APT Malware (advanced persistent threat)

Поділитися
Вставка
  • Опубліковано 5 жов 2024
  • jh.live/snyk || Try Snyk for free and find vulnerabilities in your code and applications! ➡ jh.live/snyk
    Learn Cybersecurity - Name Your Price Training with John Hammond: nameyourpricet...
    Learn Coding: jh.live/codecr...
    WATCH MORE:
    Dark Web & Cybercrime Investigations: • Tracking Cybercrime on...
    Malware & Hacker Tradecraft: • Malware Analysis & Thr...
    📧JOIN MY NEWSLETTER ➡ jh.live/email
    🙏SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎FOLLOW ME EVERYWHERE ➡ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/discord ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware
    🔥UA-cam ALGORITHM ➡ Like, Comment, & Subscribe!

КОМЕНТАРІ • 102

  • @AgentAsteriski
    @AgentAsteriski 3 місяці тому +73

    the commitment to pronouncing it "collenction" as written is appreciated

  • @codebeta_cr
    @codebeta_cr 3 місяці тому +23

    That iColumn looks like it’s used to prevent it from running multiple times after it’s opened…

  • @ertaku1870
    @ertaku1870 3 місяці тому +7

    Excuse me. Where are the links that should have been in the description?

  • @jasonp3484
    @jasonp3484 3 місяці тому +4

    Loved the video Sir. The walk through with your thought process is extremely beneficial. Thank you.

  • @SzaboB33
    @SzaboB33 3 місяці тому +92

    Who else thought it was about the ubuntu package manager?

    • @Cyber_Gas
      @Cyber_Gas 3 місяці тому +36

      *debian package manager and i thought that too

    • @000t9
      @000t9 3 місяці тому +2

      😂 bro

    • @Dimitrys_af
      @Dimitrys_af 3 місяці тому +5

      *debian(?)

    • @sofiaknyazeva
      @sofiaknyazeva 3 місяці тому +14

      It's Debian's package manager, on which Ubuntu is based on.

    • @Cyber_Gas
      @Cyber_Gas 3 місяці тому +2

      @@sofiaknyazeva ye

  • @Goku_Black_SSJG
    @Goku_Black_SSJG 3 місяці тому +8

    I like how he brings the perfect amount of Entertainment and Education to the Table, You're my second favorite ICT Tutor! :D (First is NetworkChuck and Third is David Bombal)

  • @l3s7r0z
    @l3s7r0z 3 місяці тому +6

    Sick analysis bro!

  • @Max-kl7il
    @Max-kl7il 3 місяці тому +10

    "let me fulfill a contractual obligation" does Mr. Hammond watch Schlatt?

  • @mattplaygamez
    @mattplaygamez 3 місяці тому +3

    John, you could use WinUtil to remove Defender completely

  • @daniellowrie
    @daniellowrie 3 місяці тому +5

    Excel-lent job, my friend 😅😁
    Seriously though, loved this video.Two thumbs up
    👍👍

  • @GNUGradyn
    @GNUGradyn Місяць тому

    Interesting that you get the actual copy dialog when you copy in vbscript

  • @Ahri--
    @Ahri-- 3 місяці тому +3

    Very interesting, thanks for showing!

  • @sofiaknyazeva
    @sofiaknyazeva 3 місяці тому +7

    Looks like malware from 1998.

  • @bloodborneloverrr7646
    @bloodborneloverrr7646 3 місяці тому +9

    A pakistani advanced persistent threat??

  • @christophertharp7763
    @christophertharp7763 3 місяці тому +3

    this is what we love john!!!

  • @KaranYadav-mb7tl
    @KaranYadav-mb7tl 3 місяці тому +9

    Delhi is a capital of India Jhon 🇮🇳

  • @W0lfCL
    @W0lfCL 3 місяці тому +2

    Why did the creator include these Replace("_", "") or whatever in the code? I doubt it somehow bypasses virus protection and it really doesn't obfuscate the code that much

    • @blinking_dodo
      @blinking_dodo 3 місяці тому +7

      To prevents static analysis.
      If someone or something searches for common strings like "autorun", having it split up into "auto_" and "whaterver_run" makes it harder to find.
      It won't completely bypass AV's, but it does a pretty good job to not make it easy either, i'd say.

