Malware Analysis & Threat Intel: UAC Bypasses

Поділитися
Вставка
  • Опубліковано 21 лис 2024

КОМЕНТАРІ • 70

  • @SERGEX42069
    @SERGEX42069 8 місяців тому +83

    dude you move through this file like butter

    • @nickadams2361
      @nickadams2361 7 місяців тому +7

      he did it before, this is a planned demo. Normal stuff you should be able to do at work

    • @MalikAbubaker-s3j
      @MalikAbubaker-s3j 7 місяців тому

      ​@@nickadams2361😊😊😊😊😊😊😊😊😊

    • @IOwnThisHandle
      @IOwnThisHandle 6 місяців тому +1

      It is rehearsed

  • @markcentral
    @markcentral 7 місяців тому +20

    Thanks for the video. Is the anyrun segment part of a sponsored deal? If not, I would have preferred you continued to demonstrate how to deconstruct the malware locally. There's a lot of educational value and wisdom potential being lost by moving things to an online platform that requires a subscription vs local

  • @hedgehogform
    @hedgehogform 7 місяців тому +29

    VSCode has a powershell formatter

    • @HachikoTanuki
      @HachikoTanuki 7 місяців тому +7

      I feel like such a casual that I know none of the tools John is using, while VSCode is too casual for John to know it has a Powershell formatter 😭

    • @_MasterLink_
      @_MasterLink_ 2 місяці тому

      The point is teaching us to not need to rely on such things, and to know what it is we are seeing with our own eyes. ;)

  • @gabriell4815162342
    @gabriell4815162342 7 місяців тому +24

    I love your videos, as a foreigner and because I don't speak native English, I feel very comfortable and can understand everything because of the calm and concise way you speak. In addition to practicing my English, I learn a lot about cyber security

    • @Alfred-Neuman
      @Alfred-Neuman 7 місяців тому +2

      I learned English by watching lot of UA-cam videos like this.
      If you are curious enough and/or determined, you'll be able to write some English poetry pretty soon. ;D

    • @severinghams
      @severinghams 7 місяців тому

      @@Alfred-Neuman I don't understand foreigners' fascination with English poetry. Why is poetry something that so many non-English speakers flock to when they learn English? Why not debate, or music, or popular speeches, or literature- why _specifically_ poetry? What is so special about poetry?

    • @Alfred-Neuman
      @Alfred-Neuman 7 місяців тому

      @@severinghams
      How many languages do you speak outside of English?

  • @J-ih6so
    @J-ih6so 2 місяці тому

    i know nothing about computers, but i watch your videos to feel something

  • @antifreeze44
    @antifreeze44 8 місяців тому +6

    You're take on the Apex stuff was AWESOME, thanks John!

  • @Carambolero
    @Carambolero 7 місяців тому +3

    Nice start, but next time if you want to promote a tool, just go to the point and state it in the Title. Tx.

  • @valk9789
    @valk9789 8 місяців тому +5

    Treat at the end~ love John's laugh😅❤

  • @Duy1P3
    @Duy1P3 7 місяців тому

    I'd really like to see your homelab setup and see how you run things and do your investigations and with what tools and stuff.

  • @cypher2226
    @cypher2226 8 місяців тому +2

    I didn't know about that UAC bypass

  • @YuKonSama
    @YuKonSama 7 місяців тому

    I kind of like the sublime approach to clean the sample up but I also would be interested into automating stuff like this (guess R.E.M has tools for this). For example, deleting variables that are assigned but never used should be a pretty easy task.

  • @Adkali
    @Adkali 8 місяців тому

    Love the threat analysis using the dynamic analysis. Again, thanks john for another fun schooling video

  • @codytrout3257
    @codytrout3257 7 місяців тому

    Pro tip- change the speed to slower if you cant keep up with the commands fully, yet, like me.

  • @Supstone8519
    @Supstone8519 7 місяців тому

    Very insightful. Thank you for doing this video.

  • @PMM619
    @PMM619 8 місяців тому +2

    hey fan from Morocco, all the love !!

  • @memeconnect4489
    @memeconnect4489 7 місяців тому +9

    a lot of danish words in that code

    • @7YBzzz4nbyte
      @7YBzzz4nbyte 7 місяців тому

      Seems to be fluff to obfuscate the code itself. Seems like Danish-inspired gobbledegook, words stacked without meaning, though a scanner would not know (at least not before AI). 😮

  • @k.g.c.karunathilaka9781
    @k.g.c.karunathilaka9781 7 місяців тому

    Thanks

  • @learnsomething564
    @learnsomething564 8 місяців тому +3

    First one ooooo now i have millions in my account

  • @ShayBlez
    @ShayBlez 7 місяців тому

    Never thought Id see Bonzi Buddy again.. XD

  • @eikichi9050
    @eikichi9050 8 місяців тому +1

    Hello Mr Hammond it is possible to defend against these type of attacks? Sorry for my english

    • @UnfiItered
      @UnfiItered 7 місяців тому +4

      If your end users don't use/run vbs/batch/PS1 scripts. You can make a group policy to require UAC to run them or disable them completely.

  • @allofabout7064
    @allofabout7064 7 місяців тому

    I hope you discuss Qlin Ransomware, and how to overcome it (recovery)

  • @Streetrack
    @Streetrack 7 місяців тому

    I really like this one!!

  • @dipongkorroy6424
    @dipongkorroy6424 8 місяців тому +2

    Love from Bangladesh ❤

    • @user-lq3tv4nd8w
      @user-lq3tv4nd8w 8 місяців тому +1

      Why did you bang ladesh tho, poor fella

  • @capability-snob
    @capability-snob 8 місяців тому

    What was the intended use of this .ini file and the class named by the guid?

  • @JohnSmith-jc7dk
    @JohnSmith-jc7dk 8 місяців тому

    why vbs is required to deploy remcos and not deploying remcos directly?

    • @UnfiItered
      @UnfiItered 7 місяців тому +1

      Vbs was just a stager to build the powershell to run. Basically the hacker was trying to hide what they were doing behind a bunch of dead end code.

    • @chri-k
      @chri-k 7 місяців тому +1

      The point is that anyone who finds the malware but doesn't know how to handle this (including antiviruses) will likely not try to, which hopefully buys some more time before it gets logged into a malware registry.
      Inflated file sizes also stop VirusTotal and some antiviruses from analysing the file

  • @AustinHypes
    @AustinHypes 7 місяців тому

    NICE this is really menace :)

  • @carteldebellamy677
    @carteldebellamy677 7 місяців тому

    Awesome video

  • @RandomytchannelGD
    @RandomytchannelGD 8 місяців тому

    Hi

  • @psbharathkumarachari4005
    @psbharathkumarachari4005 8 місяців тому +2

    hi man
    fan from india

  • @liljeep3631
    @liljeep3631 8 місяців тому

    You guys use uac?

    • @UnfiItered
      @UnfiItered 7 місяців тому +1

      ? Everyone in the AD world uses UAC. You don't want your end users in a lower privilege group policy to just download and run anything without UAC. You're opening yourself up to so many threat vector by doing that.

    • @liljeep3631
      @liljeep3631 7 місяців тому +1

      @@UnfiItered vector these nuts

    • @UnfiItered
      @UnfiItered 7 місяців тому

      @@liljeep3631 okay, obviously you're a troll.

    • @liljeep3631
      @liljeep3631 7 місяців тому

      @@UnfiItered don’t need uac

    • @UnfiItered
      @UnfiItered 7 місяців тому

      @@nezu_cc other than stealing files via emails and accessing network, everything else should require UAC via group policy (cmd, pwsh, windows native file encryption tools, vbs, portable exe etc..). Even then, group policy should dictate which user have access to which network drive. Outlook is the only email client used. Attachment is disallowed unless sending to internal email.

  • @PoojaRautrai-e9f
    @PoojaRautrai-e9f 7 місяців тому +1

    voice

  • @carsonjamesiv2512
    @carsonjamesiv2512 8 місяців тому

    NICE!😃

  • @johnvardy9559
    @johnvardy9559 7 місяців тому

    I love y john

  • @SlipperyCarrot
    @SlipperyCarrot 7 місяців тому +1

    Whole lot of Danish word in that sample..

  • @Hacker_Solo
    @Hacker_Solo 7 місяців тому

    Where can we obtain this sample for free

    • @XtremuZ
      @XtremuZ 3 місяці тому

      malware bazaar

  • @PoojaRautrai-e9f
    @PoojaRautrai-e9f 7 місяців тому +1

    mom

  • @frinkifail7063
    @frinkifail7063 8 місяців тому +1

    sure love assimilationist one hundred thirty nine

  • @bamboozledbamboozler
    @bamboozledbamboozler 5 місяців тому

    I... i got so fucking lost. To be fair idk shit but i still find coding nonsense interesting

  • @mdfourhadkhan1842
    @mdfourhadkhan1842 8 місяців тому +1

    ❤❤❤❤❤❤

  • @runandwin5396
    @runandwin5396 8 місяців тому +1

    Chapters please?

  • @PoojaRautrai-e9f
    @PoojaRautrai-e9f 7 місяців тому +1

    @#

  • @PoojaRautrai-e9f
    @PoojaRautrai-e9f 7 місяців тому +1

    mobile no.

  • @Monothefox
    @Monothefox 8 місяців тому

    It's in Danish.

  • @iamwitchergeraltofrivia9670
    @iamwitchergeraltofrivia9670 7 місяців тому

    Fucking intel

  • @PoojaRautrai-e9f
    @PoojaRautrai-e9f 7 місяців тому

    bhabhi

  • @radityaharya
    @radityaharya 8 місяців тому

    ur audio sounds weird