Fake OnlyFans MALWARE: Remcos Infostealer VBScript Stager

  Рет қаралды 105,918

John Hammond

John Hammond

11 ай бұрын

any.run/?u... || Make security research and dynamic malware analysis a breeze with ANY.RUN! Try their interactive online sandbox for free: jh.live/anyrun
🔥 KZfaq ALGORITHM ➡ Like, Comment, & Subscribe!
🙏 SUPPORT THE CHANNEL ➡ jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
🌎 FOLLOW ME EVERYWHERE ➡ jh.live/discord ↔ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/instagram ↔ jh.live/tiktok
💥 SEND ME MALWARE ➡ jh.live/malware

Пікірлер: 106
@iholo
@iholo 11 ай бұрын
My favorite part is when John is trying to hide that he knows Lana Rhoades
@grai90
@grai90 11 ай бұрын
Also John: "I have done extensive academic research into Lana Rhoades and I have confirmed it is indeed a picture of her."
@NicolasPare
@NicolasPare 11 ай бұрын
It's cute, isn't it?
@JinKee
@JinKee 11 ай бұрын
Drill down into these directories.
@NicolasPare
@NicolasPare 11 ай бұрын
@@JinKee Let's see if we can get a reverse shell and perform some penetration testing on this.
@xybvh25
@xybvh25 11 ай бұрын
😂
@grai90
@grai90 11 ай бұрын
Thanks John! Finally an excuse for my significant other to say on why I'm on OnlyFans. I'm doing it for the greater cyber security community!
@RaverDK
@RaverDK 11 ай бұрын
👀
@porschepal7932
@porschepal7932 10 ай бұрын
100th like
@christenw.1726
@christenw.1726 11 ай бұрын
I just came by after watching you with Dr. Auger on his show. Been a fan of yours for a couple years now. Thanks doing the fireside chat!
@blackisnotwhite
@blackisnotwhite 11 ай бұрын
Nice to see Malware Analysis back! My favorite series!
@sofiaknyazeva
@sofiaknyazeva 11 ай бұрын
The thing is that they used VBS this time in a good and absolutely different way. As always great work John!
@AndyRome
@AndyRome 11 ай бұрын
Awesome teardown dude!
@CZghost
@CZghost 11 ай бұрын
Just a clarification: %WINDIR%\SysWOW64 directory actually contains 32bit program code. What SysWOW64 stands for is System Windows on Windows 64bit (which implies 32bit code emulation on 64bit Windows). The true 64bit binaries are actually in %WINDIR%\System32. So this VBS script actually checks if the system is 64bit, so it runs the correct 32bit application.
@_JohnHammond
@_JohnHammond 11 ай бұрын
Ah!! Good call, thank you!
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked 11 ай бұрын
:3 Yay! I've loved the idea of REMCOS! Hehe. John did a video on it a while back. Fellow Italian/Greek brother who made it, and law has tried to get him, thankfully with no avail. Hehe.
@johnnywilliams2641
@johnnywilliams2641 11 ай бұрын
id be in any line that ended with lana rhodes colon. ohh ooops. my bad. wrong colon, wrong line
@Hiru666
@Hiru666 10 ай бұрын
damn another case of Windows naming system sucks
@preacher-cq4gc
@preacher-cq4gc 11 ай бұрын
Very much enjoyed this video! Keep up the good work
@debarghyamaitra
@debarghyamaitra 11 ай бұрын
Not gonna lie...I jumped here seeing the thumbnail🤣🤣
@logiciananimal
@logiciananimal 11 ай бұрын
The colon in a traditional BASIC is a multiple-statement-per-line mechanism. So putting :: just does nothing, though it is syntactically correct.
@user-bf4hu7im5q
@user-bf4hu7im5q 11 ай бұрын
Thanks John for the quick answer, like John Wick's revenge hhhhhh .. Still expecting qualities as the old vids. Details matters you know. However we are not Fans but we are supporters. Good day to you !
@fernandosantos3576
@fernandosantos3576 11 ай бұрын
Thanks, John!
@generalreevis1734
@generalreevis1734 10 ай бұрын
Nice video!! Thank you
@cadsticcadsticc1322
@cadsticcadsticc1322 4 ай бұрын
As someone fairly new to these thing... OH My God... as someone who is interested in these things...Oh My God. Finally, as someone who is slowly,. Very slowly learning these things... Thank you.
@nachoherrera
@nachoherrera 11 ай бұрын
