Is THIS a VIRUS? Finding a Remcos RAT - Malware Analysis

2021 ж. 17 Ақп.
356 990 Рет қаралды

If you would like to support the channel and I, check out Kite! Kite is a coding assistant that helps you code faster, on any IDE offer smart completions and documentation. www.kite.com/get-kite/?... (disclaimer, affiliate link)
For more content, subscribe on Twitch! / johnhammond010
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
PayPal: paypal.me/johnhammond010
E-mail: johnhammond010@gmail.com
Discord: johnhammond.org/discord
Twitter: / _johnhammond
GitHub: github.com/JohnHammond

Пікірлер
  • "This is just 75 lines of code" *Half hour later* "201 thousand characters selected"

    @johnjohnerd6921@johnjohnerd69213 жыл бұрын
    • that's how they get you man, that's how they get you.

      @AlucardNoir@AlucardNoir3 жыл бұрын
    • @@AlucardNoir AND YOU BUT GUESS WHO NOT?! ME AND JOHN

      @geist453@geist4533 жыл бұрын
    • Majorly loaded by a fake jpg ;)

      @GuyMassicotte@GuyMassicotte3 жыл бұрын
    • @@geist453 l

      @bansku570@bansku5702 жыл бұрын
    • @@bansku570 I

      @nojusnojus8015@nojusnojus80152 жыл бұрын
  • Times must be hard, Ed Sheeran is writing python.

    @richie7425@richie74253 жыл бұрын
    • Lmaooo💀💀

      @batmanasdasd@batmanasdasd3 жыл бұрын
    • he looks like an unscuffed burgerplanet

      @HiramSalinas@HiramSalinas3 жыл бұрын
    • This is ed sheerhan and Seth rogans kid.

      @realitynowassigned@realitynowassigned3 жыл бұрын
    • You are the hacker version of pewdiepie. Very entertaining to watch.

      @HaxorBird@HaxorBird3 жыл бұрын
    • Nah he looks like a de deobfuscated Ed Sheeran

      @lusthetics@lusthetics3 жыл бұрын
  • Love this malware analysis series!

    @0xRalu@0xRalu3 жыл бұрын
    • Me too! Amazing series

      @ismhdez@ismhdez3 жыл бұрын
    • I love it too!

      @syverlunde9622@syverlunde96223 жыл бұрын
    • me too, this guy is really good.

      @jbgaud@jbgaud2 жыл бұрын
    • Sir. Can I use remcos rat to hack Android...

      @s.broyal5128@s.broyal5128 Жыл бұрын
  • Ngl, never thought it would be so much fun watching someone analyse and breakdown a virus.

    @DenyardTV@DenyardTV3 жыл бұрын
    • I was thinking the same thing! I might have just discovered my new rabbit hole lol

      @KrakenPipe@KrakenPipe3 жыл бұрын
    • Woow

      @AmbitionErudition@AmbitionErudition2 жыл бұрын
  • I love how they went through six stages of obsfuscation, and a lot of effort into hiding what they were doing.... but their payload was literally called "Attack.jpg" like surely they could have named it something at least slightly less blatant.

    @bennettpalmer1741@bennettpalmer17413 жыл бұрын
    • Perhaps they didn't care to hide it at that point? I know that obfuscation helps to counter analysts, but when the code is downloading data from a URL, then I suppose it wouldn't've been worth their effort to obscure the name of the download. Then again, they could've made a second download with totally unnecessary data. Either way - this thing is bad (for you)! xD

      @FilliamPL@FilliamPL3 жыл бұрын
  • The REMCOS developer "discourages malicious use". For sure, everyone will use solely for legitimate purposes.

    @slygamer01@slygamer013 жыл бұрын
    • 'sure if you say so' meanwhile no one uses it legitimately

      @aliencatmeow@aliencatmeow3 жыл бұрын
    • Malicious actors: amma head out

      @karimmohamed3744@karimmohamed37443 жыл бұрын
    • Ethical hackers don't sell hacking toolkits, ethics and all that... 🤷‍♂️

      @garethevans9789@garethevans97893 жыл бұрын
    • @@garethevans9789 Pentesting tools are released open source because not only is open source more effective, but it makes sure that the developers are not potentially profiting off of malicious actors, intentionally or not.

