Rick & Morty MALWARE!? - sLoad - PowerShell & VBScript

  Рет қаралды 60,291

John Hammond

John Hammond

Күн бұрын

Пікірлер: 198
@_JohnHammond
@_JohnHammond 3 жыл бұрын
Some incredible folks in the Discord (shout out to you, @db!) helped fill me in that this is actually the "sLoad" malware family. Good links for further reading and exploration: svmvzypnse2tk4cg4e4l32t6oy-adwhj77lcyoafdy-cert-agid-gov-it.translate.goog/news/malware-sload-sfrutta-pec-[…]alevolo-annidato-in-doppio-zip/ twitter.com/luc4m/status/1331550804990373890 www.microsoft.com/security/blog/2019/12/12/multi-stage-downloader-trojan-sload-abuses-bits-almost-exclusively-for-malicious-activities/
@TwinTailTerror
@TwinTailTerror 3 жыл бұрын
ya unless you cant talk in any channel and you point that fact out and the admin aka you kicks you why bother to invite ppl to discord if they cant assign there own roles and speak? and if they do point that out via pm you just boot them cuz it breaks the rules i mean how else u gonna get something fixed kinda dooshy move guy.
@bobmclane3017
@bobmclane3017 3 жыл бұрын
Love the ilSpy and Malware decoding but equally miss your CTF (tryhackme/HTB etc) :) please keep both coming John
@K-Anator
@K-Anator 3 жыл бұрын
@@TwinTailTerror Dude. Did you just forget how to read when you joined the server? I joined purely out of curiosity to see just how daft you were. And oh boy, you're daft af. If you read two sentences, you would have been able to join in discussions no problem. You had to type one command in the welcome channel, and react to one message in the roles channel. It's literally that simple.
@ddjazz
@ddjazz 3 жыл бұрын
Would be nice to see qn update with a follow up video part 2 :)
@its_code
@its_code Жыл бұрын
Does vbscript still used in today modern windows computer like 11 . Vbscript default compiler by default installed in windows 11
@eklypzn
@eklypzn 3 жыл бұрын
I think there's a happy medium that you can find between this and your normal long form videos. I think the way this was done would be fine occasionally, but I do enjoy going on the adventure of the long form videos.
@worm628
@worm628 3 жыл бұрын
I agree with this comment.
@errr-iw4lz
@errr-iw4lz 3 жыл бұрын
I agree with this comment.
@styleee1337
@styleee1337 3 жыл бұрын
I agree with this comment.
@dosu360
@dosu360 3 жыл бұрын
Same here. The "live" version makes me feel as if we are solving it "together" in a way.
@kill3rvill3
@kill3rvill3 3 жыл бұрын
agreed
@MrKuma352
@MrKuma352 3 жыл бұрын
I really like the educational style of the normal videos. Doing it on the fly and taking a look into your thought process is really entertaining
@JeeliBeeli
@JeeliBeeli 3 жыл бұрын
This malware had a disturbing lack of tangent functions
@yigglesmoto
@yigglesmoto 3 жыл бұрын
the "Try Harder" sticker above you while slamming your head into the door fits perfectly. love these shorter style videos, don't always have the time to watch your full 1h+ long videos. The editing style was refreshing too
@Lampe2020
@Lampe2020 Жыл бұрын
I didn't expect you to make such a funny video, I always thought you'd just make very professional videos, no big jokes, just get the malware into pieces. Very nice to lighten that up with some jokes!
@viv_2489
@viv_2489 3 жыл бұрын
We do like older style as well :), going through slowly, trying different things to get over
@MrDawgTagz
@MrDawgTagz 3 жыл бұрын
Just wanted to help the algorithms a bit, also wanted to let you know you've been a big inspiration for me. I went from watching your videos and not understanding anything, to now running my own kali machine and having lots of fun!! Thanks for the content, keep it up!
@galaktoza
@galaktoza 3 жыл бұрын
Did you just blow up in subscribers? Well done man, deserved!
@tuckerward9844
@tuckerward9844 3 жыл бұрын
I like getting to see your creativity come through some more with the editing, but also still personally prefer the long-form (less edited) videos just as personal preference. I'm watching either way.
