$2 MILLION DOLLARS STOLEN in Bitcoin/Ethereum - JScript Malware Analysis

  Рет қаралды 137,571

John Hammond

John Hammond

Күн бұрын

Пікірлер: 306
@_JohnHammond
@_JohnHammond 3 жыл бұрын
Update: Thanks to @Wikidude in comments for pointing this out. The "Mizu" address that I didn't do a good job of digging into is apparently a BTC address. Looking this up, it has over 2.5 MILLION dollars, with transactions in March of 2021. Absolutely crazy. www.blockchain.com/btc/address/1NSrjTotDiuK7S1xMm9yuppq4dr4Uf9saM
@hackingguy
@hackingguy 3 жыл бұрын
It was really awesome!!! It felt like a real movie hacker like stuff 🔥🔥🔥🔥
@void_p
@void_p 3 жыл бұрын
change the video title for moar clickbait!
@wikidude
@wikidude 3 жыл бұрын
We are Big Boi investigators now xD
@Basieeee
@Basieeee 3 жыл бұрын
Holy smokes
@SV_Sangha
@SV_Sangha 3 жыл бұрын
Wow.... makes one wonder doesn't it.... all stolen or mined, hmmm...
@jht5225
@jht5225 3 жыл бұрын
I just wanted to say. You have inspired me. I have officially enrolled in university again as a mature student finally and will be working towards a bachelors in Cyber security
@philipstringer4425
@philipstringer4425 3 жыл бұрын
same i didnt know what i wanted to do in life, but john has shown me a path
@deepergodeeper7618
@deepergodeeper7618 3 жыл бұрын
@@philipstringer4425 you now know the way
@Nunya58294
@Nunya58294 3 жыл бұрын
Hell yeah!
@chillytheprogrammer
@chillytheprogrammer 3 жыл бұрын
I am currently studying cybersecurity too!
@hackman44
@hackman44 3 жыл бұрын
@@chillytheprogrammer Best field to get into. Lot's of money to be made as long as you have the right mindset.
@alessandro.rossini
@alessandro.rossini 3 жыл бұрын
39:05 this is in a language that I do not speak: Proceeds in realtime reading and translation from Italian to English with no issues
@MrCyphersphinx
@MrCyphersphinx 3 жыл бұрын
Excellent work, watching this helped me realize that this cyber security degree I am finishing up is something that is achievable and interesting. So much of our classes are report driven and it is great to see a real world example of what actual analysis looks like and the progression through it. Thank you!
@EmaCannella
@EmaCannella 3 жыл бұрын
The Threat Report PDF at 38:53 was in Italian and yes was a report about a similar malware Italiani facciamoci sentire :)
@valeriobertoncello1809
@valeriobertoncello1809 3 жыл бұрын
Spaghetti code ftw
@heinrich3427
@heinrich3427 3 жыл бұрын
This video inspired me to get into ethical hacking. I literally watched over 20 hours of videos about hacking in the last 2 days. I haven't been this excited since I started programming 17 years ago. Just hacked into my Bose soundtouch 😂 Thank you for bringing back the fun and fire in me for computers 😁
@royslapped4463
@royslapped4463 2 жыл бұрын
This video inspired me to make a bot net that is spreading around the earth and sending millions of dollars to me from "inactive" crypto wallets. 😉 I am almost on the leader board of top 500 humans!
@Flaneur27
@Flaneur27 2 жыл бұрын
How Tf did you have that
@jeromed.salinger647
@jeromed.salinger647 Жыл бұрын
Updates? Was it short-term hype or you stick to it up until now?
@wikidude
@wikidude 3 жыл бұрын
Hey John, the BTC address (Mizu in the sample) that you didn't check properly on blockchain explorer, has received $2.5 Million. Should probably change the title. $2.560.000 looks better xD
@_JohnHammond
@_JohnHammond 3 жыл бұрын
Holy shit.
@salticidae1.618
@salticidae1.618 3 жыл бұрын
@@_JohnHammond yeah it's 72 BTC at 44,000+ USD each xD
@jimmyadaro
@jimmyadaro 3 жыл бұрын
@@salticidae1.618 BTC is up to $56k each right now
@jbarriossandrea
@jbarriossandrea 3 жыл бұрын
Is 13 millions now
@BigBeesNase
@BigBeesNase 3 жыл бұрын
It was an interesting dig and got spicier with those dollar numbers. Keep up the good work!!
