Hacker's Gave me a Game and I Found a Virus

แชร์
ฝัง
  • เผยแพร่เมื่อ 11 ม.ค. 2025

ความคิดเห็น • 528

  • @acuifex
    @acuifex 2 ปีที่แล้ว +3519

    Now imagine what's it like for malware researchers. You go trough all of those hoops every day, just to find out that it's an xmr miner

    • @astronemir
      @astronemir 2 ปีที่แล้ว +60

      It runs monero miner while waiting for something better.

    • @Kristukas1337
      @Kristukas1337 2 ปีที่แล้ว +5

      let me guess not a big computer guy?

    • @mraloush8959
      @mraloush8959 2 ปีที่แล้ว +86

      @@Kristukas1337 average chris with python as his pfp acting like he knows everything. you probably tell your classmates you're a hacker

    • @Kristukas1337
      @Kristukas1337 2 ปีที่แล้ว +14

      @@mraloush8959 I think the video on your channel speaks for itself

    • @claritix101
      @claritix101 2 ปีที่แล้ว +4

      @@Kristukas1337 lmao

  • @SpeckyYT
    @SpeckyYT 2 ปีที่แล้ว +1096

    The creativity of the hacker to just name the game as an already existing one

    • @Rice7th
      @Rice7th 2 ปีที่แล้ว +5

      ooo ciao specky!

    • @aziskgarion378
      @aziskgarion378 2 ปีที่แล้ว +57

      One that of a game that is very known and has a known indie developer. That's like writing FnaF 17, and people recognizing the user is not Scott Cawthon.
      Pretty sure the guy who wrote the malware isn't the same one who is spreading it.

    • @bombie
      @bombie 2 ปีที่แล้ว +4

      no way its the real specky

    • @whisconsin
      @whisconsin 2 ปีที่แล้ว +9

      @@aziskgarion378 To be fair, nowadays FNAF is community run, as Scott Cawthon retired.

    • @monhi64
      @monhi64 2 ปีที่แล้ว +23

      LLL had edited the vast majority of that scammer messages text so that no one actually typed that URL in and got scammed so I just assumed he (LLL) named it after a known game to be more anonymous. But yeah it’s definitely possible that’s the one part of the URL he didn’t change you never know

  • @KunningFox
    @KunningFox 2 ปีที่แล้ว +179

    1:26 Looks like the malware maker uses Sprinthost's technical domain to host the virus. The subdomain is the username of the client. It might be a good idea to inform the hosting provider that one of their clients uses their servers for malicious purposes. The clients must provide the scan of their passport (or other documents if it's a legal entity) in order to use their services.

    • @evoluckievo
      @evoluckievo ปีที่แล้ว +2

      yeah i saw that too but its not really worth it tbh well if i wanted to maybe for the lulz yk

    • @Renni-kg6vf
      @Renni-kg6vf ปีที่แล้ว +6

      @@evoluckievo ???

    • @evoluckievo
      @evoluckievo ปีที่แล้ว

      @@Renni-kg6vf the domain is known for malware

  • @bit0fun
    @bit0fun 2 ปีที่แล้ว +1002

    Might not have been the hack of the century, but still interesting to learn what they were attempting to do. Could maybe do a video in the future trying to dig into it a bit more? Maybe even an overview on how to write a deobfuscator? Would be neat

    • @IlyesCodes
      @IlyesCodes 2 ปีที่แล้ว +12

      Yes pls

    • @noeaguilar4521
      @noeaguilar4521 2 ปีที่แล้ว +3

      I second that

    • @truestopguardatruestop164
      @truestopguardatruestop164 2 ปีที่แล้ว +1

      Yes

    • @kebman
      @kebman 2 ปีที่แล้ว +4

      It's the Hack of the ... Last Five Minutes! :D

    • @tamnker8465
      @tamnker8465 ปีที่แล้ว +1

      I wonder if chatGPT could deobfuscate… Hmmm…

  • @billigerfusel
    @billigerfusel 2 ปีที่แล้ว +1733

    I could enjoy a 30 minute video on this topic.

  • @shimadabr
    @shimadabr 2 ปีที่แล้ว +359

    A longer video explaining the intricacies of your discovery process would be awesome.

