$2 MILLION DOLLARS STOLEN in Bitcoin/Ethereum - JScript Malware Analysis

2021 ж. 5 Сәу.
136 894 Рет қаралды

If you would like to support the channel and I, check out Kite! Kite is a coding assistant that helps you code faster, on any IDE offer smart completions and documentation. www.kite.com/get-kite/?... (disclaimer, affiliate link)
For more content, subscribe on Twitch! / johnhammond010
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
PayPal: paypal.me/johnhammond010
E-mail: johnhammond010@gmail.com
Discord: johnhammond.org/discord
Twitter: / _johnhammond
GitHub: github.com/JohnHammond

Пікірлер
  • Update: Thanks to @Wikidude in comments for pointing this out. The "Mizu" address that I didn't do a good job of digging into is apparently a BTC address. Looking this up, it has over 2.5 MILLION dollars, with transactions in March of 2021. Absolutely crazy. www.blockchain.com/btc/address/1NSrjTotDiuK7S1xMm9yuppq4dr4Uf9saM

    @_JohnHammond@_JohnHammond3 жыл бұрын
    • It was really awesome!!! It felt like a real movie hacker like stuff 🔥🔥🔥🔥

      @hackingguy@hackingguy3 жыл бұрын
    • change the video title for moar clickbait!

      @void_p@void_p3 жыл бұрын
    • We are Big Boi investigators now xD

      @wikidude@wikidude3 жыл бұрын
    • Holy smokes

      @Basieeee@Basieeee3 жыл бұрын
    • Wow.... makes one wonder doesn't it.... all stolen or mined, hmmm...

      @SV_Sangha@SV_Sangha3 жыл бұрын
  • I just wanted to say. You have inspired me. I have officially enrolled in university again as a mature student finally and will be working towards a bachelors in Cyber security

    @jht5225@jht52253 жыл бұрын
    • same i didnt know what i wanted to do in life, but john has shown me a path

      @philipstringer4425@philipstringer44253 жыл бұрын
    • @@philipstringer4425 you now know the way

      @deepergodeeper7618@deepergodeeper76183 жыл бұрын
    • Hell yeah!

      @Nunya58294@Nunya582943 жыл бұрын
    • I am currently studying cybersecurity too!

      @chillytheprogrammer@chillytheprogrammer3 жыл бұрын
    • @@chillytheprogrammer Best field to get into. Lot's of money to be made as long as you have the right mindset.

      @newbunny93@newbunny933 жыл бұрын
  • 39:05 this is in a language that I do not speak: Proceeds in realtime reading and translation from Italian to English with no issues

    @alessandro.rossini@alessandro.rossini3 жыл бұрын
  • The Threat Report PDF at 38:53 was in Italian and yes was a report about a similar malware Italiani facciamoci sentire :)

    @EmaCannella@EmaCannella3 жыл бұрын
    • Spaghetti code ftw

      @valeriobertoncello1809@valeriobertoncello18092 жыл бұрын
  • Impressive how you managed to understand obfuscated italian though

    @LuisSieira@LuisSieira3 жыл бұрын
    • ...

      @haloball12@haloball122 жыл бұрын
    • Bruh

      @FascistTrex@FascistTrex2 жыл бұрын
    • 🤦🏻‍♂️

      @LinuxJedi@LinuxJedi2 жыл бұрын
    • So just Italian?

      @dumbidiot1119@dumbidiot11192 жыл бұрын
    • What is being insinuated here? Just curious.

      @deutscher649@deutscher6492 жыл бұрын
  • Hey John, the BTC address (Mizu in the sample) that you didn't check properly on blockchain explorer, has received $2.5 Million. Should probably change the title. $2.560.000 looks better xD

    @wikidude@wikidude3 жыл бұрын
    • Holy shit.

      @_JohnHammond@_JohnHammond3 жыл бұрын
    • @@_JohnHammond yeah it's 72 BTC at 44,000+ USD each xD

      @salticidae1.618@salticidae1.6183 жыл бұрын
    • @@salticidae1.618 BTC is up to $56k each right now

      @jimmyadaro@jimmyadaro3 жыл бұрын
    • Is 13 millions now

      @jbarriossandrea@jbarriossandrea3 жыл бұрын
  • This video inspired me to get into ethical hacking. I literally watched over 20 hours of videos about hacking in the last 2 days. I haven't been this excited since I started programming 17 years ago. Just hacked into my Bose soundtouch 😂 Thank you for bringing back the fun and fire in me for computers 😁

    @heinrich3427@heinrich34273 жыл бұрын
    • This video inspired me to make a bot net that is spreading around the earth and sending millions of dollars to me from "inactive" crypto wallets. 😉 I am almost on the leader board of top 500 humans!

