1 (edited by hh86 2013-07-10 10:09:06)

Topic: Valhalla 4 announcement

Hello,
this year Valhalla is opening its gates for anyone who would like to publish their material on a high-quality, old-school ezine.

Topics:

- new infection techniques on old/new file formats
- POC viruses/worms for every kind of platform that allows self-replication (can you write the finest old-school virus for a mobile device?)
- POC viruses in new programming languages or languages that were not used before for viruses [1]
- cryptography: new encryption/decryption techniques applied in viruses/worm
- innovative ways of polymorphism/metamorphism
- new spreading techniques for worms using modern network-technology (not lame exploits)
- ideas/techniques for autonomous learning for self-replicating codes
- ideas for information transfer (communication) between independent viruses
- out-of-the-box thoughts on self-replication

[1]: SPTH has made a list of many programming languages that have been used in virus writing, and listed some that not yet.  That's a great starting point.  Can you take the challenge?

http://spth.virii.lu/LIP.html


Deadline

This time we will take more time, and give people more time to work on their stuff.  There is a lot of complex projects that require it.  So, this year the deadline is 1st of November 2013.


Contributions Review

The  material  you send to us is subject to our AI automated analysis, that works better than any anti-virus automated  testing of samples.  We have no restriction in the format, but we must be able to handle it from the HTML viewer.


Contact

For comments, questions and contributions you, can contact here:
agonisthh86/at/gmail.com


Previous Issues

05/08/2011 - Valhalla #1

Featuring:
- world's first cross-platform virus using Heaven's Gate, W32/W64.Heaven by roy g biv
- world's first cross-platform infector for 010 Editor scripts, W32/1SC.To_Be by roy g biv
- world's first JScript virus using Prototypes to run the code, JS.Protato by roy g biv
- virus that apply evolution based ideas from microbiology, W32.Evolus by SPTH
- polymorphic virus via overlapping code, W32.Kitti by SPTH
- virus that uses complex mathematical methods for decoding and tau-obfuscation, Matlab.MicrophoneFever2 by SPTH
- world's first EPO virus using Exception Directory, W64.Haley by hh86
- cross-platform virus, first attempt to a single code path, W32/W64.Sofia by hh86
- world's first virus encoded using Intel MMX "MASKMOVQ", W64.Sigrun.A by hh86
- world's first virus encoded using Intel MMX "PMOVMASKB", W32.Sigrun.B by hh86

and much more!


15/03/2012 - Valhalla #2

Featuring:
- world's first truly polymorphic Batch virus, BAT.Polymer by roy g biv
- self-emulating virus, W32.Evenstar by mos6581
- world's first virus encoded using ENTER instruction, W32.Fizzy by hh86
- world's first virus encoded via INT 3 and CALL, W32.POSEY by hh86
- first cross-infector that infects 4 different languages by SPTH
- virus that autonomously learns new anti-emulation tricks, W32.Addisco by SPTH
- virus that uses subtle side-effects of flags for mutation, W32.Filly by SPTH

and much more!


21/12/2012 - Valhalla #3

Featuring:
- world's first metamorphic JScript virus, JS.Transcriptase by SPTH
- world's first virus using GPGPU for decryption, W32.OGLe by roy g biv
- world's first virus using Virtual Code in Windows 7, W32.Relock.B by roy g biv
- world's first infector using CFF Explorer scripting language, W32.CFFe by hh86
- world's first virus using inline JScript for decryption, W32.Unit00 by hh86
- world's first virus using debugging for decoding, W32.Atlas by hh86
- world's first virus using Intel AES-NI for decryption, W32.Sigrun.C by hh86
- world's first virus using Waveform Audio API for RNG, W32.Wave by (o)
- world's first Java JAR infector using JavaCompiler, Java.JavaInfector by R3s1stanc3

and much more!
--





PS: pr0mix has announced that _they_ are releasing an ezine (EOF4?), most likely in October.  Check out his post: http://vxheaven.org/forum/viewtopic.php?id=2197

"This is the girl they keep calling a monster. I want you to keep that firmly in mind. The girl who could be satisfied with a hamburger and a dime root beer after her only school dance so her momma wouldn't be worried..."

Thumbs up +6 Thumbs down

Re: Valhalla 4 announcement

good!

It's not EOF#4, it's new project smile

Re: Valhalla 4 announcement

Sounds good.

It's always right to keep it Old-School, that's the way to go..

says an old man (me) wink

“Expose yourself to your deepest fear; after that, fear has no power, and the fear of freedom shrinks and vanishes. You are free.”
― Jim Morrison

Thumbs up Thumbs down

Re: Valhalla 4 announcement

resu wrote:

Well, its only about labels, what's the advantage of zine over publishing stuff by yourself.
Why you cannot omit "Valhalla" label and just all together release one zine from the "scene"? Oh, thats right, you want to be leet. Well, that doesnt makes you "leet". And your statement "high quality zine" made me smile. A label without people is nothing more than a label, why people should send stuff exactly to you? In my opinion, zine must be unique by itself, what you do is just promoting label(s), and any other popular group in the past did the same, like 29a.