    • @LowLevelTV
      @LowLevelTV  2 ปีที่แล้ว +97

      Noted!

    • @pancak3
      @pancak3 2 ปีที่แล้ว +10

      @@LowLevelTV this video is kinda useless since this wasnt sent by a human. it was a mass dm tool which has responses for everything

    • @spoils8179
      @spoils8179 2 ปีที่แล้ว +17

      @@pancak3 but useful nonetheless because some people have no idea that this happens.
      Also an idea on what not to do, or how to run it in a decent environment.

  • @fwilhe
    @fwilhe 2 ปีที่แล้ว +256

    Nice. Tell us more about the sandbox tool at 1:45. Is that something I should know about? I was expecting a VM, is this some wrapper for a (cloud?) VM? What considerations do you make before running sketchy binaries to avoid them breaking out of the sandbox and affecting the host system?

    • @fwilhe
      @fwilhe 2 ปีที่แล้ว +44

      @@Finkelfunk thanks I never heard of that before

    • @zafmafattack
      @zafmafattack 2 ปีที่แล้ว +34

      Sandboxes designed for malware are pretty much normal virtual machines with extra features to help with analysis. Sandbox escape malware isn't usually an issue for the analysis environment if other precautions have been taken like making an isolated network segment (with a managed switch you can create vlans)

    • @CunningBard
      @CunningBard 2 ปีที่แล้ว +4

      thoughts on windows sandbox?

    • @kirill9064
      @kirill9064 2 ปีที่แล้ว +1

      @@tacokoneko Sandboxie-Plus. It is open source too.

    • @natsudragneelthefiredragon
      @natsudragneelthefiredragon 2 ปีที่แล้ว

      @@tacokoneko But its still on YOUR device...

  • @TowelPanel1852
    @TowelPanel1852 2 ปีที่แล้ว +18

    FYI, the first stage is called a dropper because it downloads/drops malware from another computer onto yours

  • @ZarkWiffle
    @ZarkWiffle 2 ปีที่แล้ว +27

    A friend of mine got hit with a similar scheme but this one stole passwords and other data from chromnium browsers. Once I found the malwares put requests I may or may not have uploaded a few hundred fields of fake generated data into their server.

    • @vinylSummer
      @vinylSummer 2 ปีที่แล้ว +5

      Should've made an sql injection

    • @balllord3546
      @balllord3546 2 ปีที่แล้ว +4

      @@vinylSummer stealers dont store data in sql dbs most of the time and if they do it is most likely sanitized so wouldnt work

    • @ggsap
      @ggsap 11 หลายเดือนก่อน +5

      @@vinylSummer what is this? the 90s? if they smart enough to develop such kind of software they surely wont have a sql injection vuln lol

  • @CallousCoder
    @CallousCoder 2 ปีที่แล้ว +9

    “I just ran it” and that actually is often the easier thing to do. Because some code can indeed be hellishly obfuscated or even compressed and/or encrypted and to reverse engineer that can take ages. Just running it, whilst having wireshark logging and memory dumping the data segments and on Linux I live to run strace or Solaris truss as well. And see what kernel calls with what data are done.
    Now I never reversed engineered malware but mainly copy protection and old unsupported software (statue of limitations has passed 😂), or create cheats in games (a lot of that on this channel too) and debug unsupported code that still ran (and probably still is).

    • @JonahTheWhite
      @JonahTheWhite 2 หลายเดือนก่อน

      Being able to use windows filtering platform efficiently makes you immune to %99.99 of malware...

  • @heroclix0rz
    @heroclix0rz 2 ปีที่แล้ว +107

    Would be good to explain in as much detail as possible what steps you take to ensure a virus will not be run on your main machine and will definitely be isolated to the sandbox of your choice. Don't want a random 14 year old feeling invincible, only to get their mom's laptop pwned because they don't know how to put a VM in the DMZ.

