Is THIS a VIRUS? Finding a Remcos RAT - Malware Analysis

  Рет қаралды 364,210

John Hammond

John Hammond

Күн бұрын

Пікірлер: 898
@_JohnHammond
@_JohnHammond 20 күн бұрын
goodness gracious here's the kicker you can learn more cybersecurity at jh.live/training and check out jh.live/newsletter :)
@Evan-d2g
@Evan-d2g Күн бұрын
here's the thing so I kind of "accidentally" downloaded it so I could just try and learn some coding and one of my protection services saw it had ransomware.agent right now it's contained but I don't know how to get rid of it completely. It's like a file that downloads over after deleting it
@johnjohnerd6921
@johnjohnerd6921 3 жыл бұрын
"This is just 75 lines of code" *Half hour later* "201 thousand characters selected"
@AlucardNoir
@AlucardNoir 3 жыл бұрын
that's how they get you man, that's how they get you.
@geist453
@geist453 3 жыл бұрын
@@AlucardNoir AND YOU BUT GUESS WHO NOT?! ME AND JOHN
@GuyMassicotte
@GuyMassicotte 3 жыл бұрын
Majorly loaded by a fake jpg ;)
@bansku570
@bansku570 3 жыл бұрын
@@geist453 l
@nojusnojus8015
@nojusnojus8015 3 жыл бұрын
@@bansku570 I
@DenyardTV
@DenyardTV 3 жыл бұрын
Ngl, never thought it would be so much fun watching someone analyse and breakdown a virus.
@KrakenPipe
@KrakenPipe 3 жыл бұрын
I was thinking the same thing! I might have just discovered my new rabbit hole lol
@0xRalu
@0xRalu 3 жыл бұрын
Love this malware analysis series!
@ismhdez
@ismhdez 3 жыл бұрын
Me too! Amazing series
@syverlunde9622
@syverlunde9622 3 жыл бұрын
I love it too!
@jbgaud
@jbgaud 3 жыл бұрын
me too, this guy is really good.
@s.broyal5128
@s.broyal5128 2 жыл бұрын
Sir. Can I use remcos rat to hack Android...
@baremetalHW
@baremetalHW 3 жыл бұрын
Damn that was fun to watch!! Thanks and keep them coming!!!!!!
@NickyPuff
@NickyPuff 3 жыл бұрын
I love when John is laughing over the Attack.jpg url
@livroz454
@livroz454 3 жыл бұрын
best part
@Corb4nm0noxide
@Corb4nm0noxide 3 жыл бұрын
So far this is the most fun I've had watching hacking videos. Your analysis is fantastic and I enjoy seeing your process. Keep it up!
@richie7425
@richie7425 3 жыл бұрын
Times must be hard, Ed Sheeran is writing python.
@batmanasdasd
@batmanasdasd 3 жыл бұрын
Lmaooo💀💀
@HiramSalinas
@HiramSalinas 3 жыл бұрын
he looks like an unscuffed burgerplanet
@realitynowassigned
@realitynowassigned 3 жыл бұрын
This is ed sheerhan and Seth rogans kid.
@HaxorBird
@HaxorBird 3 жыл бұрын
You are the hacker version of pewdiepie. Very entertaining to watch.
@lusthetics
@lusthetics 3 жыл бұрын
Nah he looks like a de deobfuscated Ed Sheeran
@bennettpalmer1741
@bennettpalmer1741 3 жыл бұрын
I love how they went through six stages of obsfuscation, and a lot of effort into hiding what they were doing.... but their payload was literally called "Attack.jpg" like surely they could have named it something at least slightly less blatant.