      @technoturnovers7072@technoturnovers70723 жыл бұрын
    • Meh, skids are gonna find a way anyway. With our without this program.

      @cyber1377@cyber13773 жыл бұрын
  • I love when John is laughing over the Attack.jpg url

    @NickyPuff@NickyPuff3 жыл бұрын
    • best part

      @livroz454@livroz4543 жыл бұрын
  • Damn that was fun to watch!! Thanks and keep them coming!!!!!!

    @baremetalHW@baremetalHW3 жыл бұрын
  • Content like this is why I don't have to pay for cable, satellite, or netflix!

    @andmo90@andmo903 жыл бұрын
    • But then he would have been on 8-12 screens and typed those 200k characters (hacking is typing fast), it's all hard to follow. It would be like watching the Matrix.

      @garethevans9789@garethevans97893 жыл бұрын
    • Yeah

      @viv_2489@viv_24893 жыл бұрын
    • Okay, but consider this: TOS and TNG are on Netflix.

      @SiveenO@SiveenO Жыл бұрын
  • Scheduling this to start at the same time as the new mars rover is landing... Bold move cotton, let's see how it works out

    @TracyNorrell@TracyNorrell3 жыл бұрын
    • Bah, totally didn't even realize xD Ah well!

      @_JohnHammond@_JohnHammond3 жыл бұрын
    • @@_JohnHammond I’d prefer watching this over some rover landing

      @originalgaming9062@originalgaming90623 жыл бұрын
    • @@tripplefives1402 isn’t the rover automatically controlled because the delay would be 10 minutes long?

      @originalgaming9062@originalgaming90623 жыл бұрын
  • the evolving of rat is so amazing, i remember in late 90's where sub7, netbus and back orifice was so popular and inspired me into hacking. IRC was the channel to go to before and dial up is your connection.

    @vannialora3476@vannialora34763 жыл бұрын
  • John, as you are very good, you should stand this comment: In Powershell a "split (..)" is a regular expression splitten in string in portione of two characters, ie "4142" becomes "41", "42", in Hex AB

    @donaldduck6198@donaldduck61983 жыл бұрын
  • "is this the newest version? because that would be pretty slick" *immediately scrolls past the version number 3.1.0 showing it is the latest version*

    @whamer100@whamer1003 жыл бұрын
  • Whatever that quality is that great teachers have, you have it. Never change the format of your videos. I love seeing you troubleshoot and reason through everything live.

    @willo7734@willo77342 жыл бұрын
  • I'm just finding this channel and its quickly becoming my favorite content. Im fascinated with all of this. Really inspires me to get started with basic coding to get my feet wet.

    @TheSeakr@TheSeakr3 жыл бұрын
  • So far this is the most fun I've had watching hacking videos. Your analysis is fantastic and I enjoy seeing your process. Keep it up!

    @fragrenader1@fragrenader13 жыл бұрын
  • I love John’s response when the light bulb goes off and all the hard work comes together. Great video as always.

    @randallsalyer@randallsalyer3 жыл бұрын
  • Great video, I love this series. Also special thanks for zooming in this much, watching code-related stuff on phone is usually a pain, but not in your case. Keep up the good work!

    @PerfectEn3my@PerfectEn3my2 жыл бұрын
  • The guy that wrote the script watching this video rn must be like 👁️👄👁️

    @ultimate8673@ultimate86733 жыл бұрын
  • This style of video really helps me with my start in forensics and malware analysis. I love liveoverflow and other CTF summary channels but they often feel like magic in the way they present their findings. Keep up the great work :3

    @ycoihmn6388@ycoihmn63883 жыл бұрын
  • Remcos: "We specialize in ethical hacking" Also Remcos: *is used in malicious code*

    @vedritmathias9193@vedritmathias91933 жыл бұрын
  • Dude you are simply awesome...it's so enriching for all of your viewers to see your hard work and all your skills, and the best of all is that we can see you enjoying so we enjoy and learn too. Regards from Spain!

