TGViewer
vx-underground vx-underground @vxunderground · 52.4K subscribers
Post #9502 4.03K
> be me
> get dm from malwrhunterteam
> "smelly, i found goop"
> wtf i love goop (malware)
> he didn't actually say that
> i'm only saying that for consistency
> "Found a fake POS update domain, I can't remember the last time I heard malware specifically targeting a POS system"
> "smica83 saved it, uploaded it to MalwareBazaar"
> ok
> download file
> look inside
> POS_System_Update.msi
> open in Orca
> tool used for examining .msi installer thingies
> .msi extracts .dll from itself
> executes function inside .msi called EdgeUpdateMain
> image 1
> open in Ida
> lots of string stuff
> registers machine based off of stuff
> sends request to fake POS website
> toastposupdate(.)com
> expects specific user-agent to connect
> opbZMeJMJZmmveM7Nnck3g
> image 2
> can accept commands from web server
> can "db_dump", "ram_scrape", "intercept"
> db_dump dumps everything from POS DB
> ram_scrape pulls credit-cards out of memory
> intercept looks for other POS terminals
> image 3

This code is strange because it isn't obfuscated at all. Additionally, it is inconsistent with some of its functionality. In some segments it used the WinAPI to perform web requests with WinHTTPConnect, WinHTTPOpenRequest, WinHTTPSendRequest. In other instances, it uses cURL from the system environment with the POST parameter.

This payload also has code in place for stealing chrome credentials. It also has another .exe embedded in it.

This is very silly goop. It is designed to target ToastPOS, which is used for restaurants. I'm curious how these individuals learned the internals of ToastPOS to develop malware which would work against it.
  • ❤ 69
  • 🔥 16
  • 🤔 11
  • 🎉 1
More from @vxunderground
  1. Oct 11, 2026Honestly bro, if you really want to learn about goop, I'd recommend just reading over MITR…
  2. Oct 11, 2026Someone sent me some really fucking annoying goop. The malware (maybe accidentally?) infec…
  3. Oct 11, 2026Oh I see, this is a known thing and the FBI recent put out a thingie about this in April.…
  4. Oct 11, 2026In order to get the good goop from this goop loader I'd have to setup a fake VM, make it a…
  5. Oct 11, 2026> be me > get dm > "smelly, i found goop" > wtf i love goop (malware) > weird .vbs file se…
  6. Oct 11, 2026Hello Little People Living Inside My Computer, I have a lot of goop to push to the interne…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →