This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
import os | |
import time | |
while True: | |
os.mkdir('F:\\A') | |
time.sleep(10) | |
os.rmdir('F:\\A') |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
-=] Sandbox Analysis Report generated by Noriben v1.7.0 | |
-=] Developed by Brian Baskin: brian @@ thebaskins.com @bbaskin | |
-=] The latest release can be found at https://github.com/Rurik/Noriben | |
-=] Analysis time: 61.84 seconds | |
Processes Created: | |
================== | |
[CreateProcess] python.exe:2420 > "C:\malware\hehda.exe" [Child PID: 1764] | |
[CreateProcess] hehda.exe:1764 > "%WinDir%\system32\cmd.exe" [Child PID: 692] |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
# Procmon Rule Parser v0.02 | |
# Brian Baskin - @bbaskin | |
# Reads default rules from an exported Procmon Configuration (.PMC) or Procmon Filter (.PMF) file | |
# Example output: | |
""" | |
12:09:59-bbaskin@~/Development/Noriben$ python parse_procmon_filters.py -f ProcmonConfiguration.pmc | |
[Exclude] Process Name is Procmon64.exe | |
[Exclude] Operation is QueryStandardInformationFile | |
[Exclude] Operation is RegOpenKey | |
[Exclude] Operation is NotifyChangeDirectory |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
### Tracks a public Twitter List and posts updates to a given Slack channel | |
### Example: https://i.imgur.com/RMQB27N.png | |
import datetime | |
import time | |
import twitter | |
from slackclient import SlackClient | |
slack_bot_id = '<FILL OUT>' | |
slack_channel = '<FILL OUT>' |
OlderNewer