Navdeep

42 posts

Navdeep banner
Navdeep

Navdeep

@ItsNavdeep

malware executor @IndianCERT, ex @ZSAssociates

India انضم Mayıs 2011
345 يتبع95 المتابعون
Navdeep
Navdeep@ItsNavdeep·
@nickharbour Looks like a couple of names from as early as top 30 were removed. That’s quite interesting..
English
1
0
0
1.4K
nickharbour
nickharbour@nickharbour·
#flareon11 I just removed (banned) 40 "finishers" for cheating. If you are a winner this year please recheck the scoreboard, you might have a better place than you thought!
English
3
14
108
20.7K
Navdeep
Navdeep@ItsNavdeep·
Just completed the Flare-On challenge for this year! Planning to do it at a more relaxed pace over the full six weeks next time. #flareon11
Navdeep tweet media
English
2
0
12
1.4K
Navdeep
Navdeep@ItsNavdeep·
Every year I spend a lot of time learning some new witchcraft, thanks to @6502_ftw - only to realise later that I didn’t need to. #flareon11
English
1
0
4
1.8K
Navdeep
Navdeep@ItsNavdeep·
@fsharp123 I patched the 10k score in memory after crc32 check.
English
0
0
1
99
fsharp
fsharp@fsharp123·
Has anyone solved flake from #flareon10 the way I did? To bypass the snake length check, I patched the hardcoded high score to a low number. I then bypassed the constants object CRC check during runtime and played the game normally. No need to mess with the config file.
English
3
0
3
545
Navdeep
Navdeep@ItsNavdeep·
@thehellu Great analysis! Would like to just point out one minor oversight in the report: The bytes 08 08 08… are not a hard-coded delimiter. They are instead the 4 DNS lookup IP addresses used to resolve C2 domains: 8.8.8.8 8.8.4.4 4.4.4.4 4.2.2.2
Navdeep tweet media
English
1
0
2
220
Daniel Lunghi
Daniel Lunghi@thehellu·
VB released my talk on a #Shadowpad sample delivered by a Pakistan gov application. It contains an analysis of the modified MSI installer, some tricks to pivot on old and new Shadowpad samples, an overview of the #APT campaign, and attribution discussion youtube.com/watch?v=i52MH-…
YouTube video
YouTube
English
2
23
54
7.8K
Navdeep
Navdeep@ItsNavdeep·
Completed another Flare-On challenge. FLARE team didn't hold back on difficulty this time around. Was (mostly) fun though! #flareon10
Navdeep tweet media
English
1
0
16
1.1K
Navdeep
Navdeep@ItsNavdeep·
@m_r_tz Thanks! Definitely didn’t have Patience to type or try OCR..
English
0
0
0
108
Moritz
Moritz@m_r_tz·
lVHz/Pqbr8VCgd9KfqTrG9kg== FlArEonFlArEonFlArEonFlArEonFlArEonFlArEonFlArEonFlArEonFlArEonFlArEonFlArEonFlArEonFlArEonFlArEonFlArEonFlArEonFlArEon #flareon10
Română
2
1
1
1.2K
Navdeep
Navdeep@ItsNavdeep·
@IngHidaka @G2Thijs AAECAfHhBByW6AP36AOm7wPN+QPhpATlsATHsgSWtwSY1ASa1AS42QT04wT84wT+4wSU5ASJ5gSP7QSk7wSH9gSy9wSz9wS2+gSrgAWogQWimQWXpAWfpAXipAUBieQEAA==
0
0
2
493
Thijs
Thijs@ThijsTCG·
Tried something else and been on a sick streak with Highlander Blood DK. Suprisingly successful, nothing more fun than +45 lifes with Reno 😄 Deckcode: SJ5gSP7QSk7wSH9gSy9wSz9wS2+gSrgAWogQWimQWXpAWfpAXipAUBieQEAA==
Thijs tweet mediaThijs tweet media
English
16
17
312
97.4K
Navdeep
Navdeep@ItsNavdeep·
Time has been scarce recently.. happy to still complete #flareon9 much faster than last year. Thanks @nickharbour and rest of the FLARE team. Looking forward to next year!
Navdeep tweet media
English
3
0
27
0