@kingpopaul
@kingpopaul 3 жыл бұрын
I think this is pretty small compared to ransomware in terms of value and damage. Though it's nice to see a John spambot.
@LuisSieira
@LuisSieira 3 жыл бұрын
Impressive how you managed to understand obfuscated italian though
@haloball12
@haloball12 3 жыл бұрын
...
@HatTrex
@HatTrex 3 жыл бұрын
Bruh
@LinuxJedi
@LinuxJedi 3 жыл бұрын
🤦🏻‍♂️
@dumbidiot1119
@dumbidiot1119 3 жыл бұрын
So just Italian?
@deutscher649
@deutscher649 3 жыл бұрын
What is being insinuated here? Just curious.
@SV_Sangha
@SV_Sangha 3 жыл бұрын
Great work... love how fluent you are in this. Kudos to you John!
@SV_Sangha
@SV_Sangha 3 жыл бұрын
@John Hammond Thankfully I have not. However, I try and stay isolated as best I can. I love the programming and security in the videos.... and am doing some entry level hackme items trying to learn. Your inspiring, thanks!
@_asidy
@_asidy 3 жыл бұрын
Sailing Sangha that was a fake account
@SV_Sangha
@SV_Sangha 3 жыл бұрын
@@_asidy agreed... but good interactions help the algorithms 😁
@Masterism88
@Masterism88 3 жыл бұрын
I know this video is a couple months old, but I'll still say that These videos are much better when you go through the malware for the first time, rather than explaining what you've found previously.
@joacoordonez1973
@joacoordonez1973 3 жыл бұрын
Man, i love this vids, you'r an absolute genius. I learn a lot
@kristiyangerasimov6708
@kristiyangerasimov6708 3 жыл бұрын
John thank you for the great video, I'm a complete newbie to software development, debug and analysis. I'm able to follow you perfectly, understand most of what is presented and am having a great time!
@andreastefan3825
@andreastefan3825 3 жыл бұрын
39:08 that is Italian :)
@asdqwery7593
@asdqwery7593 3 жыл бұрын
Thanks bro
@jakubklecki2963
@jakubklecki2963 3 жыл бұрын
Scammers these days pose as people who have literally just said in the video they don't know shit about crypto
@joryiansmith
@joryiansmith 3 жыл бұрын
This malware analysis is nothing short of magical
@imjustwolf
@imjustwolf 3 жыл бұрын
I love that I found your channel! I want to get into cyber security so watching you go through code and explain things is fascinating! I do have one thing to say... why do you NOT use dark mode on EVERYTHING? It is so much easier on the eyes using Window's dark theme and any dark theme where sites allow it (like twitter...).
@mikeylazokUkraineupdates
@mikeylazokUkraineupdates Жыл бұрын
Good Job , John "MALWARE" Hammond , Lovely to See and Hear Your Enthusiasm For Malware Man you Nailed IT.👊👌🤚✌🔥🔥🔥🔥As Usual 🔥🔥🔥🔥👌✌👊👊
@rickybennett9410
@rickybennett9410 3 жыл бұрын
You rock, John! Thanks for the cool videos and for being such an inspiration to all of us aspiring info-sec pros, and for educating the general public! You're the man!
@NB-ph6cv
@NB-ph6cv 3 жыл бұрын
Man, I don't understand all of it but now I remind myself that I was supposed to do other stuff and 32 minutes gone like a slap, or wait what does suppose to mean? And yeah, it's really interesting stuff! John, you are a Legend! :D
@juuse94
@juuse94 3 жыл бұрын
That clipboard trick is really slick
@hexearth8258
@hexearth8258 3 жыл бұрын
57:11 once you make a cryptocurrency transaction, it's public, everybody can see it.
