They Say This Malware is INSANE

แชร์
ฝัง
  • เผยแพร่เมื่อ 3 ต.ค. 2024
  • jh.live/htb-sh... || Join Hack The Box to solve Sherlock tasks just like this one! jh.live/htb-sh...
    Learn Cybersecurity - Name Your Price Training with John Hammond: nameyourpricet...
    Learn Coding: jh.live/codecr...
    Don't listen to other "influencer" VPN crap -- host YOUR OWN: jh.live/openvpn
    WATCH MORE:
    Dark Web & Cybercrime Investigations: • Tracking Cybercrime on...
    Malware & Hacker Tradecraft: • Malware Analysis & Thr...
    📧JOIN MY NEWSLETTER ➡ jh.live/email
    🙏SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎FOLLOW ME EVERYWHERE ➡ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/discord ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware
    🔥TH-cam ALGORITHM ➡ Like, Comment, & Subscribe!

ความคิดเห็น • 59

  • @GodDamnitTwitch
    @GodDamnitTwitch วันที่ผ่านมา +26

    the word "kindly" is like a dog whistle to me lol

  • @godliestous4658
    @godliestous4658 12 ชั่วโมงที่ผ่านมา +6

    It's sooo interesting to watch these kind of videos where you reviewing the source code and see how malwares behave on infected hosts

  • @likebot.
    @likebot. วันที่ผ่านมา +24

    the clue is in the wording "... we _kindly_ request..."

    • @nickcurrie303
      @nickcurrie303 11 ชั่วโมงที่ผ่านมา

      Lol the real clue is in the fact that your IT team would not / should not email an executable out to users to execute - this would be scripted or deployed via other means.

  • @edwardfildes2038
    @edwardfildes2038 วันที่ผ่านมา +11

    You'd think anyone with the technical know-how to run JS files would also find the request to run one from IT highly suspicious.

    • @northholdgames8596
      @northholdgames8596 วันที่ผ่านมา +6

      in windows it is just a simple double click or "run". it doesnt require any skill

    • @edwardfildes2038
      @edwardfildes2038 วันที่ผ่านมา +1

      @@northholdgames8596 ah fair play, I didnt know that

    • @bestcoolmanever
      @bestcoolmanever วันที่ผ่านมา

      @@northholdgames8596 he's saying that it's bizarre that someone fell for one of the most common and obvious "hey, run this file, it's totally safe!" phishing schemes to ever exist without even a single thought of double-checking anything. it's like getting a text from a random unaffiliated scammers number that says "it's me, your mom. send me $500, it's urgent!" while sitting a room away from your mom and still sending the scammer $500 anyways

  • @ismayonnaiseaninstrument8700
    @ismayonnaiseaninstrument8700 22 ชั่วโมงที่ผ่านมา

    This is probably the first in-depth digital forensics video I've sat around and watched, and honestly...thanks! I learned a helluva lot, and I'll be experimenting with those debug tools myself... (once I have a stronger foundation in assembly, mind you.)

  • @fdert
    @fdert วันที่ผ่านมา

    Great education here digging into IDA. I'm just getting into this field and this is very helpful to see your process, thank you!

  • @ft4jemc
    @ft4jemc วันที่ผ่านมา +7

    Neat video. Yes. Yes you loose nerd cred for not knowing LoTR.

  • @technikschaf1574
    @technikschaf1574 3 ชั่วโมงที่ผ่านมา

    "loosing a little bit of street cred" ? With a lot of luck there is a little bit left thanks to you at least recognising it as lotr.
    Thanks for taking us with you at this journey there and back again.

  • @jesperwall839
    @jesperwall839 วันที่ผ่านมา +20

    Is this a 57 minute commercial? Been to many of those lately, and I don’t want to waste my time.

    • @Twoshoes22Jason
      @Twoshoes22Jason วันที่ผ่านมา

      Yes. For HackTheBox

    • @TotesCray
      @TotesCray วันที่ผ่านมา +11

      I mean... it's a commercial showing HTB's sherlock exercises, but the "how it's solved" is great learning info regardless of the original source

    • @capability-snob
      @capability-snob วันที่ผ่านมา +1

      ​@@TotesCraycoolest username ever, well done. Must have used freon.

  • @shodannonymous9359
    @shodannonymous9359 วันที่ผ่านมา

    I'm probably gonna try this box with your guide, thanks as always John

  • @MultiDark2012
    @MultiDark2012 วันที่ผ่านมา +1

    Even though I could see the info on screen, I was still w8ing for John to say LTT. 😂😝

  • @draconic5796
    @draconic5796 วันที่ผ่านมา +3

    Seems someone is a Lord of the Rings fan lol. Finding Middle-Earth, bringing the god of everything Eru and then using the Palantir to get into Gondor haha!

  • @Rostol
    @Rostol วันที่ผ่านมา +5

    windows pro includes a secure isolated ephemeral VM, it's called Sandbox. it's awesome for testing things. Also a good tip if using VMs is to take snapshots between steps, just in case ... lol.
    35:46 it's reading the resource table on the .dll, not the .exe that's probably why the entropy was meh in the .exe resourrces

  • @josemariolladomarti4935
    @josemariolladomarti4935 13 ชั่วโมงที่ผ่านมา

    awesome work man

  • @redisbluegaming6696
    @redisbluegaming6696 วันที่ผ่านมา

    Nice channel, love learning from you

  • @ogunikitty
    @ogunikitty วันที่ผ่านมา

    Wow. Learnt a lot today. Thanks john

  • @threeMetreJim
    @threeMetreJim วันที่ผ่านมา

    Not too bad at all. The insane rating was about right if you've never done this before. Be prepared for layers of obfuscation (in the scripting parts) in real malware, just to frustrate even more. Nice to see this test also having an encrypted part to extract.