    • @ryans3979
      @ryans3979 2 ปีที่แล้ว +4

      He isn't using a VM machine in this video

    • @ToxicAtom
      @ToxicAtom 2 ปีที่แล้ว +35

      considering the sandbox he uses isn't running on his network and instead is an open web-based platform designed for inspecting malware, I'm pretty sure nobody will get the wrong idea from this video

    • @akirekoko7415
      @akirekoko7415 ปีที่แล้ว +1

      ​@@ToxicAtom ninja

  • @Rottenham12345
    @Rottenham12345 2 ปีที่แล้ว +65

    It would be great to see a detailed video on how you reverse engineered this. You speak through your process so casually when it’s actually super impressive stuff you’re doing that I’m sure a lot of us would like to better understand

    • @balllord3546
      @balllord3546 2 ปีที่แล้ว +4

      what details do you need he pretty much explained it all.

    • @casquinha132
      @casquinha132 2 ปีที่แล้ว +3

      Because it's not super impressive, you just lack background.

    • @Rottenham12345
      @Rottenham12345 2 ปีที่แล้ว +12

      @@balllord3546 there is a difference between a summary and a detailed explanation my friend.

    • @bigdraco3006
      @bigdraco3006 2 ปีที่แล้ว +4

      all he did was look at strings in ida and run it in a sandboxer tho xd

    • @balllord3546
      @balllord3546 2 ปีที่แล้ว +2

      @@Rottenham12345 bigdraco literally said all he did. this is literally all he did there is no more detail to mention unless u want to look at the sandbox’s analysis more as he didn’t unpack the final stage

  • @jumanji4037
    @jumanji4037 2 ปีที่แล้ว +55

    This is really interesting, the entire idea of reverse engineering and looking for those hard coded urls and files is really smart.
    I’d love to see a course on decompiling executables and understanding their purpose.
    Happy new year!

    • @softwarelivre2389
      @softwarelivre2389 2 ปีที่แล้ว +6

      Doesn't work if it obfuscates URLs (like calling a parse function from some weird encoding made just for that purpose), or if if just uses good old plain encrypting/decrypting on the go. But network analysis should capture it just fine.

    • @ChrisTheCringe
      @ChrisTheCringe 2 ปีที่แล้ว +7

      In a real world scenario, viruses would have that URL obfuscated. It wouldn't be that easy.

    • @balllord3546
      @balllord3546 2 ปีที่แล้ว

      @@ChrisTheCringe true.

    • @KaneYork
      @KaneYork 2 ปีที่แล้ว +1

      @@ChrisTheCringe this was a real world sample!!
      The first stage just didn't use advanced protections like the 2nd did

  • @pedroaviladressler310
    @pedroaviladressler310 ปีที่แล้ว +1

    very intelligent od someone to drop an malware disguised as a game, on a programming discord community

  • @khalilovitch_
    @khalilovitch_ 2 ปีที่แล้ว +17

    Great video, I would enjoy a detailed explanation of your approach to reverse engineer the binary

    • @LowLevelTV
      @LowLevelTV  2 ปีที่แล้ว +9

      Coming soon!

    • @kebman
      @kebman 2 ปีที่แล้ว

      @@LowLevelTV Looking forward to it!

  • @gridfighter
    @gridfighter 8 หลายเดือนก่อน +1

    This is actually a great topic. I have a few games that are open source but the only remaining versions of them are infected. So here I am learning how to decompile them to remove the malicious part and compile them again.

  • @magnusm4
    @magnusm4 ปีที่แล้ว

    What I wonder is how their code could just be run and automatically be allowed to disable essential defense programs.
    Shouldn't there be tons of checks screaming "Yo you're shutting down Windows Defender? No problem we'll just shut down all access to the computer, reboot and automatically put it in safe mode while writing a report on what you just tried to do".

  • @9superswords630
    @9superswords630 2 ปีที่แล้ว +1

    There are a lot of good malware reversing researchers here on youtube. Many don't like to/are not capable of jumping into IDA. This is great!

  • @GedasTM
    @GedasTM 2 ปีที่แล้ว +1

    Finding playtesters will now be even more difficult 😟

  • @Ldinos
    @Ldinos 2 ปีที่แล้ว +1

    Does that mean that if you run this without internet access, it will do nothing?

    • @DaxyGamer
      @DaxyGamer 2 ปีที่แล้ว

      well it will still disable registry antivirus etc and probably store itself in registry/startup for persistence

  • @vyldim3401
    @vyldim3401 2 ปีที่แล้ว +3

    0:33 Folders named \Cryptor\Loader runpe huh? Really subtle hacker, reaaaaly subtle

    • @LowLevelTV
      @LowLevelTV  2 ปีที่แล้ว

      Yeah they left a TON of build artifacts in that loader. Wild.

