vx-underground
47.6K subscribers
4.11K photos
438 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Our friend SPTHvx, the legendary virus writer, has returned from a 10 year hiatus. On his return he has produced a proof-of-concept demonstrating the encoding, decoding, and mutation of virus code using ChatGPT in a natural language.

Check it out here: https://www.vx-underground.org/other.html#code_mutation
🀯29❀10🫑5πŸ”₯4😒1πŸ’―1
We've made some updates to vx-underground.

1. We've updated the malware defense collection. We've added 92 new malware analysis papers.

2. We've updated the Archive section. We've archived Singularity OS, Microsofts open-source OS written in C#

Have a nice day.
πŸ‘3❀1
It appears vx-underground will pass 200,000 Twitter followers in June, 2023. At 200,000 followers this will unlock new functionality for vx-underground

1. Ability to cancel people on Twitter
2. We can cut in line at airports and restrooms
3. Unlocked "Don't you know who I am?"
πŸ‘50❀11😁9🀯5πŸ‘4πŸ’―1
We've updated the VX-API

- CreateProcessFromINFSectionInstallStringNoCab
- CreateProcessFromINFSetupCommand
- AmsiBypassViaPatternScan

Shellcode execution by abusing: SymEnumProcesses, ImageGetDigestStream, VerifierEnumerateResource, SymEnumSourceFiles

https://github.com/vxunderground/VX-API
❀12πŸ”₯4πŸ‘3🀯3πŸ₯°1
We've updated "The Old New Thing" collection. We've archived the month of February, 2023.

Special thanks to _BradleyVX for curating the papers.

Check it out here: https://www.vx-underground.org/the_old_new_thing.html#the_old_new_thing_-_2023_02
πŸ‘3❀2
Seeing Shell32.dll export a function titled "PathYetAnotherMakeUniqueName" makes us question the psychological well-being of Microsoft developers
🀣67πŸ€ͺ8πŸ‘4🀯3πŸ”₯1
😁44πŸ€ͺ10πŸ€”3
"The best and most beautiful things in the world cannot be seen or even touched β€” they must be disassembled with IDA." -Helen Keller
🀣50πŸ€”4πŸ”₯3πŸ‘2πŸ€ͺ2
ALPHV ransomware group has ransomed Lehigh Valley Health Network, a healthcare network based out of Pennsylvania.

ALPHV has issued threats to the healthcare organization and has begun leaking photographs of topless female breast cancer patients
😒51🀩5😁4πŸ‘3πŸ€”3πŸ‘1
ALPHV states in their message to Lehigh Valley Health Network that the photos of the cancer patients are nudes, suggesting they're pornographic (?).

ALPHV is exploiting and sexualizing breast cancer.
😒43🀯16πŸ‘6😁5🀩2
Our friend guessthepw developed us a custom malware database which will automatically sync data with VirusTotal and hatching_io


- Free to the public
- Will contain every vx-underground malware sample
- Will allow users to upload and share samples
- All thanks to our supporters

We do not know when the new site will go live. Improvements still need to be made, including beautification. This is all done in the spare time of guessthepw and vx-underground staff.

This will be a large achievement for us.

Make malware free, forever.
❀48🫑8πŸ‘7πŸ”₯3
We have no intention on competing with VirusTotal.

vx-underground will remain a free-to-use library and malware exchange. We do not intend on scanning malware, sandboxing it, blah blah blah.

VirusTotal makes millions of dollars a year. vx-underground makes about tree-fiddy.
❀92🫑23πŸ”₯11❀‍πŸ”₯8πŸ‘5πŸ‘4😒4πŸ€ͺ4
Escape from Tarkov developers have begun naming and shaming people caught cheating - they release publicly available Google Docs spreadsheets listing the usernames of banned players.

Please note the amount of people with "TTV" in their name.

Example: https://docs.google.com/spreadsheets/d/e/2PACX-1vRutocKkK3nk91ORmArC4_sOWGFpipL1hNPYytEpdQ-70WkQnVQJlxMmULIaViqpm31J_I0_pIBVTlN/pubhtml?gid=0&single=true
🀣33πŸ‘4πŸ”₯3
One question we are frequently asked is "How do anti-viruses work?"

The attached image provides a high-level overview on how anti-viruses work
🀣49🀯6πŸ‘1🫑1πŸ€ͺ1
Previously Minneapolis Public Schools reported an 'encryption event'. Today Medusa ransomware group has taken credit for the attack.

Information and updates via BrettCallow
🀣23😒8😁3
Medusa ransomware group has released a 51-minute long (474MB) video demonstrating the contents stolen from Minneapolis public schools.

It contains e-mails, student grades, building layouts, payroll information, and more.

The video also plays the Matrix soundtrack on loop 🀣
🀣59πŸ€”5πŸ‘3😁2
Media is too big
VIEW IN TELEGRAM
This is the introduction scene from the Medusa ransomware group video.
🀣64🫑19πŸ€ͺ2