  • @logiciananimal
    @logiciananimal วันที่ผ่านมา

    Nicely done - I didn't know IDA Free had a debugger. I don't do much RE, I guess.

  • @aidengoiangos4577
    @aidengoiangos4577 12 ชั่วโมงที่ผ่านมา

    Another john hammond classic

  • @mitospha
    @mitospha 9 ชั่วโมงที่ผ่านมา

    Pretty cool demo, thank you. That was rated insane? Some sites I think would honestly rate that as Medium out of easy, medium, hard. Not all CTF sites are the same I guess.

  • @h4ckh3lp
    @h4ckh3lp วันที่ผ่านมา +3

    If we weren't already aware, the "WinHTTP" autofill in IDA shows you've prepared this walkthrough which is fine, but I for one would find exponentially more value in the footage of you when you're first running through it. Because to see how you go about figuring shit out when things don't work as you would expect them to would be a lot more informative imo.

    • @IJH-Music
      @IJH-Music 16 ชั่วโมงที่ผ่านมา

      Yes and no. John does some things live and you get to see him go through problems in real time.
      For a video like this, that style of video would be impractical.

    • @h4ckh3lp
      @h4ckh3lp 15 ชั่วโมงที่ผ่านมา

      @@IJH-Music You'll never see his first go at a box, even the "live" shit is scripted (or at least outlined). I don't care if it took 6 hours instead of less than 1, if you can show me HOW TO FIGURE OUT how to figure out the unknowns, this would be greatly more valuable than showing me how to complete a challenge. But for the same reason the crowd boos when the fight is painstakingly being grappled on the ground, youtubers will forever be playing the youtube game more than providing truly meaningful information at the advanced levels.

  • @crudmonkey
    @crudmonkey วันที่ผ่านมา

    Great video John! Love these reverse engineering videos

  • @dav1dw
    @dav1dw 23 ชั่วโมงที่ผ่านมา

    Nerd cred would be to read Lord of the Rings, not just watch the movies.

  • @zerodoinkthirty0
    @zerodoinkthirty0 วันที่ผ่านมา

    W PowerShell investigation

  • @AUBCodeII
    @AUBCodeII 2 ชั่วโมงที่ผ่านมา

    Hey John, let's get OSEE+ right the flipp now

  • @shingareom
    @shingareom วันที่ผ่านมา +2

    They ?

  • @hoosiercrypto9955
    @hoosiercrypto9955 วันที่ผ่านมา +3

    They 😳

  • @QuantariousBitsoniTalvanen
    @QuantariousBitsoniTalvanen 19 ชั่วโมงที่ผ่านมา

    Why dont as many of the malware coming out have vm evasion like how it spiked a few years ago? Or is it just that it's easier now to disguise a vm now?

  • @viv_2489
    @viv_2489 5 ชั่วโมงที่ผ่านมา

    If chat gpt is capable and can be used to learn this obfuscated code?

  • @D.von.N
    @D.von.N วันที่ผ่านมา

    So what happened at the end? Did you encrypt your VM or something else?

    • @74Gee
      @74Gee วันที่ผ่านมา

      Nah, the encryption only acts on a few folders and a few filetypes within those folders so it's mostly benign. See 41:33

    • @D.von.N
      @D.von.N วันที่ผ่านมา

      @@74Gee So those were encrypted, for an average user, if it happened in their real computer, pretty much everything they have there. Riight LOL
      And so I have a clone of my OSs and data backed up multiple times elsewhere. That the ransomware transfers some of my data to the dark web, I won't be able to fix that. Just I will be one of millions other folks out there. A drop in an ocean. My data already is out there, from various hacks of databases...

  • @user_Esq
    @user_Esq 11 ชั่วโมงที่ผ่านมา

    13:54: 'Mining bitcoin cash" -?

  • @zakzak24
    @zakzak24 วันที่ผ่านมา

    hi John, I'm getting into malware analysis, is it enough to just boot up a VM then run malware inside it ? cause I read there're types of malware that could escape and infect the host machine, given that I'm doing both static & dynamic analysis

    • @GarethBaddams
      @GarethBaddams วันที่ผ่านมา +1

      Hey although it isn't impossible for malware to escape a VM it's highly unlikely, if your doing a lot of analysis maybe have separate hardware and network segregation just to make sure 😁

  • @grant-is
    @grant-is วันที่ผ่านมา +47

    Who is they? What does INSANE mean? Could we tone down the hyperbole?

    • @orderandchaos_at_work
      @orderandchaos_at_work วันที่ผ่านมา +7

      Watch the video and find out

    • @pan_golin
      @pan_golin วันที่ผ่านมา +23

      They is HTB, Insane is the difficulty rating.
      Also welcome to TH-cam.

    • @arthurbruel5545
      @arthurbruel5545 วันที่ผ่านมา +10

      Man's gotta play the youtube game. Chill.

    • @FirstnameLastname_official
      @FirstnameLastname_official วันที่ผ่านมา +22

      Everybody asks "who is they?!" but no one asks "how is they?"

  • @stefan-viorelnagy5181
    @stefan-viorelnagy5181 วันที่ผ่านมา

    how am i here so fast

  • @ARIFF861
    @ARIFF861 22 ชั่วโมงที่ผ่านมา

    does this sherlock challenge retired?

  • @SPOOKEXE
    @SPOOKEXE วันที่ผ่านมา

    lee epik

  • @darshanakhare6676
    @darshanakhare6676 วันที่ผ่านมา

    ❤❤❤❤❤❤❤