Тёмный

Is THIS a VIRUS? Finding a Remcos RAT - Malware Analysis 

John Hammond
Подписаться 1,8 млн
Просмотров 361 тыс.
50% 1

Опубликовано:

 

13 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 900   
@johnjohnerd6921
@johnjohnerd6921 3 года назад
"This is just 75 lines of code" *Half hour later* "201 thousand characters selected"
@AlucardNoir
@AlucardNoir 3 года назад
that's how they get you man, that's how they get you.
@geist453
@geist453 3 года назад
@@AlucardNoir AND YOU BUT GUESS WHO NOT?! ME AND JOHN
@GuyMassicotte
@GuyMassicotte 3 года назад
Majorly loaded by a fake jpg ;)
@bansku570
@bansku570 3 года назад
@@geist453 l
@nojusnojus8015
@nojusnojus8015 3 года назад
@@bansku570 I
@0xRalu
@0xRalu 3 года назад
Love this malware analysis series!
@ismhdez
@ismhdez 3 года назад
Me too! Amazing series
@syverlunde9622
@syverlunde9622 3 года назад
I love it too!
@jbgaud
@jbgaud 3 года назад
me too, this guy is really good.
@s.broyal5128
@s.broyal5128 2 года назад
Sir. Can I use remcos rat to hack Android...
@DenyardTV
@DenyardTV 3 года назад
Ngl, never thought it would be so much fun watching someone analyse and breakdown a virus.
@KrakenPipe
@KrakenPipe 3 года назад
I was thinking the same thing! I might have just discovered my new rabbit hole lol
@AmbitionErudition
@AmbitionErudition 2 года назад
Woow
@baremetalHW
@baremetalHW 3 года назад
Damn that was fun to watch!! Thanks and keep them coming!!!!!!
@slygamer01
@slygamer01 3 года назад
The REMCOS developer "discourages malicious use". For sure, everyone will use solely for legitimate purposes.
@aliencatmeow
@aliencatmeow 3 года назад
'sure if you say so' meanwhile no one uses it legitimately
@karimmohamed3744
@karimmohamed3744 3 года назад
Malicious actors: amma head out
@garethevans9789
@garethevans9789 3 года назад
Ethical hackers don't sell hacking toolkits, ethics and all that... 🤷‍♂️
@technoturnovers7072
@technoturnovers7072 3 года назад
@@garethevans9789 Pentesting tools are released open source because not only is open source more effective, but it makes sure that the developers are not potentially profiting off of malicious actors, intentionally or not.
@cyber1377
@cyber1377 3 года назад
Meh, skids are gonna find a way anyway. With our without this program.
@bennettpalmer1741
@bennettpalmer1741 3 года назад
I love how they went through six stages of obsfuscation, and a lot of effort into hiding what they were doing.... but their payload was literally called "Attack.jpg" like surely they could have named it something at least slightly less blatant.
@FilliamPL
@FilliamPL 3 года назад
Perhaps they didn't care to hide it at that point? I know that obfuscation helps to counter analysts, but when the code is downloading data from a URL, then I suppose it wouldn't've been worth their effort to obscure the name of the download. Then again, they could've made a second download with totally unnecessary data. Either way - this thing is bad (for you)! xD
@richie7425
@richie7425 3 года назад
Times must be hard, Ed Sheeran is writing python.
@batmanasdasd
@batmanasdasd 3 года назад
Lmaooo💀💀
@HiramSalinas
@HiramSalinas 3 года назад
he looks like an unscuffed burgerplanet
@realitynowassigned
@realitynowassigned 3 года назад
This is ed sheerhan and Seth rogans kid.
@HaxorBird
@HaxorBird 3 года назад
You are the hacker version of pewdiepie. Very entertaining to watch.
@lusthetics
@lusthetics 3 года назад
Nah he looks like a de deobfuscated Ed Sheeran
@NickyPuff
@NickyPuff 3 года назад
I love when John is laughing over the Attack.jpg url
@livroz454
@livroz454 3 года назад
best part
@andmo90
@andmo90 3 года назад
Content like this is why I don't have to pay for cable, satellite, or netflix!
@garethevans9789
@garethevans9789 3 года назад
But then he would have been on 8-12 screens and typed those 200k characters (hacking is typing fast), it's all hard to follow. It would be like watching the Matrix.
@viv_2489
@viv_2489 3 года назад
Yeah
@SiveenO
@SiveenO Год назад
Okay, but consider this: TOS and TNG are on Netflix.
@TracyNorrell
@TracyNorrell 3 года назад
Scheduling this to start at the same time as the new mars rover is landing... Bold move cotton, let's see how it works out
@_JohnHammond
@_JohnHammond 3 года назад
Bah, totally didn't even realize xD Ah well!
@originalgaming9062
@originalgaming9062 3 года назад
@@_JohnHammond I’d prefer watching this over some rover landing
@originalgaming9062
@originalgaming9062 3 года назад
@@tripplefives1402 isn’t the rover automatically controlled because the delay would be 10 minutes long?
@Corb4nm0noxide
@Corb4nm0noxide 3 года назад
So far this is the most fun I've had watching hacking videos. Your analysis is fantastic and I enjoy seeing your process. Keep it up!
@ycoihmn6388
@ycoihmn6388 3 года назад
This style of video really helps me with my start in forensics and malware analysis. I love liveoverflow and other CTF summary channels but they often feel like magic in the way they present their findings. Keep up the great work :3
@vannialora3476
@vannialora3476 3 года назад
the evolving of rat is so amazing, i remember in late 90's where sub7, netbus and back orifice was so popular and inspired me into hacking. IRC was the channel to go to before and dial up is your connection.
@Dilipkumar-ur9zx
@Dilipkumar-ur9zx 3 года назад
After watching this, gained a keen interest in Malware Analysis. Thanks for the awesome content.
@darkdagger032
@darkdagger032 3 года назад
This is one of the best educational videos i've seen
@donaldduck6198
@donaldduck6198 3 года назад
John, as you are very good, you should stand this comment: In Powershell a "split (..)" is a regular expression splitten in string in portione of two characters, ie "4142" becomes "41", "42", in Hex AB
@definesigint2823
@definesigint2823 3 года назад
I've taken apart stuff like this (when I worked in large enterprise) but the samples were rarely more than 3-4 levels deep. This actually looks a lot more like a challenge you'd get at a CTF competition _(perhaps they're getting ideas from each other)_ ?
@Edzward
@Edzward 3 года назад
You need I high level of nerdiness to find this entertaining. Proof: I find highly entertaining! Love this.
@willo7734
@willo7734 3 года назад
Whatever that quality is that great teachers have, you have it. Never change the format of your videos. I love seeing you troubleshoot and reason through everything live.
@dustinjohnson7635
@dustinjohnson7635 3 года назад
Amazing work, you deserve the money from the RU-vid overlords. Literally only commented to help boost those algos.
@m1rz
@m1rz 3 года назад
Pretty sure you need to run the obfuscated version of the AMSI bypass. Great video, would love to see more of these!
@TheSeakr
@TheSeakr 3 года назад
I'm just finding this channel and its quickly becoming my favorite content. Im fascinated with all of this. Really inspires me to get started with basic coding to get my feet wet.
@randallsalyer
@randallsalyer 3 года назад
I love John’s response when the light bulb goes off and all the hard work comes together. Great video as always.
@md123180
@md123180 3 года назад
Where have you been all my CS degree? This is awesome watching this stuff in action as you do it. I love the content! Definitely going to keep watching!
@britishpiperygo
@britishpiperygo 3 года назад
Loving this series. Would like to see some disassembling malware analysis.
@waytoofarianism
@waytoofarianism 3 года назад
That was freaking wild, man. You're sharp at this stuff
@eliasgamezgarcia3414
@eliasgamezgarcia3414 3 года назад
Dude you are simply awesome...it's so enriching for all of your viewers to see your hard work and all your skills, and the best of all is that we can see you enjoying so we enjoy and learn too. Regards from Spain!
@mechanicalfluff
@mechanicalfluff 3 года назад
i missed the premiere, but this is definitely a blast to watch. Would love to see this more
@PerfectEn3my
@PerfectEn3my 3 года назад
Great video, I love this series. Also special thanks for zooming in this much, watching code-related stuff on phone is usually a pain, but not in your case. Keep up the good work!
@rccservice
@rccservice 3 года назад
that url has to be the greatest thing ive ever seen
@whatnowsami9225
@whatnowsami9225 3 года назад
Nobody: Virus Code: * Does malicious stuff* John: Is it trying to do something bad? HAHAHA Us: Duhhh John. wtf
@whamer100
@whamer100 3 года назад
"is this the newest version? because that would be pretty slick" *immediately scrolls past the version number 3.1.0 showing it is the latest version*
@mbowler05
@mbowler05 3 года назад
Hands down one of the best malware analysis walkthroughs I’ve seen. Watched it twice.
@auto117666
@auto117666 3 года назад
In the next episode... John rewrites the kernel for more efficient find and replace..... STONKS!