@BrainD22
@BrainD22 3 жыл бұрын
This video really made me laugh! I'm normally more a fan of the videos where you go in blind to understand your thoughtprocesses but that editing was great. A good mix would be awesome!
@mef9327
@mef9327 3 жыл бұрын
For the algorithm: I just found this channel. It's fascinating even though I didn't understand any of it. I read a couple of "Visual Basic for Beginners" books and wrote a little app for myself. I know what declaring a variable is and what a function is. So, I understood about 4 sentences herein (without understanding the specific significance or context). Still a cool channel. Subbed. As for long-form vs short form, I'm too new and too inexperienced to offer any meaningful feedback. That said, *generally,* I like long-form on technical, exploratory/problem-solving subjects (i.e. not meant to be a tutorial or introduction to a subject). It seems to help to pick-up contextual clues as a thought process is being developed in real-time.
@johnwesolowski1134
@johnwesolowski1134 3 жыл бұрын
I liked this style. Still had the educational parts which are cool yet was more condensed for easier viewing. Good job on the editing :D
@real1cytv
@real1cytv 3 жыл бұрын
While we are on the topic of Rick and Morty Malware: Apparently there is a video file with an episode (or what claims to be) of rick and morty, which is actually a coin miner. That might be interesting to look at. Also, I really enjoyed the edited style
@StefanPoggenpohl
@StefanPoggenpohl 3 жыл бұрын
I very much enjoyed this style of video. This is much nicer to actively watch while I let the other long videos mostly run on a side screen when doing chores or workouts.
@lrmarquez80
@lrmarquez80 3 жыл бұрын
Watching your videos on inspecting code helped me a great amount in my first hacking competition held by the National Cyber League. Thanks John! I found out its important to stay up to date on zero days, and other exploits being found and your videos are helping me keep up with things......ps your video on the sudo vulnerability was gold!!!
@Konym
@Konym 3 жыл бұрын
3 whole days in a row of malware analysis. This is amazing.
@simonebrazioli2206
@simonebrazioli2206 3 жыл бұрын
Love both this edited video and your usual style! But your usual style in which you go through the code 'with us' is more educational and informative, I think. But, man, love me some memes!
@lfionxkshine
@lfionxkshine 3 жыл бұрын
Someone on r/cissp mentioned your name the other week. Started watching your vids to see what's up, now you are a part of my morning routine. Love your stuff, helps me be a better admin
@Tw3ntyyyy
@Tw3ntyyyy 3 жыл бұрын
Third in a row nicee, getting an evening routine
@shaank0647
@shaank0647 3 жыл бұрын
Super informative and funny, cant ask for much more in regards to keeping viewers engaged!
@RyanRath
@RyanRath 3 жыл бұрын
It was a great vid but honestly I really enjoy the raw videos and walking through the thought process with ya. so if it cuts hours off your day, Raw all the way man
@deeznutz393
@deeznutz393 3 жыл бұрын
the editing on this one is IMMACULATE
@JustinC-thetacom
@JustinC-thetacom 3 жыл бұрын
Have you tried querying the servers with different user agent strings like the one used by BITSAdmin (Microsoft BITS/7.5)?
@Timooooooooooooooo
@Timooooooooooooooo 3 жыл бұрын
I enjoyed this format. Made it a lot easier to find time to watch this
@DePhoegonIsle
@DePhoegonIsle 3 жыл бұрын
Honestly... I'd really suggest setting up a 'network cache/proxy' for a entirely shielded VM, and running the methods & seeing what the calls end up being & what ends up being sent & received. -- it's kinda how I captured several PS3 game installations to be stored ( that I legitimately owned ) I know it's kinda reckless.. but perhaps a dedicated machine of windows 10.... behind a proxy cache server w/ a very strict in/out through said proxy only might be a good way to capture the raw files & data flying back & forth... and to see if any... which tricks are used.
@glarg811
@glarg811 3 жыл бұрын
Love your work man! You inspire me to try harder! Can't wait!
@asbestinuS
@asbestinuS 3 жыл бұрын
Hi! I am thankful for your videos and this one as well. However like other commenters already said, I'm personally more a fan of the longer videos where you find stuff with your initial reaction and then following your thought process. They are already very entertaining for me (I work in IT but more as the Windows Administrator) and honestly I'm pretty shocked what is possible. But it's very interesting! Also I wanted to praise your Hafnium Exchange Server analysis, very good!
