MALWARE ANALYSIS - VBScript Decoding & Deobfuscating

MALWARE ANALYSIS - VBScript Decoding & Deobfuscating

John Hammond

3 года назад

1,033,379 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

John Hammond
John Hammond - 18.06.2021 18:18

To quiet a few annoying trolls, in this video I mistakenly said "I can't run a VBScript file because I'm running Windows right now". If I were on Windows, I could certainly execute the VBScript. I should have said "I'm running Linux" because I am clearly using Linux for this showcase. (You can still partially run VBScript code with Wine on Linux, but your mileage may vary)

Ответить
Alan
Alan - 05.09.2023 04:42

thank you for struggling with regular expressions. I always feel like an idiot when I can't get them to do what I want the first time.

Ответить
Aq_921
Aq_921 - 21.08.2023 12:58

Can you dissect some malware that I may have accidentally ran on my computer and I don’t know what has happened it’s the GitHub repo for Luna grabbed by smug246 I want to know what it might have done I have changed all my passwords and invalidated all my cookies but would like to know who is responsible thanks

Ответить
Anwesh Mahapatra
Anwesh Mahapatra - 22.07.2023 22:47

Where can I get the sample????

Ответить
Fernando Castellanos
Fernando Castellanos - 11.07.2023 07:18

I almost slept while cleaning tangent variables, but I swear this video is amazing, do people get paid for doing this?

Ответить
Sienna Walker
Sienna Walker - 24.05.2023 18:00

As me being a malware analyst, it’s definitely hard if you don’t know how to hack into the malicious content and try and hack the hacker from actually hacking other peoples malware softwares, emails, data, even ip address. I recommend being careful if your not a malware analyst or don’t know anything about malware analysis

Ответить
Kam Larz
Kam Larz - 21.05.2023 08:26

i spent years making a rat and it got so advanced at the end i had nothing to do with it. idk how useful they are today since antiviruses are strong now i think

Ответить
Night Chicken
Night Chicken - 17.05.2023 13:26

Straight up hero. Finds a random script then cleans it up and updates to publish

Ответить
为民程
为民程 - 17.05.2023 04:10

COOL!!!! More malware analyse plz!!!!!!!

Ответить
Bhagya Lakshmi
Bhagya Lakshmi - 16.05.2023 09:38

All to nonsense typ...

Ответить
AIKISBEST
AIKISBEST - 27.03.2023 12:09

Good thing you are not swedish because computer keys are called "tangent(s)" in Swedish and coding would involve a heck of a lot of tangents then XD

Ответить
AIKISBEST
AIKISBEST - 27.03.2023 12:04

Omfg this is like the gamer and/or techie version of solving sudoku puzzles and I love it!

Ответить
Gallo
Gallo - 15.03.2023 05:33

function + tit

Ответить
Jes Filio
Jes Filio - 14.03.2023 20:57

What's your top or mostly used tools for ransomware analysis?

Ответить
Zhabiboss
Zhabiboss - 12.03.2023 13:23

So that’s why we need tangent 🧐

Ответить
Ju Manj
Ju Manj - 04.02.2023 20:17

Ya know John , I am definitely Entertained, & Great Imagination/0

Ответить
melvin jacob
melvin jacob - 02.02.2023 08:54

Was going to use this to fall asleep but ended up watching the whole thing

Ответить
Justin Hunt
Justin Hunt - 25.01.2023 08:08

Nicely done 👍🏽

Ответить
MezMediciMedia
MezMediciMedia - 20.01.2023 21:46

Thanks can we do more of these like other people said you are good to watch and learn from as your train of thought is excellent and educational.

Ответить
Doctor MGL
Doctor MGL - 06.01.2023 07:10

maybe we need an episode on how to prevent VBS scripts from Silent Running in the background without permission to prevent this kind of Rats

Ответить
Talha Tariq
Talha Tariq - 12.12.2022 21:35

Really cool video.

Ответить
Scooter Girl
Scooter Girl - 27.11.2022 21:24

This malware is the definition of "baffle them with bullshit"

Ответить
Durkas T BBB Malaysia.
Durkas T BBB Malaysia. - 19.11.2022 03:44

John you idiot that is musical effects

Ответить
Davis T.
Davis T. - 13.11.2022 15:13

I liked the way the author changed the source code text to ASCII numbers. Nice puzzle.

