Hacker: Turns code into obfuscated alphabet soup 42:40 Also hacker: Adds helpful code comment to let you know this line is for Firefox
@awli88613 жыл бұрын
hecker XD
@mycotina64383 жыл бұрын
I love it so much how you speak out loud what you're thinking as you work through the code. I think this kind of video is a lot more useful than tutorials, because we get to see the thought process and from where the ideas come from trough the trials and error.
@Irisilol3 жыл бұрын
When John goes "OH NOOOOOOO" you know the code is evil.
@litmussales9750 Жыл бұрын
I'm happy seeing you having fun with my codes. I love that part where you said OMG!!!
@erin15693 жыл бұрын
Are people really complaining about python? It's incredibly comfy. It's often as simple as saying: "Jarvis, convert this code into recognizable commands", but with a few extra words.
@benjaminthelen14133 жыл бұрын
Does anyone besides me else just watch him even though you have no idea what hes doing?
@1FelixxileF13 жыл бұрын
Same
@justinboss41313 жыл бұрын
@@1FelixxileF1 same here buddy
@joancasals43653 жыл бұрын
same here
@StreuB13 жыл бұрын
Yep, absolutely no idea what he's doing but its awesome to watch brilliant people work their jam.
@codydietrich42468 ай бұрын
Same here, but he makes me wanna learn!
@BlackDragonCZ_alt3 жыл бұрын
23:52 john think: "John stop using python" Me: "John keep using python, thanks" :D
@samuelmiller16913 жыл бұрын
God I love this. I started watching your videos thanks to the KZbin Algorithm and had no idea what you are doing. Now I am starting to pick up on things here and there. More more more!
@hunterbodell11293 жыл бұрын
I hate that these are so good that I wake up at 6 for them
@murkdurk89613 жыл бұрын
You might need to rethink your priorities🤭
@alexlefevre82263 жыл бұрын
I don't wake up early to watch, but I do wake up to schedule the download, automagically chop the resolution down a bit, and finally upload to a part of my cloud storage where I store every one of these for the future. Kinda silly... But I am using these videos as a set of walkthroughs and have learned an "asston" so far. John does such a good job with these! His ah-ha moments have become the center of mass of which I orbit around. Keep it up John... Please!!! Although I know you were busy with the huge ransomware attack recently. Your name was in probably a dozen of the 15 I read. As if I didn't already respect the crap out of you
@salmqN3 жыл бұрын
@@murkdurk8961 Nah, completely agree with him
@murkdurk89613 жыл бұрын
@@salmqN not saying this isn't important, but if you set your alarm to wake up for this in the morning, you might need to get a job
@salmqN3 жыл бұрын
@@murkdurk8961 I wake up before 6:00 most days regardless of a video or not, and what does having a job got to do with watching anything xD
@slybandit81178 ай бұрын
That was some slick coding to get those vars into the correct places! Well done sir, stuff like that is why I love this channel!
@cheshirecat65193 жыл бұрын
I don’t know **** about programming language and malware decoding and reverse engineering and stuff but It’s the 5th video I watch this week on your channel. Just saying.
@sebastianinnez33953 жыл бұрын
surely John teaches us HOW to obfuscate, looks awesome!
@jannikmeissner3 жыл бұрын
At 39:38 I was like "yeees I did suspect 2031 would be the port the C2 server is running on" and it felt sooo good when this suspicion was met.
@jesseramsell18953 жыл бұрын
"What is that, Jurassic Park? I should know, I'm John Hammond." i died 😂
@rrittenhouse3 жыл бұрын
I never even realized the similarity on the name LOL. I've even made replica John Hammond Cane's for people... I should have caught that 🤣
@snake1980eyes3 жыл бұрын
that filename actualy is from romanian language and it translates to INVOICE in english
@phyotyla3 жыл бұрын
Apparently the same in Swedish and Spanish among others
@michaelvandenheuvel3173 ай бұрын
Thank God for good people like you.
@Roxas99Yami6 ай бұрын
great video 10/10 this helped me a lot deobfuscate a .js script i ripped from a site
@BloodBornKnight2 жыл бұрын
The king in cyber security huge fan.
@TobiasTimpe3 жыл бұрын
JScript is one of my favorite languages.
@eklypzn3 жыл бұрын
Hilarious. I'm wearing that shirt right now.
@_JohnHammond3 жыл бұрын
IT'S SUCH A GOOD SHIRT
@zimboiii90253 жыл бұрын
@@_JohnHammond WHAT SHIRT IS IT
@rungoranga63413 жыл бұрын
Malware Analysis -videos are the best. 👍
@happyked3 жыл бұрын
Great content as always. Are you planning to make a video about Kaseya and REvil?
