VBScript & ILSpy Analysis of a RAT

แชร์
ฝัง
  • เผยแพร่เมื่อ 27 ก.ย. 2024
  • If you would like to support the channel and I, check out Kite! Kite is a coding assistant that helps you code faster, on any IDE offer smart completions and documentation. www.kite.com/g... (disclaimer, affiliate link)
    For more content, subscribe on Twitch! / johnhammond010
    If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
    PayPal: paypal.me/john...
    E-mail: johnhammond010@gmail.com
    Discord: johnhammond.or...
    Twitter: / _johnhammond
    GitHub: github.com/Joh...

ความคิดเห็น • 168

  • @originalgaming9062
    @originalgaming9062 3 ปีที่แล้ว +75

    No body’s seen the video yet, but 13 people have already liked it. I think this goes to show that people (including myself) LOVE these malware analysis videos

    • @originalgaming9062
      @originalgaming9062 3 ปีที่แล้ว +2

      @@Marko-wi1lb I just feel bad for the one poor fellow who missed the like button

    • @herotrojan1645
      @herotrojan1645 3 ปีที่แล้ว

      can you tell me the best malware analysis course to begin with

    • @herotrojan1645
      @herotrojan1645 3 ปีที่แล้ว

      can you tell me the best malware analysis course to begin with

  • @flawlesscode6471
    @flawlesscode6471 3 ปีที่แล้ว +96

    Alternative Name:
    John from the future getting annoyed by his past self doing stupid stuff

  • @AnoNymous-ie3wc
    @AnoNymous-ie3wc 3 ปีที่แล้ว +5

    For you this video might me "amateurish" but for me it's
    1. entertaining
    2. i can learn from your mistakes
    3. it helps me even more to understand what you do
    👍 from me

  • @AkAk-jv7ig
    @AkAk-jv7ig 3 ปีที่แล้ว +5

    This is rad learning with jokes lol! You're awesome John please keep em coming!

  • @philipstringer4425
    @philipstringer4425 3 ปีที่แล้ว +6

    john gotta admit I don't mind seeing the mess ups, its very organic and wholesome I appreciates it

  • @QuibbleTrouble
    @QuibbleTrouble 3 ปีที่แล้ว +12

    I think the revenge rat used here is a fixed version that's open-source on github by a person named NYAN-x-CAT which showed up in the config.

  • @mustafamotiwala2335
    @mustafamotiwala2335 3 ปีที่แล้ว +2

    mr john yet another malware analysis?! it is indeed an auspicious week for us all. seriously these make my day so much better, thank you for doing what you do!

  • @bryanleong2846
    @bryanleong2846 3 ปีที่แล้ว +2

    keep it up John, really like all your malware analysis videos

  • @batteryman2852
    @batteryman2852 3 ปีที่แล้ว +7

    Ah yes , i like to call my Object variables by the names , vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvnnnnnnnnnnnnnnnn , and my String primitives, qaaaaaaaaaaaaaaaaazzzz..

    • @abeecee
      @abeecee 3 ปีที่แล้ว

      *verbose*

  • @thecaretaker0007
    @thecaretaker0007 3 ปีที่แล้ว +2

    I had to watch the whole video when I saw 5:45
    Also Hackthebox T-Shirt

  • @9rye
    @9rye ปีที่แล้ว

    “hey what’s up” I love how this feels like I’m just talking to a normal being, not just some TH-camr

  • @duncan3144
    @duncan3144 ปีที่แล้ว

    Another great video even if i am late to watch it. I enjoy decoding viruses etc and writing fixes. I am currently re writing my happy99 virus fix. I coded it back in 90's. Needs an upgrade.

  • @hoodieman04
    @hoodieman04 3 ปีที่แล้ว +2

    Dont worry if IPs and ports dont match up to reporting, its very common to have actors jump to new IPs or be booted by the VPS provider

  • @dr.humorous447
    @dr.humorous447 3 ปีที่แล้ว

    You are a very underrated youtuber you deserve better to be honest. Im new to your channel and I love your content that I subed for more I have no experience in hacking but I know a lot about computer both software hardware and some networking.
    Keep up the good work 👏 👍

  • @Cyberducky
    @Cyberducky 3 ปีที่แล้ว +1

    Future John getting frustrated by his past self is my new spirit animal xD

  • @roykositzky2252
    @roykositzky2252 2 ปีที่แล้ว

    god damn man your are my fav person right now thank you for being here. was that evillimeter tool a vuln or im i just a idiot? love ya man have a great day.

