Тёмный
Ryan Weil
Ryan Weil
Ryan Weil
Подписаться
Комментарии
@wittingsun7856
@wittingsun7856 5 часов назад
This guy needs to create a malware course and get big money from it
@LinuxIsBetter43
@LinuxIsBetter43 6 часов назад
Beginner RE & MA - you've earned a sub from me :). Was a bit too fast to follow, but I guess that's not a beginner malware as well.
@kylec.5476
@kylec.5476 18 часов назад
What keyboard are you using?
@RyanWeil-r1n
@RyanWeil-r1n 14 часов назад
G413 Carbon
@johnxina1681
@johnxina1681 19 часов назад
need to learn about breakpoints myself someday
@RyanWeil-r1n
@RyanWeil-r1n 19 часов назад
I hope i gave an understandable explanation of why I used a hardware breakpoint. Let me know if there was anything you didn’t understand
@RyanWeil-r1n
@RyanWeil-r1n 19 часов назад
Basically, if you are decrypting some bytes that are going to be executed and you put a normal breakpoint on those bytes intending to be hit once the instruction pointer is there, it will end up decrypting incorrectly since what a software breakpoint does is it injects an int3 instruction behind the scenes. So you are actually temporarily changing the content of whats there. So when it goes to decrypt, its going to try and decrypt the changed instruction and will decrypt to the wrong value.
@TalsonHacks
@TalsonHacks 21 час назад
Amazing video, good work! Hopefully YT will start taking action against these channels...
@alexandercharles8230
@alexandercharles8230 22 часа назад
God bless you and your work buddy! I learned alot from your videos.
@DartrIxBTD
@DartrIxBTD 22 часа назад
Awesome video dude! I learned alot
@Eikenv1
@Eikenv1 День назад
Just came across this. I like the uncut raw type of videos with no music. I dont know much about reverse engineering but it looks hella interesting
@WhiteSecz
@WhiteSecz День назад
About two weeks ago i was looking for the after effects activator and I was startled by the number of videos with the same malware and in the end I didn't find 1 video with the real activator, only malware
@kramnecknerf
@kramnecknerf День назад
Interesting but next time please sound +40dB
@RyanWeil-r1n
@RyanWeil-r1n День назад
Promise I’ll find a solution to the microphone issue next video :)
@bendover7988
@bendover7988 День назад
Hey Ryan, this analysis is awesome! You did a great job breaking down that malicious RU-vid video. It’s wild to see how many views it got. Your insights really emphasize why we need to stay vigilant about cybersecurity. Keep up the great work!
@RyanWeil-r1n
@RyanWeil-r1n День назад
“Well done 47”
@Lukewalker103
@Lukewalker103 День назад
Nice video! Dude🌹🤌
@bendover7988
@bendover7988 День назад
Thats what i was thinking
@RyanWeil-r1n
@RyanWeil-r1n День назад
Thank you!
@slametwidi1544
@slametwidi1544 8 дней назад
hallo can i get your contact?
@dagddeviren
@dagddeviren 8 дней назад
Chef, I had downloaded exact the same file which is called ''Adobe Activator'' from a stolen RU-vid Channel post while am trying to download Adobe... I did run the .exe and now I'am infected. My steam account has been stolen, my accounts including outlook accounts has been compromised. I did download and run exact the same file that you show on the video. Now, the question is how to can I get rid of that ''Lumma Stealer''. I'am still infected, my computer is still in risky situation. Please help me before too late. Help. SOS.
@RyanWeil-r1n
@RyanWeil-r1n День назад
Hello, I am uploading a video on about the sample you likely downloaded. It should be up soon. In the mean time, format your drives and reinstall WIndows. Next time use 2FA on all your accounts, never store browser passwords in the 'Saved Passwords', etc. And don't download shit off of RU-vid ever.
@Haw-pj2iw
@Haw-pj2iw Месяц назад
hey i got hacked by lummac2 stealer and i was wondering if you maybe knew how to remove it
@RyanWeil-r1n
@RyanWeil-r1n Месяц назад
How are you sure you were hacked by it?
@Haw-pj2iw
@Haw-pj2iw Месяц назад
@@RyanWeil-r1n i usead marlwarebyte and it said that ihad a data breach by lummac2 stealer
@TeamDman
@TeamDman Месяц назад
Nice, lots of good tools and insight in this. Thank you for sharing
@lullmaohaha
@lullmaohaha Месяц назад
Very informative, thanks man
@cinderwolf32
@cinderwolf32 Месяц назад
I don't have many URLs memorized, but I laughed once I saw you copy the RU-vid link
@SynagogueExploder
@SynagogueExploder Месяц назад
Im not sure, but i think clipboard sharing can get your host sytem infected if you are not careful enough
@Prim1TiveCH
@Prim1TiveCH Месяц назад
Actually a good video explainning your thoughts and mindset in an understandable and clear way.
@theunkownguy4600
@theunkownguy4600 Месяц назад
I dont understand what i've watch but I like seeing you unpacking the stuff
@Nocturnals331
@Nocturnals331 Месяц назад
can anti malware detected the malware like those pw stealer or crypto mining one
@RyanWeil-r1n
@RyanWeil-r1n Месяц назад
Not always, a lot of times it doesn't get detected until it's already too late.
@Nocturnals331
@Nocturnals331 Месяц назад
@@RyanWeil-r1n I see that's smth to be concerned about now 😭
@r3alf4kt37
@r3alf4kt37 Месяц назад
Very interesting video! Incredible to see people RE like it's nothing! May I ask how you learned these skills? Was it through university/school or self-taught?
@RyanWeil-r1n
@RyanWeil-r1n Месяц назад
Self-taught and from talking to other people interested in RE online for years.
@Il_panda
@Il_panda Месяц назад
Feels better to know that I’m not the only mf who got ida 😂
@georgeplayz3820
@georgeplayz3820 Месяц назад
So basically starts using your computer for mining crypto?
@RyanWeil-r1n
@RyanWeil-r1n Месяц назад
Lumma Stealer is a password stealer, not a crypto miner. However, it probably has download and execute capabilities so it could download one.
@georgeplayz3820
@georgeplayz3820 Месяц назад
@@RyanWeil-r1n You should do more of these malware analysis they're really cool and entertaining
@alladin7769
@alladin7769 Месяц назад
Awesome video! You really broke down how the Redline Stealer works in a way that makes sense. It's wild to see how these hacks happen. Can't wait to see what you dive into next!
@alladin7769
@alladin7769 Месяц назад
This was really well done! You made the whole analysis easy to understand, even for someone who’s not super deep into malware stuff. Crazy how these things work. Looking forward to more from this series!
@JBarszczu
@JBarszczu Месяц назад
I've just started learning RE and got blessed by the YT algorithm that recommended your channel. Good luck with it!
@antlereater72823
@antlereater72823 Месяц назад
I like this content keep going
@Nic-f5b
@Nic-f5b Месяц назад
Hey man, I was wondering if you could try to crack this game cheat. It's really popular within that community of course, I'm curious if it contains any malware. I can't post a link unfortunately, make an email address for submissions!
@TheRedDraqon
@TheRedDraqon 2 месяца назад
Found some dude using an ai deepfake to promote a cracked photoshop gen ai. saw the rar file with a password, knew immediately and chucked it into triage and got a 10/10 for lummastealer.
@zx10rad
@zx10rad 2 месяца назад
you're gonna blow up soon man keep it up
@kiyosrevival
@kiyosrevival 2 месяца назад
is there any way i can contact you? like discord?
@RyanWeil-r1n
@RyanWeil-r1n 2 месяца назад
I do not have a Discord server for the channel at the moment, maybe in the future if the channels gets bigger
@MajesticZephyr
@MajesticZephyr 2 месяца назад
I think you might see some better performance using windows hyperv, but it's really only good for windows vm's in my experience.
@RyanWeil-r1n
@RyanWeil-r1n 2 месяца назад
Will try and remember to look into this tomorrow
@MajesticZephyr
@MajesticZephyr 2 месяца назад
@@RyanWeil-r1n you need to have Windows pro version to use it but you can just use massgrave activation scripts to do it for free. Sounds a little sketchy but it's legit lol but always DYOR :)
@RyanWeil-r1n
@RyanWeil-r1n Месяц назад
Alright, I believe I have the problem fixed now for next time I upload. For some reason my VM was set to only 4GB of ram when it should've been higher, and the core count was low. Not sure why the settings seem to have been 'reset' to that.
@Tyomak-ov
@Tyomak-ov Месяц назад
@@RyanWeil-r1n It's strange, when I use VirtualBox the same kind of issue happens after I create a new VM in it. Where I have to close out and change the ram. I don't know why it doesn't let you edit it upon creation but it doesn't.