@FilliamPL
@FilliamPL 3 жыл бұрын
Perhaps they didn't care to hide it at that point? I know that obfuscation helps to counter analysts, but when the code is downloading data from a URL, then I suppose it wouldn't've been worth their effort to obscure the name of the download. Then again, they could've made a second download with totally unnecessary data. Either way - this thing is bad (for you)! xD
@ycoihmn6388
@ycoihmn6388 3 жыл бұрын
This style of video really helps me with my start in forensics and malware analysis. I love liveoverflow and other CTF summary channels but they often feel like magic in the way they present their findings. Keep up the great work :3
@andmo90
@andmo90 3 жыл бұрын
Content like this is why I don't have to pay for cable, satellite, or netflix!
@garethevans9789
@garethevans9789 3 жыл бұрын
But then he would have been on 8-12 screens and typed those 200k characters (hacking is typing fast), it's all hard to follow. It would be like watching the Matrix.
@viv_2489
@viv_2489 3 жыл бұрын
Yeah
@SiveenO
@SiveenO Жыл бұрын
Okay, but consider this: TOS and TNG are on Netflix.
@Dilipkumar-ur9zx
@Dilipkumar-ur9zx 3 жыл бұрын
After watching this, gained a keen interest in Malware Analysis. Thanks for the awesome content.
@slygamer01
@slygamer01 3 жыл бұрын
The REMCOS developer "discourages malicious use". For sure, everyone will use solely for legitimate purposes.
@aliencatmeow
@aliencatmeow 3 жыл бұрын
'sure if you say so' meanwhile no one uses it legitimately
@karimmohamed3744
@karimmohamed3744 3 жыл бұрын
Malicious actors: amma head out
@garethevans9789
@garethevans9789 3 жыл бұрын
Ethical hackers don't sell hacking toolkits, ethics and all that... 🤷‍♂️
@technoturnovers7072
@technoturnovers7072 3 жыл бұрын
@@garethevans9789 Pentesting tools are released open source because not only is open source more effective, but it makes sure that the developers are not potentially profiting off of malicious actors, intentionally or not.
@cyber1377
@cyber1377 3 жыл бұрын
Meh, skids are gonna find a way anyway. With our without this program.
@TracyNorrell
@TracyNorrell 3 жыл бұрын
Scheduling this to start at the same time as the new mars rover is landing... Bold move cotton, let's see how it works out
@_JohnHammond
@_JohnHammond 3 жыл бұрын
Bah, totally didn't even realize xD Ah well!
@originalgaming9062
@originalgaming9062 3 жыл бұрын
@@_JohnHammond I’d prefer watching this over some rover landing
@originalgaming9062
@originalgaming9062 3 жыл бұрын
@Richard Vaughn isn’t the rover automatically controlled because the delay would be 10 minutes long?
@willo7734
@willo7734 3 жыл бұрын
Whatever that quality is that great teachers have, you have it. Never change the format of your videos. I love seeing you troubleshoot and reason through everything live.
@darkdagger032
@darkdagger032 3 жыл бұрын
This is one of the best educational videos i've seen
@md123180
@md123180 3 жыл бұрын
Where have you been all my CS degree? This is awesome watching this stuff in action as you do it. I love the content! Definitely going to keep watching!
@TheSeakr
@TheSeakr 3 жыл бұрын
I'm just finding this channel and its quickly becoming my favorite content. Im fascinated with all of this. Really inspires me to get started with basic coding to get my feet wet.
@m1rz
@m1rz 3 жыл бұрын
Pretty sure you need to run the obfuscated version of the AMSI bypass. Great video, would love to see more of these!
@vannialora3476
@vannialora3476 3 жыл бұрын
the evolving of rat is so amazing, i remember in late 90's where sub7, netbus and back orifice was so popular and inspired me into hacking. IRC was the channel to go to before and dial up is your connection.
@randallsalyer
@randallsalyer 3 жыл бұрын
I love John’s response when the light bulb goes off and all the hard work comes together. Great video as always.
@Edzward
@Edzward 3 жыл бұрын
You need I high level of nerdiness to find this entertaining. Proof: I find highly entertaining! Love this.