    @eliasgamezgarcia3414@eliasgamezgarcia34143 жыл бұрын
  • Where have you been all my CS degree? This is awesome watching this stuff in action as you do it. I love the content! Definitely going to keep watching!

    @md123180@md1231803 жыл бұрын
  • What a great catch! This is by far the most interesting video I've watched on KZhead for a very long time. I love this of unedited video.

    @ThomasGabrielsen@ThomasGabrielsen3 жыл бұрын
  • I've taken apart stuff like this (when I worked in large enterprise) but the samples were rarely more than 3-4 levels deep. This actually looks a lot more like a challenge you'd get at a CTF competition _(perhaps they're getting ideas from each other)_ ?

    @definesigint2823@definesigint28233 жыл бұрын
  • Nobody: Virus Code: * Does malicious stuff* John: Is it trying to do something bad? HAHAHA Us: Duhhh John. wtf

    @whatnowsami9225@whatnowsami92253 жыл бұрын
  • After watching this, gained a keen interest in Malware Analysis. Thanks for the awesome content.

    @Dilipkumar-ur9zx@Dilipkumar-ur9zx3 жыл бұрын
  • Hands down one of the best malware analysis walkthroughs I’ve seen. Watched it twice.

    @mbowler05@mbowler053 жыл бұрын
  • Loving this series. Would like to see some disassembling malware analysis.

    @britishpiperygo@britishpiperygo3 жыл бұрын
  • This is one of the best educational videos i've seen

    @darkdagger032@darkdagger0323 жыл бұрын
  • Totally enjoyed the video. It was an absolute rollercoaster ride. I love the way you present and explain the details in all your videos. And also none of your videos ever seem to be monotonous even when we are dealing with such mind boggling stuff because of the way you laugh and get excited when you crack/deobfuscate a piece of code. 😁 Thank you so much for taking the effort and sharing the awesome work😊

    @nilanjana25@nilanjana252 жыл бұрын
  • You make easy to understand videos as you break things down. i really enjoy them. I have a vague understanding of coding and the way you work is easy to follow.

    @Cinual@Cinual2 жыл бұрын
  • That was freaking wild, man. You're sharp at this stuff

    @waytoofarianism@waytoofarianism3 жыл бұрын
  • Pretty sure you need to run the obfuscated version of the AMSI bypass. Great video, would love to see more of these!

    @m1rz@m1rz3 жыл бұрын
  • Wow, that was awesome video. It is so nice to see you go through all the steps and thinking while deobfuscing. This RAT is kind of really scary for everything it can do. I would like to see more of this in the future! Keep up the good work

    @uimstar5254@uimstar52543 жыл бұрын
  • John - This is great content. I really am learning a lot watching you work these out. Keep it up! The masses demand more of this!

    @mattgwalker@mattgwalker3 жыл бұрын
  • I was watching some scam baiting videos and also doing some deep dives into RATs and just... CyberSec/CompSci things in general and found this video. I'm glad I bumped into your channel. Really good stuff you have going on here

    @kitrodriguez992@kitrodriguez9923 жыл бұрын
  • i missed the premiere, but this is definitely a blast to watch. Would love to see this more

    @mechanicalfluff@mechanicalfluff3 жыл бұрын
  • This was actually fun to watch and go on this journey with you! Loving these videos

    @zamant88@zamant882 жыл бұрын
  • Awesome awesome video John! I have followed these de-obfuscation things and when I get to the PE32 I usually say f-it and give up and upload it to virustotal. I'm so glad you went further with this. Thanks so much man!

    @ihatethesensors@ihatethesensors3 жыл бұрын
  • "Can I get anything out of Melons?" You can get juice, John. Juice.