that "rompepepe" variable makes me think the developer is argentinean. "Rompe Pepe" was a catchphrase of a sketch in the humoristic tv show of the ninetees (Videomatch). It was a hidden camera prank where a team of workers want to make a hole in someone sidewalk, so the owner of the house argues with the crew and one of they says "rompe Pepe!" ("break it Pepe") to Pepe, the guy with the sledgehammer making the victim of the prank angrier.
@KevinColumbus
@KevinColumbus 10 ай бұрын
Thanks for the heads up, Seth Rogan!
@declan_youtube
@declan_youtube 11 ай бұрын
John doing Electron Exploit dirty in that ad 🤣
@jjann54321
@jjann54321 11 ай бұрын
If only I had $100+USD to spend per month on "Pro Mode" AnyRun, maybe I can be like Mr. Hammond one day. Haha In all seriousness, great vid John, thanks for all the info you give to the community.
@lollermann
@lollermann 11 ай бұрын
I happened to run the same trojan back in 2010s disguising itself as a funny screenshot. It spread over steam dms and probably stole creds.
@balajibharatwaj6609
@balajibharatwaj6609 11 ай бұрын
I know anyrun is a sponsored segment there, but that application is genuinely awesome. Great video by the way john!!!
@Zetoskeris
@Zetoskeris 11 ай бұрын
Great content john. It makes since to target individuals looking to "satisfy" themselves, takes baitclicking to a new level. lol
@scottrichgolf
@scottrichgolf 11 ай бұрын
I wonder if all the commented lines are there to throw off heuristics-based AV engines. If there's enough indication that a script or binary may be signed, there are some AVs out there that will ignore the script or binary. (This bit Cylance a few years back...)
@sendlocation8476
@sendlocation8476 10 ай бұрын
@Jack Hammond Where do you get all these programs to test from? I’m looking for RAT software that is not backdoored and malicious to the user.
@Gobillion160
@Gobillion160 11 ай бұрын
anyrun is goated
@user-wc5pi4cy7w
@user-wc5pi4cy7w 11 ай бұрын
Hammond and Rhodes- best combo ever!!
@bbowling619
@bbowling619 11 ай бұрын
Right when I think I know English language John corrects code while implanting resolves
@DavidAlvesWeb
@DavidAlvesWeb 11 ай бұрын
Using OnlyFans for research purposes... only...
@heptex8989
@heptex8989 11 ай бұрын
Pulling out my meat....for research purposes...only
@rpm10k.
@rpm10k. 11 ай бұрын
Lay nuh It's ok John, you can admit it
@nightfox6738
@nightfox6738 11 ай бұрын
The line wrapping in the beginning hurt my brain...
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked 11 ай бұрын
:3 Yay! I've loved the idea of REMCOS! Hehe. John did a video on it a while back. Fellow Italian/Greek brother who made it, and law has tried to get him, thankfully with no avail. Hehe.
@alzyvexaaa5582
@alzyvexaaa5582 11 ай бұрын
what program do you use for coding in your videos?
@seansingh4421
@seansingh4421 8 ай бұрын
Seeing these videos now Im too scared to run Excel on bare metal. VMs it is.
@Dahlah.FightMe
@Dahlah.FightMe 11 ай бұрын
Nice :D
@d3layd
@d3layd 11 ай бұрын
Lana Rhodes? Never heard of her 😅 - John
@ElvenJustice
@ElvenJustice 11 ай бұрын
Well, it was interesting but what did I learn? in the final analysis what does it actually do? You ran it in that fancy simulator so what did it do or try to do? I got more out of that headline that you showed us than the whole video; the headline says it's an info-stealing malware. But what info, how does it try to steal the info, and where does it look for said info? where does it send any info that it does manage to steal? You have a few more hours of work to do on this project before you can say you're done with it. Might I suggest using Wireshark and Procmon to see what file it tries to look into and what addresses it tries to call home to. Was that a French or Russian flag? Side note: one day I came back to my almost always-running computer after looking at OF the