be me > get dm > "smelly i found goop" > wtf i love goop (malware) >… — vx-underground — TG.ME

> be me
> get dm
> "smelly i found goop"
> wtf i love goop (malware)
> fake cloudflare download page
> tries to convince roblox nerds its robux
> haha_classic.gif
> look inside
> downloads powershell script
> curl file
> redirects, fails a bunch
> curl file again, but ask to not redirect
> goop download successful
> goop strategy so far is lots of staging
> .ps1 -> .exe -> .exe downloads more .exe
> ok
> curl next .exe
> fails, redirects again
> omfg bro
> curl file again, but ask to not redirect
> works
> look inside
> .exe with manually written COM for custom .NET
> tl;dr manual .NET loader
> whoa neato
> bonk with stick
> manually strip out .net code from .exe
> goop strategy thus far
> .ps1 -> .exe -> .exe -> .exe custom load csharp .exe
> look inside
> heavily obfuscated c# .exe
> evades emulation
> hehe silly goop
> decompile with ILSPY
> follow code execution manually
> checks system environment (fingerprinting)
> checks to see if .exe is in russia (lmfao)
> kills itself if its russian IP address (lmfao)
> checks gpu, cpu, ram, etc
> connects to spoopy IP address (tries to be sneaky)
> 158.94.208.92:61120
> tells 158.94.208.92:61120 what kind of PC its on
> 158.94.208.92:61120 asks what files are on PC
> gives 158.94.208.92:61120 file listing of PC
> csharp .exe waits for 158.94.208.92:61120
> 158.94.208.92:61120 may deliver more goop later

haha silly goop, this is v v silly

stage 1: cloudenterprisenew(.)com
stage 2: 8758aa166281eca53eecf11d167bf069ac3c3c07490b16f2efa687fd514081e8
stage 3: 1e0a8824261e3edb36d12fd5ce659cbb3989d4470809d2310cc56cd47da53555
stage 4: 6c14ea6f34a3a8f6a5eaa576e95c191326a2c4d58f9c19a0faf8ad139970a713

Stage 2 and Stage 4 weren't on VT

pic unrelated
❤51😁9😍2👍1😢1
August 31, 2026 2.4K 17