Malware's LAST Stand: SELF-DELETION

Поділитися
Вставка
  • Опубліковано 28 лис 2024

КОМЕНТАРІ • 157

  • @crr0ww
    @crr0ww  Рік тому +27

    📌 Use code "CROW10" for 10% off your order when you checkout at Maldev Academy FOR A LIMITED TIME! ---> maldevacademy.com/?ref=crow
    I better see you dorks in kernel-land soon >:)
    🫠 ERRATA:
    - 51:43 I meant the opposite. You're copying data from your SOURCE into your DESTINATION. Y'KNOW, LIKE A NORMAL PERSON WOULD SAY.

    • @peppidesu
      @peppidesu Рік тому

      CROOOOOOOOOOOOOOOOOOOW

    • @DaxSudo
      @DaxSudo Рік тому +1

      Ahhh this is only for the lifetime subscription. Dang

    • @PlanetComputer
      @PlanetComputer Рік тому

      YES

    • @crckrbrrs
      @crckrbrrs Рік тому

      see you next year on your next upload

  • @_JohnHammond
    @_JohnHammond Рік тому +39

    YEAHH!!!!!

  • @sinatra02
    @sinatra02 Рік тому +94

    CROW'S FIRST SPONSER???? LETS GOOOOOOOOOOOO

  • @danomaly8943
    @danomaly8943 Рік тому +22

    2:37 I mentioned this in a seminar and everyone including the professor talked about me like I was crazy or I’m a bad guy or that ethical hackers wouldn’t dream of doing such a thing. We just run nmap and metasploit…don’t mean to vent but it’s good to know I’m not crazy for thinking that way

  • @real2late
    @real2late Рік тому +20

    This is one of the few Tutorials I know that actually are fun to watch, love the way you make the videos

  • @bollamebendrikb1923
    @bollamebendrikb1923 Рік тому +10

    Bro I literally thought of this and was trying to make it yesterday how tf am I this lucky that crow is covering it

  • @PeteClean
    @PeteClean Рік тому +3

    This is the only channel i know where sponsors doesn't feel like garbage, my lifetime subscription to MDA is going BRRRRRRR

  • @captdev
    @captdev Рік тому +9

    I love the shear joy CROW shares when everything comes together at the end 😁

  • @omerfaruksonmez5668
    @omerfaruksonmez5668 Рік тому +1

    i mean, watching this at like literally 3 am and so inspired that im gonna try it out my self instead of sleeping. amazing content bro keep it up

  • @danomaly8943
    @danomaly8943 Рік тому +16

    Another masterpiece. I have learned SO much from these videos and what I have read from the discord.

  • @cryptohoagie963
    @cryptohoagie963 Рік тому +5

    This is f*cking awesome, never knew this was even possible lol, was literally creating a new process to delete my malware for self deletion 🙃 keep it up crow best mal dev on youtube for sure

  • @detective5253
    @detective5253 Рік тому +2

    Ohhh yeaaaaa we need lots of videos like this about modern red team and malware development please

  • @Sizzlik
    @Sizzlik Рік тому +2

    A wise man once said "With great power, comes great electricity-bill"

  • @byte-sec
    @byte-sec Рік тому +6

    Perfect content, Perfect quality, Perfect explanation 🔥

  • @ttj_
    @ttj_ Рік тому +1

    never have i clicked on an hour long youtube video faster than i have with this. I'm in a for a treat!

  • @D3ltaLabs
    @D3ltaLabs Рік тому +1

    I'm itching for the 4th video in this series. Thanks for the videos crow.

  • @torphedo6286
    @torphedo6286 Рік тому

    Why write in assembly instead of implementing it in C like the kernel does? It's way more readable, you don't need to deal with linking in an assembly file, and there's no "extern"s required in your headers.
    Also, it's kinda overkill, but another fun approach to anti-anti-debugging would be to hook the program's anti-debugging function and force it to always return false (or just patch the binary). Anyway, loved the video! This was super informative. I've had a lot of issues with my non-malicious process injection getting flagged by Defender. I never even thought to re-implement suspicious imports myself.

  • @believeit5450
    @believeit5450 Рік тому +1

    The Maplestory BGM is what keep me watching

  • @AM-og2oi
    @AM-og2oi Рік тому +1

    Bro the video editing was great, awesome new vid!

  • @animeshshukla6758
    @animeshshukla6758 Рік тому +2

    Sorry for asking, but the file that is still being viewed, it can not delete itself in the middle right? the deletion is only possible after the executable is done running.
    but this is a problem, if a file is being gives a command for self deletion, it is technically still running, and running file can not be deleted. Is it some sort of extrafile buffer? like, windows gets the command to delete and it does after the file is done running?

