Discord Malware - "i hacked MYSELF??"

  Рет қаралды 192,979

John Hammond

John Hammond

3 жыл бұрын

To help support me, check out Kite! Kite is a coding assistant that helps you faster, on any IDE offer smart completions and documentation. www.kite.com/get-kite/?... (disclaimer, affiliate link)
For more content, subscribe on Twitch! / johnhammond010
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
PayPal: paypal.me/johnhammond010
E-mail: johnhammond010@gmail.com
Discord: johnhammond.org/discord
Twitter: / _johnhammond
GitHub: github.com/JohnHammond

Пікірлер: 494
@_JohnHammond
@_JohnHammond 3 жыл бұрын
For the frenzy of folks that are concerned YoOuUUuU LLEeeEAAaKKEEDdA TOOKKkKEKEENNNNN!N!N!N!!nn1n1hhbjgngn: No. If you got clever and looked at individual frames, the one you see returns an Unauthorized. Others have been obscured. Thank you for your concern. :)
@rxy10
@rxy10 3 жыл бұрын
Very nice video
@DoorThief
@DoorThief 3 жыл бұрын
I feel like I was called out on this, lol
@nikolanojic6861
@nikolanojic6861 3 жыл бұрын
Dosent tokens change with time
@XenorioWasTaken
@XenorioWasTaken 3 жыл бұрын
If you stitch together the frames where the working token is visible, you can make out about half of a token. Just to be sure, i would advise changing your password as that generates a new authentication token and invalidates the old one. You wouldn't even have had to blur any tokens if you did that before releasing the video.
@_JohnHammond
@_JohnHammond 3 жыл бұрын
Yes, passwords were changed before releasing the video ;)
@jamesoneill2606
@jamesoneill2606 3 жыл бұрын
Please don't stop explaining the simple stuff, I've learned loads thanks.
@Khusyasy
@Khusyasy 2 жыл бұрын
same
@ajayk643
@ajayk643 2 жыл бұрын
Then why did you see these kind of videos
@ajayk643
@ajayk643 2 жыл бұрын
John Hammond thanks for this video😍😍
@trouty7947
@trouty7947 2 жыл бұрын
It's good to remember every video, especially when they're popular, will have a lot of new people that this is literally their first in depth look at malware analysis. So it's always worth explaining for the new guys.
@oltn7142
@oltn7142 2 жыл бұрын
same here
@flightstatic4662
@flightstatic4662 3 жыл бұрын
I don't think I have ever heard anyone say "please send me malware" before
@ko-Daegu
@ko-Daegu 3 жыл бұрын
it's all over Twitter if you follow at least one malware analyst
@recommendastra_hack_zoneon709
@recommendastra_hack_zoneon709 3 жыл бұрын
A ban was placed on my Ticktok, PSN account which affected my score but all Thanks To #global_hackweiser1 i got all access to my banned accounts within some minutes which i summon the trust to work with him after i saw most of his good recommandations on You-Tube. You trully a Man of your word.💯
@recommendastra_hack_zoneon709
@recommendastra_hack_zoneon709 3 жыл бұрын
A ban was placed on my Ticktok, PSN account which affected my score but all Thanks To #global_hackweiser1 i got all access to my banned accounts within some minutes which i summon the trust to work with him after i saw most of his good recommandations on You-Tube. You trully a Man of your word.💯
@tamilxctf4075
@tamilxctf4075 3 жыл бұрын
@@recommendastra_hack_zoneon709 y spam.exe
@bitten2up
@bitten2up 2 жыл бұрын
tbh I said that to someone who was infected with this malware so then I can report the links
@xFalduR
@xFalduR 3 жыл бұрын
I'm only 5 minutes in, but i feel its relevant to say I appreciate the "easy baby stuff" being reiterated for people like me. I'm learning python for data science. I don't know what all of these imports do. So when you explain every import or at least give basic descriptions of what they do, it really helps me follow along.
@JonSnyderfudge
@JonSnyderfudge 3 жыл бұрын
Lol yup. Never assume our knowledge base. Those that already know python can easily skip forward that part if they want.
@cedricvillani8502
@cedricvillani8502 2 жыл бұрын
Ok well lol, if your actually learning python you KNOW what import does. Lmao think about the word for a moment…… hmmm do a little work looking up maybe? No? Just wait for someone to do it for you?
@xFalduR
@xFalduR 2 жыл бұрын
@@cedricvillani8502 not only are you pretentious, you also can't read. That's astounding.
@issecret1
@issecret1 2 жыл бұрын
@@cedricvillani8502 yes. Feel free to lose your mind over this fact
@shawazonfire
@shawazonfire Жыл бұрын
Well said, I think that's probably the reason I like this guy's videos. Clear, comprehensive step by step instructions and explanations.
@davidfrischknecht8261
@davidfrischknecht8261 3 жыл бұрын
That ".il" file is actual CIL (Common Intermediate Language, formerly known as MSIL) code that C# and VB source code files are compiled down to before they're turned into executables.
@nimitzufo94
@nimitzufo94 3 жыл бұрын
thanks man
@THEbraylonbarnes
@THEbraylonbarnes 3 жыл бұрын
thanks david frisk neck
@yeppiidev
@yeppiidev 2 жыл бұрын
@@THEbraylonbarnes lmaoo
@rogogo1244
@rogogo1244 2 жыл бұрын
@@THEbraylonbarnes Its german: David Fresh-Knight
@94flow93
@94flow93 3 жыл бұрын
This will blow up. So many script kiddies on DS
@_JohnHammond
@_JohnHammond 3 жыл бұрын
I tried to make this as cl1ckb@!t as possible 😎
@JarredRandom
@JarredRandom 3 жыл бұрын
@@_JohnHammond i think youve succeeded in making it that
@JimTheScientist
@JimTheScientist 3 жыл бұрын
I see them every day. Lots of the exploits people use “generators” for (python scripts you can find on GitHub) are electron related. So many ways to download files to other people’s computers and to crash other people’s computers.
@JarredRandom
@JarredRandom 3 жыл бұрын
@@JimTheScientist lol hey jim, fancy seeing you here!
@94flow93
@94flow93 3 жыл бұрын
JimTheScientist electron is a shit piece of software and I wish permanent annoyance on its devs and applications that use it. should not crash because of a video codec issue
@matthewlandry1352
@matthewlandry1352 3 жыл бұрын
Omg..can’t wait for this I started seeing a lot of discord trojans in the news last year and I would love to here more in depth analysis.
@Marten..
@Marten.. 3 жыл бұрын
one of your most easy to understand videos yet. well explained. learned a lot. thank you John!
@MrTubeMeToo
@MrTubeMeToo Жыл бұрын
Thanks for making it 'approachable'. I am a beginner in all of this and your quick description of the basic commands is extrememely helpful. It allows me to continue to follow what you are doing and also learn about a wide variety of commands. Of course, further real study is necessary but your presentation helps one broaden understanding of the overall field to be studied. Thanks.
@Nitradoz
@Nitradoz 3 жыл бұрын
200k! good job man you deserve it :)
@DoorThief
@DoorThief 3 жыл бұрын
Love your content, John! It's really fun to step through code with you.
@unknownlordd
@unknownlordd 2 жыл бұрын
Honestly I've not watched a full malware analysis vid from you but this one rly interesting and honestly very well written
@nv_takeout
@nv_takeout 2 жыл бұрын
Recently stumbled upon some of your malware analysis videos and boy am I hooked! love your approach, you make things super easy to understand even for someone with little to no coding knowledge. I hope soon I can find some videos on your channel about learning to program in some of these languages that you work in with malware :) some more gamer-catered stuff would be awesomeee too! thanks John for some very entertaining videos!
@MsThekiller02
@MsThekiller02 2 жыл бұрын
Learning new stuff with you is always great. You always manage to draw my attention for a whole hour.
@joeymelo2882
@joeymelo2882 3 жыл бұрын
Great content! Thank you for your contribution and for taking the risk of exposing yourself. Very informative.
@evinces
@evinces 3 жыл бұрын
Omg, we need to see more of this hog stealer code and whatever else you can find in the land of Discord malware! Keep up the great work and congrats on 200k!
@kylelarson7840
@kylelarson7840 3 жыл бұрын
Hey John a little off topic for this video, but your terminator vid, (among all the others!) really helped me pass the eJPT in less than 4 hours last week. Thanks for all great content man!
@driden1987
@driden1987 3 жыл бұрын
Awesome content as always, John 👏🏻
@lethalboar6755
@lethalboar6755 3 жыл бұрын
Great video John, would love to see you de-obfuscate that JavaScript!
@andyburton5912
@andyburton5912 3 жыл бұрын
Was doing exchange patching a week ago and they reference @john Hammond gist love it
@Basieeee
@Basieeee 3 жыл бұрын
I Love you John. Great video again, interpreted languages is cool to reverse. Congratz on the 200k :)
@alincraciunescu
@alincraciunescu 3 жыл бұрын
You are the best! Thank you for explaining also for the beginners.
@aravbudhiraja
@aravbudhiraja 3 жыл бұрын
ayy congrats on 200k John!
@jaygeemmo
@jaygeemmo 2 жыл бұрын
ive learned allot from this and that says something because time enrolled in college for this and I feel like these breakdowns help immensely for someone like myself.
@Kurowe.
@Kurowe. 2 жыл бұрын
I hope more of you guys look into this Discord malware, a lot of this stuff is going undetected and creating a lot of headaches and some of these stealers have keyloggers, gets login sessions from your browsers etc.
@jonoisedev
@jonoisedev 3 жыл бұрын
I literaly saw this on my youtube feed and inmediately went to make popcorn!!
@apollogeist8513
@apollogeist8513 3 жыл бұрын
Congrats on 200k!
@randallsalyer
@randallsalyer 3 жыл бұрын
You always have great videos!
@djoser4977
@djoser4977 2 жыл бұрын
THC For (4) L(ife) 9-TetraHydroCannabinol (THC) is a chemical component in Weed and Hasj. Probably a smoker. nice vid btw, Learned a lot!
@Kemankes111
@Kemankes111 2 жыл бұрын
Awsome video man. I appreciate it a lot
@elthxr4692
@elthxr4692 3 жыл бұрын
You're making it happen John ! :) BigUps . Learned lot from you my Guy !! Hopefully more to come. Peace
@shivashiva8021
@shivashiva8021 3 жыл бұрын
I am eagerly waiting .
@jonny-mp3
@jonny-mp3 3 жыл бұрын
Hey John, love the Malware stuff. Would love to see some Dynamic Analysis with some ransomware or something , cheers
@algalib2631
@algalib2631 2 жыл бұрын
YOUR explanation is Osm!!!🖤🖤🖤
@crazymonkeyVII
@crazymonkeyVII 2 жыл бұрын
Absolutely fantastic content!
@keissetje
@keissetje 3 жыл бұрын
Holy smokes, how can it be so easy to retrieve all your discord data without logging in essentially. I wouldn't have guessed that discord is saving these tokens as plaintext in your appdata folder. Very nice video! You've got another sub :)
@ayva1106
@ayva1106 2 жыл бұрын
Late comment, but they're finally releasing a beta tests that encrypts your tokens... and it only took them a few years
@MakotoIchinose
@MakotoIchinose Жыл бұрын
@@ayva1106 And even then it's still compromised. People found out malware that circumvented it and managed to reverse engineer it for documentation.
@omniflas_2065
@omniflas_2065 Жыл бұрын
I love these kind of videos, fun new channel to nerd out to. :) Joined the Discord as well! :p
@rabbitear0
@rabbitear0 3 жыл бұрын
Great Video, and learned a bunch!
@rahealmazumder6811
@rahealmazumder6811 3 жыл бұрын
Great video John! Many thanks :-)
@shawazonfire
@shawazonfire Жыл бұрын
i'm not gonna lie to you bro, the way you teach is excellent and i appreciate your videos more than you could ever imagine... ever...
@krlst.5977
@krlst.5977 3 жыл бұрын
Great video, man. As always :)
@ajayk643
@ajayk643 2 жыл бұрын
Thanks for this video sir
@jdbjdb2
@jdbjdb2 3 жыл бұрын
The delay is to prevent maxing out discord API requests so it's maximum efficiency
@ape4926
@ape4926 3 жыл бұрын
This is going to be an amazing video!
@Enigmahax
@Enigmahax 3 жыл бұрын
really good explication, please keep this up
@hubsoftecommerce
@hubsoftecommerce 3 жыл бұрын
cant wait for 200k so excited !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
@JimTheScientist
@JimTheScientist 3 жыл бұрын
This is going to be interesting. I’ve studied RCE attacks and Trojans on discord, as well as some more tame malware. I can say that discord is really bad in the security area, but it’s not much to worry about as there are few people who know how to do the attacks and how they work. Edit: I’ve started watching the video, and I’ve seen almost this exact same script before while moderating a server
@Odsku
@Odsku 3 жыл бұрын
More advanced scripts add malicious js to discord core modules it allows the malware to keep persistence while having a low detection rate
@DM-qm5sc
@DM-qm5sc 3 жыл бұрын
That's ok, only a few people know how these attacks work
@Odsku
@Odsku 3 жыл бұрын
@@DM-qm5sc only the RCE are private but the scripts are well public
@tlocto
@tlocto 2 жыл бұрын
oh hey jim fancy seeing you here
@JimTheScientist
@JimTheScientist 2 жыл бұрын
@@tlocto hello
@superpowerforhire
@superpowerforhire 3 жыл бұрын
This is much better, John. You’ve dissect each components and explained thoroughly. Rather than rushing always.
@charismaticmedia8585
@charismaticmedia8585 3 жыл бұрын
Love your videos sir .Hope you have a great day.
@sentinalprime8838
@sentinalprime8838 3 жыл бұрын
amazing content john
@syrefaen
@syrefaen 3 жыл бұрын
Oh its a fun series keep it up!
@vittthevecc1390
@vittthevecc1390 3 жыл бұрын
This seems very intresting. Can't wait to see it
@cassandradawn780
@cassandradawn780 3 жыл бұрын
by the end of the premiere you're gonna have 200k.
@JimTheScientist
@JimTheScientist 3 жыл бұрын
true
@abdiwahabahmedomar2399
@abdiwahabahmedomar2399 3 жыл бұрын
i dont think but i hope
@slonkazoid
@slonkazoid 3 жыл бұрын
199K NOOOOOOOOO
@yourfellowhumanbeing2323
@yourfellowhumanbeing2323 3 жыл бұрын
@@slonkazoid Just miss :(
@cassandradawn780
@cassandradawn780 3 жыл бұрын
@Jocelyn M's Alice are you ok?
@tocraft573
@tocraft573 3 жыл бұрын
Props to this guy managing to get a discord nuker/token logger to 1 hour
@aty4282
@aty4282 3 жыл бұрын
@@recommendastra_hack_zoneon709 hope it gets banned again, tiktok does not deserve users
@IkeVoodoo
@IkeVoodoo 3 жыл бұрын
@@aty4282 Its a bot, he is so shit and one of the worst people ngl (the person running the bot)
@aty4282
@aty4282 3 жыл бұрын
@@IkeVoodoo goddamn, cant believe that i fell for the classic ones
@DZ-lm4le
@DZ-lm4le 3 жыл бұрын
you have a new sub keep it up.
@TehIdiotOne
@TehIdiotOne 2 жыл бұрын
By no means the most advanced malware i've seen, like it does rely on a lot of user error to work, but still nice breakdown
@Car777777777
@Car777777777 3 жыл бұрын
yes i am interested in more discord stuff and yes it is bad, but it's good to see and know what is actually out there
@marckerkvliet2999
@marckerkvliet2999 3 жыл бұрын
Great video!
@aalekhmotani3877
@aalekhmotani3877 Жыл бұрын
you are genius, you are exceptional tutor, thank you, thank you so much, i got a project idea from this vid.
@dommbrown
@dommbrown 2 жыл бұрын
Love ya work chap! Sub'd
@dtvdavid
@dtvdavid Жыл бұрын
Instant pressed like, as I saw the Triforce. :)
@dedkeny
@dedkeny 3 жыл бұрын
I thought it was clickbait, but DAMN!! legit content
@DoorThief
@DoorThief 3 жыл бұрын
I definitely want to see your deobfuscuate that js code :D
@Haroon_abbasi
@Haroon_abbasi 3 жыл бұрын
happy 200k
@picardftw1313
@picardftw1313 3 жыл бұрын
yikes. .. follow up on what more you learn about this for sure lol. dropped a like. already subbed.
@narayanyadav8591
@narayanyadav8591 3 жыл бұрын
thank you posting a topic of choice.
@acticfl
@acticfl 3 жыл бұрын
I was thinking if i should like this video - then you pointed out your TLOZ shirt. You win
@Vicente75480
@Vicente75480 3 жыл бұрын
John! Do the thing!
@WeirdDuck781
@WeirdDuck781 2 жыл бұрын
If you open the webhook URL you can identify the name of the webhook, the Guild ID and Channel ID. That information is kinda basic but might help when reporting to Discord
@NevRS32
@NevRS32 2 жыл бұрын
51:50 Hammond enters the freaking Matrix... xD You know a content creator is entertaining when you don't understand shit, and still watches until the end, entertained!
@LokiCDK
@LokiCDK Жыл бұрын
Oh wow! I'm impressed. Only importing that actually used functions, not the whole libraries.
@Beateau
@Beateau 3 жыл бұрын
Hair was on point.
@funil6871
@funil6871 Жыл бұрын
thank you
@lucasedkins2095
@lucasedkins2095 2 жыл бұрын
I liked at the Zelda shirt. Thanks!
@HomelessDeamon
@HomelessDeamon 3 жыл бұрын
Yooo Hammond cool haircut 👌
@falcongamingdev8810
@falcongamingdev8810 3 жыл бұрын
that sever crasher is probably allowing the person to join servers and spam the server with that users token
@Jack-zr4kc
@Jack-zr4kc 3 жыл бұрын
For the Browsers It takes The Tokens From Them, Because Some People Log into to them. Like you said :)
@hk5716
@hk5716 3 жыл бұрын
it could be the location for discord tokens in those browser since discord uses electron which uses chromium which chrome and a lot of other browsers also use, so it might be that cookies are stored there.
@KnightOfEvil
@KnightOfEvil 3 жыл бұрын
The path has leveldb which is a nosql db where chromium stores it's cookies and local storage
@Deralica
@Deralica 3 жыл бұрын
54:55 I was kind of expecting a "it's bad mmmkay?"
@JonSnyderfudge
@JonSnyderfudge 3 жыл бұрын
Looked like that first sketchy website at 33:50 was a peertube instance. It was probably a community dedicated for malware videos.
@bryanvuyk
@bryanvuyk 3 жыл бұрын
Seriously the best content creator out there. Love the videos. Keep them coming.
@EddiePenta
@EddiePenta 3 жыл бұрын
I believe it is grabbing also grabbing Chrome, Opera and Brave tokens. The file structure generated by get_tokens seem to also work for those other directories listed
@funguslars
@funguslars 3 жыл бұрын
I love how the token stealer disguises as a token stealer 🤣
@mehmetedex
@mehmetedex 3 жыл бұрын
I am entertained way more than watching LiveOverflow
@buleini
@buleini 3 жыл бұрын
I don't mind you ending this one on sort of a cliffhanger. I thought to myself, I have Discord but I don't have a Python installation. I remembered I specifically installed Perl (yeah not Python) for Blender, and then I searched for Python on my machine. Python comes with a lot of programs ( I have ones for Blender, GIMP 2, Inkscape, LibreOffice, Visual Studio Community Edition ..... and in Windows Apps?? What The ?) This developer dad does not install a default extension handler without blinking at least once, but it seems the Python script is not as harmless if you accepted to automatically open .py files??
@greenworld99441
@greenworld99441 3 жыл бұрын
WOw! This is so new to me !
@juvival1758
@juvival1758 3 жыл бұрын
Please go through the obfuscated Java-Script in another Video. Keep it up man❤
@ryd3v
@ryd3v 3 жыл бұрын
Love it 🤟🙂
@diarm.hunter6822
@diarm.hunter6822 2 жыл бұрын
"NSFW_allowed: "yes" " 25:57 Nice, John
@KriTixXPlayer1
@KriTixXPlayer1 Жыл бұрын
Hey! Can u make a list of all the malware you have explored so far, making we all can send unique malware programs
@buleini
@buleini 3 жыл бұрын
Ok, seeing this premiere I think I can do two unfair bets right now. 1. Bet I'm subscribing here. 2. There's something malicious on my son's PC.
