Is THIS a VIRUS? Finding a Remcos RAT - Malware Analysis

Поділитися
Вставка
  • Опубліковано 25 лис 2024

КОМЕНТАРІ • 899

  • @johnjohnerd6921
    @johnjohnerd6921 3 роки тому +1756

    "This is just 75 lines of code"
    *Half hour later*
    "201 thousand characters selected"

    • @AlucardNoir
      @AlucardNoir 3 роки тому +56

      that's how they get you man, that's how they get you.

    • @geist453
      @geist453 3 роки тому +4

      @@AlucardNoir AND YOU BUT GUESS WHO NOT?! ME AND JOHN

    • @GuyMassicotte
      @GuyMassicotte 3 роки тому +19

      Majorly loaded by a fake jpg ;)

    • @bansku570
      @bansku570 3 роки тому +1

      @@geist453 l

    • @nojusnojus8015
      @nojusnojus8015 3 роки тому +1

      @@bansku570 I

  • @DenyardTV
    @DenyardTV 3 роки тому +362

    Ngl, never thought it would be so much fun watching someone analyse and breakdown a virus.

    • @KrakenPipe
      @KrakenPipe 3 роки тому +14

      I was thinking the same thing! I might have just discovered my new rabbit hole lol

  • @0xRalu
    @0xRalu 3 роки тому +780

    Love this malware analysis series!

    • @ismhdez
      @ismhdez 3 роки тому +5

      Me too! Amazing series

    • @syverlunde9622
      @syverlunde9622 3 роки тому +2

      I love it too!

    • @jbgaud
      @jbgaud 3 роки тому +1

      me too, this guy is really good.

    • @s.broyal5128
      @s.broyal5128 2 роки тому

      Sir. Can I use remcos rat to hack Android...

  • @andmo90
    @andmo90 3 роки тому +217

    Content like this is why I don't have to pay for cable, satellite, or netflix!

    • @garethevans9789
      @garethevans9789 3 роки тому +5

      But then he would have been on 8-12 screens and typed those 200k characters (hacking is typing fast), it's all hard to follow. It would be like watching the Matrix.

    • @viv_2489
      @viv_2489 3 роки тому

      Yeah

    • @SiveenO
      @SiveenO Рік тому

      Okay, but consider this: TOS and TNG are on Netflix.

  • @bennettpalmer1741
    @bennettpalmer1741 3 роки тому +155

    I love how they went through six stages of obsfuscation, and a lot of effort into hiding what they were doing.... but their payload was literally called "Attack.jpg" like surely they could have named it something at least slightly less blatant.

    • @FilliamPL
      @FilliamPL 3 роки тому +8

      Perhaps they didn't care to hide it at that point? I know that obfuscation helps to counter analysts, but when the code is downloading data from a URL, then I suppose it wouldn't've been worth their effort to obscure the name of the download. Then again, they could've made a second download with totally unnecessary data. Either way - this thing is bad (for you)! xD

  • @slygamer01
    @slygamer01 3 роки тому +384

    The REMCOS developer "discourages malicious use". For sure, everyone will use solely for legitimate purposes.

    • @aliencatmeow
      @aliencatmeow 3 роки тому +17

      'sure if you say so' meanwhile no one uses it legitimately

    • @karimmohamed3744
      @karimmohamed3744 3 роки тому +20

      Malicious actors: amma head out

    • @garethevans9789
      @garethevans9789 3 роки тому +28

      Ethical hackers don't sell hacking toolkits, ethics and all that... 🤷‍♂️

    • @technoturnovers7072
      @technoturnovers7072 3 роки тому +34

      @@garethevans9789 Pentesting tools are released open source because not only is open source more effective, but it makes sure that the developers are not potentially profiting off of malicious actors, intentionally or not.

    • @cyber1377
      @cyber1377 3 роки тому +4

      Meh, skids are gonna find a way anyway. With our without this program.

  • @baremetalHW
    @baremetalHW 3 роки тому +295

    Damn that was fun to watch!! Thanks and keep them coming!!!!!!

  • @NickyPuff
    @NickyPuff 3 роки тому +136

    I love when John is laughing over the Attack.jpg url

  • @richie7425
    @richie7425 3 роки тому +977

    Times must be hard, Ed Sheeran is writing python.

    • @batmanasdasd
      @batmanasdasd 3 роки тому +11

      Lmaooo💀💀

    • @HiramSalinas
      @HiramSalinas 3 роки тому +6

      he looks like an unscuffed burgerplanet

    • @realitynowassigned
      @realitynowassigned 3 роки тому +27

      This is ed sheerhan and Seth rogans kid.