  • @devilemox2824
    @devilemox2824 3 ปีที่แล้ว +2

    "MATH IS HARD" :) **Agreed**

  • @imTyp0_
    @imTyp0_ ปีที่แล้ว

    Love these kinds of videos :)

  • @jaymar921
    @jaymar921 3 ปีที่แล้ว +9

    He looks like a senior dev looking at the code provided by the junior dev 😅

  • @48pluto
    @48pluto 3 ปีที่แล้ว

    It was a interesting video as always. I like these decoding stuff. What caught my eye was at @53:13 Set objFSO = CreateObject("... Next line set objFSO = Nothing That was funny :)

  • @tuckerward9844
    @tuckerward9844 3 ปีที่แล้ว

    'John from the future' bit got me, thank you John

  • @BackWithTheBoom
    @BackWithTheBoom 3 ปีที่แล้ว +9

    Creating some in GO while watching this, lets goo.

    • @__theycallmeaadi3316
      @__theycallmeaadi3316 3 ปีที่แล้ว

      What you creating in go ?

    • @hdconnoisseur7932
      @hdconnoisseur7932 3 ปีที่แล้ว

      @@__theycallmeaadi3316 I assume a RAT

    • @__theycallmeaadi3316
      @__theycallmeaadi3316 3 ปีที่แล้ว

      @@hdconnoisseur7932 yea i think so i'm also creating malware in go that's why i asked

    • @__theycallmeaadi3316
      @__theycallmeaadi3316 3 ปีที่แล้ว

      @@j.u.g.y nah that's they call me "aadi" aadi is my name.

    • @__theycallmeaadi3316
      @__theycallmeaadi3316 3 ปีที่แล้ว +1

      @@j.u.g.y no problems I'm lone enough that these things make me happy 😅

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 ปีที่แล้ว

    Thank you brother amarphal always love dance santa

  • @tortotifa5287
    @tortotifa5287 3 ปีที่แล้ว +2

    Hey John, Sometimes when you see that 'Client.exe', that might means that it could be some kind of RAT (talking based on experience). When I saw that ILSpy gave it to you as Lime, I was pretty sure it was Lime Rat. You have its source code on GH !
    Also I do not think that with ILSpy you could do some refactor, but definitely you can with dnSpy. I suggest you to swith over a Windows VM when doing some .NET analysis, it'll get you life easier

  • @donutcream4944
    @donutcream4944 3 ปีที่แล้ว

    I love this series ! Looking forward for more ;)

  • @danieldaszkiewicz7313
    @danieldaszkiewicz7313 3 ปีที่แล้ว

    These videos are great, keep them coming! :D

  • @norboost
    @norboost 3 ปีที่แล้ว

    John sounding like Olivander in Harry Potter. "After all, insert-virus-name-here does great things. Terrible! Yes. But great."

  • @dancingtiger577
    @dancingtiger577 3 ปีที่แล้ว

    these vids are so fun and educational

  • @TheItalohugo
    @TheItalohugo 2 ปีที่แล้ว

    "Heavly edited" : Three jump cuts lololol

  • @almostanengineer
    @almostanengineer 3 ปีที่แล้ว

    I enjoy these and I've absolutely no idea why 🤷🏼‍♂️

  • @Basieeee
    @Basieeee 3 ปีที่แล้ว

    Coool stuff. Ahmed

  • @davidmiller9485
    @davidmiller9485 3 ปีที่แล้ว

    For those who don't know Hwy 75 that runs through Dallas all they way through plano and Richardson and beyond is just chock full of high tech companies. I miss the drive at night, i don't miss the fucking 110 F days.

  • @xn1kkix
    @xn1kkix 2 ปีที่แล้ว +1

    Mavis Beacon Teaches Typing

  • @zitrax506
    @zitrax506 3 ปีที่แล้ว

    Arab hackers: A group of hacker children who depend most of their concept RAT While do not realize what are the foundations of the penetration "I mean the majority "

  • @talinross
    @talinross 3 ปีที่แล้ว

    Keep up the great work love these videos

  • @obitorasu1760
    @obitorasu1760 3 ปีที่แล้ว

    John from the future bullies present John for 1 hour straight.

  • @dedkeny
    @dedkeny 3 ปีที่แล้ว

    Dude, that is the funniest intro you've done yet lol

  • @luks1337
    @luks1337 3 ปีที่แล้ว

    omfg, I love this edit ... btw john u edit in Linux?

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 ปีที่แล้ว

    Gidra assembly code in the bic checking.

  • @Mustardoable
    @Mustardoable 3 ปีที่แล้ว

    Dallas has a few data centres, I'd expect the IPs to be there as that's where they were running the RAT (Remote Access Tool) controller / CnC (Command and Control) server from there

  • @slygamer01
    @slygamer01 3 ปีที่แล้ว

    They ran the C# DLL through an obfuscator. Trying to decipher obfuscated code is not a trivial task.

  • @h8handles
    @h8handles 3 ปีที่แล้ว

    your videos have gotten SO FREAKING GOOD which is hard to imagine because i have loved them since the python tutorials.

  • @MySisterIsASlytherin
    @MySisterIsASlytherin 3 ปีที่แล้ว

    John From the Future is my spirit animal

  • @1wk407
    @1wk407 3 ปีที่แล้ว

    dallas needs an intervention

  • @yamsol1911
    @yamsol1911 3 ปีที่แล้ว

    Dude... this guy is sick kkkkkkk I love your videos

  • @solpex
    @solpex ปีที่แล้ว

    John what ssh client do you use and open a new shell and so forth I really love it fotgot -
    got what you said with Thanks alot!

  • @HalValla01
    @HalValla01 3 ปีที่แล้ว

    37:19 Cover you ears, kids

  • @temolantern9091
    @temolantern9091 3 ปีที่แล้ว

    POV: you're in the comments to see if world of hacker replied to the video with "thanks for the shoutout!"

  • @tomasgorda
    @tomasgorda 3 ปีที่แล้ว +1

    Hahaha i like John from future and his comments 🤣🤣🤣🤣🤣🤣

  • @watchdog2864
    @watchdog2864 3 ปีที่แล้ว +1

    Where do you get these samples from John? I’d love to do some of this myself!

  • @SF-eg3fq
    @SF-eg3fq 2 ปีที่แล้ว

    Hi john, i speak arabic n stuff this guy's content are nothing more than skiddie stuff? in fact 99% of the "arabic hacking" videos on youtube are just a bunch of script kiddies being utra cringe. the page you saw on facebook is not a marketplace it just for his "tutorials" cringy kind of sutff, i even doubt he's behind the vbscript's, those guys really thinks once they learned how to setup kali virtual machines they become "hacking masters" or somethin 🤣, nice video and please do not take those guy's seriously in anything🤣🤣

  • @maliusribeiroborges7578
    @maliusribeiroborges7578 3 ปีที่แล้ว +1

    Damn, this is way above my level lol

    • @jwbulmer
      @jwbulmer 3 ปีที่แล้ว

      It’s all above my level.

  • @gabrote42
    @gabrote42 2 ปีที่แล้ว

    Hilarious 20 20 retrospective

  • @TheAngelOfDeath01
    @TheAngelOfDeath01 3 ปีที่แล้ว

    C# code... and it's not the engine behind a chess game that code there covers!

  • @surajsawant6469
    @surajsawant6469 3 ปีที่แล้ว +1

    hey, it's fun to see your vids. could you please also share the samples?

  • @BSJuliaMagna
    @BSJuliaMagna 3 ปีที่แล้ว +2

    Hackers from Texas? Yeeehaaaackers?