@mustafaismail57733 жыл бұрын
too inspiring, despite I'm in totally other field of work actually now I'm involved in my free time in coding with python & analysis of C applications since I started watching you almost one year ago. High respect brother keep it up always !!
@jkobain3 жыл бұрын
No, the syntax highlight in Sublime Text was working fine, the problem was in escaping borderline quote symbols, for instance.
@Colaholiker3 жыл бұрын
Seeing this, I am so glad that my computer would not be vulnerable to this. I doubt, I can apt install WSH. And even if I could, I would not. :-)
@vexraill3 жыл бұрын
These are always so fun to watch, thanks for sharing your research with us!
@kaihuang54203 жыл бұрын
no way. I am literally learning OSEP materials chapter where they go over Jscript and C#.. The big data has gotten me
@ChymekJR3 жыл бұрын
Your work inspires me! This is so cool
@gustinstamatinos99103 жыл бұрын
I could sit back with a beer and watch these all month. ...okay, a few beers.
@ViperDerKranke5 ай бұрын
12:20 says it all
@bendavis84613 жыл бұрын
Oooo woow Malware Analysis, great stuff.
@ikhmalfahmi93083 жыл бұрын
Reallyy missing your ctf videos :,((((((((
@logiciananimal3 жыл бұрын
"Please commit Sudoku"? Not while I'm supposedly at work! This video is at least job related sort of otherwise.
@larziel71073 жыл бұрын
Thanks to you I'm trying to learn Python myself! :)
@LouisSerieusement3 жыл бұрын
I think you were slightly peaking your audio interface sometimes But thank you so much, your videos are very informative !
@KeithGriffiths3 жыл бұрын
Great video John. Good walk through.
@bosch53033 жыл бұрын
Fun fact. Factura in romanian means invoice
@nordgaren23583 жыл бұрын
Great reference to Jurassic Park!
@drasticwarrior53572 жыл бұрын
@John Hammond, Do you ever go live?? and if so may i please ask what your preferred platform is
@AnthonyBlakley3 жыл бұрын
This was quite the episode..
@theragequitgamer2463 жыл бұрын
I'm afraid to scan the qr code on that shirt lol
@viv_24893 жыл бұрын
😂
@camerontgore3 жыл бұрын
I get a good chuckle everytime you say Show-toast 😂
@DD-hn2jr3 жыл бұрын
First I saw somebody using pkill in real life
@DahlFreeman3 жыл бұрын
Great video!!! So much fun to watch
@fordorth3 жыл бұрын
This was a great video... very fast!
@andrewloucks65683 жыл бұрын
Anyone ever wonder why the bears need so much toilet paper in the charmin advertisements that keep playing ??
@sjslife3 жыл бұрын
I fookin love u J, loads of love from UK
@dustyboyle3 жыл бұрын
Thanks for the video. Very cool
@jimo84863 жыл бұрын
What I use to look up an IP I use check-host and it will tell u all about the hosting
@realMattGavin3 жыл бұрын
I think John was the one who stole the $600mil of ETH and was trying to bring us valuable ententertaining content. Also the way that John acts reminds me of the somewhat "innocence" of the ETH hacker... like "uh, oh, what did I do?" Then returns it all back.
@pbezunartea3 жыл бұрын
Great video! Amazing job!
@marlonius05 Жыл бұрын
interesting.. still learning... h1senzz3... Hisense? So Huawei/Honor???
@guky6673 жыл бұрын
THIS IS SO FRICKIN COOL, WTF!!!
@jkobain3 жыл бұрын
I've never used NodeJS to casually run JS manually, rhino is a thing, IMO.
@dowLoveTap3 жыл бұрын
just found this channel, i'm sevral hours in.. oof
@MartinHaunschmid3 жыл бұрын
Now I REALLY want to know what 'show-toast' is. EDIT: Now I do. Don't know what I expected.
@awndolznmowdlzkwndznwua3 жыл бұрын
What was it, Martin?
@balazsolah19763 жыл бұрын
What was it, MARTIN?
@MartinHaunschmid3 жыл бұрын
@@awndolznmowdlzkwndznwua I guess an endpoint for returning Messages to the C2
@cyrussecurity3 жыл бұрын
Toast to "show-toast" :D
@johtodev3 жыл бұрын
love these videos
@claudiafischering9013 жыл бұрын
I found a wired server with a bunch of applications from a doc vba file. But I think this server should be offline now. I think I delete the file because the file which has been downloaded was not on the server. All I know is that target was windows - but it was sended up to a MAC User - that is a little bit stupid I guess. Thanks for video - I have a lot of fun.
@corbezzz3 жыл бұрын
KZbin algorithm things
@Dooglet2 жыл бұрын
maybe I missed it but how does this usually detonate?