@noahpeltier
@noahpeltier 3 жыл бұрын
I’m sure someone has suggested this already but It’s possible there is a key used in the code somewhere that passes to the GET request in the headers. Might use a Basic auth method.
@BloodyfreezeYT
@BloodyfreezeYT 3 жыл бұрын
I came cause it was a suggested link for Rick and Morty. I subbed cause it was a great breakdown. Love the format. If it's a large time consumer, maybe cut down the frequency of the fun stuff, but was enjoyable.
@nullp01nter20
@nullp01nter20 3 жыл бұрын
I really love this method. It's funny and informative. I hope you continue. :)
@vgarzareyna
@vgarzareyna 3 жыл бұрын
Wish I could wake up early enough to watch the premier
@LeonVQZ
@LeonVQZ 3 жыл бұрын
it was a fun video! I liked the style. I like the shorter video format, but I don't mind a 2 hour long video from time to time in the weekends.
@ApfelJohannisbeere
@ApfelJohannisbeere 3 жыл бұрын
For very long episodes I really really love the summary! Though for sure most will want to have very interesting stuff full 'verbose' of these interesting sections (especially those that you haven't covered already with your other videos)!
@itairon9338
@itairon9338 3 жыл бұрын
I LOVE this new approach and style, i hope you do more of these
@rodpombo598
@rodpombo598 3 жыл бұрын
I like how your youtube skillz are growing!! thanks for all the great content (even for a noob like me!)
@TrueBenja14
@TrueBenja14 3 жыл бұрын
Love the edited format. Great video as always
@joyzyyy7810
@joyzyyy7810 3 жыл бұрын
Yooo, i love the new editing style, keep it up
@cscogin22
@cscogin22 3 жыл бұрын
Awesome video man, I enjoyed the new approach, entertaining and moved along at a good pace! Also very funny!
@DavidAlvesWeb
@DavidAlvesWeb 3 жыл бұрын
Now this is my kind of malware 😎
@Sawta
@Sawta 3 жыл бұрын
Personally, I like it when you figure it out on camera, but whatever helps you keep putting out content works for me. I'd be interested to know: for people who want to start examining Malware the way you do, what steps should be taken to stay safe-ish? I realize doing it in a VM is a must, but any other major points?
@yossig7316
@yossig7316 3 жыл бұрын
I like the new style of video, but I love the normal ones you always do more ! This was very fun though :-) Thank you!
@AgLenoir
@AgLenoir 3 жыл бұрын
Love this segment and the style of made it fun as well as informative
@DHIRAL2908
@DHIRAL2908 3 жыл бұрын
The meme editing was hilarious!😆
@WhyDoIPosttt
@WhyDoIPosttt 3 жыл бұрын
28:16 ... enhance.. Enhance... ENHANCE *CSI Zoom Enhance*. Great video John keep it up!
@otesunki
@otesunki 3 жыл бұрын
2:17 that INSTANTLY jumps out at me as c:\windows\
@kalote86
@kalote86 3 жыл бұрын
The montage level of this video is hilarious and fricking awesome. Thanks a ton o/ ... The content is also good :)
@ca7986
@ca7986 3 жыл бұрын
Ahaha love this new editing! ❤️
@dreamz420
@dreamz420 3 жыл бұрын
that video was well cutted, good one john
@caleboleary182
@caleboleary182 3 жыл бұрын
Nice editing my man. Made me laugh out loud several times.
@chrisbishop6928
@chrisbishop6928 3 жыл бұрын
I will never be able to view the plumbus the same after this one
@Red4mber
@Red4mber 3 жыл бұрын
i LOVE this new style of videos Keep it up, it's excellent !
@Phaix
@Phaix 3 жыл бұрын
You could check if they implemented an UserAgent check. If i want to limit access from spiders/robots or normal browsers i would implement a check for the UserAgent
@alexandrecovolan8145
@alexandrecovolan8145 3 жыл бұрын
Pretty neat the new style of video. Loved it.
@romanokeser
@romanokeser 3 жыл бұрын
Yo this was a neat video, not too fast, not too slow. I like it a lot.