      @royslapped4463@royslapped44632 жыл бұрын
    • How Tf did you have that

      @Flaneur27@Flaneur27 Жыл бұрын
    • Updates? Was it short-term hype or you stick to it up until now?

      @jeromed.salinger647@jeromed.salinger6478 ай бұрын
  • Excellent work, watching this helped me realize that this cyber security degree I am finishing up is something that is achievable and interesting. So much of our classes are report driven and it is great to see a real world example of what actual analysis looks like and the progression through it. Thank you!

    @MrCyphersphinx@MrCyphersphinx3 жыл бұрын
  • I know this video is a couple months old, but I'll still say that These videos are much better when you go through the malware for the first time, rather than explaining what you've found previously.

    @Masterism88@Masterism882 жыл бұрын
  • 39:08 that is Italian :)

    @andreastefan3825@andreastefan38253 жыл бұрын
    • Thanks bro

      @asdqwery7593@asdqwery75933 жыл бұрын
    • Scammers these days pose as people who have literally just said in the video they don't know shit about crypto

      @jakubklecki2963@jakubklecki29633 жыл бұрын
  • It was an interesting dig and got spicier with those dollar numbers. Keep up the good work!!

    @BigBeesNase@BigBeesNase3 жыл бұрын
    • I think this is pretty small compared to ransomware in terms of value and damage. Though it's nice to see a John spambot.

      @kingpopaul@kingpopaul3 жыл бұрын
  • John thank you for the great video, I'm a complete newbie to software development, debug and analysis. I'm able to follow you perfectly, understand most of what is presented and am having a great time!

    @kristiyangerasimov6708@kristiyangerasimov67083 жыл бұрын
  • Great work... love how fluent you are in this. Kudos to you John!

    @SV_Sangha@SV_Sangha3 жыл бұрын
    • @John Hammond Thankfully I have not. However, I try and stay isolated as best I can. I love the programming and security in the videos.... and am doing some entry level hackme items trying to learn. Your inspiring, thanks!

      @SV_Sangha@SV_Sangha3 жыл бұрын
    • Sailing Sangha that was a fake account

      @_asidy@_asidy3 жыл бұрын
    • @@_asidy agreed... but good interactions help the algorithms 😁

      @SV_Sangha@SV_Sangha3 жыл бұрын
  • Man, i love this vids, you'r an absolute genius. I learn a lot

    @joacoordonez1973@joacoordonez19732 жыл бұрын
  • You rock, John! Thanks for the cool videos and for being such an inspiration to all of us aspiring info-sec pros, and for educating the general public! You're the man!

    @rickybennett9410@rickybennett94103 жыл бұрын
  • That clipboard trick is really slick

    @juuse94@juuse943 жыл бұрын
  • I love that I found your channel! I want to get into cyber security so watching you go through code and explain things is fascinating! I do have one thing to say... why do you NOT use dark mode on EVERYTHING? It is so much easier on the eyes using Window's dark theme and any dark theme where sites allow it (like twitter...).

    @imjustwolf@imjustwolf3 жыл бұрын
  • This malware analysis is nothing short of magical

    @joryiansmith@joryiansmith3 жыл бұрын
  • You have no Idea How much i love your videos ❤️

    @Tramontano_T@Tramontano_T3 жыл бұрын
  • The only thing me and you have in common is that we both speak English good, but man I love your content, style, etc. Thanks for doing this and please keep it up! Subscribed. And I watch until the end.

    @structure7@structure73 жыл бұрын
  • Yo Johnny!! I've been a fan of yours for the longest bruv! Malware analysis is a neat content twist👌🏽.. Looking forward to more bro. **Side note : PLEASE CREATE YOUR OWN MALWARE, AND UPLOAD A VIDEO EXPLAINING THE CODE AS WELL AS A DEMO USING IT.. PRETTY PLEASE!! 😭😍🔥🙏🏽

    @timothysnyders1426@timothysnyders14263 жыл бұрын
  • Great fun again John. Great work

    @Henchman0077@Henchman00773 жыл бұрын
  • excellent stuff. Love your content. Keep it up.

    @StanLTU@StanLTU2 жыл бұрын
  • Man, I don't understand all of it but now I remind myself that I was supposed to do other stuff and 32 minutes gone like a slap, or wait what does suppose to mean? And yeah, it's really interesting stuff! John, you are a Legend! :D

    @NB-ph6cv@NB-ph6cv3 жыл бұрын
  • Great job... I've learned so much... plz continue with this... cya

    @chervesblezz@chervesblezz3 жыл бұрын
  • dude you are doing really cool stuff, keep going!