@definesigint2823
@definesigint2823 3 жыл бұрын
I've taken apart stuff like this (when I worked in large enterprise) but the samples were rarely more than 3-4 levels deep. This actually looks a lot more like a challenge you'd get at a CTF competition _(perhaps they're getting ideas from each other)_ ?
@eliasgamezgarcia3414
@eliasgamezgarcia3414 3 жыл бұрын
Dude you are simply awesome...it's so enriching for all of your viewers to see your hard work and all your skills, and the best of all is that we can see you enjoying so we enjoy and learn too. Regards from Spain!
@PerfectEn3my
@PerfectEn3my 3 жыл бұрын
Great video, I love this series. Also special thanks for zooming in this much, watching code-related stuff on phone is usually a pain, but not in your case. Keep up the good work!
@britishpiperygo
@britishpiperygo 3 жыл бұрын
Loving this series. Would like to see some disassembling malware analysis.
@dustinjohnson7635
@dustinjohnson7635 3 жыл бұрын
Amazing work, you deserve the money from the KZbin overlords. Literally only commented to help boost those algos.
@donaldduck6198
@donaldduck6198 3 жыл бұрын
John, as you are very good, you should stand this comment: In Powershell a "split (..)" is a regular expression splitten in string in portione of two characters, ie "4142" becomes "41", "42", in Hex AB
@mbowler05
@mbowler05 3 жыл бұрын
Hands down one of the best malware analysis walkthroughs I’ve seen. Watched it twice.
@mechanicalfluff
@mechanicalfluff 3 жыл бұрын
i missed the premiere, but this is definitely a blast to watch. Would love to see this more
@kitrodriguez992
@kitrodriguez992 3 жыл бұрын
I was watching some scam baiting videos and also doing some deep dives into RATs and just... CyberSec/CompSci things in general and found this video. I'm glad I bumped into your channel. Really good stuff you have going on here
@rccservice
@rccservice 3 жыл бұрын
that url has to be the greatest thing ive ever seen
@thedemonlord9232
@thedemonlord9232 3 жыл бұрын
you got my sub for this. its 3am in the morning and I've watched the entire thing having so much fun. keep on with the good stuff
@ThomasGabrielsen
@ThomasGabrielsen 3 жыл бұрын
What a great catch! This is by far the most interesting video I've watched on KZbin for a very long time. I love this of unedited video.
@Krampfey
@Krampfey 3 жыл бұрын
Damn, I just watched over an hour of stuff I have no clue of and I still feel educated and entertained. It even kinda makes sense, when you talk about it and explain some stuff. Thank you very much! :)
@MikeKirkpatrick
@MikeKirkpatrick 3 жыл бұрын
Well worth the watch. This is a great video. Please do more. :)
@georgehammond867
@georgehammond867 3 жыл бұрын
how do you copy and paste into VirtualBox in Windows 10
@agentsmith9753
@agentsmith9753 5 ай бұрын
That was epic dude! Felt like a real rollercoaster. I can't believe you got to them within 24 hours of release. So nuts.
@auto117666
@auto117666 3 жыл бұрын
In the next episode... John rewrites the kernel for more efficient find and replace..... STONKS!
@DarkFaken
@DarkFaken 2 жыл бұрын
I love these malware analysis videos. You break stuff down to a fairly easy to understand level for most technical people. I'm just getting into cyber security and I'm really enjoying your content, thank you.
@Flobert97
@Flobert97 3 жыл бұрын
Did i just watch AN HOUR of malware analysis? Dude, you're awesome!
@patchbyte6856
@patchbyte6856 3 жыл бұрын
this is gonna be good
@AnthonyBlakley
@AnthonyBlakley 3 жыл бұрын
Indeed Indeed :D
@snuffy6449
@snuffy6449 3 жыл бұрын
I binge your videos every day all day at work. Gets me through the day and I learn some new/cool stuff.
@rubenolguin2180
@rubenolguin2180 2 жыл бұрын
Wow, that was a crazy ride! Thanks for taking us on the journey.
