Karan

5.1K posts

Karan banner
Karan

Karan

@0xDISREL

CTI Analyst & Malware Researcher | Staff at @vxunderground | PTC

Canada Katılım Ağustos 2020
668 Takip Edilen2.9K Takipçiler
Sabitlenmiş Tweet
Karan
Karan@0xDISREL·
Curiositas Incarnatus
Español
0
0
0
3K
Karan
Karan@0xDISREL·
I HAVE A NEW KITTEN AND HER NAME IS WILLIE
Karan tweet mediaKaran tweet media
English
2
0
15
560
The Bingus Man
The Bingus Man@NotNordgaren·
I have an idea for a payload with VBScript but now I have to write VBScript AAAAAAAAAAAAAAAAAAAAAAAA
GIF
English
7
2
43
2.4K
Karan
Karan@0xDISREL·
@NotNordgaren @dodo_sec I think yes, vbscript.dll, RIP an era tho it’s getting phased out by MSFT soon
English
1
0
1
29
The Bingus Man
The Bingus Man@NotNordgaren·
@0xDISREL @dodo_sec Honestly already spend enough of my time in MSDN. Actually it might be VBA. It's a quality of the msvbvm dlls that I need, although if vbscript has dlls that get loaded specifically for vbscript, it probably works, too.
English
1
0
1
33
Karan
Karan@0xDISREL·
@dodo_sec @NotNordgaren VBScript is arguably even more annoying than VBA DEADASS Betting 5 dollars you will be expert at navigating MSDN by the end of your payload 🫡
English
1
0
1
28
Karan
Karan@0xDISREL·
@BengalsKorey Shit dude… sorry bout that. Prayers… 🙏
English
0
0
1
146
Korey 🐅
Korey 🐅@BengalsKorey·
Need you guys to pray for me and my family 😞 we lost our little one yesterday..
English
178
13
1K
82.7K
Karan retweetledi
SleeperBengals
SleeperBengals@SleeperBengals·
When Joe Burrow injured his wrist in 2023, Chiefs fans rallied together to donate money to both his foundation and his hunger relief, using $9 donations. With Patrick Mahomes now having to battle through an injury as well, I think #Bengals fans should look to donate to his own foundation, 15 and the Mahomies. Here’s the link: 15andthemahomies.org/donate/ Get well soon, Pat!
SleeperBengals tweet media
English
187
590
4.8K
484.7K
Karan retweetledi
HIDEO_KOJIMA
HIDEO_KOJIMA@HIDEO_KOJIMA_EN·
Good Morning.
HIDEO_KOJIMA tweet media
English
354
2.3K
27K
2.5M
Karan retweetledi
vx-underground
vx-underground@vxunderground·
If you want to learn more about malware the easiest method is learning malware TTPs (Threats Tactics and Procedures). Basically, understand some of the techniques employed by malware authors to do stuff Some malware techniques are simple and old Some malware techniques are incredibly sophisticated What you'll notice though with malware TTPs is each TTP is a "stepping stone". For example, the most advanced evasion techniques often stem from the most basic of evasion techniques. Research and improvements on malware don't come from nowhere. Each technique comes from standing (metaphorically) on the work of others. Malware TTPs are broken down kind of subjectively. They're hard to categorize. MITRE is the industry standard for malware TTPs, but even then there is some debate on the effectiveness of it. By effectiveness I mean, if you have a simple malware technique that is slightly modified, is it the same malware technique? Is it a whole new category? How many "modifications" until it has its own entry? It's just debating classification. For Windows malware however malware is defined as something along the lines of: 1. How was it delivered to the machine? 2. How many "chains" or "stages" or "redirects" were performed until the payload was detonated? 3. How was the payload detonated? 4. Is the payload persistent? 5. What was the objective of the malware? On missiles and stuff, the part that explodes is the payload. It is the same concept with malware. The actual malicious code that does the malicious stuff is the payload. With chains, or redirects, or stages, ... modern malware is often not as simple as someone double clicking a .exe the payload detonates. While this is true for common malware, more sophisticated malware will often jump through a series of hoops until the actual payload is detonated. For example, more sophisticated malware may send a malicious email attachment that is a .Lnk file (shortcut file). When the user double clicks the .Lnk file the .Lnk file may download a .zip file. The . Lnk file will extract the .zip which will contain a malicious .JS file. The .Lnk file will execute the .JS file. The .JS file will delete the .Lnk and .zip. The .JS file with then generate a .PS1 script and execute it. The .PS1 file will delete the .JS file and download a .exe file. The .exe file then will download a .dll file. The .DLL is the payload. 1. Lnk downloads .zip 2. Lnk extracts zip 3. Lnk runs .JS 4. JS deletes .Lnk 5. JS deletes .zip 6. JS makes .ps1 7. ps1 downloads .exe 8. ps1 deletes .JS 9. .exe downloads .DLL 10. .exe runs .DLL payload The reason malware does this is because it makes it difficult for anti virus software to identify the final payload. Researchers will need to reconstruct the series of events which lead to the payload delivery. Additionally, malware authors may modify the chaining at any given moment to make detection much more difficult. Okay, that's enough schizo ranting for now.
vx-underground tweet media
English
21
98
985
45.3K
Chad Johnson
Chad Johnson@ochocinco·
Good goal line stand 🚧
English
4
2
112
27K
Karan retweetledi
Ki Holo 🌊
Ki Holo 🌊@KingOfCantSleep·
Navy Red (maroon) such a fire ass color mane
English
0
1
3
284
Kilgore Trout
Kilgore Trout@OnTopicFeegs·
Beautiful day for a football game though
Kilgore Trout tweet media
English
1
0
6
153
Karan retweetledi
Ki Holo 🌊
Ki Holo 🌊@KingOfCantSleep·
Ki Holo 🌊 tweet media
ZXX
0
1
3
252
Ki Holo 🌊
Ki Holo 🌊@KingOfCantSleep·
@_yorgus_ Yea those cats are black sometimes T, he says they panthers or something
English
1
0
1
39
Karan
Karan@0xDISREL·
#WhoDey killing themselves tonight if we lose the unc bowl?
English
0
0
1
278
Karan retweetledi
Goodberry
Goodberry@JoeGoodberry·
One of my favorite things about checking Reddit: When somebody accidentally posts their Bengal Cat in the Bengals subreddit. This happens pretty routinely and is generally met with excitement and "can he tackle?" or "I'd rather see this anyway" It gets me every time.
Goodberry tweet media
English
14
23
665
33K
Karan
Karan@0xDISREL·
@ZooL_Smith Valve doesn’t have the R&D like Apple, and they would need to build a translation layer like Rosetta to actually make it viable + make PC games compatible. Once they capitalize on the market they could debate moving and forcing game dev industry to develop ARM native.
English
0
0
1
183
ZooL
ZooL@ZooL_Smith·
I'm a bit out of the loop on what's up with ARM, I don't fully understand why the new Steam Machine is on amd64. They're building a whole Arch distro for ARM with FEX and all, but the Steam Machine isn't on it? Apple moved on from it, why wouldn't Valve commit to go full ARM?
English
39
2
74
7.7K