    @kunma3214@kunma32143 жыл бұрын
  • Exelente video!! Gracias por compartir

    @pedror9314@pedror93143 жыл бұрын
  • great job John fascinating stuff as always

    @2514ben88@2514ben882 жыл бұрын
  • Love em. keep em coming

    @internetdoggo4839@internetdoggo48393 жыл бұрын
  • that pdf was in italian! c: very entertaining video :)

    @fra1897@fra18973 жыл бұрын
  • Good Job , John "MALWARE" Hammond , Lovely to See and Hear Your Enthusiasm For Malware Man you Nailed IT.👊👌🤚✌🔥🔥🔥🔥As Usual 🔥🔥🔥🔥👌✌👊👊

    @mikeylazok8789@mikeylazok8789 Жыл бұрын
  • pls someone make something that looks like malware but in the end it gives you a youtube link to rickroll (and send this to him, pretending its crazy malware)

    @kerbatonbaton8108@kerbatonbaton81083 жыл бұрын
    • Lol

      @SpoiledBread24@SpoiledBread243 жыл бұрын
    • You know what? You bet! :D

      @CZghost@CZghost3 жыл бұрын
    • @John Hammond Shut it off, we know you're fake ↑ Real one would have a tick next to his name, as an author of this video highlighted name and updated profile picture...

      @CZghost@CZghost3 жыл бұрын
  • Love your content, John. I've learned a lot just listening while I work. I have applied a bunch to using Linux and have implemented your techniques starting Hack the Box. Just bought a shirt from ya👍. Keep up the good work. It would be cool if sometime you could make a mini series specifically about writing little tools, but I know your videos often contain python scripts you write on fly (which is really dope btw).

    @Hitmonkey420@Hitmonkey4203 жыл бұрын
  • love your videos john keep it up!

    @rastabong420@rastabong4203 жыл бұрын
  • Another great video. Keep it up!

    @foxdk@foxdk3 жыл бұрын
  • 57:32 that's batman voice noice

    @TheSauxer@TheSauxer2 жыл бұрын
  • Amazing as always!

    @420Schmat@420Schmat2 жыл бұрын
  • many thanks for content, man

    @ivanboiko8975@ivanboiko89753 жыл бұрын
  • God, i learn so much from watching John's videos it literally takes me 3 days to digest one

    @tylercoombs1@tylercoombs13 жыл бұрын
    • I know right it's amazing

      @OmniPhantom@OmniPhantom Жыл бұрын
  • 39:05 greetings from Italy ❤️

    @sorrefly@sorrefly3 жыл бұрын
  • I do not know why this came up in my feed ... I understand absolutely nothing of what I'm watching ... Good work to get a subscriber who has no idea what he is subscribing to. and yes the text is with Google translate ;-)

    @skalman2262@skalman22623 жыл бұрын
  • You know I have searched extensively to see if anyone actually does anything like what you do for this malware/virus/ransomware/ect... No one displays it like you. This information digging explorer style of the software. Most try to show off a tool or explain how you can learn to go do this and how it benefits you career. But no one is doing what you're doing here. I can't get enough of it cuz it is incredibly awesome.

    @kylefaust7743@kylefaust7743 Жыл бұрын
  • Would have been interesting to see this part @51:45 via Burp suite :)

    @sammo7877@sammo78773 жыл бұрын
  • ammount of good advices and the fact you actually read them and use them is really creating that community vibe... me like it... also, i like it more when you come somewhat uprepared and research this like you would usual, sometimes it feels like you wanna make these videos to be explorations when they are clearly well prepared demonstrations, that feels more natural to me... and ofc tnx for all the good and spicy insides on how this is done! 👊

    @pahvalrehljkov@pahvalrehljkov3 жыл бұрын
  • 0:30 onions aren't spicy, John 🤦‍♂️

    @jameselliot9114@jameselliot91143 жыл бұрын
  • On the POST - the server doesn't have to answer - it could be doing nothing visible to avoid another IOC. Also, for all we know it could have been compromised itself, partially taken down by intelligence or law enforcement, etc.

    @logiciananimal@logiciananimal3 жыл бұрын
  • I would be interested in building something that automatically beautifies. We could use Go and an API call. Thanks for the content.

    @BryceChudomelka@BryceChudomelka3 жыл бұрын
  • I think the simplest thing would simply be to rewrite the "eval" function to print instead. it would also be somewhat more secure since it might be called from other places as well.

