Fileless Malware Analysis & PowerShell Deobfuscation

แชร์
ฝัง
  • เผยแพร่เมื่อ 4 มิ.ย. 2024
  • Integrate ANY.RUN solutions into your company: jh.live/anyrun-demo ||
    Make security research and dynamic malware analysis a breeze with ANY.RUN! Try their online interactive cloud sandbox for free: jh.live/anyrun
    Learn Cybersecurity - Name Your Price Training with John Hammond: nameyourpricetraining.com
    WATCH MORE:
    Dark Web & Cybercrime Investigations: • Tracking Cybercrime on...
    Malware & Hacker Tradecraft: • Malware Analysis & Thr...
    📧JOIN MY NEWSLETTER ➡ jh.live/email
    🙏SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎FOLLOW ME EVERYWHERE ➡ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/discord ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware
    🔥TH-cam ALGORITHM ➡ Like, Comment, & Subscribe!

ความคิดเห็น • 35

  • @goingcrazy-mg9sf
    @goingcrazy-mg9sf 24 วันที่ผ่านมา +27

    id watch the unlisted video, always exciting seeing the journey

  • @Max-kl7il
    @Max-kl7il 24 วันที่ผ่านมา +42

    Nothing better than some John Hammond to start the morning

    • @Mr0rris0
      @Mr0rris0 24 วันที่ผ่านมา +2

      This guy got coffee too?

  • @donttrusttheape
    @donttrusttheape 24 วันที่ผ่านมา +3

    Because of this videos i was able to be quite high in rankings on Huntress ctf so keep em coming friend (also first ctf ever).

  • @0xazyz897
    @0xazyz897 23 วันที่ผ่านมา +2

    That's the content we want to see john , Thank you !

  • @tincup033
    @tincup033 24 วันที่ผ่านมา +1

    I know you aren’t sure about the value of showing things like breaking user policy but I have to say, there is a ton of value in seeing that. I actually met you at B Sides in SF last year and mentioned that one of my favorite things about your videos is observing your process. So many of us have gotten where we are by trying and breaking things and once in a while, we feel…dumb lol. Seeing someone else going through a lot of the headaches we have or struggling with some of the same things we have is both valuable and extremely helpful. Please keep making awesome content good sir and thank you!

  • @heatherhammons
    @heatherhammons 23 วันที่ผ่านมา +1

    Hi John I am Heather Hammons, I went to school with a Hammond at Rio Linda High school

  • @user-vq3zt3xn3z
    @user-vq3zt3xn3z 12 วันที่ผ่านมา

    You're looking for a very big applause to thank you so much john sir.

  • @BlendLogDev
    @BlendLogDev 24 วันที่ผ่านมา +1

    pronunciation of the word "malware" as "meowlware" so cool😊

  • @DePhoegonIsle
    @DePhoegonIsle 24 วันที่ผ่านมา +2

    That is interesting, I am also curious about what it attempted to write and what about windows login writes to the HKCU. That if we know that and the agent or process of the system/user that does it, a tighter security measure could be put into control and a better understanding of what is and isn't needed.
    Though part of me suspects that HKCU is a fully temp tree, that is recreated each and every time on login, but I am not sure...
    a deeper dive on this would be of value I think.

  • @justinpinson8575
    @justinpinson8575 24 วันที่ผ่านมา +2

    love this kind of content ❤

  • @nixielee
    @nixielee 24 วันที่ผ่านมา +1

    Haven't seen a lot of deobfuscation lately, nice one

  • @notavoicechanger1808
    @notavoicechanger1808 24 วันที่ผ่านมา

    Now to modify the kernel to make your changes actually functional. :)

  • @LazyPlays_
    @LazyPlays_ 24 วันที่ผ่านมา

    i knew this would make a good and unusual educational video, glad to see u took my recommendation for a video idea and kinda used it in a more safe way. (if u even used my idea lol).

    • @LazyPlays_
      @LazyPlays_ 24 วันที่ผ่านมา

      also a note: my situation actually had it posting a .log file, not downloading it. and as far as restricting, you should set powershell to only be interactive mode, which means it doesnt run scripts, this is what stopped mine from executing and made it a little more safe.

  • @anonymode
    @anonymode 24 วันที่ผ่านมา

    Nice video @john

  • @ulisesgezmain
    @ulisesgezmain 24 วันที่ผ่านมา

    Excelente video 👌

  • @Ma-ug7ww
    @Ma-ug7ww 24 วันที่ผ่านมา

    John! In order for this to work, threat actors have to input those HKCU keys into the system, how would that be done?

  • @jvcss
    @jvcss 24 วันที่ผ่านมา

    anyrun needs to improve their SEO because I was looking for this one a month ago!!! why don't just include "online virtual machine" in the description? please help others with this! make more easy and simple descriptions. I know it can do some fancy stuff but remember most of us just want to test a site to see if it's a malware etc.

  • @kenpachizero
    @kenpachizero 23 วันที่ผ่านมา

    i missed these

  • @logiciananimal
    @logiciananimal 24 วันที่ผ่านมา

    I find it amusing that someone who was once Coast Guard is talking about *land* mines. Not a criticism of course, but ...

  • @SirHackaL0t.
    @SirHackaL0t. 23 วันที่ผ่านมา

    Was that website limited to 100 users? It seemed to be still active - very active

  • @mitch381
    @mitch381 24 วันที่ผ่านมา

    I would just disable autoruns entirely if not necessary for the organization

  • @halloworld184
    @halloworld184 3 วันที่ผ่านมา

    Hello

  • @51cle
    @51cle 24 วันที่ผ่านมา +2

    dang

  • @Monothefox
    @Monothefox 24 วันที่ผ่านมา

    That's Norwegian or Danish.

  • @DWaseem89
    @DWaseem89 22 วันที่ผ่านมา

    Become my tutor.

  • @ohmsohmsohms
    @ohmsohmsohms 24 วันที่ผ่านมา +2

    Diddy ram

  • @bertosudu9506
    @bertosudu9506 24 วันที่ผ่านมา

    👍👍👍👍👍👍👍👍👍

  • @domelessanne6357
    @domelessanne6357 22 วันที่ผ่านมา

    erlaerlar

  • @VSEC.Academy
    @VSEC.Academy 24 วันที่ผ่านมา

    most of modern antimalware softwares nowadays blocks PowerShell execution ( notify user for ask permission ) in HIPS technology so if anyone configure HIPS properly i think it would stop most of malicious codes

  • @Iandavidandrino
    @Iandavidandrino 24 วันที่ผ่านมา

    what is html ?

  • @sunniglory514
    @sunniglory514 24 วันที่ผ่านมา

    Is it love?
    😂 duh!

  • @capability-snob
    @capability-snob 24 วันที่ผ่านมา +2

    Fanglette9. You can't help but love these obfuscated function names.

  • @jamesroycoronel4987
    @jamesroycoronel4987 24 วันที่ผ่านมา

    Pwsh