@MajesticZephyr
@MajesticZephyr Месяц назад
@@RyanWeil-r1n actually I've been playing around with hyperv a bit, and Linux VM's actually work pretty well too just need a bit more set up.
@thor-q7s
@thor-q7s 2 месяца назад
pretty interesting video, good luck in the future
@Sam-mp4jn
@Sam-mp4jn 2 месяца назад
virustotal should have detected it, no? I've always used virustotal before downloading anything
@RyanWeil-r1n
@RyanWeil-r1n 2 месяца назад
The samples I’ve showed so far have a good detection rate on there, but there are definitely cases where it will have a low detection rate on VT and in some cases will be FUD. I’ve noticed the people running the malware campaign will link to a folder in their videos so they regularly update the executable when it gets detected and get to keep the same link.
@genericplayr
@genericplayr 2 месяца назад
Idk why, but your RE videos are so satisfying
@RyanWeil-r1n
@RyanWeil-r1n 2 месяца назад
Like in a Bob Ross painting kind of way? 😁 Thank you for the comment! Also, do you a particular type of content you’d like to see on this channel?
@genericplayr
@genericplayr 2 месяца назад
@@RyanWeil-r1n As I said, reverse engineering malware
@bendover7988
@bendover7988 2 месяца назад
Really appreciate this deep dive into the Lumma Stealer, Ryan! It's crazy how these hacked RU-vid channels are spreading malware. You do a great job of making this stuff understandable even for those of us who aren’t experts. Keep the awesome content coming!
@RyanWeil-r1n
@RyanWeil-r1n 2 месяца назад
Thank you Mr. ChatGPT
@bendover7988
@bendover7988 2 месяца назад
@@RyanWeil-r1n im not chat gpt im a real person sir
@wittingsun7856
@wittingsun7856 2 месяца назад
Can you do some hard ransomware?
@RyanWeil-r1n
@RyanWeil-r1n 2 месяца назад
Any particular one you have in mind?
@wittingsun7856
@wittingsun7856 2 месяца назад
@@RyanWeil-r1n maybe noescape, hunters and kasseika, what do you think?
@RyanWeil-r1n
@RyanWeil-r1n 2 месяца назад
@@wittingsun7856 Kasseika looks cool because it uses BYOVD. May be worth looking at when I have more time. Otherwise, I am not interested in ransomware at all in terms of its encryption scheme, etc. so I'd probably just analyze the attack chain itself! Also, from what I've heard the ransomware payload is virtualized with Themida, so even if I wanted to do some static analysis on it I'd stand no chance against that haha (and I find dynamic analysis boring).
@bendover7988
@bendover7988 2 месяца назад
Great breakdown, Ryan! Your detailed analysis of how Redline Stealer was used in the hacked channel is both informative and eye-opening. I appreciate how you explained the process step by step, making it accessible for those of us who are newer to malware analysis. Looking forward to more content like this keep up the fantastic work!
@prodKossi
@prodKossi 2 месяца назад
Really interesting - I couldn't follow 100%, as I'm fairly new to de-obfuscating, but it's really cool to get a glimpse of an actual workflow! Keep uploading videos like these man 💜
@RyanWeil-r1n
@RyanWeil-r1n 2 месяца назад
Thanks for the kind words. I didn't do too much regarding deobfuscation in this video other than using the de4dot fork I specified in the description to deobfuscate both of the stage one files. If you are interested in learning how to write your own (relatively) basic de4dot deobfuscator, I have an article about that on my GitHub site: ryan-weil.github.io/posts/AGENT-TESLA-2/
@godlike4423
@godlike4423 2 месяца назад
Very nice vid, that's the recommendations I love.
@trieshah
@trieshah 2 месяца назад
not a clue whats going on but this just got posted bros going somewhere 100%
@lekicohen8724
@lekicohen8724 2 месяца назад
Hey I’m watching but am very confused love it tho :)
@sebastianfischer429
@sebastianfischer429 2 месяца назад
I almost feel honoured to have been recommended this video. 8 views and a channel created today. Maybe this is because the type of video is quite similar to those of Eric Parker, who I watch a lot, although your video appears lot more in depth. Very interesting, but due to lack of the technological knowledge, I could not understand a lot. Let's see if the algorithm blesses you with more recommendations. 😊