  • @alaminiumar
    @alaminiumar 3 місяці тому +2

    Thanks 🎉

  • @phuk_propaganda
    @phuk_propaganda 3 місяці тому +2

    Do APT malware not bother to break through VM’s?

    • @skycaptain95
      @skycaptain95 3 місяці тому +1

      It is very difficult to escape a properly set up virtual machine.

    • @detective5253
      @detective5253 3 місяці тому +3

      It does, that's implemented via anti-sandboxing technique where the malware acting smart and being able to detect whether the operating system is running on VM box or not. Some really evasive malware coded to specifically sleep for amount of time untill it find some ways to sneak in to the user's environment by just infecting external storage devices etc...

  • @badrakhariunchimeg1031
    @badrakhariunchimeg1031 3 місяці тому

    Can be used as smart saver?

  • @wardrich
    @wardrich 3 місяці тому +7

    apt-get install malware

    • @j_ray0101
      @j_ray0101 3 місяці тому +2

      Instructions unclear, my PC is ssh into Iran somewhere

    • @callummcclure2186
      @callummcclure2186 3 місяці тому +1

      Instructions unclear, it removed my desktop environment.

  • @threeMetreJim
    @threeMetreJim 2 місяці тому

    22:20 - "that doesn't seem like a real worthwhile IP address..." - Obviously didn't geolocate it.

  • @ExploreSciFi
    @ExploreSciFi 3 місяці тому +4

    Pakistan????

  • @ChandravijayAgrawal
    @ChandravijayAgrawal 3 місяці тому +1

    people in government who use PC are not as smart in using computers, so even if this malware function is somewhat old, people would still become its victim, but I wonder what kind of data has been leaked by this, I know Aadhaar including biometric of every Indian is available somewhere on internet, with so weak security, if it somehow reaches India missile control center, it would be dangerous, could cause world war 3

  • @davidmuriithi1809
    @davidmuriithi1809 3 місяці тому +1

    Thought it was APT the package manager. Lol

  • @johnaloe
    @johnaloe 3 місяці тому

    this is great thanks johnny🥰

  • @maxim9376
    @maxim9376 3 місяці тому +5

    1:48 Diagnosis: Brain damage, you literally just had to click activate to see the macros.

  • @vainkrantz
    @vainkrantz 3 місяці тому

    Where can I find the malware file?

  • @E-Power2023
    @E-Power2023 19 днів тому +1

    Don't upload in virus total

  • @MalwareHunter_07
    @MalwareHunter_07 3 місяці тому

    malware sample hash?

  • @olnnn
    @olnnn 3 місяці тому +1

    Why are excel macros allowed to access all these things? no wonder excel macros are a security nightmare

    • @adhitamaputra-73
      @adhitamaputra-73 3 місяці тому

      .b.i.n.a. .s.a.r.a.n.a. .i.n.f.o.r.m.a.t.i.k.a.

  • @aakashraman274
    @aakashraman274 3 місяці тому +1

    Loved this!

  • @steiner254
    @steiner254 3 місяці тому +1

    nice!

    • @l3s7r0z
      @l3s7r0z 3 місяці тому

      Very nice 😅

  • @Tatsuia0
    @Tatsuia0 2 місяці тому

    love this content

  • @Manavetri
    @Manavetri 3 місяці тому

    Brilliant.

  • @xCheddarB0b42x
    @xCheddarB0b42x 3 місяці тому

    Congrats to Huntress on $1.5B valuation. o_O

  • @carsonjamesiv2512
    @carsonjamesiv2512 3 місяці тому

    INTERESTING!