    @FalcoGer@FalcoGer Жыл бұрын
  • I love how self-remove is "UnMonk"

    @szymusu@szymusu2 жыл бұрын
  • have u deobfuscated a pyarmor obfuscated script? (python) a video on that topic would be interesting, thanks!

    @hgjfgjghfj8920@hgjfgjghfj89203 жыл бұрын
  • Microsoft Defender better watch out

    @mihalachebogdan1@mihalachebogdan13 жыл бұрын
  • Hey John, base64 decoding multiple js comment blocks as one base64 string will certainly not work out. First split up the different /* ... */ blocks and decode them separately.

    @kherkert@kherkert3 жыл бұрын
  • I actually use ESET several years now and for me looks good, also not expensive, sure have some things that can take it down but mostly gets a lot of things

    @custume@custume3 жыл бұрын
  • Thanks 🙏

    @bhagyalakshmi1053@bhagyalakshmi105311 ай бұрын
  • great video 😉

    @custume@custume3 жыл бұрын
  • I have one question, this script changes your clipboard with another BTC/ETH address right? But do they hope you immediately send btc after that or something? What happens when you ctrl C something else, will it overwrite? I don't get that part.

    @paashaasXD@paashaasXD3 жыл бұрын
  • Is there a Windows policy that will just disable this pattern "Function(string)()"?

    @mjmeans7983@mjmeans79833 жыл бұрын
  • As someone who works as a Software Developer since 17 years I am suprised how trivial the malware is. What I like most is how creativ it is with the clipboard. Are there common malware patterns?

    @heinrich3427@heinrich34273 жыл бұрын
    • Malware authors to me are some of the most creative people. I am sure there many patterns for achieving specific tasks, one I see a lot and here for example is to find the Startup Windows folder and copy it self to it. Some of them even go to the extend of making the icon invisible in said folder

      @alvarocarrascosapenabad4355@alvarocarrascosapenabad43552 жыл бұрын
  • Very Good my teacher 👨‍🏫

    @mauritaniainjector3736@mauritaniainjector373610 ай бұрын
  • 57:11 once you make a cryptocurrency transaction, it's public, everybody can see it.

    @hexearth8258@hexearth82583 жыл бұрын
    • _laughs in monero_

      @_Fen@_Fen2 жыл бұрын
  • Thanks John. You really inspired my to sit on my lazy ass and continue watching your videos!

    @Bluscream@Bluscream2 жыл бұрын
  • Stage 1: beautified Stage 2: beautified Stage 3: beautified Stage 4: beautifiee Stage 5: BEAUTIFIER

    @pxdav@pxdav2 жыл бұрын
  • LIGHT MODEEEE AHHHHHHHHH MAKE IT STOPPPPP, and then you beef me for JavaScript.. low blows dude low blows xD Na for real keep it up dude these viddies are great

    @creativereasons7588@creativereasons75883 жыл бұрын
  • hey John, i am new to cybersecurity ..just subscribed

    @regishbabu1790@regishbabu17903 жыл бұрын
    • Malayali aano

      @yourfellowhumanbeing2323@yourfellowhumanbeing23233 жыл бұрын
    • @@yourfellowhumanbeing2323 alla

      @3xpl0i79@3xpl0i793 жыл бұрын
    • @@3xpl0i79 lla

      @grandmakisses9973@grandmakisses99733 жыл бұрын
    • Now what are you consider this kind of code malware spyware or adware

      @gotithowigetityoutube8144@gotithowigetityoutube81443 жыл бұрын
    • @@3xpl0i79 hehehe

      @yourfellowhumanbeing2323@yourfellowhumanbeing23233 жыл бұрын
  • I enjoy your videos because of the not-so-awkward silent moments.

    @ieatpushpops@ieatpushpops Жыл бұрын
  • It feels good and sad to see that these guys put so much efforts to obfuscate and encrypt the code, and you can just remove the eval function and let the computer decode all of it for you ^^

    @Freeak6@Freeak62 жыл бұрын
  • Your the best men 🔥❤

    @heizenbergwhite5669@heizenbergwhite56693 жыл бұрын
  • Could you try the notpron riddle - see how far you get?

    @theSidyous@theSidyous3 жыл бұрын
  • I love how languages over lap -- di comando e controllo

    @whtiequillBj@whtiequillBj3 жыл бұрын
  • I am surprised only eset detected it

    @DarkAngel-ov2fu@DarkAngel-ov2fu3 жыл бұрын
  • I'm curious what infection vector they use to get this into a victim machine and executed.