Regarding Valhalla zines, well, i havent seen something complete and interesting there in any of the issues. All hh86's codes looks the same, like you would use template and release new virus with fewer changes, same counts for rgb (aka peter ferrie). SPTH is so "surrealistic" that his codes looses any meaning. Well, only hope remains on contributors.

I hope u can accept a little of criticism. wink

I think that many publications is a good thing, in case of disappearance of a zine, another can take the authors (and readers) of the dead one. And if both persist that allows two point of views / two philosophies.
If you find a zine is not enough "leet" ... show them what you can do and give them a crazy article !
Why people should send their articles? Maybe because they intend to distribute, and no many people do that !

That's just my point of view !

Good luck to Valhalla team & pr0mix for their zines !

Thumbs up +2 Thumbs down

5 (edited by SPTH 2013-07-10 23:34:53)

Re: Valhalla 4 announcement

Looking forward to valhalla4 and pr0mixs zine, I hope i can contribute my "surrealistic" stuff to both of you - if just there were more hours per day huh.. But thats a usual challange I guess wink

6 (edited by slek 2013-07-10 19:58:19)

Re: Valhalla 4 announcement

Roy g biv is peter ferrie?! OMG OMG .. resu, is that the reaction you wanted? AVer or not, we know him under that handle as a talented virus writer, his personal life is none of our business.

spth looks funny? lol! naww you hurt his feelings sad

eval(join$",qw/perl " ( print another Just ; girl )/[qw/3 2 1 5 4 0 7 1 8 6/]);

Thumbs up +1 Thumbs down

Re: Valhalla 4 announcement

resu wrote:

"Talented" doesn't means good person, i don't like his repetitive style, just to be first one among others. Also, he steals ideas from others.

I'm not willing to discuss here personal lifes, i know who is h86, who is spth, who is roy g biv, who is herm1t and many others in real life, and i know you too, kels (genetix), but it would be foolish to talk about your personal lifes here.

you forgot kelsey^^ well you have the right to like whoever you want to like ..

do I know you under a different handle?

eval(join$",qw/perl " ( print another Just ; girl )/[qw/3 2 1 5 4 0 7 1 8 6/]);

Thumbs up Thumbs down

Re: Valhalla 4 announcement

slek wrote:

do I know you under a different handle?

I think he sounds like izee.
Maybe he also wrote the post on pastebin.

Thumbs up +1 Thumbs down

Re: Valhalla 4 announcement

boojum wrote:
slek wrote:

do I know you under a different handle?

I think he sounds like izee.
Maybe he also wrote the post on pastebin.

WE SHALL NEVER KNOW! ^^

eval(join$",qw/perl " ( print another Just ; girl )/[qw/3 2 1 5 4 0 7 1 8 6/]);

Thumbs up Thumbs down

Re: Valhalla 4 announcement

Ah enough time for preparation smile

Greetings Perforin

~ Enjoy the beauty of malware ~

Re: Valhalla 4 announcement

resu wrote:

"Talented" doesn't means good person, i don't like his repetitive style, just to be first one among others. Also, he steals ideas from others.

I'm not willing to discuss here personal lifes, i know who is h86, who is spth, who is roy g biv, who is herm1t and many others in real life, and i know you too, kels (genetix), but it would be foolish to talk about your personal lifes here.


Hey 01(or whoever u r, u r back))) didn't u get my message well not to create disposable accs with mailcatch??))))

Thumbs up 0 Thumbs down

Re: Valhalla 4 announcement

resu wrote:

From what i know, he committed suicide like 1 year ago or so, so you are wrong, im not him, but that psycho had some nice ideas.

He's not dead^^ IF you were him then you may have forgotten that we talked a few months ago^^

resu wrote:

By the way, speaking of monopoly, why pr0m1x's announcement about zine wasn't sticked here? It isn't democracy, thats unfair, he also wants to do e-zine, but he will get much less contributors because valhalla is first. Okay, okay, there is no difference, same shit big_smile

Life is unfair! but maybe hh86 asked for it to be stickied and pr0mix hasn't? I have no idea.. if it was stickied just because it's Valhalla then I agree with you.. but I doubt that's the case.. and I doubt it would mean pr0mix get's any less contributions.. hh86 is strict with the zines content and that could swing people in pr0mix's direction.. not to say that she shouldn't be but some people like me are lazy^^ but I find Valhalla very interesting in a crazy kinda way..

