vx-underground

vx-underground

@vxunderground · Twitter ·

> be me > get dm > "smelly i found goop" > wtf i love goop (malware) > sends like to GitHub > download > look inside .zip > instantly, at the blink of an eye, i recognize it > SmartLoader every single time, without fail, this is precisely how the SmartLoder malware campaign works > find random github repo > kind of popular > make identical github but with typo or smth > make "download" button link to .zip > .zip contains EXACTLY 4 files > launcher.bat, lua51.dll, *.exe, *.txt > tell user to run .bat > .bat tells .exe to read .txt > .exe is lua engine thingie > .txt is obfuscated lua > always uses Prometheus obfuscator > always uses ETH smart contracts for c2 stuff I've had so many various SmartLoader campaigns sent to me I can smell the stink off of it from a mile away. The SPLIT SECOND they tell me something like, "haha ya it was a github kind of like the one i wanted" i IMMEDIATELY KNOW its fucking SmartLoader