    @Dan-uo9fw@Dan-uo9fw3 жыл бұрын
    • From downloading pirated software i suppose.

      @hunterhunter6517@hunterhunter65173 жыл бұрын
  • great video

    @irtizaali3334@irtizaali33343 жыл бұрын
    • @John Hammond no 🤣

      @irtizaali3334@irtizaali33343 жыл бұрын
  • where do you find these?

    @GabrielSultanGabyyy@GabrielSultanGabyyy3 жыл бұрын
  • I was laughing so hard as it went further and further down the loophole and when it got to stage 6 I was dying

    @cloud7982@cloud79822 жыл бұрын
  • 53:51 Has he made a video on the minecraft malware??

    @chillytheprogrammer@chillytheprogrammer3 жыл бұрын
  • i don't even understand it but I still keep watching. I don't know why.

    @letsrugem@letsrugem Жыл бұрын
  • Don't mind me, just keeping up the engagement.

    @gauthamkrishna.s2912@gauthamkrishna.s29123 жыл бұрын
  • Awesome!

    @diddyman1958@diddyman19583 жыл бұрын
  • Fantastic

    @James-is6tg@James-is6tg2 жыл бұрын
  • Right has left the chat!

    @xdamijancoding7331@xdamijancoding73313 жыл бұрын
  • Aw I like watching you deobfuscate code

    @ianowens1905@ianowens19053 жыл бұрын
  • I have no idea what I just watched. But it was interesting

    @mawortz@mawortz3 жыл бұрын
  • I am once again asking you to beautify the code

    @cweasegaming2692@cweasegaming26923 жыл бұрын
  • Is wscript enabled by default in win 10?

    @killerskincanoe@killerskincanoe3 жыл бұрын
  • Is it maybe also a nice idea to build honeypots out of this code to monitor what these malicious actors are doing?

    @diecyde@diecyde3 жыл бұрын
  • why did the developer used the "new function()" syntax in the first layers instead of an eval? it is an evasion technique?

    @mpcabete@mpcabete3 жыл бұрын
    • Solid chance this is the reason why ! Also maybe just to throw off researchers.

      @maxpowell3528@maxpowell35282 жыл бұрын
  • What if the maker of this scripts is watching this video xD "oh shiiiiii"

    @paashaasXD@paashaasXD3 жыл бұрын
  • When does this actually trigger? When does it hijack the clipboard?

    @rydmerlin@rydmerlin3 жыл бұрын
  • I've heard of similar malwares that have a whole dictionary of addresses bundled with them, and will sub in the one that most closely matches the real one they're replacing. Spooky scary. Always check your addresses thoroughly, not just the last couple digits!

    @caleboleary182@caleboleary1823 жыл бұрын
    • Was about to comment that whoever made this malware should've done exactly this.

      @theairaccumulator7144@theairaccumulator71443 жыл бұрын
  • Where can I get the original sample? :(

    @imroot2454@imroot24543 жыл бұрын
  • So the whole script relies on people not checking what they paste when sending money?

    @NikolayRogchev@NikolayRogchev2 жыл бұрын
    • Why there is request to localserver if the video is only about what u said

      @code-to-design@code-to-design11 ай бұрын
  • its march 10th 2020

    @leuropaische@leuropaische3 жыл бұрын
  • do you have a discord server?

    @pedroneo4103@pedroneo41032 жыл бұрын
  • Now if only it was this easy to find their current physical address. I'd go say hello to them, and introduce their backend to a soft viper.

    @SomethingEternal@SomethingEternal Жыл бұрын
  • Dang, I can't imagine writing a code like this. I'd die.

    @royslapped4463@royslapped44632 жыл бұрын
  • line 220 in 4:51 it's variable but without name 🤔

    @blazi_0@blazi_03 жыл бұрын
  • Thanks , wonderful walkthrough

    @viv_2489@viv_24893 жыл бұрын
  • Any plan to do the Wreath network? Would love another super long livestream like Throwback going through the whole thing.

    @Californ1a@Californ1a3 жыл бұрын
    • Yes ^^^

      @grandmakisses9973@grandmakisses99733 жыл бұрын
    • Dude that box keeps disconnecting. I really hope he does it so the devs can see how bad the box is.

      @giovannitomczak6826@giovannitomczak68263 жыл бұрын
  • How they make people to download and run this script ?

    @eugene5096@eugene50963 жыл бұрын
  • 1:15 almost slipped out a BULLSH**

    @randykitchleburger2780@randykitchleburger27802 жыл бұрын
KZhead