@patchbyte6856
@patchbyte6856 3 года назад
this is gonna be good
@AnthonyBlakley
@AnthonyBlakley 3 года назад
Indeed Indeed :D
@vargnaar
@vargnaar 3 года назад
"Can I get anything out of Melons?" You can get juice, John. Juice.
@pumpkin7976
@pumpkin7976 3 года назад
Plottwist: this is all just an advertisement for BreakingSecurity
@uniquechannelnames
@uniquechannelnames 3 года назад
Algorithm, give this man the recs.
@TexasTimelapse
@TexasTimelapse 3 года назад
It worked. That's why I'm here.
@ultimate8673
@ultimate8673 3 года назад
The guy that wrote the script watching this video rn must be like 👁️👄👁️
@MikeKirkpatrick
@MikeKirkpatrick 3 года назад
Well worth the watch. This is a great video. Please do more. :)
@georgehammond867
@georgehammond867 3 года назад
how do you copy and paste into VirtualBox in Windows 10
@kitrodriguez992
@kitrodriguez992 3 года назад
I was watching some scam baiting videos and also doing some deep dives into RATs and just... CyberSec/CompSci things in general and found this video. I'm glad I bumped into your channel. Really good stuff you have going on here
@Krampfey
@Krampfey 3 года назад
Damn, I just watched over an hour of stuff I have no clue of and I still feel educated and entertained. It even kinda makes sense, when you talk about it and explain some stuff. Thank you very much! :)
@Ayayron_e3
@Ayayron_e3 3 года назад
"guys, you might think i'm dumb" LOL exact opposite.
@thedemonlord9232
@thedemonlord9232 3 года назад
you got my sub for this. its 3am in the morning and I've watched the entire thing having so much fun. keep on with the good stuff
@shawnio
@shawnio 3 года назад
every single line "I don't exactly know what is going on here" so basically this guy is just us trying to understand code. got it.
@agentsmith9753
@agentsmith9753 Месяц назад
That was epic dude! Felt like a real rollercoaster. I can't believe you got to them within 24 hours of release. So nuts.
@wazoozastoob1234567
@wazoozastoob1234567 3 года назад
THOSE DOWNVOTES....GTFO...this dude is a legend
@ThomasGabrielsen
@ThomasGabrielsen 3 года назад
What a great catch! This is by far the most interesting video I've watched on RU-vid for a very long time. I love this of unedited video.
@HBTwardy
@HBTwardy 3 года назад
John: releases a video with malware analysis Me after watching a video: *Lemme check real quick whether notepad.exe is running in the background or not in Task Manager*
@benricok
@benricok 3 года назад
Imagine using windows 🤔
@Reelix
@Reelix 3 года назад
@@benricok Imagine thinking that exploit-db had 0 results for Linux 🤔
@benricok
@benricok 3 года назад
​@@Reelix I didn't even mention an OS? I am aware that Linux isn't perfect as so with every software product (opensource or not). The worst thing you can do to your security is to be over confident in your defense.
@theluckyscav3487
@theluckyscav3487 3 года назад
@@benricok Imagine being a pompous asshole. Some people want to, you know, play normal games on their computer.
@jixs4v
@jixs4v 3 года назад
@@theluckyscav3487 I mean linux gaming has come a long way, but it still needs some time to flourish
@rubenolguin2180
@rubenolguin2180 2 года назад
Wow, that was a crazy ride! Thanks for taking us on the journey.
@bigp3t3_cpt
@bigp3t3_cpt 3 года назад
so where did you get the jscript if it was only released so recently...
@victorhmg8080
@victorhmg8080 3 года назад
i wanna know too
@ExcludedLayman
@ExcludedLayman 3 года назад
The actual payload was hosted remotely, so that can be updated separately.
@sannyboi7298
@sannyboi7298 2 года назад
Brilliant. You make malware reversing so fun to watch.
@CristiNeagu
@CristiNeagu 3 года назад
59:31 No. That's the noun "licence" as opposed to the verb "license". It's a British thing.
@JM-tf3rg
@JM-tf3rg Год назад
This was so fun to watch. The sketchy url was very funny, fitting pun on with the ‘holy cow’
@tears_falling
@tears_falling 3 года назад
Attack.jpg, that was hilarious
@danielbaker3063
@danielbaker3063 3 года назад
Always learn something new watching your content!
@bradlad1574
@bradlad1574 3 года назад
That's a rabbit hole if I've ever seen one haha great stuff man!
@definesigint2823
@definesigint2823 3 года назад
If only it (the rabbit holes) were rare. 😥
@ulbed
@ulbed 3 года назад
Follow the white rabbit!
@hexnull4343
@hexnull4343 3 года назад
Man i'm brazillian, and i love all of this videos, but this... mannn to amazing !! Continue delivery this content to us, i apreciate this
@temitopehardhekheyhe7359
@temitopehardhekheyhe7359 3 года назад
Please mahn ... we need more malware analysis like this!! ... and also ... C source code analysis (something like that)
@redslay5
@redslay5 3 года назад
Loved the video! Can you share where or how you are picking your samples to analyze? In addition, for future videos can you post the hashes so if we want to follow along we have the option?
@hexadeque1101
@hexadeque1101 3 года назад
I was wondering the same thing
@1XXXJoker
@1XXXJoker 3 года назад
I have basically no connection to it-sec, but this stuff is addictive ... love the videos
@sheldongroom18
@sheldongroom18 3 года назад
Please more Malware Analysis videos. So much fun to watch.
@thedosiusdreamtwister1546
@thedosiusdreamtwister1546 3 года назад
Where do you get such fresh samples? That hash isn't even on VT yet.
@Anonymous-vh6kp
@Anonymous-vh6kp 3 года назад
Plot twist: John actually wrote it
@Flobert97
@Flobert97 3 года назад
Did i just watch AN HOUR of malware analysis? Dude, you're awesome!
@Zachucks
@Zachucks 3 года назад
"I don't like these advertisements..." "You didn't see this here folks!" "Not in a John Hammond video!"
@deantammam
@deantammam 2 года назад
You know so much about so many things... I've learned so many things in the few videos I've watched so far. Super, super inspiring.
@kingknight100
@kingknight100 3 года назад
The Title is like Asking if water is wet LOL
@DarkFaken
@DarkFaken 2 года назад
I love these malware analysis videos. You break stuff down to a fairly easy to understand level for most technical people. I'm just getting into cyber security and I'm really enjoying your content, thank you.
@vedritmathias9193
@vedritmathias9193 3 года назад
Remcos: "We specialize in ethical hacking" Also Remcos: *is used in malicious code*
@Seluj78
@Seluj78 3 года назад
Really interesting video, thanks !! I'm impressed at the obfuscation job done on this malware it's impressive
@nickyfranshel1210
@nickyfranshel1210 3 года назад
I have no idea what I'm watching but I'm enjoying it :)
@internetuser8922
@internetuser8922 3 года назад
It's actually not a bad way to learn, at least starting out - if you're interested. I have a background in software engineering, but I only understand maybe 75% of what's going on.
@snuffy6449
@snuffy6449 3 года назад
I binge your videos every day all day at work. Gets me through the day and I learn some new/cool stuff.
@azurnxo2134
@azurnxo2134 3 года назад
Amazing stuff. Learned a lot from this video. I have a question: how did you come across this script? Did someone give it to you? Anything like that? Loving these malware analysis videos, John. Keep 'em coming!
@DallasGraves
@DallasGraves 3 года назад
From beginner hand-holding on picoCTF to obfuscating obfuscated obfuscation LOL. This channel has it all, thanks for the great content!
@kerrickfanning6910
@kerrickfanning6910 3 года назад
I just want to know how it’s humanly possible to obtain the level of programming and CS knowledge needed to be capable of doing what he does in this video
@DaCaveman84
@DaCaveman84 3 года назад
It’s depressing but motivating also!
@alexcolley205
@alexcolley205 2 года назад
Yeah imagine who made this
@emanuel6934
@emanuel6934 Год назад
Actually, not too much. Deobfuscating such stuff is not very complicated, but he is still doing a good job. But tbh .. most parts could be much faster by debugging functions step by step instead of trying to deobfuscating every var and func.
@nilanjana25
@nilanjana25 2 года назад
Totally enjoyed the video. It was an absolute rollercoaster ride. I love the way you present and explain the details in all your videos. And also none of your videos ever seem to be monotonous even when we are dealing with such mind boggling stuff because of the way you laugh and get excited when you crack/deobfuscate a piece of code. 😁 Thank you so much for taking the effort and sharing the awesome work😊
@gabrote42
@gabrote42 2 года назад
I honestly never appreciated Search and Replace until today. Everything is so clear now! 19:35 One learns more every day 33:44 What the hell this is hilarious 44:00 I hope you saved 56:13 I judt read a Online Keylogger Started so I guess yes 1:01:52 Oh so test hacks? Was this retrofitted to be malicious or you just were smart? 1:03:08 Imagine if Jim's Scammers used this crap. My god 1:10:00 Fresh off the oven and unobfudcated
@rave4ever2020
@rave4ever2020 3 года назад
Awesome work buddy !!! watching your videos while at work coding my self ... thanks for the vids
@KlaypexDelusion
@KlaypexDelusion 3 года назад
BTW... next thing. Do remcos guide, analysis and stuff
@Cinual
@Cinual 3 года назад
You make easy to understand videos as you break things down. i really enjoy them. I have a vague understanding of coding and the way you work is easy to follow.
@tomriddle2427
@tomriddle2427 3 года назад
That was more than a safari ride! It's awsm
@mclovin748
@mclovin748 3 года назад
59:06 love how scrolls past when looking at string in the executable "Offline Keylogger Started" "Online Keylogger Started" "Online Keylogger Stopped" "Offline Keylogger Stopped" Yes John sees the key strokes and is like, "is this doing keylogging?"
@SaeedAlFalasi
@SaeedAlFalasi 3 года назад
Next video Stuxnet analysis :D
@facekickr
@facekickr 3 года назад
That was a great video. I don't know a whole lot about what you do, but it was super fun watching you do it. Thanks so much!
@testingstuff6111
@testingstuff6111 3 года назад
was great :)
@mattgwalker
@mattgwalker 3 года назад
John - This is great content. I really am learning a lot watching you work these out. Keep it up! The masses demand more of this!
@petersva
@petersva 3 года назад
1:07:15 coronavirus was around at that time, it started spreading as soon as 17 dec. in china, possibly even sooner
@dieSpinnt
@dieSpinnt 3 года назад
Thanks Peter, I wanted to comment also on this. COVID-19 after the temporary name “2019-nCoV”. In mid-February it was also known in many countries (including Germany ... Trend Micro), the WHO had warned (January 30, 2020). Unfortunately, it wasn't taken very seriously. We all know what happened next ... see also: www.euro.who.int/en/health-topics/health-emergencies/coronavirus-covid-19/novel-coronavirus-2019-ncov
@ManMan-sh9xz
@ManMan-sh9xz 3 года назад
Hey john can you put a link to download these malwares to try to analyze it our selfs btw perfect vidoe❤️
@picocode
@picocode 3 года назад
Waiting for it :)
@kipchickensout
@kipchickensout 2 года назад
You can also Ctrl+Scroll Wheel to zoom into notepad Edit: I watched the whole thing and I really had fun, really interesting and high quality Your circlular camera mask and your energy break reminded me of networkchuck and his coffee break xD You got a new subscriber :)
@AhmedAbbas-hp5ej
@AhmedAbbas-hp5ej 3 года назад
Legend
@musingmuse9064
@musingmuse9064 3 года назад
Watched the whole thing from start to finish - loved it! Make more!
@picocode
@picocode 3 года назад
Have you ever tried something with LUA before and i might be able to give you an interesting file!
@_daniel.w
@_daniel.w 3 года назад
Didn't expect to see you here lmao;
@picocode
@picocode 3 года назад
@@_daniel.w yh i play ctf
@xyphelon
@xyphelon 2 года назад
Just watched this now, been on my watch list for a while. Great Video.
@sammo7877
@sammo7877 3 года назад
comment for youtube algo :)
@jeehill9592
@jeehill9592 2 года назад
As a prospective sw engineer, at ~54:00 that obfuscated spaghetti mess made me never want to be a malware analyst 🤣😂🤣 glad to have people with your mettle in this world
@SinanAkkoyun
@SinanAkkoyun 3 года назад
Now I got my GF *_There he is_*
@King-Julien
@King-Julien Год назад
I knew exactly what it was a few minutes of you scrolling few the strings!!! I feel proud! And thank you for making this video, I learned a lot.
@vincepod
@vincepod 3 года назад
Enjoying the malware analysis videos. Very informative.
@h4wk_n377
@h4wk_n377 3 года назад
Keep on doing those Malware Analysis. It's really fun to watch and it's quite educative too!
Далее
Mozi Malware - Finding Breadcrumbs...
50:16
Просмотров 199 тыс.
Discord Malware - "i hacked MYSELF??"
58:21
Просмотров 195 тыс.
TARGETED Phishing - Fake Outlook Password Harvester
47:09
Cursor Is Beating VS Code (...by forking it)
18:00
Просмотров 103 тыс.
Finding WEIRD Devices on the Public Internet
27:48
Просмотров 281 тыс.
FAKE Antivirus? Malware Analysis of Decoy 'kaspersky.exe'
1:28:19
He tried to hack me...
34:15
Просмотров 381 тыс.
JScript Deobfuscation - More WSHRAT (Malware Analysis)
1:02:01
Unraveling the IcedID Malware Stager & Phishing Email
33:34
Snip3 Crypter/RAT Loader - DcRat MALWARE ANALYSIS
1:42:04
HTA JScript to PowerShell - Novter Malware Analysis
1:24:19