Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. ransomware except in addition to encrypting data it plays a 10 hour supercut of all yotubes worst jarjar binks impressions and zingers forever until they pay

ransomware except in addition to encrypting data it plays a 10 hour supercut of all yotubes worst jarjar binks impressions and zingers forever until they pay

Scheduled Pinned Locked Moved Uncategorized
74 Posts 19 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • viss@mastodon.socialV viss@mastodon.social

    @winterknight1337 wow its been a while since i had to use a real c2. i didnt even know these were a thing! i guess ive been lolling too hard in various clouds and posessing the still-living semi-corpses of github workflows too long

    winterknight1337@infosec.exchangeW This user is from outside of this forum
    winterknight1337@infosec.exchangeW This user is from outside of this forum
    winterknight1337@infosec.exchange
    wrote last edited by
    #60

    @Viss they’re super nice! Only issue is that they’re written in C, so if they crash they take your payload down with it, but they’re designed to avoid cobalt strike’s fork and run behaviors. But generally speaking, it’s a stealthier way to expand C2 payloads.

    viss@mastodon.socialV 1 Reply Last reply
    0
    • viss@mastodon.socialV viss@mastodon.social

      ransomware except it signs absolutely every single person in the company who has an email address up to the elon musk fan club

      evilstevie@mastod1.ddns.netE This user is from outside of this forum
      evilstevie@mastod1.ddns.netE This user is from outside of this forum
      evilstevie@mastod1.ddns.net
      wrote last edited by
      #61

      @Viss oof. too far. just encrypt the drives with a randomised hash at this point.

      1 Reply Last reply
      0
      • viss@mastodon.socialV viss@mastodon.social

        ransomware except it volunteers you to be a CEH exam proctor

        winterknight1337@infosec.exchangeW This user is from outside of this forum
        winterknight1337@infosec.exchangeW This user is from outside of this forum
        winterknight1337@infosec.exchange
        wrote last edited by
        #62

        @Viss oh this is awful

        viss@mastodon.socialV 1 Reply Last reply
        0
        • viss@mastodon.socialV viss@mastodon.social

          ransomware except that it specifically finds any machines that still have diskette drives in them and plays the mexican hat dance, the imperial march, or the mario theme on them either until their stepper motors burn out, or the ransom is paid

          viss@mastodon.socialV This user is from outside of this forum
          viss@mastodon.socialV This user is from outside of this forum
          viss@mastodon.social
          wrote last edited by
          #63

          ransomware except, stuxnet style, specifically looks for any computers that are interfaces to mainframes, are mainframe adjacent, or otherwise in a critical workflow path, pauses all the queues in the mainframe, empies them, then rms all the regular computers. doesnt even aim for a ransom. overwrites the bootloader with the nyancat one, except instead of a cat its the fight club bar of soap

          winterknight1337@infosec.exchangeW 1 Reply Last reply
          0
          • winterknight1337@infosec.exchangeW winterknight1337@infosec.exchange

            @Viss oh this is awful

            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.social
            wrote last edited by
            #64

            @winterknight1337 it gets worse 😄

            1 Reply Last reply
            0
            • viss@mastodon.socialV viss@mastodon.social

              @quinn true. they wouldnt disclose

              drwho@masto.hackers.townD This user is from outside of this forum
              drwho@masto.hackers.townD This user is from outside of this forum
              drwho@masto.hackers.town
              wrote last edited by
              #65

              @Viss @quinn <thoughtful noises>

              1 Reply Last reply
              0
              • viss@mastodon.socialV viss@mastodon.social

                ransomware except that it specifically finds any machines that still have diskette drives in them and plays the mexican hat dance, the imperial march, or the mario theme on them either until their stepper motors burn out, or the ransom is paid

                scottwilson@infosec.exchangeS This user is from outside of this forum
                scottwilson@infosec.exchangeS This user is from outside of this forum
                scottwilson@infosec.exchange
                wrote last edited by
                #66

                @Viss How about

                import subprocess
                import time

                CMD = ["eject", "-t"]
                DELAY_SECONDS = 1.0

                def main():
                while True:
                try:
                subprocess.run(CMD, check=False)
                except Exception:
                # ignore errors and continue
                pass
                time.sleep(DELAY_SECONDS)

                if __name__ == "__main__":
                main()

                viss@mastodon.socialV 1 Reply Last reply
                0
                • winterknight1337@infosec.exchangeW winterknight1337@infosec.exchange

                  @Viss they’re super nice! Only issue is that they’re written in C, so if they crash they take your payload down with it, but they’re designed to avoid cobalt strike’s fork and run behaviors. But generally speaking, it’s a stealthier way to expand C2 payloads.

                  viss@mastodon.socialV This user is from outside of this forum
                  viss@mastodon.socialV This user is from outside of this forum
                  viss@mastodon.social
                  wrote last edited by
                  #67

                  @winterknight1337 oh.. some shit crashing your payload you say?

                  and it takes down some more shit with it you say?