About SPTH.. well, he thinks WAY outside the box, it's people like him that are remembered. You can dislike him all you want but no one can go to his website and deny his creativity and uniqueness... and skill.

eval(join$",qw/perl " ( print another Just ; girl )/[qw/3 2 1 5 4 0 7 1 8 6/]);

Thumbs up +1 Thumbs down

Re: Valhalla 4 announcement

Ok, let me get this straight:

1. pr0mix vs hh86 and sticking shit: hh86 post was stuck because it was published in news and announcement, which in my opinion brings definite will and aim. pr0mix's post was published as "thought" - why wouldn't we... If pr0mix would be definite to announce his aims in an appropriate thread - he would definitely got his post stuck!!!

For now, i want to proclaim there are no preferences, likes,dislikes and other shit, except the violation of code of ethics of this board.

offtop:

2. o1, resu or whoever u are - if u don't stop flaming Administration and other members, that are respectful part of VX, creating garbage accs, posting stupid meaningless posts and just being shit - i'll be putting any efforts possible to end this story.
If u don't like this board, me and whatever - i'm just asking u one question - what the heck are u doing here????

P.S.: to all the members - please, consider your behavior, and flame in an appropriate place

Thumbs up 0 Thumbs down

Re: Valhalla 4 announcement

resu wrote:

i don't like his repetitive style, just to be first one among others.

If the infection technique is the only thing that changes, then the rest of the code will be the same every time, and rewriting it to make it look different is simply a waste of time.
So the template idea is a good one.

resu wrote:

Also, he steals ideas from others.

I would like to hear more about this.  You have examples?

Thumbs up 0 Thumbs down

Re: Valhalla 4 announcement

can not w8
happy to hear your are back hh86

Thumbs up +1 Thumbs down

Re: Valhalla 4 announcement

Hey boojum!
You are of course right, it makes totally sense to use templates for proving new ideas. You have your standard code, and then add you new implementation. This has several advantages:

1) You can implement your ideas much faster, without needing to care about parts that are not interesting for you for the moment. Imagine you have a cool idea about how to use GPGPU or some novel AES instructions for encoding, it is of course convinient to have the rest of the code small/stable.
2) By using a stable template, you dont introduce bugs in parts of the code that are actually not even the thing that you want to present.
3) For everybody who wants to understand the trick its much easier to only have to focus on the new part, and not going thru a different implementation of nonimportant things every day.
4) Actually it is common knowlegde in mathematics and science that in order to show something new that you discovered, you need to pinpoint exactly to it, you need to focus as much as possible on your new things, and remove all other oddments.

So using templates is the absolute correct way. I also do that usually, having my small worming-template, and can build my engines around it. It saves so much time, and presents my ideas much clearer.

If somebody has an idea for a new polymorphism, new file infection and new EPO, and asks me what to do, I would definitivly suggest to present it in three separate projects.

About stealing: it is not true that either hh86 or roy g biv steal any idea of others. Maybe they sometimes base their thoughts on creations that have been developed already (I do that aswell of course), or bring ideas into different contexts etc. Thats the usual procedere when you want to have progress. Thats the main idea of science and developement: Standing on the shoulders of gigants. And of course, this is no opinion but a scientific standard smile

I am surprised why somebody who is going with anonymous handles is trying to destroy the discussions here (including offending the Administrator who works hard as hell to give us this place); i would like to invite this person to work with us to share ideas and thoughts - this can be useful at whatever level of skill you are; no matter what happened before showing how it has to be done correctly in your opinion. Otherwise if that person is not interested, I wonder why (s)he does not leave. Being destructive is sad.

kind regards!
SPTH

Re: Valhalla 4 announcement

†† wrote:

About roy g biv stealing ideas and even codes from others, that's a story for another day

This is a most serious accusation that you are making, and then you don't explain why you say it.
That day should be today.

Thumbs up Thumbs down

Re: Valhalla 4 announcement

†† wrote:

rgb always puts that huge intro in any of his articles, what a poser, he could separate it to different file, but the funny thing is, that intro may overgrow the article itself someday

We agree on something then^^ I was like "ok..ok..great..so where's the code?!?" lol.. he has a huge ego! but whatever..

eval(join$",qw/perl " ( print another Just ; girl )/[qw/3 2 1 5 4 0 7 1 8 6/]);

Thumbs up Thumbs down

19 (edited by alcopaul 2013-07-13 00:16:16)

Re: Valhalla 4 announcement

I know that my opinion is not warranted but since this is the forums, ill toss my few cents.