  • @Pedakin
    @Pedakin 2 ปีที่แล้ว +2

    This is why I can’t just “throw on a video” around people for everyone to watch. This is the kind of shit I like.

  • @toperri
    @toperri ปีที่แล้ว +1

    just found this channel and I can't stop watching his videos

  • @davidmurphy563
    @davidmurphy563 2 ปีที่แล้ว +22

    ".ru" what a surprise.

    • @jp4_
      @jp4_ 2 ปีที่แล้ว +4

      php file's named bebra as well which is a russian meme so

    • @bill8126
      @bill8126 9 หลายเดือนก่อน +4

      anyone from anywhere could rent that russian hosting. So it doesn't usually say about hacker nationality

    • @mbrofoc
      @mbrofoc 9 หลายเดือนก่อน

      xD...

    • @mbrofoc
      @mbrofoc 9 หลายเดือนก่อน

      ​@@bill8126yeap. Some people need to see the host map around the world and realize that you don't need any identification docs about you to buy host😂

  • @NutflX
    @NutflX 2 ปีที่แล้ว +4

    i almost fell for this a few months ago
    but the part that made it believeable was it from one of my friends hacked accounts. and he was developing a basic platformer so i didnt think twice about it.
    i only realised once a cmd opened and discord restarted to the login page.

    • @TheTacticalTuna
      @TheTacticalTuna 2 ปีที่แล้ว

      That sucks, did you just reinstall windows after that?

    • @stevenglikin3219
      @stevenglikin3219 ปีที่แล้ว +3

      That's like "almost" falling for an irs scam when you already gave them 500$ of gift cards

  • @billyjoejimbob75
    @billyjoejimbob75 2 ปีที่แล้ว +1

    That's funny. Always wondered why nobody ever took my old DOS screensavers back in the 90s. Then I realized they thought everyone on the internet was out to get them.

    • @RationalFunction
      @RationalFunction ปีที่แล้ว

      What do DOS screensavers have to do with this?

  • @wChris_
    @wChris_ 2 ปีที่แล้ว +5

    actually your IP doesnt matter! just restart your router and you will get a new one. leaking your IP address is only an issue if you have a static one which im 99.99% sure you dont have.

    • @LowLevelTV
      @LowLevelTV  2 ปีที่แล้ว +5

      DHCP be like

    • @wChris_
      @wChris_ 2 ปีที่แล้ว +3

      @@LowLevelTV DHCP only assigns private IPs to your devices connected to your router. You probably have heard that we are running out of IPs and for the most part this is true, but to combat that issue NAT was invented, which resolves this issue by translating your private IP address into the public IP everyone see on the internet. This way IP addresses are not wasted to end users who realy dont need them.

    • @wChris_
      @wChris_ 2 ปีที่แล้ว +1

      @@LowLevelTV you can check that you really only have 1 IP by searching 'what is my IP' or something similar on multiple devices.

    • @Sevenhens
      @Sevenhens 2 ปีที่แล้ว +2

      @@wChris_ ISPs give out residential IPs by DHCP themselves (hence why your IP can change when you restart your router).

  • @Wannabe-channeL
    @Wannabe-channeL 2 ปีที่แล้ว

    Because of the hacker like this. As an indie game developer, it’s hard to find someone to play my game and they started accusing me of being a scam 😔

  • @chadengineer
    @chadengineer 2 ปีที่แล้ว +17

    Nice video, you should do more videos about this IDA tool, it's really interesting

  • @iuhere
    @iuhere 2 ปีที่แล้ว +1

    whoa , this is new content or am i missing such content on your channel, may be youtube is filtering such content of your channel to not show in my noti... they might be watching me (or my history) 🤣 as if... anyways great video , never thought of skipping as every second of the video was nicely curated and data being pitched in simple way. the comic timing was awesome and fairly placed with the context of the video. Keep up the good work, simply put enjoyed this one.