                  OH WHAT EVER DO YOU MEANhttps://github.com/EmpireProject/Empire/issues/589

                  viss@mastodon.socialV 1 Reply Last reply
                  0
                  • viss@mastodon.socialV viss@mastodon.social

                    ransomware except in addition to encrypting data it plays a 10 hour supercut of all yotubes worst jarjar binks impressions and zingers forever until they pay

                    occult@vox.ominous.netO This user is from outside of this forum
                    occult@vox.ominous.netO This user is from outside of this forum
                    occult@vox.ominous.net
                    wrote last edited by
                    #68

                    @Viss don't threaten me with a good time.

                    1 Reply Last reply
                    0
                    • viss@mastodon.socialV viss@mastodon.social

                      @TrillionB we used to pull that shit on people who left their workstations unlocked back when i was in websense tech support in like 2001

                      trillionb@mstdn.socialT This user is from outside of this forum
                      trillionb@mstdn.socialT This user is from outside of this forum
                      trillionb@mstdn.social
                      wrote last edited by
                      #69

                      @Viss yep, the same when I worked in IT. "You're too cool for Ctrl+Alt+Del + L?"

                      1 Reply Last reply
                      0
                      • viss@mastodon.socialV viss@mastodon.social

                        ransomware except, stuxnet style, specifically looks for any computers that are interfaces to mainframes, are mainframe adjacent, or otherwise in a critical workflow path, pauses all the queues in the mainframe, empies them, then rms all the regular computers. doesnt even aim for a ransom. overwrites the bootloader with the nyancat one, except instead of a cat its the fight club bar of soap

                        winterknight1337@infosec.exchangeW This user is from outside of this forum
                        winterknight1337@infosec.exchangeW This user is from outside of this forum
                        winterknight1337@infosec.exchange
                        wrote last edited by
                        #70

                        @Viss we’ve got new bootloader overwrites now too!

                        viss@mastodon.socialV 1 Reply Last reply
                        0
                        • winterknight1337@infosec.exchangeW winterknight1337@infosec.exchange

                          @Viss we’ve got new bootloader overwrites now too!

                          viss@mastodon.socialV This user is from outside of this forum
                          viss@mastodon.socialV This user is from outside of this forum
                          viss@mastodon.social
                          wrote last edited by
                          #71

                          @winterknight1337 show me 😄

                          winterknight1337@infosec.exchangeW 1 Reply Last reply
                          0
                          • scottwilson@infosec.exchangeS scottwilson@infosec.exchange

                            @Viss How about

                            import subprocess
                            import time

                            CMD = ["eject", "-t"]
                            DELAY_SECONDS = 1.0

                            def main():
                            while True:
                            try:
                            subprocess.run(CMD, check=False)
                            except Exception:
                            # ignore errors and continue
                            pass
                            time.sleep(DELAY_SECONDS)

                            if __name__ == "__main__":
                            main()

                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.social
                            wrote last edited by
                            #72

                            @scottwilson can ... can laptops do the pc speaker beep anymore? is that even still a thing?

                            scottwilson@infosec.exchangeS da_667@infosec.exchangeD schrotthaufen@mastodon.socialS ridge@tilde.zoneR 4 Replies Last reply
                            0
                            • viss@mastodon.socialV viss@mastodon.social

                              @scottwilson can ... can laptops do the pc speaker beep anymore? is that even still a thing?

                              scottwilson@infosec.exchangeS This user is from outside of this forum
                              scottwilson@infosec.exchangeS This user is from outside of this forum
                              scottwilson@infosec.exchange
                              wrote last edited by
                              #73

                              @Viss Oooh that would be great. I don't know!

                              1 Reply Last reply
                              1
                              0
                              • viss@mastodon.socialV viss@mastodon.social

                                @scottwilson can ... can laptops do the pc speaker beep anymore? is that even still a thing?

                                da_667@infosec.exchangeD This user is from outside of this forum
                                da_667@infosec.exchangeD This user is from outside of this forum
                                da_667@infosec.exchange
                                wrote last edited by
                                #74

                                @Viss @scottwilson I don't know about laptops, but my ali-express chinesium pfSense router can.

                                viss@mastodon.socialV 1 Reply Last reply
                                1
                                0
                                Reply
                                • Reply as topic
                                Log in to reply
                                • Oldest to Newest
                                • Newest to Oldest
                                • Most Votes


                                • Login

                                • Login or register to search.
                                • First post
                                  Last post
                                0
                                • Categories
                                • Recent
                                • Tags
                                • Popular
                                • World
                                • Users
                                • Groups