"This is just 75 lines of code" *Half hour later* "201 thousand characters selected"
@AlucardNoir3 жыл бұрын
that's how they get you man, that's how they get you.
@geist4533 жыл бұрын
@@AlucardNoir AND YOU BUT GUESS WHO NOT?! ME AND JOHN
@GuyMassicotte3 жыл бұрын
Majorly loaded by a fake jpg ;)
@bansku5703 жыл бұрын
@@geist453 l
@nojusnojus80153 жыл бұрын
@@bansku570 I
@DenyardTV3 жыл бұрын
Ngl, never thought it would be so much fun watching someone analyse and breakdown a virus.
@KrakenPipe3 жыл бұрын
I was thinking the same thing! I might have just discovered my new rabbit hole lol
@0xRalu3 жыл бұрын
Love this malware analysis series!
@ismhdez3 жыл бұрын
Me too! Amazing series
@syverlunde96223 жыл бұрын
I love it too!
@jbgaud3 жыл бұрын
me too, this guy is really good.
@s.broyal51282 жыл бұрын
Sir. Can I use remcos rat to hack Android...
@slygamer013 жыл бұрын
The REMCOS developer "discourages malicious use". For sure, everyone will use solely for legitimate purposes.
@aliencatmeow3 жыл бұрын
'sure if you say so' meanwhile no one uses it legitimately
@karimmohamed37443 жыл бұрын
Malicious actors: amma head out
@garethevans97893 жыл бұрын
Ethical hackers don't sell hacking toolkits, ethics and all that... 🤷♂️
@technoturnovers70723 жыл бұрын
@@garethevans9789 Pentesting tools are released open source because not only is open source more effective, but it makes sure that the developers are not potentially profiting off of malicious actors, intentionally or not.
@cyber13773 жыл бұрын
Meh, skids are gonna find a way anyway. With our without this program.
@bennettpalmer17413 жыл бұрын
I love how they went through six stages of obsfuscation, and a lot of effort into hiding what they were doing.... but their payload was literally called "Attack.jpg" like surely they could have named it something at least slightly less blatant.
@FilliamPL3 жыл бұрын
Perhaps they didn't care to hide it at that point? I know that obfuscation helps to counter analysts, but when the code is downloading data from a URL, then I suppose it wouldn't've been worth their effort to obscure the name of the download. Then again, they could've made a second download with totally unnecessary data. Either way - this thing is bad (for you)! xD
@richie74253 жыл бұрын
Times must be hard, Ed Sheeran is writing python.
@batmanasdasd3 жыл бұрын
Lmaooo💀💀
@HiramSalinas3 жыл бұрын
he looks like an unscuffed burgerplanet
@realitynowassigned3 жыл бұрын
This is ed sheerhan and Seth rogans kid.
@HaxorBird3 жыл бұрын
You are the hacker version of pewdiepie. Very entertaining to watch.
@lusthetics3 жыл бұрын
Nah he looks like a de deobfuscated Ed Sheeran
@andmo903 жыл бұрын
Content like this is why I don't have to pay for cable, satellite, or netflix!
@garethevans97893 жыл бұрын
But then he would have been on 8-12 screens and typed those 200k characters (hacking is typing fast), it's all hard to follow. It would be like watching the Matrix.
@viv_24893 жыл бұрын
Yeah
@SiveenO Жыл бұрын
Okay, but consider this: TOS and TNG are on Netflix.
@NickyPuff3 жыл бұрын
I love when John is laughing over the Attack.jpg url
@livroz4543 жыл бұрын
best part
@baremetalHW3 жыл бұрын
Damn that was fun to watch!! Thanks and keep them coming!!!!!!
@whatnowsami92253 жыл бұрын
Nobody: Virus Code: * Does malicious stuff* John: Is it trying to do something bad? HAHAHA Us: Duhhh John. wtf
@donaldduck61983 жыл бұрын
John, as you are very good, you should stand this comment: In Powershell a "split (..)" is a regular expression splitten in string in portione of two characters, ie "4142" becomes "41", "42", in Hex AB
@Corb4nm0noxide3 жыл бұрын
So far this is the most fun I've had watching hacking videos. Your analysis is fantastic and I enjoy seeing your process. Keep it up!
@ycoihmn63883 жыл бұрын
This style of video really helps me with my start in forensics and malware analysis. I love liveoverflow and other CTF summary channels but they often feel like magic in the way they present their findings. Keep up the great work :3
@darkdagger0323 жыл бұрын
This is one of the best educational videos i've seen
@vannialora34763 жыл бұрын
the evolving of rat is so amazing, i remember in late 90's where sub7, netbus and back orifice was so popular and inspired me into hacking. IRC was the channel to go to before and dial up is your connection.