@humanflybzzz4568
@humanflybzzz4568 3 жыл бұрын
This was oddly fun and satisfying. I'm really bad at powershell and vbs, but this gives me an itch to learn it :)
@amaz404
@amaz404 3 жыл бұрын
“Morty, I’m a drunk - not a hack!” ~Rick Sanchez, season 3 episode 4
@omarora7119
@omarora7119 3 жыл бұрын
New channel logo is great !
@sameurbenhmouda1456
@sameurbenhmouda1456 3 жыл бұрын
About the video style and format.., I think We'll still watch ur videos either it's a 30 min video or more than an hour xD just do whatever makes u feel comfortable xP
@tordanielsen8458
@tordanielsen8458 3 жыл бұрын
Like the mix of edited and live :D
@lepsycho3691
@lepsycho3691 3 жыл бұрын
That was nice, a little bit easier on the time and overall digestibility, but I think it makes it feel more real when we experience it as you go and see the thought process behind. Maybe you could do twice the content, one livestream of the long style and one edited like this one? What do you think?
@PanoptesDreams
@PanoptesDreams 3 жыл бұрын
I really liked the long format
@h8handles
@h8handles 3 жыл бұрын
I stand by my point you are making great vids each time better
@Mike-bs5pi
@Mike-bs5pi 3 жыл бұрын
Did you try setting user agent and referrer for the curl? Dunno what if any bits admin uses.
@vasylboyko7299
@vasylboyko7299 3 жыл бұрын
After watching your malware analisis videos i decided to disable VBScript on my machine. I also overwrote Invoke-Expresion cmdlet in powershell. Seriously, if there at least a single malware, which uses powershell and doesn't use IEX?
@charmquark0
@charmquark0 3 жыл бұрын
Well you video is awesome. I love your content. I do hope that you do not keep spending more and more time editing and then get burnt out.... Please dont burn out :)
@crypt1c_mdp
@crypt1c_mdp 3 жыл бұрын
i REALLY like those VBScript malware debunking vids great content keep it up
@dean8012
@dean8012 3 жыл бұрын
6:47 I have no idea why that made me laugh so hard.
@hydejel3647
@hydejel3647 3 жыл бұрын
this style is fun but i think the old one is more valuable as a learning resource
@abdeabdc6964
@abdeabdc6964 3 жыл бұрын
feedback: the editing is nice and funny
@hasmukhlalji6102
@hasmukhlalji6102 3 жыл бұрын
i like this video very informative and entertaining at the same time very nice
@TheOnymousillusion
@TheOnymousillusion 3 жыл бұрын
John, Thank you for everything that you do! I'm new to this space and was curious about the URLs you find in malicious code. This could be my lack of understanding about how curl works and if it is I'm sorry, but aren't you worried about your public IP address being captured by these servers? This is assuming you're not using some kind of proxy in the background we don't know about. Thank you again for sharing the knowledge.
@fredb5626
@fredb5626 3 жыл бұрын
Hey John, love you content man - dont ever change, you insipre me and give me drive, so thank you ❤
@dutchprime1488
@dutchprime1488 3 жыл бұрын
I like this new style of video!
@alexanderwidgren8821
@alexanderwidgren8821 3 жыл бұрын
great video, love the new editing style too
@hamzarashid7579
@hamzarashid7579 2 жыл бұрын
Video editing is amazing!!
@WatsonInfosec
@WatsonInfosec 3 жыл бұрын
This was awesome please keep it up John, thanks!
@_dot_
@_dot_ 3 жыл бұрын
Let's boooost this channel into everyone's recommend videos!
@ibnsaltus
@ibnsaltus 3 жыл бұрын
this style is so much better :)
@piolix0004
@piolix0004 3 жыл бұрын
Hah some fun editing this time, I like it.
@StanLTU
@StanLTU 3 жыл бұрын
Dude I will watch all your videos
@Basieeee
@Basieeee 3 жыл бұрын
These vids keep delivering😍😍
@squirrel1620
@squirrel1620 3 жыл бұрын
Maybe look at the request bitadmin creates when it runs with that option. Maybe the web server is expecting something in the headers, like user-agent
@Psychopatz
@Psychopatz 3 жыл бұрын
Sir, great video as always. Btw can you please decompile the infamous kmspico, I've used that stuff a long time ago and I want to know how it works logically. That would be awesome.