  • @TheOneTrueDragonKing
    @TheOneTrueDragonKing ปีที่แล้ว

    This is a VERY common occurrance on Discord. Hackers, malicious actors, cybercriminals, even terrorists.

  • @cpaw
    @cpaw 2 ปีที่แล้ว +1

    I wish one of my friends knew about scams like this before he lost his whole online presence due to a virus

  • @LegoWormNoah101
    @LegoWormNoah101 ปีที่แล้ว +1

    Just imagine being the hacker and seeing this video.

  • @SkippyDa
    @SkippyDa 2 ปีที่แล้ว +1

    I had a similar thing, got send to a website to download their game, reverse engineered it, was a basic cookie/discord session stealer, including the non obfuscated code.

  • @ryyott
    @ryyott 2 ปีที่แล้ว

    Bro could have given you a legit game with a silent miner compiled into it and most people would have no idea. Weird hacker with absolute no idea...

  • @shapelessed
    @shapelessed 11 หลายเดือนก่อน

    "Hacker is gave me a game" - What a great and completely correctly written title.

  • @lynx1436
    @lynx1436 2 ปีที่แล้ว +3

    There's been a virus around on discord working kind of the same way as this although it gets access to accounts and someone text the hacked accounts friends from it which makes it so people dont think about downloading the file and running it. My best friend had this happen to them and the hacker sent the file to me from their account and i almost fell for the trap, my friend is too stupid to make a game so was skeptical from the start ahha

  • @DccToon
    @DccToon 2 ปีที่แล้ว

    wait, the person named "not a hacker" reminds me of when i created my discord account, i called it "not a hacker" but then i decided to change it

  • @not_herobrine3752
    @not_herobrine3752 2 ปีที่แล้ว

    reminds me of the time i wanted to watch a movie and ended up finding out that its a piece of shitty malware with a stupider method of delivering its payload

  • @Cenk57
    @Cenk57 2 ปีที่แล้ว

    Bro got out of there as fast as he could 💀

  • @shayanaayan6533
    @shayanaayan6533 ปีที่แล้ว

    Me looking up reverse engineering malware.. Because i downloaded a pre activated software i need for my work... And here i am... Learning something new throughout the vid
    Thank You 💯

  • @tastyshadow5489
    @tastyshadow5489 ปีที่แล้ว

    Dumb people: download malware
    Smart people: avoid malware
    Reverse engineers: download malware

  • @ivanignacio2353
    @ivanignacio2353 7 หลายเดือนก่อน +1

    how is called that app that you used for sandboxing?
    Great video

  • @alexestefan7521
    @alexestefan7521 2 ปีที่แล้ว +1

    Guessing the game requires admin privileges like anything else on windows

  • @technomind88
    @technomind88 ปีที่แล้ว +1

    I liked the part where you "found their IP address"

  • @fusngakoucjrisknbllh
    @fusngakoucjrisknbllh 2 ปีที่แล้ว

    Nice video man, be careful with your IP

  • @alphaknight1181
    @alphaknight1181 ปีที่แล้ว

    that "game me and my friends made" actually sounds like the users discord account was hacked and then the hacker sent the malware to everywhere that user was on in hopes some would click it

  • @Miles-co5xm
    @Miles-co5xm 2 ปีที่แล้ว +1

    Just wanted to check it someone can reverse my malware, thank you!

  • @nachosncheez2492
    @nachosncheez2492 2 ปีที่แล้ว +1

    reverse engineering series ? tips and tricks and longer beginner to advanced videos?

  • @minirop
    @minirop 2 ปีที่แล้ว +2

    I miss the time where the discord malwares where simply stealing your discord token to get access to your account by sending it to a webhook. I had fun times spamming the webhooks with disgusting imagery.

    • @balllord3546
      @balllord3546 2 ปีที่แล้ว

      these still exist

    • @minirop
      @minirop 2 ปีที่แล้ว

      @@balllord3546 sad then. I only got crypto miners in the past year or so.

  • @Purlime
    @Purlime 2 ปีที่แล้ว

    man really uses light mode and dark mode at the same time

  • @NOT_A_ROBOT
    @NOT_A_ROBOT 2 ปีที่แล้ว

    oh hey that's totally not my evil hacker clone in the thumbnail!