@IkeVoodoo
@IkeVoodoo 3 жыл бұрын
Depends if he downloaded it...
@TheHyperplayer
@TheHyperplayer 3 жыл бұрын
I would advise you to use solid colored bars instead of pixelation since there is currently a promising tool in development that can reverse pixelation to some extend.
@eericjacobson
@eericjacobson 2 жыл бұрын
hollywood isnt real bro
@LucifSD02
@LucifSD02 Жыл бұрын
Reversing pixelation requires context and information, now I haven't actually seen the pixelated part in this video but unless the pixelated content is unambiguously readable as any character, an algorithm won't know either, I bet you'd be able to get an approximation of what it could look like but that may just be as unreadable as it already is, but less pixelated
@lonelyanthem
@lonelyanthem Жыл бұрын
@@eericjacobson neural networks exist, and they've been in use for years.
@thengakola6217
@thengakola6217 3 жыл бұрын
onto 200k.... yyyayayayyyayayya
@Zahid8080
@Zahid8080 Жыл бұрын
wow Ed Sheeran into malware xD Love from India vro
@the2dstuart
@the2dstuart 3 жыл бұрын
been wondering about discords security for a while now... this should be good
@Odsku
@Odsku 3 жыл бұрын
Discord is not focused on security if u want maximium security while using discord u should use an very lite version of discord such as discord-cli its not the best nor does it support voice calls but it is very secure as it does stores the token in memory and rce exploits should be near impossible
@hypedz1495
@hypedz1495 2 жыл бұрын
ah yes.. john.. john hammond does it again.
@dieSpinnt
@dieSpinnt 3 жыл бұрын
Sometimes you make me really nervous, John. No, not the tokens, the clumsiness in the shell:P echo %LOCALAPPDATA% ... or cd %APPDATA% jFYI But never mind, thanks for the video :)
@Jade_3375
@Jade_3375 3 жыл бұрын
As someone who works with the discord api it's scary how easy it is to get information with a token
@roottokyo
@roottokyo 3 жыл бұрын
It’s also scary to notice how soo much information including cached payment information is in the OVERLAY_INITIALIZE payload.
@Cl4r1ty_
@Cl4r1ty_ 3 жыл бұрын
Let’s get 200k!
@kobiassvilli
@kobiassvilli 3 жыл бұрын
I think the references to Chrome Opera etc is not the malware looking for passwords within these programs as I'm sure Chrome stores you saved passwords encrypted, but it is probably looking for the Discord tokens saved in Chrome for auto login / cookies
He tried to hack me...
34:15
John Hammond
Рет қаралды 372 М.
MINHA IRMÃ MALVADA CONTRA O GADGET DE TREM DE DOMINÓ 😡 #ferramenta
00:40
Help Herobrine Escape From Spike
00:28
Garri Creative
Рет қаралды 55 МЛН
ISSEI funny story 😂😂😂Strange World 🌏 Green
00:27
ISSEI / いっせい
Рет қаралды 84 МЛН
This Discord Server Controls my PC (with Malware)!
8:07
No Text To Speech
Рет қаралды 956 М.
HAFNIUM - Post-Exploitation Analysis from Microsoft Exchange
1:18:33
John Hammond
Рет қаралды 137 М.
TARGETED Phishing - Fake Outlook Password Harvester
47:09
John Hammond
Рет қаралды 256 М.
Rick & Morty MALWARE!? - sLoad - PowerShell & VBScript
30:31
John Hammond
Рет қаралды 59 М.
I Tried a Disney Secret Project!
11:33
Marques Brownlee
Рет қаралды 4,3 МЛН
HackTheBox - "Remote" - Umbraco & Windows
48:23
John Hammond
Рет қаралды 81 М.
I Bought a Recording Jammer. It’s Legal.
14:00
Linus Tech Tips
Рет қаралды 1 МЛН
Finding WEIRD Devices on the Public Internet
27:48
John Hammond
Рет қаралды 120 М.
Information Stealer - Malware Analysis (PowerShell to .NET)
47:56
John Hammond
Рет қаралды 51 М.
MINHA IRMÃ MALVADA CONTRA O GADGET DE TREM DE DOMINÓ 😡 #ferramenta
00:40