@Serverfrog
@Serverfrog Жыл бұрын
As you saw a Certificate: Maybe its using Client-Certificate authentication with an nginx config like ssl_verify_client optional; if ($ssl_client_verify != "SUCCESS") { return 403; }
@malakasitchan
@malakasitchan 3 жыл бұрын
I love this format! gosh!
@philipbraatz1948
@philipbraatz1948 3 жыл бұрын
It was good, IDK if it is worth the time to edit. I just want it cut down some from the normal vids
@MALACHAI39
@MALACHAI39 3 жыл бұрын
@ 5:40+ Dude, that is funny :)
@makkam7575
@makkam7575 3 жыл бұрын
You can try using requests in python I am no expert but you can try making a post request with the json argument and put random things in it. Also we dont know if there's a specific header needed or something. But in my opinion woth a try. Would highly recommend using jupyter or #%% in vscode to do so. If not you can try using postman.
@parmleyhunt
@parmleyhunt 3 жыл бұрын
Love your videos but this one was gold couldnt stop laughing
@lambdaboy-29
@lambdaboy-29 3 жыл бұрын
Wow I l
@alincraciunescu
@alincraciunescu 3 жыл бұрын
Super! Thank you!
@PaulGuerra74
@PaulGuerra74 3 жыл бұрын
You can use client certificates as an authorization method, maybe that's the $Encrypted stuff, You should try adding that in the request headers.
@foxdk
@foxdk 3 жыл бұрын
Really wish this video was done live. That being said, I still love your vids. But you scrambling around, trying to figure out the try-catch issues, would actually have been very interesting.
@finthefail9599
@finthefail9599 2 жыл бұрын
he did very serious research there
@arronk3
@arronk3 3 жыл бұрын
holy jesus another video, lets go
@Lars-ce4rd
@Lars-ce4rd 3 жыл бұрын
30:08 ah yes, I see it too
@chedrgamedev
@chedrgamedev 3 жыл бұрын
Nice new style ... I can feel the effort and hard work on this video. Well done :)
@daniel173880
@daniel173880 3 жыл бұрын
Man I love your videos!!!!
@jht5225
@jht5225 3 жыл бұрын
I like this vid but if I had to choose between this style and the one before this. I definitely prefer the other one
Information Stealer - Malware Analysis (PowerShell to .NET)
47:56
John Hammond
Рет қаралды 53 М.
Mozi Malware - Finding Breadcrumbs...
50:16
John Hammond
Рет қаралды 201 М.
We Attempted The Impossible 😱
00:54
Topper Guild
Рет қаралды 56 МЛН
Support each other🤝
00:31
ISSEI / いっせい
Рет қаралды 81 МЛН
It works #beatbox #tiktok
00:34
BeatboxJCOP
Рет қаралды 41 МЛН
Мясо вегана? 🧐 @Whatthefshow
01:01
История одного вокалиста
Рет қаралды 7 МЛН
VBScript & ILSpy Analysis of a RAT
1:05:19
John Hammond
Рет қаралды 53 М.
Cryptocoin Miner - Unpeeling Lemon Duck Malware
1:01:02
John Hammond
Рет қаралды 96 М.
SQLite Blind SQL Injection - HackTheBox Cyber Apocalypse CTF
35:25
John Hammond
Рет қаралды 72 М.
Discord Malware - "i hacked MYSELF??"
58:21
John Hammond
Рет қаралды 196 М.
DEF CON 30 - Sam Bent - Tor - Darknet Opsec By a Veteran Darknet Vendor
48:29
What Enterprise-Grade malware looks like
20:09
Eric Parker
Рет қаралды 72 М.
I Redesigned the ENTIRE YouTube UI from Scratch
19:10
Juxtopposed
Рет қаралды 1 МЛН
Spying on Scammers
22:26
John Hammond
Рет қаралды 48 М.
Making the Matrix Screensaver in C on a PDP-11/83
14:42
Dave's Garage
Рет қаралды 55 М.
We Attempted The Impossible 😱
00:54
Topper Guild
Рет қаралды 56 МЛН