  • @bsherman8236
    @bsherman8236 Рік тому +2

    Crazy production, information and comedy

  • @animeshshukla6758
    @animeshshukla6758 Рік тому +1

    I saw a one hour video with
    A language i dont use
    A field i am not in
    terms i have no clue about
    OS i dont know much about
    10/10 will watch again.

  • @goobertnelius
    @goobertnelius Рік тому +3

    I cant believe I watched a 1 hour video involving a language I don't even code in on a daily basis (I do code in C++ rarely for a variety of reasons so don't go all: "C++ is superior" on me)

  • @vespervenom2343
    @vespervenom2343 Рік тому +3

    Keep coming out with these videos. Love them 🔥

  • @TreeloPlays
    @TreeloPlays Рік тому +3

    Babe wake up new crow just dropped!

  • @Gobillion160
    @Gobillion160 Рік тому +2

    oh my god mom cancel my plans new crow video just dropped!!

  • @black_wolf365
    @black_wolf365 Рік тому +2

    Just yesterday, I was wondering when's your next video coming ... And today I get this notification! 😊 Thank you crow! 🍻 😊

  • @uirwi9142
    @uirwi9142 Рік тому +1

    it is illegal to delete this video!
    Crow=Legend!

  • @user-bg1xh3yl5o
    @user-bg1xh3yl5o Рік тому +3

    Great video and congrats on the sponsor man keep it up!

  • @mohammedzaid6634
    @mohammedzaid6634 Рік тому +2

    What a interesting stuff!!!!!!
    I learned a TON!!!!!!!!
    CAN'T WAIT TO SEE YOUR NEXT VIDEO

  • @trintlermint
    @trintlermint Рік тому +5

    I am crying from happiness at the moment, I am truly happy that you got your video out which you worked hard on crow. I hope you take a break and dont suffer from burnout my brother :)

  • @nutbowl3459
    @nutbowl3459 Рік тому +3

    Amazing video, keep up the good work

  • @crckrbrrs
    @crckrbrrs Рік тому +1

    holy shit holy shit holy shit holy shit
    CONGRATS ON YOUR FIRST SPONSOR DUDE

  • @nightlockhayze
    @nightlockhayze Рік тому +1

    YAYY!! NEW CROW VIDEOO WE MISSED YOUUU

  • @nocnoc146
    @nocnoc146 Рік тому +1

    i love the maplestory music

  • @Limofeus
    @Limofeus Рік тому +1

    So, intead of self deletion I had an idea once of a program that would embed some data inside the executable file. I wonder if it is possible to do with alternate data streams, would be cool to have a single exe that saves all the data it generated traveling between different machines.

  • @icoudntfindaname
    @icoudntfindaname Рік тому +2

    Your's is the only hour long video i'd watch

  • @martin_nav
    @martin_nav Рік тому +2

    You forgot to tickle Mr. Rat. He will not be happy. I hear 22kHz here. (Only people from discord server understand)

  • @NopeNotThatGuy
    @NopeNotThatGuy Рік тому +1

    Lord Have Mercy on My Analyst Soul 😧

  • @donadoamed
    @donadoamed Рік тому +3

    you're my hero.

  • @kernelpanics
    @kernelpanics 11 місяців тому

    It's just remembering me of 29a VX group in 2000's 😃

  • @snk-js
    @snk-js Рік тому +2

    these are the best of the whole yt prove me wrong

  • @nickmullen9510
    @nickmullen9510 Рік тому +1

    the pricing is absolutely insane

    • @lavender0666
      @lavender0666 Рік тому

      Been on the platform for a month now and can say that it's completely worth it, there are cheaper options though (Sektor 7 for example) though they're not as in-depth/up to date as maldev academy

  • @rozer4660
    @rozer4660 9 місяців тому

    Let's go man this channel is amazing keep on the good work fr best channel on UA-cam damn

  • @pbnjdev
    @pbnjdev Рік тому +1

    Me compiling a hello world program and executing only for the executable to get blocked by Windows Defender as malware.
    Also me: IAM MALWARE DEVLOPER \o/

  • @Local_microwave
    @Local_microwave Рік тому +2

    Woke up to a new video let’s go

  • @emileberteloot6546
    @emileberteloot6546 Рік тому +1

    Why renaming the default datastream before deleting it ?
    Can't you just delete the default one ?

  • @999_jah
    @999_jah Рік тому +3

    This video is amazing man, keep it up :)

  • @cjsmax75
    @cjsmax75 8 місяців тому

    Hello, thanks for the video,
    When getting a handle to the file, from where did we find that we can give the CreateFileW the values (delete | sync) for the dwDesiredAccess field, since I haven't found that documented anywhere !!!