  • @theejoshhh
    @theejoshhh ปีที่แล้ว

    I fell for this one myself! Not sure why I ran the file, I was like 99% sure it was a hacker but they messaged me from a friend's account that I hadn't spoken to in a while. Not sure exactly what happened in the background but I'm relatively certain they stole my cookies. I found them logged into my discord and kicked them off almost immediately before wiping my whole system.

  • @pr0xythegodofhax
    @pr0xythegodofhax 2 ปีที่แล้ว +2

    thanks for making a video about this, you never fail to amaze me :)
    love reverse engineering

    • @LowLevelTV
      @LowLevelTV  2 ปีที่แล้ว +1

      Glad you liked it!

    • @pr0xythegodofhax
      @pr0xythegodofhax 2 ปีที่แล้ว

      @@LowLevelTV also what's the name of the online sandbox you used?

  • @mathildaleina4771
    @mathildaleina4771 2 ปีที่แล้ว

    Can someone make a game where the plot is making all your files encrypted like how ransomware works. Instead of paying to get access to your file, the victim must play a lot of puzzles, mystery or any games that filled with like lore.
    For example, the encrypted files will be called "princess" and the victim is the hero. The hero must finished all task like puzzles and secret messages to get access to another levels until they reach the final level where they save the princess "their encrypted files" and that virus is completely gone to the computer.
    i found it interesting but no one done it.

  • @beastly_neon
    @beastly_neon 2 ปีที่แล้ว

    There was a similar malware campaign from 6 months ago where they ask people to check their game and it check, saved passwords, discord auth token, cryptocurrency information, etc to a russian ip. My friend got hit by it and they stole discord token and ran it using a automated to script to further distribute the malware to all server and his friends

  • @CupidGaming522
    @CupidGaming522 5 หลายเดือนก่อน

    Yeah this is a pretty common discord scam, seen it too many times. Funny everytime, great breakdown.

  • @Мистер-ю6й
    @Мистер-ю6й ปีที่แล้ว

    the last thing you must do: DDOS THEM.

  • @fridosteffers891
    @fridosteffers891 2 ปีที่แล้ว +11

    Happy new year!
    Thanks for sharing this very nice piece of information! There’s a lot to learn I guess 😀
    Keep them coming, I’m hooked 😉

    • @LowLevelTV
      @LowLevelTV  2 ปีที่แล้ว +1

      Thank you! You too!

  • @Littlefighter1911
    @Littlefighter1911 2 ปีที่แล้ว +6

    I've received a very interesting malware once, that was a Java file, but all classes and functions were renamed to sound like they were part of a game.
    (Like "Map", "House", "Inventory", etc.)
    But if you looked into the classes you could see by the behavior that this wasn't a game at all.
    So be careful when trying to assume things from using string.
    Some madman might have been smart enough to just rename everything.

    • @ThatNiceDutchGuy
      @ThatNiceDutchGuy ปีที่แล้ว

      Yes or appended some sneaky code into legit classes.

  • @arodtube7668
    @arodtube7668 2 ปีที่แล้ว

    Lmao. “What the hell dude”
    Do you think they ACTUALLY stood a chance? 😂

  • @bouncyduckk
    @bouncyduckk 2 ปีที่แล้ว

    he knew it was malware before he even checked it💀
    as soon as he saw the file size he knew

  • @OliveGardenWorker
    @OliveGardenWorker 2 ปีที่แล้ว

    i could watch a 5 hour video of this dude just reverse engineering viruses

  • @jacobp.2024
    @jacobp.2024 2 ปีที่แล้ว

    All that work just to harmlessly mine Minero. I'm honestly impressed he didn't take it any farther.

  • @ThatNiceDutchGuy
    @ThatNiceDutchGuy ปีที่แล้ว

    I had this several times already. It installed Windows, it was full of monitoring user metrics.

  • @Defiler151
    @Defiler151 4 หลายเดือนก่อน

    Ngl this was sent to me by my friend (he was hacked) and I thought it was my friend who actually sent it, so I opened it and literally all my accounts were stolen. Luckily I managed to recover every single on of them. Be safe out there ladies and gents

  • @blankspace1959
    @blankspace1959 2 ปีที่แล้ว +2

    this was awesome, I would like to see this more in depth . keep up the wonderful work.