    @vargnaar@vargnaar3 жыл бұрын
  • Amazing work, you deserve the money from the KZhead overlords. Literally only commented to help boost those algos.

    @dustinjohnson7635@dustinjohnson76353 жыл бұрын
  • I love these malware analysis videos. You break stuff down to a fairly easy to understand level for most technical people. I'm just getting into cyber security and I'm really enjoying your content, thank you.

    @DarkFaken@DarkFaken Жыл бұрын
  • Absolutely brilliant! I've discovered your channel yesterday and I can't stop watching. This stuff makes me want to give it a shot as well. Never knew that deconstructing programs/scripts (especially ones with malicious intent) could be this much fun! Subbed+bell.

    @crazymonkeyVII@crazymonkeyVII2 жыл бұрын
  • Plottwist: this is all just an advertisement for BreakingSecurity

    @pumpkin7976@pumpkin79763 жыл бұрын
  • that url has to be the greatest thing ive ever seen

    @rccservice@rccservice3 жыл бұрын
  • Wow, that was a crazy ride! Thanks for taking us on the journey.

    @rubenolguin2180@rubenolguin21802 жыл бұрын
  • That was a great video. I don't know a whole lot about what you do, but it was super fun watching you do it. Thanks so much!

    @facekickr@facekickr3 жыл бұрын
  • In the next episode... John rewrites the kernel for more efficient find and replace..... STONKS!

    @auto117666@auto1176663 жыл бұрын
  • Algorithm, give this man the recs.

    @uniquechannelnames@uniquechannelnames3 жыл бұрын
    • It worked. That's why I'm here.

      @TexasTimelapse@TexasTimelapse3 жыл бұрын
  • you got my sub for this. its 3am in the morning and I've watched the entire thing having so much fun. keep on with the good stuff

    @thedemonlord9232@thedemonlord92323 жыл бұрын
  • Keep on doing those Malware Analysis. It's really fun to watch and it's quite educative too!

    @h4wk_n377@h4wk_n3773 жыл бұрын
  • this is gonna be good

    @patchbyte6856@patchbyte68563 жыл бұрын
    • Indeed Indeed :D

      @AnthonyBlakley@AnthonyBlakley3 жыл бұрын
  • Well worth the watch. This is a great video. Please do more. :)

    @MikeKirkpatrick@MikeKirkpatrick3 жыл бұрын
    • how do you copy and paste into VirtualBox in Windows 10

      @georgehammond867@georgehammond8673 жыл бұрын
  • Awesome work buddy !!! watching your videos while at work coding my self ... thanks for the vids

    @sergergar@sergergar3 жыл бұрын
  • Damn, I just watched over an hour of stuff I have no clue of and I still feel educated and entertained. It even kinda makes sense, when you talk about it and explain some stuff. Thank you very much! :)

    @Krampfey@Krampfey2 жыл бұрын
  • "guys, you might think i'm dumb" LOL exact opposite.

    @ayayron9452@ayayron94523 жыл бұрын
  • Attack.jpg, that was hilarious

    @tears_falling@tears_falling3 жыл бұрын
  • Brilliant. You make malware reversing so fun to watch.

    @sannyboi7298@sannyboi72982 жыл бұрын
  • You know so much about so many things... I've learned so many things in the few videos I've watched so far. Super, super inspiring.

    @deantammam@deantammam2 жыл бұрын
  • THOSE DOWNVOTES....GTFO...this dude is a legend

    @wazoozastoob1234567@wazoozastoob12345673 жыл бұрын
  • 59:31 No. That's the noun "licence" as opposed to the verb "license". It's a British thing.

    @CristiNeagu@CristiNeagu3 жыл бұрын
  • This is crazy. I've learned more about malwares in a few vids I saw from you, than the time I spent trying to get into the field years ago. I'm a fulltime dev now and have been working for over 7 years. Reminds me of my recent grad days where all I wanted was to understand this. Much easier to follow now, and damn, learning so much so quick now. Props to you.