  • @TuruMas-b3r
    @TuruMas-b3r 3 місяці тому

    You good?

  • @クールな奴ら
    @クールな奴ら 3 місяці тому

    Nice!

  • @msalih
    @msalih 3 місяці тому

    20:31 isEsaean catch my eyes. I saw another case Russian hackers put their ransomwares an indicator whether the system use russian keyboard or not..
    isEsaean maybe isAsian to protect computers from friendly fires also

  • @planktonfun1
    @planktonfun1 3 місяці тому

    its a zombie factory file

  • @draxler.a
    @draxler.a 3 місяці тому

    but i don't see any advance in all this!!!!

  • @аутофелляция
    @аутофелляция 3 місяці тому

    hi

  • @aldyreal
    @aldyreal 3 місяці тому

    One minute ago is crazy

  • @rakeshchowdhury202
    @rakeshchowdhury202 3 місяці тому

    If apple was a construction company: iColunn

  • @surgeon23
    @surgeon23 3 місяці тому +2

    I wonder what that "summer collenction" might be, let's just open it ¯\_(ツ)_/¯

    • @KenderGuy
      @KenderGuy Місяць тому

      only 8 nearly identical images, what a waste of time
      now to log into my bank

  • @RaGhav363
    @RaGhav363 3 місяці тому

    Delhi india

  • @dgoncalo
    @dgoncalo 3 місяці тому +3

    How is this an APT malware if you need to disable defender to run it? LOL

    • @eFxAstro
      @eFxAstro 3 місяці тому +2

      Because since its discovery, it has been added to defenders checklist.

  • @JohnDoe-bq5oo
    @JohnDoe-bq5oo 3 місяці тому

    ""advanced"" persistent threat but they can't even spell collection..

    • @zaryabK-vi8fh
      @zaryabK-vi8fh 3 місяці тому +1

      i was surprised that Pakistan has an apt and spelling in English doesn't make someone a good hacker like look at the Russian or north koreans

  • @TotalImmort7l
    @TotalImmort7l 3 місяці тому

    Sneak? Man I thought they are Synk.
    Edit: Shit I just realised that I've been pronouncing it wrong for almost 3 years 💀

  • @gooniesfan7911
    @gooniesfan7911 3 місяці тому

    Lol an unobfuscated and outdated crimsonrat they weren’t going to get any infections like that 😂

  • @Bakesyy
    @Bakesyy 3 місяці тому +1

    Close to first

  • @pekhejdj
    @pekhejdj 3 місяці тому

    woo 500 views?

  • @LDowning0190
    @LDowning0190 3 місяці тому

    Comment for the algorithm 🎉

  • @minisaints
    @minisaints 3 місяці тому

    not not first

  • @Joker-gl7se
    @Joker-gl7se 3 місяці тому +1

    first

  • @a_random_duck_on_youtube
    @a_random_duck_on_youtube 3 місяці тому

    not first

  • @TheCat-jk2vq
    @TheCat-jk2vq 3 місяці тому

    yea APT def not using macros these days bro

    • @_JohnHammond
      @_JohnHammond  3 місяці тому +3

      This sample is two weeks old. yea they def are bro

    • @TheCat-jk2vq
      @TheCat-jk2vq 3 місяці тому

      @@_JohnHammond ok? sample is 2 weeks old this has been old news for over a year no one uses this

    • @skycaptain95
      @skycaptain95 3 місяці тому +1

      yea nobody uses phishing attacks anymore these days bro it's totally obsolete

    • @TheCat-jk2vq
      @TheCat-jk2vq 3 місяці тому

      @@skycaptain95 yep thats what i said LOL

    • @vaibhav3852
      @vaibhav3852 3 місяці тому

      ​@@_JohnHammondif I was able to understand its working, I would say it's not atleast advance

  • @amodo80
    @amodo80 3 місяці тому

    BirvTrving 2024

  • @vsivakrishna9647
    @vsivakrishna9647 3 місяці тому

    damn