VBScript & ILSpy Analysis of a RAT

  Рет қаралды 53,242

John Hammond

John Hammond

Күн бұрын

Пікірлер: 168
@originalgaming9062
@originalgaming9062 3 жыл бұрын
No body’s seen the video yet, but 13 people have already liked it. I think this goes to show that people (including myself) LOVE these malware analysis videos
@originalgaming9062
@originalgaming9062 3 жыл бұрын
@@Marko-wi1lb I just feel bad for the one poor fellow who missed the like button
@herotrojan1645
@herotrojan1645 3 жыл бұрын
can you tell me the best malware analysis course to begin with
@herotrojan1645
@herotrojan1645 3 жыл бұрын
can you tell me the best malware analysis course to begin with
@flawlesscode6471
@flawlesscode6471 3 жыл бұрын
Alternative Name: John from the future getting annoyed by his past self doing stupid stuff
@Nuclear__HS
@Nuclear__HS 3 жыл бұрын
John, I LOVE all these cuts "from the future", they're hilarious xD
@ca7986
@ca7986 3 жыл бұрын
💯
@donovanelliott9060
@donovanelliott9060 2 жыл бұрын
I really wanna like this comment but I can't because it has 69 likes
@AnoNymous-ie3wc
@AnoNymous-ie3wc 3 жыл бұрын
For you this video might me "amateurish" but for me it's 1. entertaining 2. i can learn from your mistakes 3. it helps me even more to understand what you do 👍 from me
@uumas
@uumas 3 жыл бұрын
ok the 3min 50s self flame is freaking awesome. absolutely love the humor ! Keep it going man. Just the second video i watch from you but can already tell i'll probably watch some more for the personality alone
@philipstringer4425
@philipstringer4425 3 жыл бұрын
john gotta admit I don't mind seeing the mess ups, its very organic and wholesome I appreciates it
@AnoNymous-ie3wc
@AnoNymous-ie3wc 3 жыл бұрын
Same here.
@AkAk-jv7ig
@AkAk-jv7ig 3 жыл бұрын
This is rad learning with jokes lol! You're awesome John please keep em coming!
@QuibbleTrouble
@QuibbleTrouble 3 жыл бұрын
I think the revenge rat used here is a fixed version that's open-source on github by a person named NYAN-x-CAT which showed up in the config.
@AhmedFromKSA
@AhmedFromKSA 3 жыл бұрын
The banner at 38:47 says "encrypt(ing?) all servers the rat clean" so you were probably in the right place
@gowthamujjineni8422
@gowthamujjineni8422 3 жыл бұрын
These type of vedios are wonderful to see. I love these type of vedios with comedy sprinkles in between
@yasincomps2056
@yasincomps2056 Жыл бұрын
i thoght you wouldn't have noticed but you have a great sense of humor
@TheDuerden
@TheDuerden 3 жыл бұрын
I have watched a lot of your videos lately - and I am subbed - but this is my favourite so far...hilarious :)
@mustafamotiwala2335
@mustafamotiwala2335 3 жыл бұрын
mr john yet another malware analysis?! it is indeed an auspicious week for us all. seriously these make my day so much better, thank you for doing what you do!
@bryanleong2846
@bryanleong2846 3 жыл бұрын
keep it up John, really like all your malware analysis videos
@duncan3144
@duncan3144 Жыл бұрын
Another great video even if i am late to watch it. I enjoy decoding viruses etc and writing fixes. I am currently re writing my happy99 virus fix. I coded it back in 90's. Needs an upgrade.
@y6nv
@y6nv Жыл бұрын
“hey what’s up” I love how this feels like I’m just talking to a normal being, not just some KZbinr
@ripcityraider9469
@ripcityraider9469 3 жыл бұрын
Dude you are so awesome!!! I can't stop watching your videos. Keep up the great work!