@JM-tf3rg
@JM-tf3rg Жыл бұрын
This was so fun to watch. The sketchy url was very funny, fitting pun on with the ‘holy cow’
@jeehill9592
@jeehill9592 3 жыл бұрын
As a prospective sw engineer, at ~54:00 that obfuscated spaghetti mess made me never want to be a malware analyst 🤣😂🤣 glad to have people with your mettle in this world
@whatnowsami9225
@whatnowsami9225 3 жыл бұрын
Nobody: Virus Code: * Does malicious stuff* John: Is it trying to do something bad? HAHAHA Us: Duhhh John. wtf
@hexnull4343
@hexnull4343 3 жыл бұрын
Man i'm brazillian, and i love all of this videos, but this... mannn to amazing !! Continue delivery this content to us, i apreciate this
@JackAllpikeMusic
@JackAllpikeMusic 3 жыл бұрын
This was fabulous! I hope to see more!
@sheldongroom18
@sheldongroom18 3 жыл бұрын
Please more Malware Analysis videos. So much fun to watch.
@uniquechannelnames
@uniquechannelnames 3 жыл бұрын
Algorithm, give this man the recs.
@TexasTimelapse
@TexasTimelapse 3 жыл бұрын
It worked. That's why I'm here.
@SuperBryantheman
@SuperBryantheman 3 жыл бұрын
Dope analysis! The streets need this type of content. Keep it coming.
@nilanjana25
@nilanjana25 2 жыл бұрын
Totally enjoyed the video. It was an absolute rollercoaster ride. I love the way you present and explain the details in all your videos. And also none of your videos ever seem to be monotonous even when we are dealing with such mind boggling stuff because of the way you laugh and get excited when you crack/deobfuscate a piece of code. 😁 Thank you so much for taking the effort and sharing the awesome work😊
@sannyboi7298
@sannyboi7298 3 жыл бұрын
Brilliant. You make malware reversing so fun to watch.
@deantammam
@deantammam 3 жыл бұрын
You know so much about so many things... I've learned so many things in the few videos I've watched so far. Super, super inspiring.
@DallasGraves
@DallasGraves 3 жыл бұрын
From beginner hand-holding on picoCTF to obfuscating obfuscated obfuscation LOL. This channel has it all, thanks for the great content!
@facekickr
@facekickr 3 жыл бұрын
That was a great video. I don't know a whole lot about what you do, but it was super fun watching you do it. Thanks so much!
@GeekBeerRS
@GeekBeerRS 3 жыл бұрын
Man I love these videos. As a junior network tech I love watching this, so interesting and entertaining!
@christianf21
@christianf21 3 жыл бұрын
This is crazy. I've learned more about malwares in a few vids I saw from you, than the time I spent trying to get into the field years ago. I'm a fulltime dev now and have been working for over 7 years. Reminds me of my recent grad days where all I wanted was to understand this. Much easier to follow now, and damn, learning so much so quick now. Props to you.
@Cinual
@Cinual 3 жыл бұрын
You make easy to understand videos as you break things down. i really enjoy them. I have a vague understanding of coding and the way you work is easy to follow.
@svilenSt.
@svilenSt. 3 жыл бұрын
Nice. I really impressed at final "detective" processing :) Keep it that way
@somnitek
@somnitek 3 жыл бұрын
Dude... That was solid. Loved it. Kinda dragged in the middle but I was invested enough I just jumped ahead maybe ten minutes before I was stuck back in. Nice nice so nice I had to say it twice, then one more time too.
@h4wk_n377
@h4wk_n377 3 жыл бұрын
Keep on doing those Malware Analysis. It's really fun to watch and it's quite educative too!
@Seluj78
@Seluj78 3 жыл бұрын
Really interesting video, thanks !! I'm impressed at the obfuscation job done on this malware it's impressive
@syverlunde9622
@syverlunde9622 3 жыл бұрын
Pls keep up the malware analysis videos! Its so fun to watch!