  • @eklypzn
    @eklypzn 3 ปีที่แล้ว

    I see you have the Huntress shirt too. You can use -o with curl to download. John is about to get DMCA'd by these hackers PepeLaugh

  • @TwinTailTerror
    @TwinTailTerror 3 ปีที่แล้ว

    Server is victim in the world of rat. Client is attacker on the norm

  • @fade8148
    @fade8148 3 ปีที่แล้ว

    Best dud

  • @rckrs-jf8lb
    @rckrs-jf8lb 2 ปีที่แล้ว

    Excellent video man, if you can share the sample, would be great.

  • @ThatBoringDeveloper
    @ThatBoringDeveloper 2 ปีที่แล้ว

    I am by no means a ethical hacker or someone who is into malware analysis i am more of a web developer than anything but isn't this dangerous even in a virtual machine?

  • @TwinTailTerror
    @TwinTailTerror 3 ปีที่แล้ว

    Update that ip is a vpn in tex by nord i think

  • @Dodo-rb4zf
    @Dodo-rb4zf 3 ปีที่แล้ว +1

    me doing code review on my company

  • @Lars-ce4rd
    @Lars-ce4rd 3 ปีที่แล้ว

    Here's a funny problem to consider, who gets more value out of .Net code obfuscating itself at build time, good guys or bad guys? Have we made life harder on ourselves?

  • @nickreed7277
    @nickreed7277 2 ปีที่แล้ว

    if it makes you feel better John. im not one of those people who notice anything wrong that you do. im a noob :)

  • @L0PREZ
    @L0PREZ 3 ปีที่แล้ว +1

    I would not mind an entire video of you looking through Legend of Zelda lore/artwork. also great videeo as usual!

  • @killerskincanoe
    @killerskincanoe 3 ปีที่แล้ว

    Math actually is hard yo

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 ปีที่แล้ว

    Count numbers also explain anonymous details skillsonics tell me
    Tufan gentleman songs

  • @rrkatamakata7874
    @rrkatamakata7874 3 ปีที่แล้ว

    i am cse student and i feel like oh god there is no way i can write this stuffs. (i want to mention the hardness of these stuff not the hacking part)

  • @computerGeekOffical
    @computerGeekOffical 3 ปีที่แล้ว

    Damn how did you git this crypter

  • @ivanboiko8975
    @ivanboiko8975 3 ปีที่แล้ว +1

    ho ho ho, time to malware :D

  • @ir4640
    @ir4640 3 ปีที่แล้ว

    Where do you usually find the malware?

  • @phyyl
    @phyyl 3 ปีที่แล้ว

    Hey John! where do you find these?

  • @hosnymubark6528
    @hosnymubark6528 3 ปีที่แล้ว +1

    John isn't excited like every video.
    Are you ok?

  • @arivanhouten6343
    @arivanhouten6343 3 ปีที่แล้ว

    i was here before you could even watch it

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 ปีที่แล้ว

    Bytes gising

  • @garcand
    @garcand 3 ปีที่แล้ว +1

    What career position would I search for to do something like this?

    • @maans2001
      @maans2001 3 ปีที่แล้ว

      malware analysis maybe

    • @Babakinha
      @Babakinha 3 ปีที่แล้ว

      Cybersecurity?

    • @maans2001
      @maans2001 3 ปีที่แล้ว +1

      @@Babakinha Malware Analysis is a part of Cyber Security yes

    • @adhamhalabi7472
      @adhamhalabi7472 3 ปีที่แล้ว

      You can either take master degree in cybersecurity or it security that has focus on practical side more than theoretical side, make sure to check their courses to see if they teach what interest you, or you can go to EC-Council and learn this online they have many courses that varies from ethical hacking to forensic investigator, both options costs quite a bit.

    • @ko-Daegu
      @ko-Daegu 3 ปีที่แล้ว

      @@adhamhalabi7472 imagine thinking you need a useless master degree to do practical malware analysis

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 ปีที่แล้ว

    Pasta explain mex ing pag

  • @astropgn
    @astropgn 3 ปีที่แล้ว

    if(false)... hacker, dude... what the hell?