@dustinjohnson76353 жыл бұрын
Amazing work, you deserve the money from the KZbin overlords. Literally only commented to help boost those algos.
@Dilipkumar-ur9zx3 жыл бұрын
After watching this, gained a keen interest in Malware Analysis. Thanks for the awesome content.
@willo77343 жыл бұрын
Whatever that quality is that great teachers have, you have it. Never change the format of your videos. I love seeing you troubleshoot and reason through everything live.
@uniquechannelnames3 жыл бұрын
Algorithm, give this man the recs.
@TexasTimelapse3 жыл бұрын
It worked. That's why I'm here.
@definesigint28233 жыл бұрын
I've taken apart stuff like this (when I worked in large enterprise) but the samples were rarely more than 3-4 levels deep. This actually looks a lot more like a challenge you'd get at a CTF competition _(perhaps they're getting ideas from each other)_ ?
@TracyNorrell3 жыл бұрын
Scheduling this to start at the same time as the new mars rover is landing... Bold move cotton, let's see how it works out
@_JohnHammond3 жыл бұрын
Bah, totally didn't even realize xD Ah well!
@originalgaming90623 жыл бұрын
@@_JohnHammond I’d prefer watching this over some rover landing
@originalgaming90623 жыл бұрын
@@tripplefives1402 isn’t the rover automatically controlled because the delay would be 10 minutes long?
@m1rz3 жыл бұрын
Pretty sure you need to run the obfuscated version of the AMSI bypass. Great video, would love to see more of these!
@Edzward3 жыл бұрын
You need I high level of nerdiness to find this entertaining. Proof: I find highly entertaining! Love this.
@rccservice3 жыл бұрын
that url has to be the greatest thing ive ever seen
@TheSeakr3 жыл бұрын
I'm just finding this channel and its quickly becoming my favorite content. Im fascinated with all of this. Really inspires me to get started with basic coding to get my feet wet.
@vargnaar3 жыл бұрын
"Can I get anything out of Melons?" You can get juice, John. Juice.
@patchbyte68563 жыл бұрын
this is gonna be good
@AnthonyBlakley3 жыл бұрын
Indeed Indeed :D
@randallsalyer3 жыл бұрын
I love John’s response when the light bulb goes off and all the hard work comes together. Great video as always.
@Ayayron_e33 жыл бұрын
"guys, you might think i'm dumb" LOL exact opposite.
@auto1176663 жыл бұрын
In the next episode... John rewrites the kernel for more efficient find and replace..... STONKS!
@md1231803 жыл бұрын
Where have you been all my CS degree? This is awesome watching this stuff in action as you do it. I love the content! Definitely going to keep watching!
@PerfectEn3my3 жыл бұрын
Great video, I love this series. Also special thanks for zooming in this much, watching code-related stuff on phone is usually a pain, but not in your case. Keep up the good work!
@britishpiperygo3 жыл бұрын
Loving this series. Would like to see some disassembling malware analysis.
@mbowler053 жыл бұрын
Hands down one of the best malware analysis walkthroughs I’ve seen. Watched it twice.
@wazoozastoob12345673 жыл бұрын
THOSE DOWNVOTES....GTFO...this dude is a legend
@eliasgamezgarcia34143 жыл бұрын
Dude you are simply awesome...it's so enriching for all of your viewers to see your hard work and all your skills, and the best of all is that we can see you enjoying so we enjoy and learn too. Regards from Spain!
@kitrodriguez9923 жыл бұрын
I was watching some scam baiting videos and also doing some deep dives into RATs and just... CyberSec/CompSci things in general and found this video. I'm glad I bumped into your channel. Really good stuff you have going on here
@ultimate86733 жыл бұрын
The guy that wrote the script watching this video rn must be like 👁️👄👁️
@mechanicalfluff3 жыл бұрын
i missed the premiere, but this is definitely a blast to watch. Would love to see this more
@pumpkin79763 жыл бұрын
Plottwist: this is all just an advertisement for BreakingSecurity
@whamer1003 жыл бұрын
"is this the newest version? because that would be pretty slick" *immediately scrolls past the version number 3.1.0 showing it is the latest version*
@mclovin7483 жыл бұрын
59:06 love how scrolls past when looking at string in the executable "Offline Keylogger Started" "Online Keylogger Started" "Online Keylogger Stopped" "Offline Keylogger Stopped" Yes John sees the key strokes and is like, "is this doing keylogging?"
@shawnio3 жыл бұрын
every single line "I don't exactly know what is going on here" so basically this guy is just us trying to understand code. got it.
