>_0xFORUM
Sign in

A drop-folder pipeline that does not explode on a 4GB 'txt'

in Tools24 replies1.8k views

Caps: size, entropy, format sniff, then YARA, then queue. The 4GB txt was a misnamed dump. The cap saved the box.

Caps are the pipeline. The fancy tools are decorations.

Refs: YARA

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 24 REPLIES

Please keep the hashes and drop the mystery zips. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, format sniff, then YARA, then queue. FakeNet that can reach the internet is not a simulator. I wrote a 12-line script and then threw it away. The listing was enough.

@inject

Please keep the hashes and drop the mystery zips. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, for

I would have written the opposite conclusion a year ago. The load-bearing line: Caps: size, entropy, format sniff, then YARA, then queue. Do not detonate in Docker. Shared kernel. VMs for samples, containers for tools. Took me 5 hours the first time.

@johnflex

I would have written the opposite conclusion a year ago. The load-bearing line: Caps: size, entropy, format sniff, then YARA, then queue. Do

I am not moving this to DMs so you can yell. Stay on the class. I want the listing, not the decompiler story. «A drop-folder pipeline that does not explode on a 4GB 'txt'» — specifically Caps: size, entropy, format sniff, then YARA, then queue. FakeNet that can reach the internet is not a simulator. I will +rep a listing and −rep a vibe. That is the deal.

I tried the naive path first and wasted a morning. You wrote «Caps: size, entropy, format sniff, then YARA, then queue». That is the sentence I keep. Dirty VM means throw it. Do not apt upgrade a dirty box. Did page heap see it, or only the sanitizer? I still have the snapshot named tool-264-pre.

I disagree with the tone, not the bytes. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, format sniff, then YARA, then queue. FakeNet that can reach the internet is not a simulator. I will +rep a listing and −rep a vibe. That is the deal.

I will argue the opposite and then probably agree. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, format sniff, then YARA, then queue. Name snapshots date plus hash plus pre/post. 'snapshot 12' loses a week. Version in my shot: current lab snapshot, not last year's blog.

Please keep the hashes and drop the mystery zips. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, format sniff, then YARA, then queue. Caps on the drop folder saved the box. The 4GB 'txt' was a dump. Version in my shot: current lab snapshot, not last year's blog.

Also: Transfer samples as a hashed read-only ISO. Not drag-drop.

Bookmarking this for the lab wiki. You wrote «Caps: size, entropy, format sniff, then YARA, then queue». That is the sentence I keep. Caps on the drop folder saved the box. The 4GB 'txt' was a dump. If anyone DMs me a zip I will not open it. Hash in-thread.

@lawrencex

I tried the naive path first and wasted a morning. You wrote «Caps: size, entropy, format sniff, then YARA, then queue». That is the sentenc

Quietly the best note on this board this month. The load-bearing line: Caps: size, entropy, format sniff, then YARA, then queue. FakeNet that can reach the internet is not a simulator. I still have the snapshot named tool-264-pre.

@alpha

I ran this on a licensed corpus binary. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, format sniff,

I still keep a paper notebook for this kind of note. «A drop-folder pipeline that does not explode on a 4GB 'txt'» — specifically Caps: size, entropy, format sniff, then YARA, then queue. Clipboard off on the detonation VM. I pasted a token once. I reproduced it on lab build 1398.

Quietly the best note on this board this month. You wrote «Caps: size, entropy, format sniff, then YARA, then queue». That is the sentence I keep. Transfer samples as a hashed read-only ISO. Not drag-drop. After you did that, did the decompiler pick it up or did you dump? My note id for this: 108-23.

@n0xturn

I will argue the opposite and then probably agree. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, fo

You are treating a checksum as a signature again. I ran this on a licensed corpus binary. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, format sniff, then YARA, then queue. Caps on the drop folder saved the box. The 4GB 'txt' was a dump. Did you force-create the function or did auto-analysis luck into it? My note id for this: 108-18.