  • @moylababa8196
    @moylababa8196 Рік тому

    kindly give us a roadmap "how to learn cyber security from scratch to advance"

  • @principleshipcoleoid8095
    @principleshipcoleoid8095 Рік тому

    Tbf, in a war malware can be handy. Like let's say hypothetically Russia starts a war with another country, but all their electronics suddenly show a ransomware message

    • @lavender0666
      @lavender0666 Рік тому

      Cyber Warfare is a real thing already, there are state sponsored hackers in all governments (see NSA/CIA for US)

  • @RandomDude_404
    @RandomDude_404 Рік тому

    Like always awesome vid! btw what IDE do you use?, and also, can you do a video on how to setup windows 10 for malware development? cuz downloading the C++ compiler (gcc) is making me want to "self delete" if u know what I mean

  • @hydradragonantivirus
    @hydradragonantivirus 8 місяців тому

    Heuristics is most power come from at antivruses.

  • @grandjagon3190
    @grandjagon3190 6 місяців тому

    All your videos are amazing dude thanks ! Keep it up !
    However here I don’t get why we need ADS, can’t the malware goes to deletion phase directly ?

  • @nathanezra1
    @nathanezra1 Рік тому +1

    This gonna last me for the next month

  • @vackor
    @vackor Рік тому +3

    ur vids are great! i feel violated by the stream of information that we have access too in this day and age :^)

  • @danomaly8943
    @danomaly8943 Рік тому +3

    Gotta take another crack at this from the beginning. Somehow my smart dumbass got the program to work but in reverse. I’ve played around with it and even tried some else statements but still a great video. I learned a lot…just gotta rest my eyes…

    • @danomaly8943
      @danomaly8943 Рік тому

      I’m an idiot lol. The joys and pain of coding. Smh

  • @gojo1825
    @gojo1825 Місяць тому

    I love your videos! Please don't stop 🙏

  • @dead-wi2el
    @dead-wi2el Рік тому +1

    HYPEEEE NEW CROW VIDEO

  • @meatdawizardpat
    @meatdawizardpat Рік тому

    4:40 what is that obsidian theme tho 🔥

  • @phantompuma228
    @phantompuma228 Рік тому +1

    A SPONSOR AND CROWS RAT VOICE REVEAL. TODAY'S A GOOD DAY.

  • @amirakmel123
    @amirakmel123 Рік тому +1

    why do I think of you as my personal mentor😊

  • @dvxv4016
    @dvxv4016 Рік тому

    28:07 there actually was a 1337 process on my pc, i was wondering why it didn't and i was getting a handle wtf

    • @lavender0666
      @lavender0666 Рік тому +1

      The process is different for everyone, they're not hardcoded in but given on runtime (process creation)

  • @Mauzy0x00
    @Mauzy0x00 Рік тому +2

    I shall become a rat amongst men

  • @AtomicBl453
    @AtomicBl453 Рік тому

    Their AI needs to train on a protection less computer so it can best serve both sides.

  • @lowHP_
    @lowHP_ Рік тому +1

    great video, thanks a lot 👍

  • @mnageh-bo1mm
    @mnageh-bo1mm Рік тому +1

    this vid is god tier.

  • @bam6693
    @bam6693 Рік тому

    Make a video how malware can tell if the OS is updated using windows update.

  • @PlanetComputer
    @PlanetComputer Рік тому +1

    YES CROW

  • @petevenuti7355
    @petevenuti7355 Рік тому

    So is there any defensive software you would recommend? That primarily uses behavioral heuristics without having to be online...‽

    • @lavender0666
      @lavender0666 Рік тому +1

      EDRs, XDRs and AVs rely on being online to update their signatures and whatnot, having them offline can make it harder for them to pick up newer malware strains

    • @petevenuti7355
      @petevenuti7355 Рік тому

      @@lavender0666 automatic updates feel like a good attack vector, heck if that were my thing that would be one of the first ways I'd try and get in, by emulating the antivirus vendors servers, even if I failed I'd be able to figure out what I was up against.

    • @lavender0666
      @lavender0666 Рік тому

      @@petevenuti7355 that's not a new thing, they're called Trojans and they've been around for decades

  • @_____666______
    @_____666______ Рік тому

    is it possible to patch memory that is protected by vmprotect ?

  • @0123bar
    @0123bar Рік тому +1

    Hi crow great content!! I really enjoy your videos,Can you do a video about how memory works, virtual memory, pages and memory protections?

  • @repairstudio4940
    @repairstudio4940 Рік тому

    How'd you learn C and Assembly? MalDev Academy or TCM. DeWalt, Alex and the crew at TCM are awesome.