@hexnull43433 жыл бұрын
Man i'm brazillian, and i love all of this videos, but this... mannn to amazing !! Continue delivery this content to us, i apreciate this
@Krampfey3 жыл бұрын
Damn, I just watched over an hour of stuff I have no clue of and I still feel educated and entertained. It even kinda makes sense, when you talk about it and explain some stuff. Thank you very much! :)
@thedemonlord92323 жыл бұрын
you got my sub for this. its 3am in the morning and I've watched the entire thing having so much fun. keep on with the good stuff
@Flobert973 жыл бұрын
Did i just watch AN HOUR of malware analysis? Dude, you're awesome!
@MikeKirkpatrick3 жыл бұрын
Well worth the watch. This is a great video. Please do more. :)
@georgehammond8673 жыл бұрын
how do you copy and paste into VirtualBox in Windows 10
@orbyfied3 жыл бұрын
these videos are underrated hidden gems. i swear why didnt i get them in my reccomended earlier.
@SuperBryantheman3 жыл бұрын
Dope analysis! The streets need this type of content. Keep it coming.
@tears_falling3 жыл бұрын
Attack.jpg, that was hilarious
@agentsmith97533 ай бұрын
That was epic dude! Felt like a real rollercoaster. I can't believe you got to them within 24 hours of release. So nuts.
@sheldongroom183 жыл бұрын
Please more Malware Analysis videos. So much fun to watch.
@Zachucks3 жыл бұрын
"I don't like these advertisements..." "You didn't see this here folks!" "Not in a John Hammond video!"
@ThomasGabrielsen3 жыл бұрын
What a great catch! This is by far the most interesting video I've watched on KZbin for a very long time. I love this of unedited video.
@notrace_03 жыл бұрын
I never write a comment under a video but I saw every single second and I really really loved it. Thanks for your video and keep doing it sharing your passion with us!
@HBTwardy3 жыл бұрын
John: releases a video with malware analysis Me after watching a video: *Lemme check real quick whether notepad.exe is running in the background or not in Task Manager*
@benricok3 жыл бұрын
Imagine using windows 🤔
@Reelix3 жыл бұрын
@@benricok Imagine thinking that exploit-db had 0 results for Linux 🤔
@benricok3 жыл бұрын
@@Reelix I didn't even mention an OS? I am aware that Linux isn't perfect as so with every software product (opensource or not). The worst thing you can do to your security is to be over confident in your defense.
@theluckyscav34873 жыл бұрын
@@benricok Imagine being a pompous asshole. Some people want to, you know, play normal games on their computer.
@jixs4v3 жыл бұрын
@@theluckyscav3487 I mean linux gaming has come a long way, but it still needs some time to flourish
@rubenolguin21802 жыл бұрын
Wow, that was a crazy ride! Thanks for taking us on the journey.
@GeekBeerRS2 жыл бұрын
Man I love these videos. As a junior network tech I love watching this, so interesting and entertaining!
@brentbice11513 жыл бұрын
I love that you used strings and am glad I'm not the only one who does. :-) It's a highly under-rated tool, IMHO.
@scab30453 жыл бұрын
LOVE YOUR VIDS BRO. I UNDERSTAND LIKE 5% OF WHAT I SEE.
@DallasGraves3 жыл бұрын
From beginner hand-holding on picoCTF to obfuscating obfuscated obfuscation LOL. This channel has it all, thanks for the great content!
@jwbulmer3 жыл бұрын
I still have no idea what's going on, but I enjoy these videos all the same. Thanks for the upload John.
@musingmuse90643 жыл бұрын
Watched the whole thing from start to finish - loved it! Make more!
@helenageorge92233 жыл бұрын
Just for the KZbin algorithm to know, I love malware analysis series! keep them coming!!!!!!
@thedosiusdreamtwister15463 жыл бұрын
Where do you get such fresh samples? That hash isn't even on VT yet.
@Anonymous-vh6kp3 жыл бұрын
Plot twist: John actually wrote it
@bradlad15743 жыл бұрын
That's a rabbit hole if I've ever seen one haha great stuff man!
@definesigint28233 жыл бұрын
If only it (the rabbit holes) were rare. 😥
@ulbed3 жыл бұрын
Follow the white rabbit!
@sannyboi72982 жыл бұрын
Brilliant. You make malware reversing so fun to watch.
@danielbaker30633 жыл бұрын
Always learn something new watching your content!
@somnitek3 жыл бұрын
Dude... That was solid. Loved it. Kinda dragged in the middle but I was invested enough I just jumped ahead maybe ten minutes before I was stuck back in. Nice nice so nice I had to say it twice, then one more time too.
@jeehill95922 жыл бұрын
As a prospective sw engineer, at ~54:00 that obfuscated spaghetti mess made me never want to be a malware analyst 🤣😂🤣 glad to have people with your mettle in this world
@DarkFaken2 жыл бұрын
I love these malware analysis videos. You break stuff down to a fairly easy to understand level for most technical people. I'm just getting into cyber security and I'm really enjoying your content, thank you.