@batteryman2852
@batteryman2852 3 жыл бұрын
Ah yes , i like to call my Object variables by the names , vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvnnnnnnnnnnnnnnnn , and my String primitives, qaaaaaaaaaaaaaaaaazzzz..
@abeecee
@abeecee 3 жыл бұрын
*verbose*
@dr.humorous447
@dr.humorous447 3 жыл бұрын
You are a very underrated youtuber you deserve better to be honest. Im new to your channel and I love your content that I subed for more I have no experience in hacking but I know a lot about computer both software hardware and some networking. Keep up the good work 👏 👍
@tuckerward9844
@tuckerward9844 3 жыл бұрын
'John from the future' bit got me, thank you John
@thecaretaker0007
@thecaretaker0007 3 жыл бұрын
I had to watch the whole video when I saw 5:45 Also Hackthebox T-Shirt
@hoodieman04
@hoodieman04 3 жыл бұрын
Dont worry if IPs and ports dont match up to reporting, its very common to have actors jump to new IPs or be booted by the VPS provider
@bhagyalakshmi1053
@bhagyalakshmi1053 Жыл бұрын
Thank you brother amarphal always love dance santa
@imTyp0_
@imTyp0_ 2 жыл бұрын
Love these kinds of videos :)
@dancingtiger577
@dancingtiger577 3 жыл бұрын
these vids are so fun and educational
@arronk3
@arronk3 3 жыл бұрын
2 videos basically back to back? pog
@roykositzky2252
@roykositzky2252 2 жыл бұрын
god damn man your are my fav person right now thank you for being here. was that evillimeter tool a vuln or im i just a idiot? love ya man have a great day.
@errollgnargnar9534
@errollgnargnar9534 2 жыл бұрын
Thanks for keeping it real
@48pluto
@48pluto 3 жыл бұрын
It was a interesting video as always. I like these decoding stuff. What caught my eye was at @53:13 Set objFSO = CreateObject("... Next line set objFSO = Nothing That was funny :)
@almostanengineer
@almostanengineer 3 жыл бұрын
I enjoy these and I've absolutely no idea why 🤷🏼‍♂️
@davidmiller9485
@davidmiller9485 3 жыл бұрын
For those who don't know Hwy 75 that runs through Dallas all they way through plano and Richardson and beyond is just chock full of high tech companies. I miss the drive at night, i don't miss the fucking 110 F days.
@Cyberducky
@Cyberducky 3 жыл бұрын
Future John getting frustrated by his past self is my new spirit animal xD
@norboost
@norboost 3 жыл бұрын
John sounding like Olivander in Harry Potter. "After all, insert-virus-name-here does great things. Terrible! Yes. But great."
@BackWithTheBoom
@BackWithTheBoom 3 жыл бұрын
Creating some in GO while watching this, lets goo.
@__theycallmeaadi3316
@__theycallmeaadi3316 3 жыл бұрын
What you creating in go ?
@hdconnoisseur7932
@hdconnoisseur7932 3 жыл бұрын
@@__theycallmeaadi3316 I assume a RAT
@__theycallmeaadi3316
@__theycallmeaadi3316 3 жыл бұрын
@@hdconnoisseur7932 yea i think so i'm also creating malware in go that's why i asked
@__theycallmeaadi3316
@__theycallmeaadi3316 3 жыл бұрын
@@j.u.g.y nah that's they call me "aadi" aadi is my name.