@_Fen
@_Fen 3 жыл бұрын
_laughs in monero_
@pahvalrehljkov
@pahvalrehljkov 3 жыл бұрын
ammount of good advices and the fact you actually read them and use them is really creating that community vibe... me like it... also, i like it more when you come somewhat uprepared and research this like you would usual, sometimes it feels like you wanna make these videos to be explorations when they are clearly well prepared demonstrations, that feels more natural to me... and ofc tnx for all the good and spicy insides on how this is done! 👊
@Tramontano_T
@Tramontano_T 3 жыл бұрын
You have no Idea How much i love your videos ❤️
@kerbatonbaton8108
@kerbatonbaton8108 3 жыл бұрын
pls someone make something that looks like malware but in the end it gives you a youtube link to rickroll (and send this to him, pretending its crazy malware)
@SpoiledBread24
@SpoiledBread24 3 жыл бұрын
Lol
@CZghost
@CZghost 3 жыл бұрын
You know what? You bet! :D
@CZghost
@CZghost 3 жыл бұрын
@John Hammond Shut it off, we know you're fake ↑ Real one would have a tick next to his name, as an author of this video highlighted name and updated profile picture...
@tylercoombs1
@tylercoombs1 3 жыл бұрын
God, i learn so much from watching John's videos it literally takes me 3 days to digest one
@OmniPhantom
@OmniPhantom 2 жыл бұрын
I know right it's amazing
@kylefaust7743
@kylefaust7743 2 жыл бұрын
You know I have searched extensively to see if anyone actually does anything like what you do for this malware/virus/ransomware/ect... No one displays it like you. This information digging explorer style of the software. Most try to show off a tool or explain how you can learn to go do this and how it benefits you career. But no one is doing what you're doing here. I can't get enough of it cuz it is incredibly awesome.
@timothysnyders1426
@timothysnyders1426 3 жыл бұрын
Yo Johnny!! I've been a fan of yours for the longest bruv! Malware analysis is a neat content twist👌🏽.. Looking forward to more bro. **Side note : PLEASE CREATE YOUR OWN MALWARE, AND UPLOAD A VIDEO EXPLAINING THE CODE AS WELL AS A DEMO USING IT.. PRETTY PLEASE!! 😭😍🔥🙏🏽
@pedror9314
@pedror9314 3 жыл бұрын
Exelente video!! Gracias por compartir
@StanLTU
@StanLTU 3 жыл бұрын
excellent stuff. Love your content. Keep it up.
@structure7
@structure7 3 жыл бұрын
The only thing me and you have in common is that we both speak English good, but man I love your content, style, etc. Thanks for doing this and please keep it up! Subscribed. And I watch until the end.
@heinrich3427
@heinrich3427 3 жыл бұрын
As someone who works as a Software Developer since 17 years I am suprised how trivial the malware is. What I like most is how creativ it is with the clipboard. Are there common malware patterns?
@alvarocarrascosapenabad4355
@alvarocarrascosapenabad4355 3 жыл бұрын
Malware authors to me are some of the most creative people. I am sure there many patterns for achieving specific tasks, one I see a lot and here for example is to find the Startup Windows folder and copy it self to it. Some of them even go to the extend of making the icon invisible in said folder
@fra1897
@fra1897 3 жыл бұрын
that pdf was in italian! c: very entertaining video :)
@sorrefly
@sorrefly 3 жыл бұрын
39:05 greetings from Italy ❤️
@2514ben88
@2514ben88 3 жыл бұрын
great job John fascinating stuff as always
@NikolayRogchev
@NikolayRogchev 3 жыл бұрын
So the whole script relies on people not checking what they paste when sending money?
@code-to-design
@code-to-design Жыл бұрын
Why there is request to localserver if the video is only about what u said
@TheSauxer
@TheSauxer 3 жыл бұрын
57:32 that's batman voice noice
@Hitmonkey420
@Hitmonkey420 3 жыл бұрын
Love your content, John. I've learned a lot just listening while I work. I have applied a bunch to using Linux and have implemented your techniques starting Hack the Box. Just bought a shirt from ya👍. Keep up the good work. It would be cool if sometime you could make a mini series specifically about writing little tools, but I know your videos often contain python scripts you write on fly (which is really dope btw).
@kunma3214
@kunma3214 3 жыл бұрын
dude you are doing really cool stuff, keep going!