    • @HaxorBird
      @HaxorBird 3 роки тому +9

      You are the hacker version of pewdiepie. Very entertaining to watch.

    • @lusthetics
      @lusthetics 3 роки тому +15

      Nah he looks like a de deobfuscated Ed Sheeran

  • @donaldduck6198
    @donaldduck6198 3 роки тому +50

    John, as you are very good, you should stand this comment: In Powershell a "split (..)" is a regular expression splitten in string in portione of two characters, ie "4142" becomes "41", "42", in Hex AB

  • @TracyNorrell
    @TracyNorrell 3 роки тому +72

    Scheduling this to start at the same time as the new mars rover is landing... Bold move cotton, let's see how it works out

    • @_JohnHammond
      @_JohnHammond  3 роки тому +21

      Bah, totally didn't even realize xD Ah well!

    • @originalgaming9062
      @originalgaming9062 3 роки тому +5

      @@_JohnHammond I’d prefer watching this over some rover landing

    • @originalgaming9062
      @originalgaming9062 3 роки тому +2

      @@tripplefives1402 isn’t the rover automatically controlled because the delay would be 10 minutes long?

  • @vannialora3476
    @vannialora3476 3 роки тому +12

    the evolving of rat is so amazing, i remember in late 90's where sub7, netbus and back orifice was so popular and inspired me into hacking. IRC was the channel to go to before and dial up is your connection.

  • @Corb4nm0noxide
    @Corb4nm0noxide 3 роки тому +62

    So far this is the most fun I've had watching hacking videos. Your analysis is fantastic and I enjoy seeing your process. Keep it up!

  • @whatnowsami9225
    @whatnowsami9225 3 роки тому +246

    Nobody:
    Virus Code: * Does malicious stuff*
    John: Is it trying to do something bad? HAHAHA
    Us: Duhhh John. wtf

  • @ycoihmn6388
    @ycoihmn6388 3 роки тому +55

    This style of video really helps me with my start in forensics and malware analysis. I love liveoverflow and other CTF summary channels but they often feel like magic in the way they present their findings. Keep up the great work :3

  • @m1rz
    @m1rz 3 роки тому +26

    Pretty sure you need to run the obfuscated version of the AMSI bypass.
    Great video, would love to see more of these!

  • @Dilipkumar-ur9zx
    @Dilipkumar-ur9zx 3 роки тому +22

    After watching this, gained a keen interest in Malware Analysis. Thanks for the awesome content.

  • @darkdagger032
    @darkdagger032 3 роки тому +35

    This is one of the best educational videos i've seen

  • @rccservice
    @rccservice 3 роки тому +18

    that url has to be the greatest thing ive ever seen

  • @dustinjohnson7635
    @dustinjohnson7635 3 роки тому +35

    Amazing work, you deserve the money from the UA-cam overlords. Literally only commented to help boost those algos.

  • @willo7734
    @willo7734 3 роки тому +7

    Whatever that quality is that great teachers have, you have it. Never change the format of your videos. I love seeing you troubleshoot and reason through everything live.

  • @definesigint2823
    @definesigint2823 3 роки тому +23

    I've taken apart stuff like this (when I worked in large enterprise) but the samples were rarely more than 3-4 levels deep. This actually looks a lot more like a challenge you'd get at a CTF competition _(perhaps they're getting ideas from each other)_ ?

  • @uniquechannelnames
    @uniquechannelnames 3 роки тому +42

    Algorithm, give this man the recs.

  • @patchbyte6856
    @patchbyte6856 3 роки тому +92

    this is gonna be good

  • @ultimate8673
    @ultimate8673 3 роки тому +83

    The guy that wrote the script watching this video rn must be like 👁️👄👁️

  • @TheSeakr
    @TheSeakr 3 роки тому +8

    I'm just finding this channel and its quickly becoming my favorite content. Im fascinated with all of this. Really inspires me to get started with basic coding to get my feet wet.

  • @Edzward
    @Edzward 3 роки тому +2

    You need I high level of nerdiness to find this entertaining. Proof: I find highly entertaining!
    Love this.

  • @britishpiperygo
    @britishpiperygo 3 роки тому +22

    Loving this series. Would like to see some disassembling malware analysis.

  • @auto117666
    @auto117666 3 роки тому +13

    In the next episode... John rewrites the kernel for more efficient find and replace..... STONKS!

  • @md123180
    @md123180 3 роки тому +7

    Where have you been all my CS degree? This is awesome watching this stuff in action as you do it. I love the content! Definitely going to keep watching!

  • @randallsalyer
    @randallsalyer 3 роки тому +5

    I love John’s response when the light bulb goes off and all the hard work comes together. Great video as always.

  • @mechanicalfluff
    @mechanicalfluff 3 роки тому +16

    i missed the premiere, but this is definitely a blast to watch. Would love to see this more

  • @Ayayron_e3
    @Ayayron_e3 3 роки тому +49

    "guys, you might think i'm dumb" LOL exact opposite.

  • @eliasgamezgarcia3414
    @eliasgamezgarcia3414 3 роки тому +4

    Dude you are simply awesome...it's so enriching for all of your viewers to see your hard work and all your skills, and the best of all is that we can see you enjoying so we enjoy and learn too. Regards from Spain!

  • @pumpkin7976
    @pumpkin7976 3 роки тому +76

    Plottwist: this is all just an advertisement for BreakingSecurity

  • @mbowler05
    @mbowler05 3 роки тому +3

    Hands down one of the best malware analysis walkthroughs I’ve seen. Watched it twice.

  • @PerfectEn3my
    @PerfectEn3my 3 роки тому +3

    Great video, I love this series. Also special thanks for zooming in this much, watching code-related stuff on phone is usually a pain, but not in your case. Keep up the good work!

  • @kitrodriguez992
    @kitrodriguez992 3 роки тому +3

    I was watching some scam baiting videos and also doing some deep dives into RATs and just... CyberSec/CompSci things in general and found this video. I'm glad I bumped into your channel. Really good stuff you have going on here

  • @whamer100
    @whamer100 3 роки тому +80

    "is this the newest version? because that would be pretty slick"
    *immediately scrolls past the version number 3.1.0 showing it is the latest version*

  • @orbyfied
    @orbyfied 3 роки тому +2

    these videos are underrated hidden gems.
    i swear why didnt i get them in my reccomended earlier.

  • @Krampfey
    @Krampfey 3 роки тому +2

    Damn, I just watched over an hour of stuff I have no clue of and I still feel educated and entertained.
    It even kinda makes sense, when you talk about it and explain some stuff.
    Thank you very much! :)

  • @shawnio
    @shawnio 3 роки тому +12

    every single line "I don't exactly know what is going on here" so basically this guy is just us trying to understand code. got it.

  • @sheldongroom18
    @sheldongroom18 3 роки тому +1

    Please more Malware Analysis videos. So much fun to watch.

  • @vargnaar
    @vargnaar 3 роки тому +20

    "Can I get anything out of Melons?"
    You can get juice, John. Juice.

  • @MikeKirkpatrick
    @MikeKirkpatrick 3 роки тому +9

    Well worth the watch. This is a great video. Please do more. :)

    • @georgehammond867
      @georgehammond867 3 роки тому

      how do you copy and paste into VirtualBox in Windows 10

  • @Flobert97
    @Flobert97 3 роки тому +1

    Did i just watch AN HOUR of malware analysis? Dude, you're awesome!

  • @hexnull4343
    @hexnull4343 3 роки тому +2

    Man i'm brazillian, and i love all of this videos, but this... mannn to amazing !! Continue delivery this content to us, i apreciate this

  • @thedemonlord9232
    @thedemonlord9232 3 роки тому +2

    you got my sub for this. its 3am in the morning and I've watched the entire thing having so much fun. keep on with the good stuff

  • @wazoozastoob1234567
    @wazoozastoob1234567 3 роки тому +12

    THOSE DOWNVOTES....GTFO...this dude is a legend

  • @DarkFaken
    @DarkFaken 2 роки тому

    I love these malware analysis videos. You break stuff down to a fairly easy to understand level for most technical people.
    I'm just getting into cyber security and I'm really enjoying your content, thank you.

  • @agentsmith9753
    @agentsmith9753 3 місяці тому

    That was epic dude!
    Felt like a real rollercoaster. I can't believe you got to them within 24 hours of release.
    So nuts.

  • @brentbice1151
    @brentbice1151 3 роки тому +1

    I love that you used strings and am glad I'm not the only one who does. :-) It's a highly under-rated tool, IMHO.

  • @rubenolguin2180
    @rubenolguin2180 2 роки тому

    Wow, that was a crazy ride! Thanks for taking us on the journey.

  • @SuperBryantheman
    @SuperBryantheman 3 роки тому

    Dope analysis! The streets need this type of content. Keep it coming.