  • @lavender0666
    @lavender0666 Рік тому +5

    LET'S GOO C:

  • @Zetty
    @Zetty Рік тому +3

    very cool very pog very based

    • @crr0ww
      @crr0ww  Рік тому +1

      I LOVE YOU, CRYPTID

  • @Karanveer-hf4gu
    @Karanveer-hf4gu Рік тому

    I'd really suggest you to upload videos to somewhere else other than UA-cam, Until and unless they delete this gem like content.

  • @ellescer
    @ellescer 5 місяців тому

    I’ve used these techniques and am now in jail.

  • @kipsangjacob270
    @kipsangjacob270 Рік тому +1

    Awesome content 🎉🎉🎉🎉

  • @thomasslone1964
    @thomasslone1964 9 місяців тому +1

    stop defending your self from non programmers just ignore them their dislikes don't matter

  • @piolix0004
    @piolix0004 Рік тому +1

    HOLY MOLY 1 ENTIRE HOUR NOW I GET WHY YOU'RE BEEN GONE SO MUCH
    GET THAT BREAD BRO

  • @Venormous98
    @Venormous98 Рік тому +1

    SORRY, CROW, BUT WHERE'S MY FUCKEN RAT

  • @Jcb-pt2qn
    @Jcb-pt2qn Рік тому

    is there any financial in malware dev (this is for educational purpose)

  • @newtonj1n
    @newtonj1n Рік тому

    Ooooh noooo, you missed UEBA!!!

  • @PratyakshaBeri
    @PratyakshaBeri Рік тому +1

    This is amazing content! I wish I found you sooner...

  • @principleshipcoleoid8095
    @principleshipcoleoid8095 Рік тому

    2:45 can malware be a form of self defence?

    • @lavender0666
      @lavender0666 Рік тому

      you're gonna have to expand on that, if you're attacking someone without explicit permission then that's a crime

    • @principleshipcoleoid8095
      @principleshipcoleoid8095 Рік тому

      @@lavender0666 Russia. Well it's military. Didn't want to get attacked? Then should had not started a war in 2014 or escalated it.

    • @lavender0666
      @lavender0666 Рік тому

      @@principleshipcoleoid8095 Look up cyber warfware. If a country is attacking another country's assets as soldiers/military personnel then that's okay but if you're doing vigilante stuff that's a legal gray

  • @lavender0666
    @lavender0666 Рік тому +3

    can we have a video on how to heck Roblox please 🥺

  • @sinatra02
    @sinatra02 Рік тому +3

    crow can you make a video on how to hack into the hexagon >:)

    • @crr0ww
      @crr0ww  Рік тому +2

      hacking is 4 nerdz and ill eagle no tanks (they're in my walls listening to me)

  • @lcizzlelc
    @lcizzlelc 10 місяців тому

    Thanks for the tutorial and infecting me with AdWare at the same time. Great! = D

    • @lcizzlelc
      @lcizzlelc 10 місяців тому

      I'm trolling. You do you boo boo. Videos are very entertaining even though I don't know wtf you are talking about. (I do, again trolling) You owe me a motherboard.

  • @DroneMothership
    @DroneMothership Рік тому +1

    OH AH!!! 10% OFF ETERNAL ACCESS!!! LETS GOOOOOOO RATS!!!

  • @URdfkfe_Hodapej-cv9zo
    @URdfkfe_Hodapej-cv9zo Рік тому

    Where are you?

  • @bv1495
    @bv1495 Рік тому

    Hey awesome tutorial ! is the source code available? i couldn't find it in GH

  • @jonbikaku6133
    @jonbikaku6133 Рік тому

    Bro do you also have courses?

  • @DanMworia
    @DanMworia 3 місяці тому

    awesome job bro. Time to kick a$$

  • @principleshipcoleoid8095
    @principleshipcoleoid8095 Рік тому

    1:38 can malware be used to arrest Putin? Can it? Can it be used for that?

  • @ismailaf3634
    @ismailaf3634 Рік тому

    it's all about that 1:00:51

  • @HTWwpzIuqaObMt
    @HTWwpzIuqaObMt Рік тому +1

    777 like btw. I use arch btw. Wonderful video btw. U got hr ass ur first sponsor congratulations 🎉🎉🎉🎉🎉🎉🎉❤❤❤ btw. (I use arch)

  • @BakA-um3kb
    @BakA-um3kb Рік тому

    Большое спасибо за твои видео 😼💖

  • @justin7oo994
    @justin7oo994 Рік тому +1

    Rule number 0.5: disconnect yourself from the internet ( the best solution )

  • @hozehd8246
    @hozehd8246 Рік тому

    First ever crow video that confuses me...

  • @alec3217
    @alec3217 6 місяців тому

    Henlo, wer video, post soon