  • @annareichelt5997
    @annareichelt5997 2 ปีที่แล้ว +1

    I consider myself somewhat critical when it comes to downloading and executing software from unknown sources, but man, I would've definitly been the idiot who downloaded that "game" to be nice.
    Thanks for reminding me that 1. Malware could be anywhere and 2. I am an idiot

    • @dejangegic
      @dejangegic ปีที่แล้ว

      You're not an idiot, just a friendly and helpful person.

  • @TheMiningLeon
    @TheMiningLeon ปีที่แล้ว

    I reverse engineered an .exe compiled python cookie logger, got bros webhook and spammed it

  • @pixel690
    @pixel690 2 ปีที่แล้ว

    interesting, the "games" i receive off of random people on discord are usually a packed nodejs program that attaches some sort of discord logger onto your client that sends them any sensitive information you may input into discord such as passwords, credit card details, etc via a webhook

    • @phoenixplays2800
      @phoenixplays2800 2 ปีที่แล้ว

      that may be Doenerium off of github, hate to see it

  • @Voorhees-Jason
    @Voorhees-Jason 2 ปีที่แล้ว +1

    I gotten that type of DM's like 4 times from random people. I ignore them generally but, the very last guy that tried, I was curious of what the scam was since it was the same pattern as I know there is scams on discord. I asked him what kind of game it was blah blah blah. He did not give me much info so I confronted him about how is it that I get DM's from different people with the exact same story. He never replied lol.

  • @ashfaquekhan7282
    @ashfaquekhan7282 ปีที่แล้ว

    can you please make some tutorials, or a roadmap video on how to get started with low level programming and what should a normal beginner level coder do to learn the extreme basics stuff like reversing a software and how to read it , not only for knowledge purpose but as a career too

  • @giftfromyoutube
    @giftfromyoutube 2 ปีที่แล้ว +2

    Man I would sit and watch a 3hours full video on this issue without getting tired. I loved it. Some more pls

  • @DiabolicCrusher
    @DiabolicCrusher ปีที่แล้ว +1

    >the second payload site is in russian domain
    Why am i not even surprised? Every fucking time.

  • @itzadam_
    @itzadam_ 2 ปีที่แล้ว +1

    moral of the story: dont trust anyone with a clyde profile picture

  • @sgmvideos5175
    @sgmvideos5175 ปีที่แล้ว

    That's reason why so hard to actually make people test my games everyone thinks it's virus T_T

  • @paradoxclover8799
    @paradoxclover8799 2 ปีที่แล้ว

    Wow. I actually received a DM with a request like this a while ago, I told them I would soon and I promptly forgot about it a few minutes later. They asked if I had played it the next day or the day after and I told them I was busy (I wasn't busy I was just too lazy to play it). I forgot about that person and the game a few minutes later after replying. I didn't know that was a scam until now!

  • @HypeLevels
    @HypeLevels ปีที่แล้ว

    Actually got sad this was only 2 minutes :(

  • @lunareclipse363
    @lunareclipse363 2 ปีที่แล้ว +1

    I have seen malware that steals your discord token and uses your account to spam your friends with the same message that got you (probably not the only thing it does).

  • @badfitz66
    @badfitz66 2 ปีที่แล้ว +7

    I got a similar one once, but from a friend, who was actually in gamedev at the time, so I didn't question it. I downloaded and ran it and noticed that:
    1. it opened the nodejs terminal for a split second
    2. i was suddenly and suspiciously logged out of discord
    I suspect it was some sort of keylogger (most likely injected itself into discord hence the nodejs stuff, logged me out, and waited for me to put my login details again). I of course deleted the virus and nuked discord before reinstalling.

    • @nanahiiragi723
      @nanahiiragi723 2 ปีที่แล้ว +2

      If it closed discord that means your token was stolen. Discord (and other apps) have some protections in place for having the token stolen, so it only stores the token in a readable state when closed. But, logging out refreshes the token, so it also injects itself into discord to capture new tokens when you log in again.
      They also are usually stealers (or at least, include stealers, because why not), usually stealing saved passwords from browsers, crypto apps, tokens of other applications, saved credit card details, etc first.

