Here is a very poorly written way to do 'whoami' using CreateNamedPipe and Advapi32!NpGetUserName.
This undocumented function will do the generic LookupAccountSidW via GetUserNameExW, but it can act as a proxy function, or something.
https://pastebin.com/raw/ZsReS7k4
This undocumented function will do the generic LookupAccountSidW via GetUserNameExW, but it can act as a proxy function, or something.
https://pastebin.com/raw/ZsReS7k4
👍25😢9🤔5❤3🔥3🎉2
We've updated the vx-underground Windows malware paper collection
- 2023-07-29 - Lord Of The Ring0 - Part 5 Sarumans Manipulation
- 2023-08-13 - LAPS 2.0 Internals
- 2023-08-29 - DevTunnels for C2
- 2023-09-06 - How to Troll an AV
- 2023-07-29 - Lord Of The Ring0 - Part 5 Sarumans Manipulation
- 2023-08-13 - LAPS 2.0 Internals
- 2023-08-29 - DevTunnels for C2
- 2023-09-06 - How to Troll an AV
🔥30
This media is not supported in your browser
VIEW IN TELEGRAM
Insider Threats come in many shapes and sizes and are a major hurdle to any organization.
😁65🤣43❤5🤔4🤓4👍2
Reminder that Threat Actors (probably) haven't paid for a Red Teaming course or any sort of formal education
👍88😁32🤔11💯9🤓7🤯4🎉4❤3😱2🤣2
"Sorry, you can't join our ransomware group, you don't have a Bachelors degree in computer science and you don't seem to have any certificates"
🤣272👍12😢12😁8🤯7💯3🤓3😱2😎2❤1🔥1
We've updated the vx-underground Windows malware paper collection
- 2023-09-10 - GIF Steganography from First Principles
- 2023-09-11 - MATLAB Reverse Shell
- 2023-10-09 - Demonstrating Sleep Obfuscation - KrakenMask
Check it out here: https://www.vx-underground.org/
- 2023-09-10 - GIF Steganography from First Principles
- 2023-09-11 - MATLAB Reverse Shell
- 2023-10-09 - Demonstrating Sleep Obfuscation - KrakenMask
Check it out here: https://www.vx-underground.org/
❤20🤯8👍4🔥4🤓2
Swift removing ++ and -- operators because they can be confusing because of code like this:
This is the beauty of the C/C++ programming language. You can make the metaphorical gun and metaphorically shoot yourself with it. Also, don't code like this
int i = 5;
i = ++i + i++;
This is the beauty of the C/C++ programming language. You can make the metaphorical gun and metaphorically shoot yourself with it. Also, don't code like this
😁83🤣31🤝9🤔8😢4❤1👍1
vx-underground
Swift removing ++ and -- operators because they can be confusing because of code like this: int i = 5; i = ++i + i++; This is the beauty of the C/C++ programming language. You can make the metaphorical gun and metaphorically shoot yourself with it. Also…
The argument is that this is potentially undefined behavior because of how the pre-increment and post-increment expression will be interpretted (and/or optimized) by the compiler.
tl;dr don't write goofy goober code
tl;dr tl;dr nerds arguing over methods to increment an integer
tl;dr don't write goofy goober code
tl;dr tl;dr nerds arguing over methods to increment an integer
😁46🤣15🤓9👍2
Hello, how are you?
We're now granting permission to individuals who would like to upload malware to our VXDB. We are only granting this to select individuals we know, or individuals we know who can be trusted (or vouched for). We are doing this to prevent our VXDB being flooded with junk data or non-malicious files.
No changes will be made to the VXDB for user registration or downloads. It will always be free.
If you'd like to contribute to the VXDB you can contact us Twitter DMs or via e-mail at staff@vx-underground.org
Additionally, we are still working on refining the VXDB, bulk download (via API) is still not supported yet. It is in our ever-growing todo list.
Thank you everyone for the love, support, donations, and sponsorships you've given us. We would not have been able to create this VXDB, get this much malware, or share it with this many people if it were not for all of you helping us out.
Love you,
We're now granting permission to individuals who would like to upload malware to our VXDB. We are only granting this to select individuals we know, or individuals we know who can be trusted (or vouched for). We are doing this to prevent our VXDB being flooded with junk data or non-malicious files.
No changes will be made to the VXDB for user registration or downloads. It will always be free.
If you'd like to contribute to the VXDB you can contact us Twitter DMs or via e-mail at staff@vx-underground.org
Additionally, we are still working on refining the VXDB, bulk download (via API) is still not supported yet. It is in our ever-growing todo list.
Thank you everyone for the love, support, donations, and sponsorships you've given us. We would not have been able to create this VXDB, get this much malware, or share it with this many people if it were not for all of you helping us out.
Love you,
❤72👍8🫡5🔥4
At this moment in time vx-underground is a daily grind - keeping the website updated with new papers, malware samples, the VX-API, the VXDB, etc.
Not entirely sure what else can be done now. Other than continuing the generic updates
Mission accomplished...?
Not entirely sure what else can be done now. Other than continuing the generic updates
Mission accomplished...?
❤67👏18🤔4
No, we're not shutting down. We're noting that we are considering exploring other projects for vx-underground (keyword: considering, nothing solid).
Also, we love all of you, especially you
Also, we love all of you, especially you
❤87❤🔥18🥰11🤓5🔥2😍2🫡2
TrustedSec has repeatedly spoken out about the importance of giving back, helping others, and making an impact on the community - whether it be them donating to educational programs to schools, creating cybersecurity conferences designed to make a positive impact on the community, sponsoring local events, or donating to people, giving away items, etc.
We spoke with Dave Kennedy, CEO of TrustedSec - he has offered us invaluable resources to aid us in our growth, given us insight into potential ways we can expand (while remaining free, vx-underground will remain free forever).
TrustedSec is also now our largest sponsor.
Thank you Dave Kennedy and friends at TrustedSec for making an impact and doing everything that you do. It is wholeheartedly appreciated it.
We spoke with Dave Kennedy, CEO of TrustedSec - he has offered us invaluable resources to aid us in our growth, given us insight into potential ways we can expand (while remaining free, vx-underground will remain free forever).
TrustedSec is also now our largest sponsor.
Thank you Dave Kennedy and friends at TrustedSec for making an impact and doing everything that you do. It is wholeheartedly appreciated it.
❤132❤🔥18🫡11👍9🤝5
It should also be noted that Dave Kennedy asked for nothing in return for sponsoring us - not even a tweet or a logo on vx-underground. He is legitimately just wildin' out and helping nerds for fun
❤105🫡31❤🔥12💯7🔥3😢2👍1
Monthly additions are now live. New additions:
- Virusshare.482 total of 52,807 new samples
- The Old New Thing for October, 2023
- Malware analysis collection - 82 new papers from malpedia
Have a nice day.
https://www.vx-underground.org/
- Virusshare.482 total of 52,807 new samples
- The Old New Thing for October, 2023
- Malware analysis collection - 82 new papers from malpedia
Have a nice day.
https://www.vx-underground.org/
🔥27❤4👏4🎉3
In 2022 Italian politician Maurizio Gasparri displayed his password on his workplace device on live TV
It was a sticker on his laptop.
"Agta123"
It was a sticker on his laptop.
"Agta123"
🤣157😁19😘6👍3😱1