@__theycallmeaadi3316
@__theycallmeaadi3316 3 жыл бұрын
@@j.u.g.y no problems I'm lone enough that these things make me happy 😅
@tortotifa5287
@tortotifa5287 3 жыл бұрын
Hey John, Sometimes when you see that 'Client.exe', that might means that it could be some kind of RAT (talking based on experience). When I saw that ILSpy gave it to you as Lime, I was pretty sure it was Lime Rat. You have its source code on GH ! Also I do not think that with ILSpy you could do some refactor, but definitely you can with dnSpy. I suggest you to swith over a Windows VM when doing some .NET analysis, it'll get you life easier
@donutcream4944
@donutcream4944 3 жыл бұрын
I love this series ! Looking forward for more ;)
@jaymar921
@jaymar921 3 жыл бұрын
He looks like a senior dev looking at the code provided by the junior dev 😅
@devilemox2824
@devilemox2824 3 жыл бұрын
"MATH IS HARD" :) **Agreed**
@MySisterIsASlytherin
@MySisterIsASlytherin 3 жыл бұрын
John From the Future is my spirit animal
@Mustardoable
@Mustardoable 3 жыл бұрын
Dallas has a few data centres, I'd expect the IPs to be there as that's where they were running the RAT (Remote Access Tool) controller / CnC (Command and Control) server from there
@Lars-ce4rd
@Lars-ce4rd 3 жыл бұрын
John from the future @ 3:40, I see a lot of myself in you. Such a misunderstanding is so relatable for me
@Basieeee
@Basieeee 3 жыл бұрын
Coool stuff. Ahmed
@obitorasu1760
@obitorasu1760 3 жыл бұрын
John from the future bullies present John for 1 hour straight.
@slygamer01
@slygamer01 3 жыл бұрын
They ran the C# DLL through an obfuscator. Trying to decipher obfuscated code is not a trivial task.
@danieldaszkiewicz7313
@danieldaszkiewicz7313 3 жыл бұрын
These videos are great, keep them coming! :D
@talinross
@talinross 3 жыл бұрын
Keep up the great work love these videos
@SF-eg3fq
@SF-eg3fq 2 жыл бұрын
Hi john, i speak arabic n stuff this guy's content are nothing more than skiddie stuff? in fact 99% of the "arabic hacking" videos on youtube are just a bunch of script kiddies being utra cringe. the page you saw on facebook is not a marketplace it just for his "tutorials" cringy kind of sutff, i even doubt he's behind the vbscript's, those guys really thinks once they learned how to setup kali virtual machines they become "hacking masters" or somethin 🤣, nice video and please do not take those guy's seriously in anything🤣🤣
@TheItalohugo
@TheItalohugo 2 жыл бұрын
"Heavly edited" : Three jump cuts lololol
@yamsol1911
@yamsol1911 3 жыл бұрын
Dude... this guy is sick kkkkkkk I love your videos
@alincraciunescu
@alincraciunescu 3 жыл бұрын
Thank you, you are unique !
@Zebby2013
@Zebby2013 3 жыл бұрын
Finally made the start of a video!
@MrRAGHUSHARMA
@MrRAGHUSHARMA 3 жыл бұрын
thanks John....
@xn1kkix
@xn1kkix 2 жыл бұрын
Mavis Beacon Teaches Typing
@mindzhd
@mindzhd 3 жыл бұрын
​"bah, fuckin ILSpy, stop" lmfao
@sammo7877
@sammo7877 3 жыл бұрын
Here we go again :D cant wait!
@dedkeny
@dedkeny 3 жыл бұрын
Dude, that is the funniest intro you've done yet lol
@solpex
@solpex 2 жыл бұрын
John what ssh client do you use and open a new shell and so forth I really love it fotgot - got what you said with Thanks alot!
@blackjackdealer204
@blackjackdealer204 3 жыл бұрын
Nerf fumble in the future..but still #respect .. I learned the $ replace with itself thingamajiggy you did
@slygamer01
@slygamer01 3 жыл бұрын
C# DllImport uses the method name as the function to load if no explicit function name is specified.
@samh3355
@samh3355 3 жыл бұрын
At first, I was thinking.. Optic Scump??
@chrisbishop6928
@chrisbishop6928 3 жыл бұрын
Dude these are just the right blend of comedy and learning on the fly. Math is hard!
@bhagyalakshmi1053
@bhagyalakshmi1053 Жыл бұрын
Gidra assembly code in the bic checking.