  • @ThomasGabrielsen
    @ThomasGabrielsen 3 роки тому +1

    What a great catch! This is by far the most interesting video I've watched on UA-cam for a very long time. I love this of unedited video.

  • @Mosern1977
    @Mosern1977 3 роки тому

    Been programming for a long time, but never really looked much into viruses and malware. Cool analysis. The authors sure work hard to make their installation as painless as possible.

  • @mclovin748
    @mclovin748 3 роки тому +1

    59:06 love how scrolls past when looking at string in the executable "Offline Keylogger Started" "Online Keylogger Started" "Online Keylogger Stopped" "Offline Keylogger Stopped"
    Yes John sees the key strokes and is like, "is this doing keylogging?"

  • @kevinwilson7213
    @kevinwilson7213 3 роки тому +2

    Nice. Never seen someone crank through something like that. Cool man, cool!

  • @snuffy6449
    @snuffy6449 3 роки тому

    I binge your videos every day all day at work. Gets me through the day and I learn some new/cool stuff.

  • @marktackman2886
    @marktackman2886 3 роки тому +1

    I could not stop watching, especially considering I can follow the concepts but the syntax is my weakness.

  • @frustro4323
    @frustro4323 3 роки тому

    I had a friend that did stuff like this and was always amazed. We fell out of touch and that's okay, I can just watch you do it now.

  • @JM-tf3rg
    @JM-tf3rg Рік тому

    This was so fun to watch. The sketchy url was very funny, fitting pun on with the ‘holy cow’

  • @tears_falling
    @tears_falling 3 роки тому +15

    Attack.jpg, that was hilarious

  • @rogan85
    @rogan85 3 роки тому

    This series of decoding Malware is the best knowledge base for getting a feel for noobs like me. Please keep it coming. Thank you.

  • @Seluj78
    @Seluj78 3 роки тому +1

    Really interesting video, thanks !! I'm impressed at the obfuscation job done on this malware it's impressive

  • @GeekBeerRS
    @GeekBeerRS 2 роки тому

    Man I love these videos. As a junior network tech I love watching this, so interesting and entertaining!

  • @DallasGraves
    @DallasGraves 3 роки тому

    From beginner hand-holding on picoCTF to obfuscating obfuscated obfuscation LOL. This channel has it all, thanks for the great content!

  • @christianf21
    @christianf21 3 роки тому

    This is crazy. I've learned more about malwares in a few vids I saw from you, than the time I spent trying to get into the field years ago. I'm a fulltime dev now and have been working for over 7 years. Reminds me of my recent grad days where all I wanted was to understand this. Much easier to follow now, and damn, learning so much so quick now. Props to you.

  • @WellnessIKIGAI
    @WellnessIKIGAI 3 роки тому

    as a computer science student, you make this profession actually seem fun. Thanks for re-kindling my interest in this field :)

  • @notrace_0
    @notrace_0 3 роки тому +1

    I never write a comment under a video but I saw every single second and I really really loved it. Thanks for your video and keep doing it sharing your passion with us!

  • @imranthoufeeque
    @imranthoufeeque 3 роки тому

    I love your videos which are not preplanned... It gives us an option for us to know how you actually resolves when you are stuck....

  • @jwbulmer
    @jwbulmer 3 роки тому +1

    I still have no idea what's going on, but I enjoy these videos all the same. Thanks for the upload John.

  • @temitopehardhekheyhe7359
    @temitopehardhekheyhe7359 3 роки тому +7

    Please mahn ... we need more malware analysis like this!! ... and also ... C source code analysis (something like that)

  • @HBTwardy
    @HBTwardy 3 роки тому +94

    John: releases a video with malware analysis
    Me after watching a video: *Lemme check real quick whether notepad.exe is running in the background or not in Task Manager*

    • @benricok
      @benricok 3 роки тому +9

      Imagine using windows 🤔

    • @Reelix
      @Reelix 3 роки тому +15

      @@benricok Imagine thinking that exploit-db had 0 results for Linux 🤔

    • @benricok
      @benricok 3 роки тому +4

      ​@@Reelix I didn't even mention an OS? I am aware that Linux isn't perfect as so with every software product (opensource or not). The worst thing you can do to your security is to be over confident in your defense.

    • @theluckyscav3487
      @theluckyscav3487 3 роки тому +18

      @@benricok Imagine being a pompous asshole. Some people want to, you know, play normal games on their computer.

    • @jixs4v
      @jixs4v 3 роки тому

      @@theluckyscav3487 I mean linux gaming has come a long way, but it still needs some time to flourish

  • @facekickr
    @facekickr 3 роки тому

    That was a great video. I don't know a whole lot about what you do, but it was super fun watching you do it. Thanks so much!