@nextlevelbruh8273 жыл бұрын
though, vim is incredible 😉
@huongkieu83353 жыл бұрын
John can you give me the link of first file in this video?
@gdk1113 жыл бұрын
Thank you John, really interesting 😊
@jkobain3 жыл бұрын
«Lua» stands for «moon», while the UAC actually mined Mars…
@real1cytv3 жыл бұрын
Well, I'm not shouting at my monitor, but with the stuff you do, I think VScode(/VSCodium) would be the better fit...
@jimmlmao3 ай бұрын
you know there is a thing called a for loop john
@razaullahkhan8099 Жыл бұрын
NICE ANDROID RUNNING NOW THANKS
@crazylegs853 жыл бұрын
vim...vim...vim! VIM!!!
@dddddddddavis3 жыл бұрын
I always watch your reviews and always wonder: what is usually your next step after the analysis? do you follow up reporting the c2 server? if you eventually find out an unreported malware will you follow up with a report? just wondering because these actions can help users in the end of the day. - also, thanks for putting out always some good content
@SuiGio3 жыл бұрын
Hey man, I have a obfuscated js code which creates a chrome extension for a game. I was wondering if you would like to share that with you, see if there's a malware in it? Would really like to see whats beneath it, since I've been using it many years now. Let me know how to reach out to you. Cheers, great content!
@_JohnHammond3 жыл бұрын
Yes please, always happy to take a look through some weird code -- you can email me with the address in the description :)
@userou-ig1ze3 жыл бұрын
didn't catch how it deploys, do you have to run the file?
@CarRamrod-uf2ub3 жыл бұрын
That 1 dislike must have been a mistake.
@baxsm3 жыл бұрын
that was from the hacker :/
@fra18973 жыл бұрын
love the bash at vim fanboys
@tsustyle62633 жыл бұрын
SHOW TOAST!
@thewhat42283 жыл бұрын
Please where can I get the code or download link to this
@thowbikdustan65153 жыл бұрын
Hey john, can you just upload the malware file anywhere and provide link. AHH maybe your github is fine !!
@cat-boy13573 жыл бұрын
38:08 - "OwO what is this?"
@btno2223 жыл бұрын
Is it good nsa
@whatthefunction91403 жыл бұрын
How would the js ever reach out of the browser?
@carterplasek4983 жыл бұрын
He references this in a few other videos, this isn't Javascript, it is JScript, which is a confusing way of saying it is Microsoft's Javascript, a scripting language using the same (or very similar) syntax to javascript, but does windows stuff and can run on windows.
@stefank23873 жыл бұрын
Finally, great content
@isosthenie82712 жыл бұрын
Python is a good language. Bite me. :D
@crystal_royal34053 жыл бұрын
Epic
@bellshoe28943 жыл бұрын
I love watching Justin Roiland hack the NSA
@0xhex3 жыл бұрын
Could you please share code source ?
@PreetisKitchenltr3 жыл бұрын
Yay!!! I am first like as well as comment! Great Content Sir!
@magnum_dingus3 жыл бұрын
John, keep using python.
@magicball603 жыл бұрын
Share code :) hehe would love to take a look at the rdp module
@daryll46453 жыл бұрын
lol Commit Sudoku
@LycanEnforcer3 жыл бұрын
Yeah, regex with that many characters is fun isn't it? Usually better to just open up python and write a script to replace characters in a document.
@hackingismylife21673 жыл бұрын
Please I need your help
@gorway68073 жыл бұрын
Why is he so scared to say “slaves” when it’s a pretty common computer term with a specific meaning? Cool content tho
@heraclitus78932 жыл бұрын
KZbin algorithm demonetisation I suppose
@techysecurity41073 жыл бұрын
Javascript = 😌😌
@MarcinGrobelkiewicz3 жыл бұрын
Can u help to how to do referendum ?how to do real voting ? How to stop fake plandemy
@Lemon_Inspector3 жыл бұрын
How demoncracy is formed?
@JNET_Reloaded3 жыл бұрын
mics way too close sounds like your shouting!
@pinkeye003 жыл бұрын
cntrl+z
@RyzekZ00083 жыл бұрын
1:02:10
@Tedd7553 жыл бұрын
More analysis/reverse engineering, less googling please. Do it off-camera, and if there's any insights, give a summary. I don't like watching someone else browse. I can do that myself.
@viv_24893 жыл бұрын
@@miyu1424 yeah agree, he is working through and displaying it to us at the same time... I think his concern is that more deep code analysis should be done for C# exe's or binaries in video but that would take immense lot of time...
@issecret13 жыл бұрын
No, thanks. Then if I don't know something he uses I get intimidated and have no idea how he found it