    @christianf21@christianf213 жыл бұрын
  • Really interesting video, thanks !! I'm impressed at the obfuscation job done on this malware it's impressive

    @Seluj78@Seluj783 жыл бұрын
  • That's a rabbit hole if I've ever seen one haha great stuff man!

    @bradlad1574@bradlad15743 жыл бұрын
    • If only it (the rabbit holes) were rare. 😥

      @definesigint2823@definesigint28233 жыл бұрын
    • Follow the white rabbit!

      @ulbed@ulbed3 жыл бұрын
  • every single line "I don't exactly know what is going on here" so basically this guy is just us trying to understand code. got it.

    @shawnio@shawnio3 жыл бұрын
  • Your knowledge is very impressive! Love learning from guys like you!

    @sgtfatboy1@sgtfatboy12 жыл бұрын
  • Fantastically enjoyable to watch you solve problems as always . Thanks John

    @cwlancaster979@cwlancaster9793 жыл бұрын
  • John: releases a video with malware analysis Me after watching a video: *Lemme check real quick whether notepad.exe is running in the background or not in Task Manager*

    @HBTwardy@HBTwardy3 жыл бұрын
    • Imagine using windows 🤔

      @benricok@benricok3 жыл бұрын
    • @@benricok Imagine thinking that exploit-db had 0 results for Linux 🤔

      @Reelix@Reelix3 жыл бұрын
    • ​@@Reelix I didn't even mention an OS? I am aware that Linux isn't perfect as so with every software product (opensource or not). The worst thing you can do to your security is to be over confident in your defense.

      @benricok@benricok3 жыл бұрын
    • @@benricok Imagine being a pompous asshole. Some people want to, you know, play normal games on their computer.

      @theluckyscav3487@theluckyscav34873 жыл бұрын
    • @@theluckyscav3487 I mean linux gaming has come a long way, but it still needs some time to flourish

      @jixs4v@jixs4v2 жыл бұрын
  • I have basically no connection to it-sec, but this stuff is addictive ... love the videos

    @1XXXJoker@1XXXJoker3 жыл бұрын
  • Found you on the recommanded page , love it !

    @executor31@executor313 жыл бұрын
  • I binge your videos every day all day at work. Gets me through the day and I learn some new/cool stuff.

    @snuffy6449@snuffy64493 жыл бұрын
  • Please mahn ... we need more malware analysis like this!! ... and also ... C source code analysis (something like that)

    @temitopehardhekheyhe7359@temitopehardhekheyhe73593 жыл бұрын
  • Waiting for it :)

    @picocode@picocode3 жыл бұрын
  • This was so fun to watch. The sketchy url was very funny, fitting pun on with the ‘holy cow’

    @JM-tf3rg@JM-tf3rg Жыл бұрын
  • I'm learning to program in college rn and I just ran across your channel and my God man the length people go to, to scoot around anti-virus software and download shit on your computer is insane. Although seeing how all these functions are working together is awesome! Keep up the good work!!!👍

    @forthewubwubs@forthewubwubs3 жыл бұрын
  • "I don't like these advertisements..." "You didn't see this here folks!" "Not in a John Hammond video!"

    @Zachucks@Zachucks3 жыл бұрын
  • That was more than a safari ride! It's awsm

    @tomriddle2427@tomriddle24273 жыл бұрын
  • Really fun to watch ! Looking forward to see more !

    @andresecre5428@andresecre54283 жыл бұрын
  • complete amazing by the skills you have for it. many questions i can think a bout it. good work man love it

    @darkinwall@darkinwall2 жыл бұрын
  • Legend

    @AhmedAbbas-hp5ej@AhmedAbbas-hp5ej3 жыл бұрын
  • I honestly never appreciated Search and Replace until today. Everything is so clear now! 19:35 One learns more every day 33:44 What the hell this is hilarious 44:00 I hope you saved 56:13 I judt read a Online Keylogger Started so I guess yes 1:01:52 Oh so test hacks? Was this retrofitted to be malicious or you just were smart? 1:03:08 Imagine if Jim's Scammers used this crap. My god 1:10:00 Fresh off the oven and unobfudcated

    @gabrote42@gabrote422 жыл бұрын
  • This was fabulous! I hope to see more!