  • @helenageorge9223
    @helenageorge9223 3 роки тому

    Just for the UA-cam algorithm to know, I love malware analysis series! keep them coming!!!!!!

  • @svilenSt.
    @svilenSt. 3 роки тому

    Nice. I really impressed at final "detective" processing :) Keep it that way

  • @sannyboi7298
    @sannyboi7298 2 роки тому

    Brilliant. You make malware reversing so fun to watch.

  • @bradlad1574
    @bradlad1574 3 роки тому +10

    That's a rabbit hole if I've ever seen one haha great stuff man!

    • @definesigint2823
      @definesigint2823 3 роки тому

      If only it (the rabbit holes) were rare. 😥

    • @ulbed
      @ulbed 3 роки тому

      Follow the white rabbit!

  • @jeehill9592
    @jeehill9592 2 роки тому

    As a prospective sw engineer, at ~54:00 that obfuscated spaghetti mess made me never want to be a malware analyst 🤣😂🤣 glad to have people with your mettle in this world

  • @nilanjana25
    @nilanjana25 2 роки тому

    Totally enjoyed the video. It was an absolute rollercoaster ride. I love the way you present and explain the details in all your videos. And also none of your videos ever seem to be monotonous even when we are dealing with such mind boggling stuff because of the way you laugh and get excited when you crack/deobfuscate a piece of code. 😁 Thank you so much for taking the effort and sharing the awesome work😊

  • @JimTheScientist
    @JimTheScientist 3 роки тому +1

    Knowing the internet is totally insecure and I should be scared of everything puts me to sleep at night. Thank you John!

  • @musingmuse9064
    @musingmuse9064 3 роки тому +1

    Watched the whole thing from start to finish - loved it! Make more!

  • @deantammam
    @deantammam 2 роки тому

    You know so much about so many things... I've learned so many things in the few videos I've watched so far. Super, super inspiring.

  • @mattgwalker
    @mattgwalker 3 роки тому

    John - This is great content. I really am learning a lot watching you work these out. Keep it up! The masses demand more of this!

  • @h4wk_n377
    @h4wk_n377 3 роки тому

    Keep on doing those Malware Analysis. It's really fun to watch and it's quite educative too!

  • @jacobti98
    @jacobti98 3 роки тому

    Watching John in 1.75x speed was awesome. very entertaining and I learned stuff. Thank you

  • @Cinual
    @Cinual 3 роки тому

    You make easy to understand videos as you break things down. i really enjoy them.
    I have a vague understanding of coding and the way you work is easy to follow.

  • @johnhelt5475
    @johnhelt5475 3 роки тому +1

    John, great interview in the Infosec OSINT podcast!

  • @karldahlin858
    @karldahlin858 3 роки тому

    Makes me nostalgic for my coding days. Love figuring out the puzzle.

  • @TechSy8
    @TechSy8 3 роки тому

    Did anyone told that to you, you're an genius buddy....
    i even can't get off my eyes on this series.... amazing

  • @danielbaker3063
    @danielbaker3063 3 роки тому +1

    Always learn something new watching your content!

  • @TobiNightcore
    @TobiNightcore 2 роки тому

    This analysis had a more exciting climax than most Hollywood movies

  • @symbiotyk9942
    @symbiotyk9942 3 роки тому

    I really enjoy lookin into this with your hand, and your happy face

  • @King-Julien
    @King-Julien Рік тому

    I knew exactly what it was a few minutes of you scrolling few the strings!!! I feel proud! And thank you for making this video, I learned a lot.

  • @somnitek
    @somnitek 3 роки тому

    Dude... That was solid. Loved it. Kinda dragged in the middle but I was invested enough I just jumped ahead maybe ten minutes before I was stuck back in. Nice nice so nice I had to say it twice, then one more time too.

  • @uimstar5254
    @uimstar5254 3 роки тому

    Wow, that was awesome video. It is so nice to see you go through all the steps and thinking while deobfuscing. This RAT is kind of really scary for everything it can do. I would like to see more of this in the future! Keep up the good work

  • @JackAllpikeMusic
    @JackAllpikeMusic 3 роки тому +2

    This was fabulous! I hope to see more!

  • @syverlunde9622
    @syverlunde9622 3 роки тому

    Pls keep up the malware analysis videos! Its so fun to watch!

  • @myusernameisrighther
    @myusernameisrighther 2 роки тому

    I’m watching this one year and one day later. Better than never.