@chervesblezz
@chervesblezz 3 жыл бұрын
Great job... I've learned so much... plz continue with this... cya
@paashaasXD
@paashaasXD 3 жыл бұрын
I have one question, this script changes your clipboard with another BTC/ETH address right? But do they hope you immediately send btc after that or something? What happens when you ctrl C something else, will it overwrite? I don't get that part.
@skalman2262
@skalman2262 3 жыл бұрын
I do not know why this came up in my feed ... I understand absolutely nothing of what I'm watching ... Good work to get a subscriber who has no idea what he is subscribing to. and yes the text is with Google translate ;-)
@internetdoggo4839
@internetdoggo4839 3 жыл бұрын
Love em. keep em coming
@chillytheprogrammer
@chillytheprogrammer 3 жыл бұрын
53:51 Has he made a video on the minecraft malware??
@sammo7877
@sammo7877 3 жыл бұрын
Would have been interesting to see this part @51:45 via Burp suite :)
@Henchman0077
@Henchman0077 3 жыл бұрын
Great fun again John. Great work
@hgjfgjghfj8920
@hgjfgjghfj8920 3 жыл бұрын
have u deobfuscated a pyarmor obfuscated script? (python) a video on that topic would be interesting, thanks!
@mjmeans7983
@mjmeans7983 3 жыл бұрын
Is there a Windows policy that will just disable this pattern "Function(string)()"?
@logiciananimal
@logiciananimal 3 жыл бұрын
On the POST - the server doesn't have to answer - it could be doing nothing visible to avoid another IOC. Also, for all we know it could have been compromised itself, partially taken down by intelligence or law enforcement, etc.
@GabrielSultanGabyyy
@GabrielSultanGabyyy 3 жыл бұрын
where do you find these?
@kherkert
@kherkert 3 жыл бұрын
Hey John, base64 decoding multiple js comment blocks as one base64 string will certainly not work out. First split up the different /* ... */ blocks and decode them separately.
@rastabong420
@rastabong420 3 жыл бұрын
love your videos john keep it up!
@foxdk
@foxdk 3 жыл бұрын
Another great video. Keep it up!
@Dan-uo9fw
@Dan-uo9fw 3 жыл бұрын
I'm curious what infection vector they use to get this into a victim machine and executed.
@hunterhunter6517
@hunterhunter6517 3 жыл бұрын
From downloading pirated software i suppose.
@szymusu
@szymusu 3 жыл бұрын
I love how self-remove is "UnMonk"
@custume
@custume 3 жыл бұрын
I actually use ESET several years now and for me looks good, also not expensive, sure have some things that can take it down but mostly gets a lot of things
@pxdav
@pxdav 2 жыл бұрын
Stage 1: beautified Stage 2: beautified Stage 3: beautified Stage 4: beautifiee Stage 5: BEAUTIFIER
@trieulieuf9
@trieulieuf9 3 жыл бұрын
How does this malware author get it installed in victim machines?
@dar1n_fgp
@dar1n_fgp Жыл бұрын
I'm wondering that too (I'm new)
@420Schmat
@420Schmat 3 жыл бұрын
Amazing as always!
@creativereasons7588
@creativereasons7588 3 жыл бұрын
LIGHT MODEEEE AHHHHHHHHH MAKE IT STOPPPPP, and then you beef me for JavaScript.. low blows dude low blows xD Na for real keep it up dude these viddies are great
@ivanboiko8975
@ivanboiko8975 3 жыл бұрын
many thanks for content, man
@blazi_0
@blazi_0 3 жыл бұрын
line 220 in 4:51 it's variable but without name 🤔
@mihalachebogdan1
@mihalachebogdan1 3 жыл бұрын
Microsoft Defender better watch out
@FalcoGer
@FalcoGer 2 жыл бұрын
I think the simplest thing would simply be to rewrite the "eval" function to print instead. it would also be somewhat more secure since it might be called from other places as well.
@imroot2454
@imroot2454 3 жыл бұрын
Where can I get the original sample? :(
@rydmerlin
@rydmerlin 3 жыл бұрын
When does this actually trigger? When does it hijack the clipboard?