@ronpaul91723 жыл бұрын
That's instantiating a new GUID. Nobody calls it CLSid. ;) :P John is either trolling, or he didn't realize this code is used for teaching reversing in numerous places. The sprinkling of RemCos into it was a cute little sleight-of-hand to distract from the fact that it's well-known as teaching material. In either case, I'm very glad to have found this channel.
@snuffy64493 жыл бұрын
I binge your videos every day all day at work. Gets me through the day and I learn some new/cool stuff.
@christianf213 жыл бұрын
This is crazy. I've learned more about malwares in a few vids I saw from you, than the time I spent trying to get into the field years ago. I'm a fulltime dev now and have been working for over 7 years. Reminds me of my recent grad days where all I wanted was to understand this. Much easier to follow now, and damn, learning so much so quick now. Props to you.
@nickyfranshel12103 жыл бұрын
I have no idea what I'm watching but I'm enjoying it :)
@internetuser89223 жыл бұрын
It's actually not a bad way to learn, at least starting out - if you're interested. I have a background in software engineering, but I only understand maybe 75% of what's going on.
@squeelyinc3 жыл бұрын
Yes keep these coming, really enjoyed that video!!
@Seluj783 жыл бұрын
Really interesting video, thanks !! I'm impressed at the obfuscation job done on this malware it's impressive
@JM-tf3rg Жыл бұрын
This was so fun to watch. The sketchy url was very funny, fitting pun on with the ‘holy cow’
@carlenkaiser9573 Жыл бұрын
Fascinating video with a crazy ending legit......
@deantammam2 жыл бұрын
You know so much about so many things... I've learned so many things in the few videos I've watched so far. Super, super inspiring.
@keiths.76343 жыл бұрын
so good. Keylogger+RAT with 45 min of Fluff! obfuscation is getting wild anymore. Thanks for the video very entertaining!
@JimTheScientist3 жыл бұрын
Knowing the internet is totally insecure and I should be scared of everything puts me to sleep at night. Thank you John!
@rogan853 жыл бұрын
This series of decoding Malware is the best knowledge base for getting a feel for noobs like me. Please keep it coming. Thank you.
@TechSy83 жыл бұрын
Did anyone told that to you, you're an genius buddy.... i even can't get off my eyes on this series.... amazing
@jacobti983 жыл бұрын
Watching John in 1.75x speed was awesome. very entertaining and I learned stuff. Thank you
@h4wk_n3773 жыл бұрын
Keep on doing those Malware Analysis. It's really fun to watch and it's quite educative too!
@Mosern19773 жыл бұрын
Been programming for a long time, but never really looked much into viruses and malware. Cool analysis. The authors sure work hard to make their installation as painless as possible.
@djzio2 жыл бұрын
That was *slick*! Mr Hammond, you are otherworldly!
@nilanjana252 жыл бұрын
Totally enjoyed the video. It was an absolute rollercoaster ride. I love the way you present and explain the details in all your videos. And also none of your videos ever seem to be monotonous even when we are dealing with such mind boggling stuff because of the way you laugh and get excited when you crack/deobfuscate a piece of code. 😁 Thank you so much for taking the effort and sharing the awesome work😊
@johnhelt54753 жыл бұрын
John, great interview in the Infosec OSINT podcast!
@facekickr3 жыл бұрын
That was a great video. I don't know a whole lot about what you do, but it was super fun watching you do it. Thanks so much!
@mattgwalker3 жыл бұрын
John - This is great content. I really am learning a lot watching you work these out. Keep it up! The masses demand more of this!
@WellnessIKIGAI3 жыл бұрын
as a computer science student, you make this profession actually seem fun. Thanks for re-kindling my interest in this field :)
@kanishkkaushik7803 жыл бұрын
These videos feel like we're going on a cool adventure, absolutely amazing!!!
@kevinwilson72133 жыл бұрын
Nice. Never seen someone crank through something like that. Cool man, cool!
@Spelter Жыл бұрын
I got this gem today into my inbox from somebody and remembered your Video. It was fun decrypting it like an onion :) And btw. I did not comment back then, but when a File starts with MZ, it's a Windows Executable ;) Mark Zbikowski was a dev of the original Dos and that's his Magic Number on Exe files.
@TheMrBurks3 жыл бұрын
Absolutely unf**king-believable. You are insanely smart. Keep inspiring
@uimstar52543 жыл бұрын
Wow, that was awesome video. It is so nice to see you go through all the steps and thinking while deobfuscing. This RAT is kind of really scary for everything it can do. I would like to see more of this in the future! Keep up the good work
@kipchickensout3 жыл бұрын
You can also Ctrl+Scroll Wheel to zoom into notepad Edit: I watched the whole thing and I really had fun, really interesting and high quality Your circlular camera mask and your energy break reminded me of networkchuck and his coffee break xD You got a new subscriber :)