    • @balllord3546
      @balllord3546 2 ปีที่แล้ว +1

      @@nanahiiragi723 this simply is not true (that discord has protections for having your token stolen

    • @slavic_commonwealth
      @slavic_commonwealth 2 ปีที่แล้ว

      @@balllord3546 nope. if you run virus, then your discord token can be easily stolen

    • @gtxg.
      @gtxg. 2 ปีที่แล้ว

      @@nanahiiragi723 tokens are stored in cookie, cookie is easily grabbed

    • @balllord3546
      @balllord3546 2 ปีที่แล้ว +1

      @@gtxg. no theyre stored in localStorage

  • @ValchyGaming
    @ValchyGaming 2 ปีที่แล้ว

    Great video man, super interesting

  • @starseer986
    @starseer986 2 ปีที่แล้ว +2

    would be nice if you explained some of the other stuff more, like why it took a desktop screenshot.

    • @bill8126
      @bill8126 9 หลายเดือนก่อน

      for example bank app shortcuts or something valueable

  • @MrSpace5260
    @MrSpace5260 2 ปีที่แล้ว

    it would be so good if you said "nice mining simulator" 😂

  • @ryanaxtell5069
    @ryanaxtell5069 2 ปีที่แล้ว

    How about this.
    Make the malware writers regret the day they touched your server. Make them shit their pants and scream that all their data and bitcoins are gone. When in reality, they're just crying wolf for no reason.

  • @texti-animates-sometimes
    @texti-animates-sometimes 2 ปีที่แล้ว

    bro made a whole crypto miner meanwhile me sitting here making a vbs script thats obviously a virus that opens a bunch of cmd prompts and notepads to annoy you💀

  • @Nethezbet
    @Nethezbet ปีที่แล้ว

    It is more sad that they know if they forward it to enough people, SOMEONE will run it.

  • @christianlbrannan1
    @christianlbrannan1 2 ปีที่แล้ว +2

    Hey I had this happen to me from someone I thought I could trust. I think they hacked my friends account and msg me through the account, thats why I thought It was trustworthy (I try to stay safe on the internet but things happen) Long story short Im still worried some of the malware could still be in my comnputer. Do you have any recommendations of how I can double check my system is clean @Low Level Learning

  • @farukdz2084
    @farukdz2084 ปีที่แล้ว

    it feels amazing to understand assembly language

  • @htbmixbox
    @htbmixbox 6 หลายเดือนก่อน

    funfact: now this link returns error but the entire site seems to be so scetchy that virustotal reports this site as malware even with 400

  • @sebgamingkid
    @sebgamingkid ปีที่แล้ว

    This is why i block connections for software that i don't 100% trust before i run it even if tested with an antivirus

  • @crimsonblitz2795
    @crimsonblitz2795 2 ปีที่แล้ว +1

    Happy new year my friend. 😊

  • @fedes1to
    @fedes1to ปีที่แล้ว

    they didnt even bother to obfuscate the strings

  • @TheMaryusz91
    @TheMaryusz91 2 ปีที่แล้ว +2

    Really nice and clear content, thank you to make people mora aware of how this kind of attacks work! 🙂

  • @aimeblack
    @aimeblack 2 ปีที่แล้ว

    man you have cool job, i wish i know how you do or where did you learn all of that. Its so cool.

  • @londiebrondie
    @londiebrondie 2 ปีที่แล้ว

    My friend actually fell for this exact virus ☠️

  • @evoredy
    @evoredy ปีที่แล้ว

    great workflow! love ida also!

  • @baali9097
    @baali9097 2 ปีที่แล้ว

    So would you say Ida got your back. Love the content

  • @PeacefulCountryLife
    @PeacefulCountryLife 5 หลายเดือนก่อน

    hacker gave him a hack and he hacked it.

  • @atalamcom
    @atalamcom ปีที่แล้ว

    Mom can we have Celeste 2?
    Mom: we have Celeste 2 in home
    Celeste 2 in home:

  • @jaroldsabillon7689
    @jaroldsabillon7689 2 ปีที่แล้ว +1

    I would love to learn how to do some of this stuff! Where can I get started? Additionally, would something like Virtual Box work to run the virus? If not what do you use?