@1wk407
@1wk407 3 жыл бұрын
dallas needs an intervention
@Lars-ce4rd
@Lars-ce4rd 3 жыл бұрын
Here's a funny problem to consider, who gets more value out of .Net code obfuscating itself at build time, good guys or bad guys? Have we made life harder on ourselves?
@logiciananimal
@logiciananimal 3 жыл бұрын
The stuff you looked at in IL seemed to be possibly an un-selfpacker, like the WSH rat stuff you browsed through.
@temolantern9091
@temolantern9091 3 жыл бұрын
POV: you're in the comments to see if world of hacker replied to the video with "thanks for the shoutout!"
@eklypzn
@eklypzn 3 жыл бұрын
I see you have the Huntress shirt too. You can use -o with curl to download. John is about to get DMCA'd by these hackers PepeLaugh
@stevejamal241
@stevejamal241 3 жыл бұрын
I bet ya that Mr Ahmed is from Eygpt cause that background is almost like Egyptian way of piracy and hacking stuff 😅😅
@0xlol64
@0xlol64 3 жыл бұрын
this why most people who sees his profile hate us egyptian and arabs btw im egyptian
@hpimpact
@hpimpact 3 жыл бұрын
egypt isn't the only arabic country tho
@ko-Daegu
@ko-Daegu 3 жыл бұрын
@@0xlol64 why thou?? I don’t get why I will hate an entire country( 100m+ people) cuz of a banner ? Also we have Russian and Chinese hackers I’m not hatin Russia or China cuz of them You are worrying for wrong reasons
@DavidAlvesWeb
@DavidAlvesWeb 3 жыл бұрын
⚠️ MATH IS HARD SHOULD BE A MOVEMENT! ⚠️
@HalValla01
@HalValla01 3 жыл бұрын
37:19 Cover you ears, kids
@maliusribeiroborges7578
@maliusribeiroborges7578 3 жыл бұрын
Damn, this is way above my level lol
@jwbulmer
@jwbulmer 3 жыл бұрын
It’s all above my level.
@nickreed7277
@nickreed7277 2 жыл бұрын
if it makes you feel better John. im not one of those people who notice anything wrong that you do. im a noob :)
@zitrax506
@zitrax506 3 жыл бұрын
Arab hackers: A group of hacker children who depend most of their concept RAT While do not realize what are the foundations of the penetration "I mean the majority "
@gabrote42
@gabrote42 2 жыл бұрын
Hilarious 20 20 retrospective
@thekurdgamer8366
@thekurdgamer8366 3 жыл бұрын
John from the future 😅😂
@tomasgorda
@tomasgorda 3 жыл бұрын
Hahaha i like John from future and his comments 🤣🤣🤣🤣🤣🤣
@TheSxW
@TheSxW 3 жыл бұрын
18:54 - yes you can
@BSJuliaMagna
@BSJuliaMagna 3 жыл бұрын
Hackers from Texas? Yeeehaaaackers?
@luks1337
@luks1337 3 жыл бұрын
omfg, I love this edit ... btw john u edit in Linux?
@rckrs-jf8lb
@rckrs-jf8lb 3 жыл бұрын
Excellent video man, if you can share the sample, would be great.
@diddyman1958
@diddyman1958 3 жыл бұрын
I like it :)
@scor-_-pions5094
@scor-_-pions5094 3 жыл бұрын
por favor faz mes que to tentando...> executar o emulador do ( ps1 duckstation ) com um comando bat para iniciar a iso do jogo sem abrir o emulador ou seja iniciar automaticamente com um click no comando .bat?
@surajsawant6469
@surajsawant6469 3 жыл бұрын
hey, it's fun to see your vids. could you please also share the samples?
@rrkatamakata7874
@rrkatamakata7874 3 жыл бұрын
i am cse student and i feel like oh god there is no way i can write this stuffs. (i want to mention the hardness of these stuff not the hacking part)
@h8handles
@h8handles 3 жыл бұрын
your videos have gotten SO FREAKING GOOD which is hard to imagine because i have loved them since the python tutorials.