Ответить
AdVapidKudos
AdVapidKudos - 12.11.2022 09:25

The lines dealing with the tangent function call is a literal tangent it put you on.

Ответить
Nick Adams
Nick Adams - 11.11.2022 18:36

Damn this content of you looking at malware is f’ing classic

Ответить
pandeomonia
pandeomonia - 17.10.2022 12:21

I have no earthly idea why you don't use VSCode instead of googling broken online beautifiers and whatever the hell else.

Ответить
DontLetFreedomDie
DontLetFreedomDie - 08.10.2022 15:44

this man deserves 10M subs.

Ответить
Miguel Angel Miñambres Prieto
Miguel Angel Miñambres Prieto - 04.10.2022 10:15

Great tutorial and thanks for providing this amazing crack)))

Ответить
C.Y.R-Cypher mc
C.Y.R-Cypher mc - 27.09.2022 19:15

This tutorial is amazing and you are really good at teaching !! great job sir !

Ответить
Eduard Privat
Eduard Privat - 26.09.2022 23:57

amazing. thx a lot. never saw that kind of analysis. would be cool if you could make an own section for different executeable stuff

Ответить
Neftalí Navarro
Neftalí Navarro - 22.09.2022 09:12

TNice tutorials was great! the way you explain tNice tutorialngs and repeating it really helps. thanks for the tutorial!

Ответить
Damaris Solange Ruiz Blas
Damaris Solange Ruiz Blas - 18.09.2022 20:39

It worked. I'm not a bot and this is my second time downloading it to a separate PC. Also his other video for AI works too

Ответить
乐快
乐快 - 18.09.2022 20:35

Loooooool its working xd

Ответить
AngelGamez 'n' drawz
AngelGamez 'n' drawz - 18.09.2022 20:25

"HAaaAA" - John Hammond, 2021

Ответить
Monik Silva
Monik Silva - 16.09.2022 17:31

thanks, downloaded, all works!

Ответить
Vambozz Official
Vambozz Official - 13.09.2022 22:19

thanks, downloaded, all works!

Ответить
calabazin
calabazin - 13.09.2022 16:28

no age restriction to make art!

Ответить
Josiscas
Josiscas - 13.09.2022 16:26

Türkce dil icin egi gecenlere tesekürler.

Ответить
FoxR ules
FoxR ules - 13.09.2022 16:19

How DO YOU OPEN A setup ALL OF THE TUTORIALS START WITH A setup

Ответить
無限未來
無限未來 - 13.09.2022 06:25

🐲4⃣️

Ответить
Linux Jedi aka Big Evil
Linux Jedi aka Big Evil - 10.09.2022 03:49

the hell how did you get malware from the vbe decoder script i thought you were just examining the process of the decoder ??

Ответить
Brandon Henderson
Brandon Henderson - 07.09.2022 03:57

Watching this video brought me back to my days of studying for the OSCP. I enjoyed this a lot more than I thought I would.

Ответить
Steven Whiting
Steven Whiting - 06.09.2022 17:27

Can you stick the code in Cyber Chef to deobfuscate it?

Ответить
zack spofford
zack spofford - 05.09.2022 04:21

Bro this is the exact same fucking thing I've been dealing with it comes up as a windows fucking update and it fucking tells me I need it .Look into windows 11 and how it pops up under actual windows updates it makes your start file go away for windows The only way you can fix these stupid fucking things is reinstalling fucking windows or having image backup backup or just resetting to a prior date hopefully it's not the date that it got put on it's honesty hell I'm sick of losing my data

Ответить
zack spofford
zack spofford - 05.09.2022 04:19

got any pointers for building Linux machine? i see ya using that ...my pc i got now is currently bitlocked to windows 11...so was gonna build new one for just only Linux....i can record this if needed for example....happens tome to time....why i never fuckin update shit for windows

Ответить
BigGuy
BigGuy - 01.09.2022 09:29

UBound gets the index of the upper portion of an array in the given dimension, where lbound gets the lower portion of an array in the given dimension.

Excecute order 66 on that malware lol

Ответить