TGViewer
vx-underground vx-underground @vxunderground · 52.4K subscribers
Post #9506 1.92K
> be me
> get dm
> "smelly, i found goop"
> wtf i love goop (malware)
> weird .vbs file sent
> "RateConfirmation.vbs"
> hmmm
> download
> look inside
> shrimple file loader
> downloads "grape" .zip from funny domain
> download grape zip file
> NodeJS electron goop
> masquerading as Grape Electron
> weird project on GitHub, legit tho
> weird outdated thingie called ChatGrape
> last update 5 years ago
> ???
> exact same source code as ChatGrape on GitHub
> index.js (start of program) modified
> does malware stuff
> launches ChatGrape regularly afterward
> malware appears to try targeting UniWays
> small to medium size company
> freight and transportation company
> covers 48/50 states in US (no alaska or hawaii)
> hmmm
> see C2
> uniwaysllc(.)com
> code sent POST request to C2
> code waits for response
> hmmmm weird
> try to manually contact C2
> nothing happens
> try again
> nothing happens
> looks like malware operator manually reviewing incoming connections

wtf? is this goop is targeting freight and transportation companies? thats awfully suspicious because last time on dragon ball z (if youve been paying attention to my goop posts) we saw a very, very similar goop doing masquerading targeting freight and transportation companies.

this is the 2nd mystery goop weve seen targeting this type of company, except this time the malware has gotten a little smarter and (potentially) manually reviews incoming connections to ensure its the actual target and not reverse engineers. clever clever goop

tell us your secrets mystery threat group attacking transportation companies in the united states. who are you and why do you need to know what truckers are delivering

rate confirmation (loader):
4f342ccb8005a82bed93d9a3c18aab45d32590ffa34834b789229f736889cf56

masqueraded grape:
e8a7ea884593cd26adecbbf602846b2cbd9bd1ec420ebd78c1bf7a64dbf73912

grape modified index.js (payload):
b6c75b53e37e37f743457d10f24fa3f7c51d6e2adc50e68b9c9aebb21c5303c5

pic unrelated
  • ❤ 43
  • 🤯 6
  • 👏 2
  • 🤔 1
More from @vxunderground
  1. Oct 11, 2026Someone sent me some really fucking annoying goop. The malware (maybe accidentally?) infec…
  2. Oct 11, 2026Oh I see, this is a known thing and the FBI recent put out a thingie about this in April.…
  3. Oct 11, 2026In order to get the good goop from this goop loader I'd have to setup a fake VM, make it a…
  4. Oct 11, 2026Hello Little People Living Inside My Computer, I have a lot of goop to push to the interne…
  5. Oct 10, 2026> be me > get dm from malwrhunterteam > "smelly, i found goop" > wtf i love goop (malware)…
  6. Oct 10, 2026IT ACTUALLY IS ATM MALWARE. IT'S FUCKING WITH ATM TRANSACTIONS. THIS IS SO FUCKING BADASS
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →