Rick & Morty MALWARE!? - sLoad - PowerShell & VBScript

Поділитися
Вставка
  • Опубліковано 1 лис 2024

КОМЕНТАРІ • 198

  • @_JohnHammond
    @_JohnHammond  3 роки тому +37

    Some incredible folks in the Discord (shout out to you, @db!) helped fill me in that this is actually the "sLoad" malware family.
    Good links for further reading and exploration:
    svmvzypnse2tk4cg4e4l32t6oy-adwhj77lcyoafdy-cert-agid-gov-it.translate.goog/news/malware-sload-sfrutta-pec-[…]alevolo-annidato-in-doppio-zip/
    twitter.com/luc4m/status/1331550804990373890
    www.microsoft.com/security/blog/2019/12/12/multi-stage-downloader-trojan-sload-abuses-bits-almost-exclusively-for-malicious-activities/

    • @TwinTailTerror
      @TwinTailTerror 3 роки тому +1

      ya unless you cant talk in any channel and you point that fact out and the admin aka you kicks you why bother to invite ppl to discord if they cant assign there own roles and speak? and if they do point that out via pm you just boot them cuz it breaks the rules i mean how else u gonna get something fixed kinda dooshy move guy.

    • @bobmclane3017
      @bobmclane3017 3 роки тому

      Love the ilSpy and Malware decoding but equally miss your CTF (tryhackme/HTB etc) :) please keep both coming John

    • @K-Anator
      @K-Anator 3 роки тому +2

      @@TwinTailTerror Dude. Did you just forget how to read when you joined the server?
      I joined purely out of curiosity to see just how daft you were. And oh boy, you're daft af.
      If you read two sentences, you would have been able to join in discussions no problem.
      You had to type one command in the welcome channel, and react to one message in the roles channel.
      It's literally that simple.

    • @ddjazz
      @ddjazz 3 роки тому

      Would be nice to see qn update with a follow up video part 2 :)

    • @its_code
      @its_code Рік тому +1

      Does vbscript still used in today modern windows computer like 11 . Vbscript default compiler by default installed in windows 11

  • @eklypzn
    @eklypzn 3 роки тому +181

    I think there's a happy medium that you can find between this and your normal long form videos. I think the way this was done would be fine occasionally, but I do enjoy going on the adventure of the long form videos.

    • @worm628
      @worm628 3 роки тому +3

      I agree with this comment.

    • @errr-iw4lz
      @errr-iw4lz 3 роки тому +3

      I agree with this comment.

    • @styleee1337
      @styleee1337 3 роки тому +3

      I agree with this comment.

    • @dosu360
      @dosu360 3 роки тому +7

      Same here. The "live" version makes me feel as if we are solving it "together" in a way.

    • @kill3rvill3
      @kill3rvill3 3 роки тому +1

      agreed

  • @MrKuma352
    @MrKuma352 3 роки тому +88

    I really like the educational style of the normal videos. Doing it on the fly and taking a look into your thought process is really entertaining

  • @JeeliBeeli
    @JeeliBeeli 3 роки тому +44

    This malware had a disturbing lack of tangent functions

  • @yigglesmoto
    @yigglesmoto 3 роки тому +19

    the "Try Harder" sticker above you while slamming your head into the door fits perfectly.
    love these shorter style videos, don't always have the time to watch your full 1h+ long videos. The editing style was refreshing too

  • @viv_2489
    @viv_2489 3 роки тому +12

    We do like older style as well :), going through slowly, trying different things to get over

  • @Lampe2020
    @Lampe2020 Рік тому +1

    I didn't expect you to make such a funny video, I always thought you'd just make very professional videos, no big jokes, just get the malware into pieces. Very nice to lighten that up with some jokes!

  • @galaktoza
    @galaktoza 3 роки тому +14

    Did you just blow up in subscribers? Well done man, deserved!

  • @StefanPoggenpohl
    @StefanPoggenpohl 3 роки тому

    I very much enjoyed this style of video. This is much nicer to actively watch while I let the other long videos mostly run on a side screen when doing chores or workouts.

  • @tuckerward9844
    @tuckerward9844 3 роки тому +3

    I like getting to see your creativity come through some more with the editing, but also still personally prefer the long-form (less edited) videos just as personal preference.
    I'm watching either way.

  • @MrDawgTagz
    @MrDawgTagz 3 роки тому +1

    Just wanted to help the algorithms a bit, also wanted to let you know you've been a big inspiration for me. I went from watching your videos and not understanding anything, to now running my own kali machine and having lots of fun!! Thanks for the content, keep it up!

  • @BrainD22
    @BrainD22 3 роки тому +2

    This video really made me laugh! I'm normally more a fan of the videos where you go in blind to understand your thoughtprocesses but that editing was great. A good mix would be awesome!

  • @lrmarquez80
    @lrmarquez80 3 роки тому

    Watching your videos on inspecting code helped me a great amount in my first hacking competition held by the National Cyber League. Thanks John! I found out its important to stay up to date on zero days, and other exploits being found and your videos are helping me keep up with things......ps your video on the sudo vulnerability was gold!!!

  • @real1cytv
    @real1cytv 3 роки тому +5

    While we are on the topic of Rick and Morty Malware: Apparently there is a video file with an episode (or what claims to be) of rick and morty, which is actually a coin miner. That might be interesting to look at.
    Also, I really enjoyed the edited style

  • @johnwesolowski1134
    @johnwesolowski1134 3 роки тому +1

    I liked this style. Still had the educational parts which are cool yet was more condensed for easier viewing. Good job on the editing :D

  • @mef9327
    @mef9327 3 роки тому

    For the algorithm:
    I just found this channel. It's fascinating even though I didn't understand any of it. I read a couple of "Visual Basic for Beginners" books and wrote a little app for myself. I know what declaring a variable is and what a function is. So, I understood about 4 sentences herein (without understanding the specific significance or context). Still a cool channel. Subbed.
    As for long-form vs short form, I'm too new and too inexperienced to offer any meaningful feedback. That said, *generally,* I like long-form on technical, exploratory/problem-solving subjects (i.e. not meant to be a tutorial or introduction to a subject). It seems to help to pick-up contextual clues as a thought process is being developed in real-time.

  • @shaank0647
    @shaank0647 3 роки тому

    Super informative and funny, cant ask for much more in regards to keeping viewers engaged!

  • @Timooooooooooooooo
    @Timooooooooooooooo 3 роки тому

    I enjoyed this format. Made it a lot easier to find time to watch this

  • @deeznutz393
    @deeznutz393 3 роки тому

    the editing on this one is IMMACULATE

  • @vgarzareyna
    @vgarzareyna 3 роки тому +15

    Wish I could wake up early enough to watch the premier

  • @Konym
    @Konym 3 роки тому +5

    3 whole days in a row of malware analysis. This is amazing.

  • @glarg811
    @glarg811 3 роки тому +3

    Love your work man! You inspire me to try harder! Can't wait!

  • @RyanRath
    @RyanRath 3 роки тому

    It was a great vid but honestly I really enjoy the raw videos and walking through the thought process with ya. so if it cuts hours off your day, Raw all the way man

  • @itairon9338
    @itairon9338 3 роки тому

    I LOVE this new approach and style, i hope you do more of these

  • @ApfelJohannisbeere
    @ApfelJohannisbeere 2 роки тому

    For very long episodes I really really love the summary!
    Though for sure most will want to have very interesting stuff full 'verbose' of these interesting sections (especially those that you haven't covered already with your other videos)!

  • @nullp01nter20
    @nullp01nter20 3 роки тому

    I really love this method. It's funny and informative. I hope you continue. :)

  • @lfionxkshine
    @lfionxkshine 3 роки тому

    Someone on r/cissp mentioned your name the other week. Started watching your vids to see what's up, now you are a part of my morning routine. Love your stuff, helps me be a better admin

  • @Tw3ntyyyy
    @Tw3ntyyyy 3 роки тому +33

    Third in a row nicee, getting an evening routine

  • @AgLenoir
    @AgLenoir 3 роки тому

    Love this segment and the style of made it fun as well as informative

  • @simonebrazioli2206
    @simonebrazioli2206 3 роки тому

    Love both this edited video and your usual style! But your usual style in which you go through the code 'with us' is more educational and informative, I think. But, man, love me some memes!

  • @DavidAlvesWeb
    @DavidAlvesWeb 3 роки тому +14

    Now this is my kind of malware 😎

  • @asbestinuS
    @asbestinuS 3 роки тому

    Hi!
    I am thankful for your videos and this one as well. However like other commenters already said, I'm personally more a fan of the longer videos where you find stuff with your initial reaction and then following your thought process. They are already very entertaining for me (I work in IT but more as the Windows Administrator) and honestly I'm pretty shocked what is possible. But it's very interesting! Also I wanted to praise your Hafnium Exchange Server analysis, very good!

  • @LeonVQZ
    @LeonVQZ 3 роки тому

    it was a fun video! I liked the style.
    I like the shorter video format, but I don't mind a 2 hour long video from time to time in the weekends.