@uimstar5254
@uimstar5254 3 жыл бұрын
Wow, that was awesome video. It is so nice to see you go through all the steps and thinking while deobfuscing. This RAT is kind of really scary for everything it can do. I would like to see more of this in the future! Keep up the good work
@danielbaker3063
@danielbaker3063 3 жыл бұрын
Always learn something new watching your content!
@musingmuse9064
@musingmuse9064 3 жыл бұрын
Watched the whole thing from start to finish - loved it! Make more!
@notrace_0
@notrace_0 3 жыл бұрын
I never write a comment under a video but I saw every single second and I really really loved it. Thanks for your video and keep doing it sharing your passion with us!
@rave4ever2020
@rave4ever2020 3 жыл бұрын
Awesome work buddy !!! watching your videos while at work coding my self ... thanks for the vids
@helenageorge9223
@helenageorge9223 3 жыл бұрын
Just for the KZbin algorithm to know, I love malware analysis series! keep them coming!!!!!!
@crazymonkeyVII
@crazymonkeyVII 3 жыл бұрын
Absolutely brilliant! I've discovered your channel yesterday and I can't stop watching. This stuff makes me want to give it a shot as well. Never knew that deconstructing programs/scripts (especially ones with malicious intent) could be this much fun! Subbed+bell.
@mattgwalker
@mattgwalker 3 жыл бұрын
John - This is great content. I really am learning a lot watching you work these out. Keep it up! The masses demand more of this!
@bradlad1574
@bradlad1574 3 жыл бұрын
That's a rabbit hole if I've ever seen one haha great stuff man!
@definesigint2823
@definesigint2823 3 жыл бұрын
If only it (the rabbit holes) were rare. 😥
@ulbed
@ulbed 3 жыл бұрын
Follow the white rabbit!
@kipchickensout
@kipchickensout 3 жыл бұрын
You can also Ctrl+Scroll Wheel to zoom into notepad Edit: I watched the whole thing and I really had fun, really interesting and high quality Your circlular camera mask and your energy break reminded me of networkchuck and his coffee break xD You got a new subscriber :)
@imranthoufeeque
@imranthoufeeque 3 жыл бұрын
I love your videos which are not preplanned... It gives us an option for us to know how you actually resolves when you are stuck....
@xyphelon
@xyphelon 3 жыл бұрын
Just watched this now, been on my watch list for a while. Great Video.
@Ayayron_e3
@Ayayron_e3 3 жыл бұрын
"guys, you might think i'm dumb" LOL exact opposite.
@mclovin748
@mclovin748 3 жыл бұрын
59:06 love how scrolls past when looking at string in the executable "Offline Keylogger Started" "Online Keylogger Started" "Online Keylogger Stopped" "Offline Keylogger Stopped" Yes John sees the key strokes and is like, "is this doing keylogging?"
@brentbice1151
@brentbice1151 3 жыл бұрын
I love that you used strings and am glad I'm not the only one who does. :-) It's a highly under-rated tool, IMHO.
@ghostindamachine
@ghostindamachine 3 жыл бұрын
Totally epic stuff!. I am not even into coding and or info sec. Just stumbled upon this video and couldn't stop watching!
@zamant88
@zamant88 3 жыл бұрын
This was actually fun to watch and go on this journey with you! Loving these videos
@King-Julien
@King-Julien Жыл бұрын
I knew exactly what it was a few minutes of you scrolling few the strings!!! I feel proud! And thank you for making this video, I learned a lot.
@forthewubwubs
@forthewubwubs 3 жыл бұрын
I'm learning to program in college rn and I just ran across your channel and my God man the length people go to, to scoot around anti-virus software and download shit on your computer is insane. Although seeing how all these functions are working together is awesome! Keep up the good work!!!👍
@peter486
@peter486 3 жыл бұрын
insane Upload John. Stage Six video :) . So much fun to watch.
@Mosern1977
@Mosern1977 3 жыл бұрын
Been programming for a long time, but never really looked much into viruses and malware. Cool analysis. The authors sure work hard to make their installation as painless as possible.