@paashaasXD
@paashaasXD 3 жыл бұрын
What if the maker of this scripts is watching this video xD "oh shiiiiii"
@mauritaniainjector3736
@mauritaniainjector3736 Жыл бұрын
Very Good my teacher 👨‍🏫
@jameselliot9114
@jameselliot9114 3 жыл бұрын
0:30 onions aren't spicy, John 🤦‍♂️
@killerskincanoe
@killerskincanoe 3 жыл бұрын
Is wscript enabled by default in win 10?
@mpcabete
@mpcabete 3 жыл бұрын
why did the developer used the "new function()" syntax in the first layers instead of an eval? it is an evasion technique?
@maxpowell3528
@maxpowell3528 3 жыл бұрын
Solid chance this is the reason why ! Also maybe just to throw off researchers.
@Freeak6
@Freeak6 2 жыл бұрын
It feels good and sad to see that these guys put so much efforts to obfuscate and encrypt the code, and you can just remove the eval function and let the computer decode all of it for you ^^
@theSidyous
@theSidyous 3 жыл бұрын
Could you try the notpron riddle - see how far you get?
@pedroneo4103
@pedroneo4103 3 жыл бұрын
do you have a discord server?
@eugene5096
@eugene5096 3 жыл бұрын
How they make people to download and run this script ?
@bhagyalakshmi1053
@bhagyalakshmi1053 Жыл бұрын
Why to file Wi-Fi hack the handling.
@BryceChudomelka
@BryceChudomelka 3 жыл бұрын
I would be interested in building something that automatically beautifies. We could use Go and an API call. Thanks for the content.
@bbowling4979
@bbowling4979 3 жыл бұрын
John, where do you get your malware samples from?
@guilhermebotossi
@guilhermebotossi 3 жыл бұрын
I was going to ask the same thing!!!! Hope someone answers!!!
@guilhermebotossi
@guilhermebotossi 3 жыл бұрын
maybe is something from virus total!!!
@guilhermebotossi
@guilhermebotossi 3 жыл бұрын
after asking some friends about this, I found this repo github.com/Virus-Samples/Malware-Sample-Sources
@regishbabu1790
@regishbabu1790 3 жыл бұрын
hey John, i am new to cybersecurity ..just subscribed
@yourfellowhumanbeing2323
@yourfellowhumanbeing2323 3 жыл бұрын
Malayali aano
@3xpl0i79
@3xpl0i79 3 жыл бұрын
@@yourfellowhumanbeing2323 alla
@grandmakisses9973
@grandmakisses9973 3 жыл бұрын
@@3xpl0i79 lla
@gotithowigetityoutube8144
@gotithowigetityoutube8144 3 жыл бұрын
Now what are you consider this kind of code malware spyware or adware
@yourfellowhumanbeing2323
@yourfellowhumanbeing2323 3 жыл бұрын
@@3xpl0i79 hehehe
@strong2147
@strong2147 3 жыл бұрын
hey everyone I was asking me one question, how can we get tha kind of Jscript/VBS/VBE/... files can someone help me thanks for your answers
@whtiequillBj
@whtiequillBj 3 жыл бұрын
I love how languages over lap -- di comando e controllo
@custume
@custume 3 жыл бұрын
great video 😉
@Bluscream
@Bluscream 2 жыл бұрын
Thanks John. You really inspired my to sit on my lazy ass and continue watching your videos!
@heizenbergwhite5669
@heizenbergwhite5669 3 жыл бұрын
Your the best men 🔥❤
@DarkAngel-ov2fu
@DarkAngel-ov2fu 3 жыл бұрын
I am surprised only eset detected it
@letsrugem
@letsrugem Жыл бұрын
i don't even understand it but I still keep watching. I don't know why.
@cloud7982
@cloud7982 3 жыл бұрын
I was laughing so hard as it went further and further down the loophole and when it got to stage 6 I was dying
@ieatpushpops
@ieatpushpops 2 жыл бұрын
I enjoy your videos because of the not-so-awkward silent moments.
@cweasegaming2692
@cweasegaming2692 3 жыл бұрын
I am once again asking you to beautify the code
@bhagyalakshmi1053
@bhagyalakshmi1053 Жыл бұрын
Thanks 🙏
@DawnBriarDev
@DawnBriarDev Жыл бұрын
Now if only it was this easy to find their current physical address. I'd go say hello to them, and introduce their backend to a soft viper.