  • @otesunki
    @otesunki 3 роки тому +2

    2:17 that INSTANTLY jumps out at me as c:\windows\

  • @BloodyfreezeYT
    @BloodyfreezeYT 3 роки тому

    I came cause it was a suggested link for Rick and Morty. I subbed cause it was a great breakdown. Love the format. If it's a large time consumer, maybe cut down the frequency of the fun stuff, but was enjoyable.

  • @yossig7316
    @yossig7316 3 роки тому

    I like the new style of video, but I love the normal ones you always do more ! This was very fun though :-) Thank you!

  • @dreamz420
    @dreamz420 3 роки тому +1

    that video was well cutted, good one john

  • @humanflybzzz4568
    @humanflybzzz4568 3 роки тому

    This was oddly fun and satisfying. I'm really bad at powershell and vbs, but this gives me an itch to learn it :)

  • @rodpombo598
    @rodpombo598 3 роки тому

    I like how your youtube skillz are growing!! thanks for all the great content (even for a noob like me!)

  • @TrueBenja14
    @TrueBenja14 3 роки тому

    Love the edited format. Great video as always

  • @alincraciunescu
    @alincraciunescu 3 роки тому

    Super! Thank you!

  • @DePhoegonIsle
    @DePhoegonIsle 3 роки тому +2

    Honestly... I'd really suggest setting up a 'network cache/proxy' for a entirely shielded VM, and running the methods & seeing what the calls end up being & what ends up being sent & received.
    -- it's kinda how I captured several PS3 game installations to be stored ( that I legitimately owned )
    I know it's kinda reckless.. but perhaps a dedicated machine of windows 10.... behind a proxy cache server w/ a very strict in/out through said proxy only might be a good way to capture the raw files & data flying back & forth... and to see if any... which tricks are used.

  • @JustinC-thetacom
    @JustinC-thetacom 3 роки тому +8

    Have you tried querying the servers with different user agent strings like the one used by BITSAdmin (Microsoft BITS/7.5)?

  • @WhyDoIPosttt
    @WhyDoIPosttt 3 роки тому

    28:16 ... enhance.. Enhance... ENHANCE *CSI Zoom Enhance*. Great video John keep it up!

  • @cscogin22
    @cscogin22 3 роки тому

    Awesome video man, I enjoyed the new approach, entertaining and moved along at a good pace! Also very funny!

  • @DHIRAL2908
    @DHIRAL2908 3 роки тому +1

    The meme editing was hilarious!😆

  • @kalote86
    @kalote86 3 роки тому

    The montage level of this video is hilarious and fricking awesome. Thanks a ton o/
    ...
    The content is also good :)

  • @PanoptesDreams
    @PanoptesDreams 3 роки тому

    I really liked the long format

  • @ca7986
    @ca7986 3 роки тому +3

    Ahaha love this new editing! ❤️

  • @omarora7119
    @omarora7119 3 роки тому

    New channel logo is great !

  • @chrisbishop6928
    @chrisbishop6928 3 роки тому +1

    I will never be able to view the plumbus the same after this one

  • @caleboleary182
    @caleboleary182 3 роки тому +3

    Nice editing my man. Made me laugh out loud several times.

  • @hydejel3647
    @hydejel3647 3 роки тому +1

    this style is fun but i think the old one is more valuable as a learning resource

  • @alexandrecovolan8145
    @alexandrecovolan8145 3 роки тому

    Pretty neat the new style of video. Loved it.

  • @finthefail9599
    @finthefail9599 2 роки тому

    he did very serious research there

  • @noahpeltier
    @noahpeltier 3 роки тому +1

    I’m sure someone has suggested this already but It’s possible there is a key used in the code somewhere that passes to the GET request in the headers. Might use a Basic auth method.

  • @joyzyyy7810
    @joyzyyy7810 3 роки тому +1

    Yooo, i love the new editing style, keep it up

  • @crypt1c_mdp
    @crypt1c_mdp 3 роки тому

    i REALLY like those VBScript malware debunking vids great content keep it up

  • @tordanielsen8458
    @tordanielsen8458 3 роки тому

    Like the mix of edited and live :D

  • @_dot_
    @_dot_ 3 роки тому

    Let's boooost this channel into everyone's recommend videos!

  • @h8handles
    @h8handles 3 роки тому

    I stand by my point you are making great vids each time better

  • @hamzarashid7579
    @hamzarashid7579 2 роки тому

    Video editing is amazing!!

  • @Red4mber
    @Red4mber 3 роки тому

    i LOVE this new style of videos
    Keep it up, it's excellent !

  • @ibnsaltus
    @ibnsaltus 3 роки тому

    this style is so much better :)

  • @romanokeser
    @romanokeser 3 роки тому +2

    Yo this was a neat video, not too fast, not too slow. I like it a lot.

  • @Phaix
    @Phaix 3 роки тому

    You could check if they implemented an UserAgent check. If i want to limit access from spiders/robots or normal browsers i would implement a check for the UserAgent

  • @dutchprime1488
    @dutchprime1488 3 роки тому

    I like this new style of video!

  • @dean8012
    @dean8012 3 роки тому

    6:47 I have no idea why that made me laugh so hard.

  • @shad0wgamer969
    @shad0wgamer969 3 роки тому

    love this video

  • @malakasitchan
    @malakasitchan 3 роки тому

    I love this format! gosh!

  • @Sawta
    @Sawta 3 роки тому

    Personally, I like it when you figure it out on camera, but whatever helps you keep putting out content works for me.
    I'd be interested to know: for people who want to start examining Malware the way you do, what steps should be taken to stay safe-ish? I realize doing it in a VM is a must, but any other major points?

  • @abdeabdc6964
    @abdeabdc6964 3 роки тому

    feedback: the editing is nice and funny

  • @amaz404
    @amaz404 3 роки тому

    “Morty, I’m a drunk - not a hack!” ~Rick Sanchez, season 3 episode 4

  • @rrkatamakata7874
    @rrkatamakata7874 3 роки тому +1

    i'd like to see part2

  • @StanLTU
    @StanLTU 3 роки тому

    Dude I will watch all your videos

  • @piolix0004
    @piolix0004 3 роки тому

    Hah some fun editing this time, I like it.

  • @melnikovjnr
    @melnikovjnr 3 роки тому +2

    Funny how he looks similar to Justin Royland

  • @sameurbenhmouda1456
    @sameurbenhmouda1456 3 роки тому

    About the video style and format.., I think We'll still watch ur videos either it's a 30 min video or more than an hour xD just do whatever makes u feel comfortable xP

  • @johnmccarty6989
    @johnmccarty6989 3 роки тому

    dude i love your videos

  • @fredb5626
    @fredb5626 3 роки тому

    Hey John, love you content man - dont ever change, you insipre me and give me drive, so thank you ❤

  • @tg7943
    @tg7943 3 роки тому

    Algo push!

  • @icantfindaproperusername
    @icantfindaproperusername 3 роки тому +1

    It's perfect

  • @diddyman1958
    @diddyman1958 3 роки тому

    Awesome!

  • @fratd.6444
    @fratd.6444 3 роки тому

    John is #1

  • @hasmukhlalji6102
    @hasmukhlalji6102 3 роки тому

    i like this video
    very informative and entertaining at the same time
    very nice

  • @daniel173880
    @daniel173880 3 роки тому

    Man I love your videos!!!!

  • @Basieeee
    @Basieeee 3 роки тому

    These vids keep delivering😍😍

  • @charmquark0
    @charmquark0 3 роки тому

    Well you video is awesome. I love your content. I do hope that you do not keep spending more and more time editing and then get burnt out.... Please dont burn out :)

  • @jht5225
    @jht5225 3 роки тому

    I like this vid but if I had to choose between this style and the one before this. I definitely prefer the other one

  • @SakkakuTamashi
    @SakkakuTamashi 3 роки тому

    We finally know what actually is a plumbus. I didn't get it even with the "How they do it..." episode

  • @WatsonInfosec
    @WatsonInfosec 3 роки тому

    This was awesome please keep it up John, thanks!

  • @alexanderwidgren8821
    @alexanderwidgren8821 3 роки тому

    great video, love the new editing style too

  • @lepsycho3691
    @lepsycho3691 3 роки тому

    That was nice, a little bit easier on the time and overall digestibility, but I think it makes it feel more real when we experience it as you go and see the thought process behind. Maybe you could do twice the content, one livestream of the long style and one edited like this one? What do you think?

  • @charismaticmedia8585
    @charismaticmedia8585 3 роки тому

    Love your videos sir

  • @RizzCreates
    @RizzCreates 3 роки тому

    Great video!

  • @arronk3
    @arronk3 3 роки тому

    holy jesus another video, lets go

  • @Bleicht124
    @Bleicht124 3 роки тому

    Nice Video!

  • @foxdk
    @foxdk 3 роки тому

    Really wish this video was done live.
    That being said, I still love your vids.
    But you scrambling around, trying to figure out the try-catch issues, would actually have been very interesting.

  • @Serverfrog
    @Serverfrog Рік тому

    As you saw a Certificate: Maybe its using Client-Certificate authentication with an nginx config like
    ssl_verify_client optional;
    if ($ssl_client_verify != "SUCCESS") { return 403; }

  • @Lars-ce4rd
    @Lars-ce4rd 3 роки тому

    30:08 ah yes, I see it too