@brute

Bookmarking this for the lab wiki. You wrote «Caps: size, entropy, format sniff, then YARA, then queue». That is the sentence I keep. Caps o

I am not moving this to DMs so you can yell. Stay on the class. Agreed on the class, not on the tool. «A drop-folder pipeline that does not explode on a 4GB 'txt'» — specifically Caps: size, entropy, format sniff, then YARA, then queue. FakeNet that can reach the internet is not a simulator. I will +rep a listing and −rep a vibe. That is the deal.

@mosesprime

I disagree with the tone, not the bytes. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, format sniff

I read the patch. You read a tweet. Those are not the same source. I would have written the opposite conclusion a year ago. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, format sniff, then YARA, then queue. Clipboard off on the detonation VM. I pasted a token once. I reproduced it on lab build 1100.

@nova

I would have written the opposite conclusion a year ago. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entro

I disagree with the tone, not the bytes. The load-bearing line: Caps: size, entropy, format sniff, then YARA, then queue. Name snapshots date plus hash plus pre/post. 'snapshot 12' loses a week. Took me 2 hours the first time.

Bookmarking this for the lab wiki. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, format sniff, then YARA, then queue. Name snapshots date plus hash plus pre/post. 'snapshot 12' loses a week. What did you key the join on — PID or process GUID? I reproduced it on lab build 1167.

Did this on ARM64 last week — same shape, different pain. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, format sniff, then YARA, then queue. FakeNet that can reach the internet is not a simulator. Version in my shot: current lab snapshot, not last year's blog.

@reconx

Did this on ARM64 last week — same shape, different pain. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entr

Do not call people skids because they use Ghidra. Did this on ARM64 last week — same shape, different pain. «A drop-folder pipeline that does not explode on a 4GB 'txt'» — specifically Caps: size, entropy, format sniff, then YARA, then queue. FakeNet that can reach the internet is not a simulator. Version in my shot: current lab snapshot, not last year's blog.

I failed this exact class in January. «A drop-folder pipeline that does not explode on a 4GB 'txt'» — specifically Caps: size, entropy, format sniff, then YARA, then queue. Tools snapshot in 8 minutes or you will not restore it. My note id for this: 108-11.

The screenshot is the useful part of the post. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, format sniff, then YARA, then queue. Tools snapshot in 8 minutes or you will not restore it. I still have the snapshot named tool-264-pre.

Also: Dirty VM means throw it. Do not apt upgrade a dirty box.

@sp4rk

The screenshot is the useful part of the post. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, format

I dumped after OEP and then did this. You wrote «Caps: size, entropy, format sniff, then YARA, then queue». That is the sentence I keep. Dirty VM means throw it. Do not apt upgrade a dirty box. Hash of the public file, or are we arguing a shape? I will +rep a listing and −rep a vibe. That is the deal.

@sysx

I dumped after OEP and then did this. You wrote «Caps: size, entropy, format sniff, then YARA, then queue». That is the sentence I keep. Dir

Take the telegram pitch to the bin. Market listing or nothing. I disagree with the tone, not the bytes. On «A drop-folder pipeline that does not explode on a 4GB 'txt'»: Caps: size, entropy, format sniff, then YARA, then queue. Profile YARA. One looping regex will eat a core. I wrote a 12-line script and then threw it away. The listing was enough.

Agreed on the class, not on the tool. You wrote «Caps: size, entropy, format sniff, then YARA, then queue». That is the sentence I keep. Caps on the drop folder saved the box. The 4GB 'txt' was a dump. I still have the snapshot named tool-264-pre.

@vultr

Agreed on the class, not on the tool. You wrote «Caps: size, entropy, format sniff, then YARA, then queue». That is the sentence I keep. Cap

Quietly the best note on this board this month. You wrote «Caps: size, entropy, format sniff, then YARA, then queue». That is the sentence I keep. PE-sieve is a lead. It is not a verdict. I will +rep a listing and −rep a vibe. That is the deal.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.