@squeelyinc
@squeelyinc 3 жыл бұрын
Yes keep these coming, really enjoyed that video!!
@rogan85
@rogan85 3 жыл бұрын
This series of decoding Malware is the best knowledge base for getting a feel for noobs like me. Please keep it coming. Thank you.
@vincepod
@vincepod 3 жыл бұрын
Enjoying the malware analysis videos. Very informative.
@sgtfatboy1
@sgtfatboy1 3 жыл бұрын
Your knowledge is very impressive! Love learning from guys like you!
@johnhelt5475
@johnhelt5475 3 жыл бұрын
John, great interview in the Infosec OSINT podcast!
@tomsite2901uk
@tomsite2901uk 2 жыл бұрын
John, I love your videos, but this video was on another level. Truly enjoyed it.
@Rick-mi4yt
@Rick-mi4yt 9 ай бұрын
This is the first video and I rung the bell! Impressive. I will follow you. Thank you.
@josephvictory9536
@josephvictory9536 3 жыл бұрын
WElp this is what got me to subscribe, love this stuff, its pretty wild seeing the layers of obfuscation. NOW TO SPEEDRUN IT
@4akat
@4akat 3 жыл бұрын
that was wild. these new malware videos are great. thanks John!
@symbiotyk9942
@symbiotyk9942 3 жыл бұрын
I really enjoy lookin into this with your hand, and your happy face
@tydewalt1018
@tydewalt1018 3 жыл бұрын
That was so entertaining. Keep the videos coming, John. :)
@arashi7693
@arashi7693 3 жыл бұрын
This was extremely enjoyable! Keep it up!
@orbyfied
@orbyfied 3 жыл бұрын
these videos are underrated hidden gems. i swear why didnt i get them in my reccomended earlier.
@TechSy8
@TechSy8 3 жыл бұрын
Did anyone told that to you, you're an genius buddy.... i even can't get off my eyes on this series.... amazing
@seawrightphotography
@seawrightphotography 3 жыл бұрын
Only 10 min in and having a blast! Awesome video. I was gonna suggest you try CyberChef for decoding stuff, but then you ended up using it. “Just use Vim.. just use Arch.. maybe rewrite the kernel while you’re at it!” - priceless.
FAKE Antivirus? Malware Analysis of Decoy 'kaspersky.exe'
1:28:19
John Hammond
Рет қаралды 277 М.
Mozi Malware - Finding Breadcrumbs...
50:16
John Hammond
Рет қаралды 201 М.
Хаги Ваги говорит разными голосами
0:22
Фани Хани
Рет қаралды 2,2 МЛН
-5+3은 뭔가요? 📚 #shorts
0:19
5 분 Tricks
Рет қаралды 13 МЛН
Snip3 Crypter/RAT Loader - DcRat MALWARE ANALYSIS
1:42:04
John Hammond
Рет қаралды 508 М.
HAFNIUM - Post-Exploitation Analysis from Microsoft Exchange
1:18:33
John Hammond
Рет қаралды 139 М.
Hacking Sony's Terrible DRM
15:20
Nathan Baggs
Рет қаралды 96 М.
MALWARE ANALYSIS - VBScript Decoding & Deobfuscating
42:23
John Hammond
Рет қаралды 1 МЛН
How Open Source Discord "Raiding" tools hide Malware
11:08
Eric Parker
Рет қаралды 231 М.
Free Coding Tool Distributes Malware
42:12
John Hammond
Рет қаралды 137 М.
HTA JScript to PowerShell - Novter Malware Analysis
1:24:19
John Hammond
Рет қаралды 97 М.
Password Cracker with Notepad!
11:41
ebola man
Рет қаралды 812 М.
Discord Malware - "i hacked MYSELF??"
58:21
John Hammond
Рет қаралды 196 М.
Хаги Ваги говорит разными голосами
0:22
Фани Хани
Рет қаралды 2,2 МЛН