I - "roy g biv is peter ferrie" accusation

when i was away and not doing virus writing in the mid 2k, virusbuster in the old 29a forums before posted that certain mails from roy g biv was emanating from the Symantec servers way back. i'm sure, if you're active during that time you have read it too. who worked in symantec during those days? peter ferrie and peter szor. peter szor could not be roy g biv. roy g biv thanks qkumba in his articles and qkumba is the ferrie. i am thinking that because of this, VB/29a got disillusioned and discontinued 29a, which couldve continued with roy g biv in his crew. Idk man. You could mail Virusbuster bout it (SPTH interviewed Virusbuster recently so you could toss him a mail.) I poked few inuendos bout this on my twitter lately and somehow SPTH got annoyed and removed me from twitter, had talk with him and it ended not well. Got hurt since I interviewed SPTH in brigada ocho #1 and held to that for old times sake so i decided to quit  and end it all and now to refrain from anything VXing etc.

Yeah, man. You think what you think. Some people believe in witchcraft and aliens. It's a crazy world out there so the idea that roy g biv is peter ferrie is not far fetched and its more sane than believing that the lochness monster exist. but who cares? we all die anyway.

but if it's REALLY true, then we all know who benefits from the chain. Who gets to write about PoC viruses that don't cause real damage in real world and gets paid for it? (Has even Peter Ferrie bothered about Stuxnet or a zero day b/rootkit?) prolly there is no chain at all for if all of this is true, he is writing basically about himself and get paid, which is fucking genius!

http://spth.virii.lu/v3/vessel/display/ … /intvb.txt

"##############################
##  How was your relationship to the anti virus community? What did you think
##  when ex-members joined some AV company (such as Benny for instance)?


In my opinion the anti virus community had a double face. Publicly they were
trash talking 29A, but in private they enjoyed our releases. I would say that
there are still people in av industry missing the golden years of vx scene.

About virus writers joining AV companies: it was the natural thing and I always
considered it fine. In fact there were several virus writers working for some AV
company and being members of a virus writing group at the same time. People knew
about it and nobody complained.
"

with the talent that roy g biv had and being an asset to 29a, he should be at least mentioned by Virus Buster. But surprisingly, there is no mention.

II - Templates are good

I agree with boojum and SPTH here. why reinvent the wheel when it will just do the same thing? it's called efficiency. And new ideas now are innovations. Inventing something from scratch is great if it's like making a computer virus evolve to biological virus by novel means. the only way to output a text in C is "printf("LOL")". There is only one way to make babies, err few ways but it is still fertilizing an egg. You get the point. It's cool if they look the same as long as they do different things. See its fine if they structurally look the same but the important things is they do new things. Like 2 men having the same physiology but one man does basketball and one man does swimming. We could get a 3rd man and let that 3rd man invent his own sport. Now that's new.

III - (Programming) Malware Is Getting Old

That's my personal view. Sure there are new platforms to infect. New languages are being made. New techniques being discovered because of the new OS. They appear new, yes. But it's an illusion. It's a modern view of a key maker making a key to unlock the lock. it's as old as that. Just transpose. It's basically the same.

And making keys are not my cup of tea anymore. I make lame keys anyway so lol.

Anyway, I would not like to downplay the VX world since there are still people in it. I would like just to say good luck and more power to my old friend SPTH, to people like hh86, roy g biv, promix (E-ZINE 2013), perforin, hermit, genetix, resistance and those new comers and those inquisitive minds that visit the forums. and to dahmer, thanks for bringing  the site back.

So those who are active writing researching, support the zines, Valhalla #4 and E-ZINE 2013.

regards,

[CQK]
Twitter: @thealcopaul

Thumbs up +2 Thumbs down

Re: Valhalla 4 announcement

alcopaul wrote:

It's a crazy world out there so the idea that roy g biv is peter ferrie is not far fetched and its more sane than believing that the lochness monster exist.

Peter Ferrie is no more roy g biv than I am.  He is a professional programmer, so unlikely to make such simple mistakes as have been seen in roy's viruses.  And why not Peter Szor (apart from obviously that roy is in Iran and Szor isn't)?  Anyway, it is almost certain that Ferrie knows who roy is.

Thumbs up Thumbs down

Re: Valhalla 4 announcement

I have material I'll be contributing as well this year.

Re: Valhalla 4 announcement

^^   very much looking forward .

~0~

Re: Valhalla 4 announcement

any news\anouns?

Thumbs up Thumbs down

Re: Valhalla 4 announcement

I'll contribute too this year.

Thumbs up Thumbs down

Re: Valhalla 4 announcement

Everything is going as expected.
This is the last month until deadline.  Hopefully, no one will be late to send their material to be published this year.

"This is the girl they keep calling a monster. I want you to keep that firmly in mind. The girl who could be satisfied with a hamburger and a dime root beer after her only school dance so her momma wouldn't be worried..."

Thumbs up Thumbs down