@caleboleary182
@caleboleary182 3 жыл бұрын
I've heard of similar malwares that have a whole dictionary of addresses bundled with them, and will sub in the one that most closely matches the real one they're replacing. Spooky scary. Always check your addresses thoroughly, not just the last couple digits!
@theairaccumulator7144
@theairaccumulator7144 3 жыл бұрын
Was about to comment that whoever made this malware should've done exactly this.
@sandeepkrishna504
@sandeepkrishna504 3 жыл бұрын
Is there some tl;dr for this video?
@gauthamkrishna.s2912
@gauthamkrishna.s2912 3 жыл бұрын
Don't mind me, just keeping up the engagement.
@Californ1a
@Californ1a 3 жыл бұрын
Any plan to do the Wreath network? Would love another super long livestream like Throwback going through the whole thing.
@grandmakisses9973
@grandmakisses9973 3 жыл бұрын
Yes ^^^
@giovannitomczak6826
@giovannitomczak6826 3 жыл бұрын
Dude that box keeps disconnecting. I really hope he does it so the devs can see how bad the box is.
@lawalargungu4257
@lawalargungu4257 3 жыл бұрын
I'm still thanking everyone who recommended *4matic_hack_* here, you all are the real Life savers,my business account is back finally with his help.
@danthe1st
@danthe1st 3 жыл бұрын
In other words: Don't use js for malware...and also don't use other languages for malware
@pXnEmerica
@pXnEmerica 3 жыл бұрын
Why write a tool to unpack it? Write a tool from the parser/processor and list/breakpoint when functions happen. You run the code, it tells you it tried to access these methods, this many times. Skip a ton of obfuscation possibly and get more to what it's actually trying to do. When it tried a shell.run, print the commands, when it tries a sendhttp, don't and print the request.
@alvarocarrascosapenabad4355
@alvarocarrascosapenabad4355 3 жыл бұрын
A tool to unpack it is obviously much easier to program than what you are suggesting, but this is indeed a great idea!
@leuropaische
@leuropaische 3 жыл бұрын
its march 10th 2020
@metalpachuramon
@metalpachuramon 3 жыл бұрын
Wait, so is there a way to report your stolen btc, or do these people simply get away with it?
@aoufiayman6274
@aoufiayman6274 3 жыл бұрын
cryptocurrencies transactions do not have a third party to manage them ( like a bank ) so yeah they simply get away with it
@randykitchleburger2780
@randykitchleburger2780 3 жыл бұрын
1:15 almost slipped out a BULLSH**
Rick & Morty MALWARE!? - sLoad - PowerShell & VBScript
30:31
John Hammond
Рет қаралды 60 М.
HTA JScript to PowerShell - Novter Malware Analysis
1:24:19
John Hammond
Рет қаралды 97 М.
Провальные провалы
29:25
GreenGrass
Рет қаралды 102 М.
HAFNIUM - Post-Exploitation Analysis from Microsoft Exchange
1:18:33
John Hammond
Рет қаралды 139 М.
Cryptocoin Miner - Unpeeling Lemon Duck Malware
1:01:02
John Hammond
Рет қаралды 96 М.
Blockchain 101 - A Visual Demo
17:50
Anders Brownworth
Рет қаралды 2,7 МЛН
FAKE Antivirus? Malware Analysis of Decoy 'kaspersky.exe'
1:28:19
John Hammond
Рет қаралды 277 М.
Node.js: The Documentary | An origin story
1:02:49
Honeypot
Рет қаралды 686 М.
How the Best Hackers Learn Their Craft
42:46
RSA Conference
Рет қаралды 2,6 МЛН
Clean Code is SLOW But REQUIRED? | Prime Reacts
28:22
ThePrimeTime
Рет қаралды 334 М.
you need to learn Kubernetes RIGHT NOW!!
29:34
NetworkChuck
Рет қаралды 1,2 МЛН
Mozi Malware - Finding Breadcrumbs...
50:16
John Hammond
Рет қаралды 201 М.