be very effective. The nuance is important to emphasize though because non-nerds on social media seem to be under the impression this is Terminator Copilot edition.
I saw some meme on social media talking about the first SAW film and September 11th.
I thought it was a meme, but it's dead ass real. At the 57:20 mark one of the actors pulls out a cell phone prop that displays September 10th, 2001
tl;dr big day tomorrow in the SAW universe
> download weird .exe
> accidentally run it
> disappears in the void
Marek, you goofy son of a bitch, with your goofy ass man-bun and bullshit risk compliance job, it isn't AI generated footage you lying little bitch.
If you're going to file a DMCA takedown request, you should write it's because RockStar games was compromised by an autistic teenager in the UK who social engineered HelpDesk support from an Amazon FireStick in a hotel room
I obviously can't file a counter claim, I'm a stinky nerd and you're representing a multi-billion dollar company, but I want you to know that you're a pussy and nobody at your job respects you
Have a nice day
My wife and I frequently yell "HELP!" when we need help with the baby.
He is 17 months and he is crazy.
The good news is that he has suddenly began screaming "HELP" in public with zero context.
It's fun holding a baby and he screams "HELP!" around a bunch of strangers.
Could they be anymore vague? Do you have any idea how many images are posted online? What is this post even supposed to mean?
Читать полностью…
> check social media
> internation cyber news digest posts
> doxes some kid
> nice broccoli haircut tho
> nerd allegedly part of meccha chamelon thingie
> worker or smthn, idfk
> shows discord cam thingie
> records his face
> idk why
> flexes $50,000
> idk why
Dawg, I don't want to sound like a hater, but you need to CHILL OUT.
Your goopies just got attention because it was video game goop. This isn't like, CL0P ransomware group extorting the United States government for $50,000,000 because of a 0day exploit they had.
You're NOT FBI most wanted, bro. They're worried about big malware campaigns. The internet has crypto-drainers bringing in $100,000/month, CSAM all over TOR, large-scale botnets wreaking havoc on home users, businesses, and critical infrastructure, and they're also dealing with state-sponsored Threat Groups which are enemies of the United States.
You popping 50 people from Schlunko McSchmeeSchmee on Steam isn't going to make Kash Patel call the President of the United States and say you're El Chapo 2.0. This only got attention because it was on Steam
Gosh dang, bro. Relax. Half these fucking people on social media talking about it unironically spend a majority of their day scrolling TikTok and arguing in the comment section on YouTube videos. It's not that deep, bro.
Everyone on X was yapping about this Meccha Chameleon malware thingie. Internet nerds have been doing some internet detective research trying to find out who did it (I have no idea why, it was a relatively small malware campaign, there is much more dangerous malware than this).
Anyway, I bonked it with a stick.
> everyone yappin about this
> look inside
> goofy ahh batch file
> http downloads from ip address
> http? not https? what year is it?
> steamb.bat
> more ghetto batch files
> not obfuscated
> ok thanks i guess idk
> more http downloads
> makes fake microsoft security center folder
> ???
> downloads auto hot key script
> notes present
> AI GENERATED TRASH
> aes256 encrypted data blob
> fragmented
> all parts are labeled (part 1 - part 66)
> aes256 iv and key labeled
> ??? WHO IS THIS FOOLING BRO
> image 1
> make goopy python script
> add p1 - p66 together
> decrypt with documented aes256 keys
> lmfao wtf
> makes .exe
> look at .exe
> .NET c# goop
> first line of code
> EXTRACT PAYLOAD FROM RESOURCE SECTION
> ???
> encrypted, but encryption goopies still there
> image 2
> extract goopies
> another .exe
> slight attempt and obfuscation
> lol crypto stealer (image 3)
> other goop that looks like for RAT
SHA256: dc9a2f090f8d7ba31e1195573bbb5b1f0891f3b3722d8ad4c159f2519b1cb5b0
> free time today
> what was bro doing with a torrent movie .exe
> download
> 1gb .exe
> lmfao binary inflation
> bonk bonk
> remove junk
> deflate binary
> 500kb
> bonk bonk
> no imports
> crt stripped
> position independent
> checks language
> kills self if in belarus or russia
> runs 2000 random functions in random order
> trying to stall to evade VMs
> decrypts .exe from inside itself
> runs mystery .exe in memory
> .exe steals goop off machine
> bonk bonk
> yara flags as lumma stealer
overall this wasnt the greatest goop ive ever seen, but i was a big fan of free_movie.exe. its a certified limewire 2002 classic.
inflated binary:
e25ae92b95809ee42f61810a0253ead29b3a6aa8adf91f785c80c9bec5f38bd8
stripped binary:
732d7a945163a3f31eae25028562bd5d9a352c31eb90c777042bceeeb1c6b3ec
in-memory payload (partially reconstructed):
3e561eecde0071766626d80d6ce3cf1626fb2dbed0ef437948f622c283a0e91e
c2:
overcjo(.)cyou
betavmt(.)cyou
hiatuft(.)cyou
auditva(.)cyou
In all seriousness seriousness, you should do this anyway whenever you accidentally malware your computer. This isn't exclusive to this malware.
Unless you don't care some stinky nerd somewhere has all your credentials, if you don't care then whatever, do your thing