  • @kushshah3682
    @kushshah3682 3 ปีที่แล้ว

    hahahahahahaha loving the energy of this vid

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 ปีที่แล้ว

    Wsh rat is malviya

  • @alansojan6190
    @alansojan6190 3 ปีที่แล้ว

    Hey peeps

  • @progress1veone83
    @progress1veone83 3 ปีที่แล้ว

    مجموعة ‏عالم الاختراق World Of hacker

  • @0xlol64
    @0xlol64 3 ปีที่แล้ว

    You won't understand because he is talking Arabic btw I'm Egyptian

  • @johnnywilliams2641
    @johnnywilliams2641 5 หลายเดือนก่อน

    'those people.' knew someone so ligght couldn't not be a(n?) f-ing razist

  • @lorenzo42p
    @lorenzo42p 3 ปีที่แล้ว

    is vb script used for anything other than viruses? why is it still a thing? tbh I loved vb6 and earlier, way back in the day, but in the real world, is it used for anything other than viruses? I really don't know, haven't touched winblows in so long. the whole os is a virus.

  • @ygjt76v0-----
    @ygjt76v0----- 3 ปีที่แล้ว

    Hi

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 ปีที่แล้ว

    Wework other persons we want coming in my father was you want you are explain per you tell me

  • @alreadydeadfunk
    @alreadydeadfunk 3 ปีที่แล้ว

    Sorry. But whenever you said VBScript, I would be intrigued.

  • @jimo8486
    @jimo8486 3 ปีที่แล้ว

    im the 1.5k like LOL

  • @wijeweerajayasundera2043
    @wijeweerajayasundera2043 3 ปีที่แล้ว

    Mal Ware 😅

  • @thomasclancy1328
    @thomasclancy1328 3 ปีที่แล้ว

    Did i make it in time for a like?

  • @killerskincanoe
    @killerskincanoe 3 ปีที่แล้ว

    Uhm.. You have a dog and haven introduced us yet? Disappointed

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 ปีที่แล้ว

    Rat ox3456 bajot work
    Code file's" c++"0xnumber

  • @Nuclear__HS
    @Nuclear__HS 3 ปีที่แล้ว +84

    John, I LOVE all these cuts "from the future", they're hilarious xD

    • @ca7986
      @ca7986 3 ปีที่แล้ว +2

      💯

    • @donovanelliott9060
      @donovanelliott9060 2 ปีที่แล้ว +1

      I really wanna like this comment but I can't because it has 69 likes

  • @uumas
    @uumas 3 ปีที่แล้ว +6

    ok the 3min 50s self flame is freaking awesome. absolutely love the humor ! Keep it going man. Just the second video i watch from you but can already tell i'll probably watch some more for the personality alone

  • @AhmedFromKSA
    @AhmedFromKSA 3 ปีที่แล้ว +3

    The banner at 38:47 says "encrypt(ing?) all servers the rat clean"
    so you were probably in the right place

  • @stevejamal241
    @stevejamal241 3 ปีที่แล้ว +4

    I bet ya that Mr Ahmed is from Eygpt cause that background is almost like Egyptian way of piracy and hacking stuff 😅😅

    • @0xlol64
      @0xlol64 3 ปีที่แล้ว

      this why most people who sees his profile hate us egyptian and arabs btw im egyptian

    • @hpimpact
      @hpimpact 3 ปีที่แล้ว +1

      egypt isn't the only arabic country tho

    • @ko-Daegu
      @ko-Daegu 3 ปีที่แล้ว

      @@0xlol64 why thou??
      I don’t get why I will hate an entire country( 100m+ people) cuz of a banner ?
      Also we have Russian and Chinese hackers I’m not hatin Russia or China cuz of them
      You are worrying for wrong reasons

  • @scor-_-pions5094
    @scor-_-pions5094 3 ปีที่แล้ว

    por favor faz mes que to tentando...> executar o emulador do ( ps1 duckstation ) com um comando bat para iniciar a iso do jogo sem abrir o emulador ou seja iniciar automaticamente com um click no comando .bat?

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 ปีที่แล้ว

    I want patient situation I am not sell controlling sorry sorry sorry sorry sorry sorry 🤖 sorry