@TheAngelOfDeath01
@TheAngelOfDeath01 3 жыл бұрын
C# code... and it's not the engine behind a chess game that code there covers!
@TwinTailTerror
@TwinTailTerror 3 жыл бұрын
Update that ip is a vpn in tex by nord i think
@Tan444
@Tan444 3 жыл бұрын
you should put the hash in the description so people can follow along
@watchdog2864
@watchdog2864 3 жыл бұрын
Where do you get these samples from John? I’d love to do some of this myself!
@TwinTailTerror
@TwinTailTerror 3 жыл бұрын
Server is victim in the world of rat. Client is attacker on the norm
@arivanhouten6343
@arivanhouten6343 3 жыл бұрын
i was here before you could even watch it
@Scaramouche122
@Scaramouche122 3 жыл бұрын
van houten
@fade8148
@fade8148 3 жыл бұрын
Best dud
@dougbongqueque
@dougbongqueque 3 жыл бұрын
I liked it 🤷
@ivanboiko8975
@ivanboiko8975 3 жыл бұрын
ho ho ho, time to malware :D
@killerskincanoe
@killerskincanoe 3 жыл бұрын
Math actually is hard yo
@jonchicoine
@jonchicoine 3 жыл бұрын
So where did you get the vbscripts from?
@Dodo-rb4zf
@Dodo-rb4zf 3 жыл бұрын
me doing code review on my company
@SamyTessier
@SamyTessier 3 жыл бұрын
Is this any malware written in Python? would be interested in an analysis of that
@ThatBoringDeveloper
@ThatBoringDeveloper 2 жыл бұрын
I am by no means a ethical hacker or someone who is into malware analysis i am more of a web developer than anything but isn't this dangerous even in a virtual machine?
@bhagyalakshmi1053
@bhagyalakshmi1053 Жыл бұрын
Vvvnnn is power files open.
Cryptocoin Miner - Unpeeling Lemon Duck Malware
1:01:02
John Hammond
Рет қаралды 96 М.
Information Stealer - Malware Analysis (PowerShell to .NET)
47:56
John Hammond
Рет қаралды 52 М.
Cool Parenting Gadget Against Mosquitos! 🦟👶 #gen
00:21
TheSoul Music Family
Рет қаралды 33 МЛН
World’s strongest WOMAN vs regular GIRLS
00:56
A4
Рет қаралды 8 МЛН
黑的奸计得逞 #古风
00:24
Black and white double fury
Рет қаралды 29 МЛН
2 MAGIC SECRETS @denismagicshow @roman_magic
00:32
MasomkaMagic
Рет қаралды 24 МЛН
HTA JScript to PowerShell - Novter Malware Analysis
1:24:19
John Hammond
Рет қаралды 96 М.
Unraveling a REMOTE ACCESS TROJAN (VBScript Deobfuscation)
31:20
John Hammond
Рет қаралды 163 М.
Three Ways to Hack Mobile Apps
43:41
John Hammond
Рет қаралды 81 М.
This Single Rule Underpins All Of Physics
32:44
Veritasium
Рет қаралды 3,3 МЛН
Apple, Stop Putting Things On the Bottom Please
9:16
TechLinked
Рет қаралды 461 М.
TryHackMe! Bypassing Upload Filters & DirtySock
53:38
John Hammond
Рет қаралды 68 М.
Simple Code, High Performance
2:50:14
Molly Rocket
Рет қаралды 258 М.
Rick & Morty MALWARE!? - sLoad - PowerShell & VBScript
30:31
John Hammond
Рет қаралды 60 М.
Uncovering NETWIRE Malware - Discovery & Deobfuscation
59:46
John Hammond
Рет қаралды 93 М.
TARGETED Phishing - Fake Outlook Password Harvester
47:09
John Hammond
Рет қаралды 258 М.
Cool Parenting Gadget Against Mosquitos! 🦟👶 #gen
00:21
TheSoul Music Family
Рет қаралды 33 МЛН