    @JackAllpikeMusic@JackAllpikeMusic3 жыл бұрын
  • Enjoying the malware analysis videos. Very informative.

    @vincepod@vincepod3 жыл бұрын
  • was great :)

    @testingstuff6111@testingstuff61113 жыл бұрын
  • Amazing stuff. Learned a lot from this video. I have a question: how did you come across this script? Did someone give it to you? Anything like that? Loving these malware analysis videos, John. Keep 'em coming!

    @azurnxo2134@azurnxo21343 жыл бұрын
  • Watched the whole thing from start to finish - loved it! Make more!

    @musingmuse9064@musingmuse90643 жыл бұрын
  • Definitely a lot of fun. Thanks for sharing man!

    @jeroentrimbach@jeroentrimbach3 жыл бұрын
  • I have no idea what I'm watching but I'm enjoying it :)

    @nickyfranshel1210@nickyfranshel12103 жыл бұрын
    • It's actually not a bad way to learn, at least starting out - if you're interested. I have a background in software engineering, but I only understand maybe 75% of what's going on.

      @internetuser8922@internetuser89223 жыл бұрын
  • The Title is like Asking if water is wet LOL

    @kingknight100@kingknight1003 жыл бұрын
  • Pls keep up the malware analysis videos! Its so fun to watch!

    @syverlunde9622@syverlunde96223 жыл бұрын
  • Hope to see more of these videos! Tons of fun

    @ethantrevino12345@ethantrevino123453 жыл бұрын
  • I just want to know how it’s humanly possible to obtain the level of programming and CS knowledge needed to be capable of doing what he does in this video

    @kerrickfanning6910@kerrickfanning69102 жыл бұрын
    • It’s depressing but motivating also!

      @DaCaveman84@DaCaveman842 жыл бұрын
    • Yeah imagine who made this

      @alexcolley205@alexcolley205 Жыл бұрын
    • Actually, not too much. Deobfuscating such stuff is not very complicated, but he is still doing a good job. But tbh .. most parts could be much faster by debugging functions step by step instead of trying to deobfuscating every var and func.

      @emanuel6934@emanuel6934 Жыл бұрын
  • so where did you get the jscript if it was only released so recently...

    @bigp3t3_cpt@bigp3t3_cpt3 жыл бұрын
    • i wanna know too

      @victorhmg8080@victorhmg80803 жыл бұрын
    • The actual payload was hosted remotely, so that can be updated separately.

      @ExcludedLayman@ExcludedLayman3 жыл бұрын
  • Hi John, Love these kinds of videos! Keep making them! Great discovery! And current! Hahaha, that was unexpected. Looking forward to some more content.

    @JacoWiese@JacoWiese3 жыл бұрын
  • John Amazing teaching methods so clear and precise i was able to follow you all the way to the end. Your amazing man, I was looking fr the next new thing to get into its malware analysis. please show me more i might be a natural at this

    @atlantianking6537@atlantianking65372 жыл бұрын
  • Where do you get such fresh samples? That hash isn't even on VT yet.

    @thedosiusdreamtwister1546@thedosiusdreamtwister15463 жыл бұрын
    • Plot twist: John actually wrote it

      @Anonymous-vh6kp@Anonymous-vh6kp3 жыл бұрын
  • BTW... next thing. Do remcos guide, analysis and stuff

    @KlaypexDelusion@KlaypexDelusion3 жыл бұрын
  • Nice. I really impressed at final "detective" processing :) Keep it that way

    @svilenSt.@svilenSt.3 жыл бұрын
  • I love your videos which are not preplanned... It gives us an option for us to know how you actually resolves when you are stuck....

    @imranthoufeeque165@imranthoufeeque1653 жыл бұрын
KZhead