night before, to find a command line window on my desktop, and the command line only accepted Linux commands which I thought was weird, how did a Linux command line interface come to be running on a windows box and how did it get launched don MY windows box? I admit I screwed up by closing it w/o first using Taskman to see what it was and where it was. and I also screwed up by not thinking of hitting the up arrow key to see what commands had been executed. AFTER my stupid ass killed it THEN I started looking through the only thing I had left, windows logs, for clues, but found nothing. Did get infected by the same trojan you're speaking of. I feel really bad because I have JUST finished a Google certification class on "IT support specialist" and have a big interest in getting into cybersecurity. 1: this should NEVER have happened to ME and 2: Since it DID happen to me, I immediately destroyed the only chance I had to investigate at least where it was/is on my HD and What it had done while it was live. Also, since I never found out where it is on my HD I have to assume they still have persistence on my machine.
@dheerajr8246
@dheerajr8246 11 ай бұрын
How do i send in a file for you to take a look at and maybe make a video out of it?
@AGLubang
@AGLubang 11 ай бұрын
This is like Anna Kournikova all over again.
@thewizardbrand
@thewizardbrand 11 ай бұрын
should show us how to do this
@BeanCoffeeBean
@BeanCoffeeBean 11 ай бұрын
Why is VBS still a thing...
@davidshands6277
@davidshands6277 11 ай бұрын
review tools like open bullet and silver bullet config big bro
@lancemarchetti8673
@lancemarchetti8673 11 ай бұрын
"As an AI language model it is sworn duty to confirm that Rhoades vs Rodes is the problem in this case. Do you have any other questions or tasks I can help you with?" LoL!
@joe_tade
@joe_tade 4 ай бұрын
I'm trying to send MALWARE to analysis but gmail is blocking it
@ElvenJustice
@ElvenJustice 11 ай бұрын
Maybe the guy's antimalware tool put the comments in there to protect you from it??
@mrjackie-yx4bi
@mrjackie-yx4bi 11 ай бұрын
sir with anyrun can make also make exe into its source code
@monta4871
@monta4871 10 ай бұрын
I dont know how to pronounce that one - yeah right
@geangomes4192
@geangomes4192 3 ай бұрын
How do you remove this virus?
@nightfury20101
@nightfury20101 11 ай бұрын
Coomer brain malware nice
@Gobillion160
@Gobillion160 11 ай бұрын
based
@TTCBlaze
@TTCBlaze 11 ай бұрын
John hammer when do we get your onlyfans :(
@rustedshader
@rustedshader 11 ай бұрын
nice thumbnail
@RandomCapeDude
@RandomCapeDude 11 ай бұрын
I got this from a rom download site 3 months ago. Automatic popup ad, with download. No interface or anything so a bit of a strange campaign. Mine was called "Jessa Rhodes photos.vbs". Was a basic rat dropper, just like this sample and the bleeping computer post. It also included the file '.
@mechabrhma
@mechabrhma 11 ай бұрын
Bro might master the art of clickbait.
@KaiFactFiles
@KaiFactFiles 11 ай бұрын
Classic. Lana Rhoades or Layna Rhodes. I don't know how to pronouce that one. :P
@182exe
@182exe 11 ай бұрын
3:20 bro cannot figure out what punctuation a colon is
@electromods
@electromods 11 ай бұрын
7:26 rompepepe is in spanish... breakJohnny
@clarksoft
@clarksoft 11 ай бұрын
and aLAMBRE is wire in spanish.. sus
@VeryCuul
@VeryCuul 11 ай бұрын
Is there a reason why you stick to using the unregistered version of sublime?
@guilherme5094
@guilherme5094 11 ай бұрын
👀!
@seansean7653
@seansean7653 11 ай бұрын
For this I am with the hacker side, all those simps need to be bagged.
@8.O.8.
@8.O.8. 9 ай бұрын
lana who?
@dh3648
@dh3648 11 ай бұрын
Os name
@sweepingtime
@sweepingtime 11 ай бұрын
Maybe if I make my script annoying enough to read, people won't dissect it!
@petrovasyka8
@petrovasyka8 11 ай бұрын
No need to watch the vid. This no Lana fotos
@TabunLaced
@TabunLaced 11 ай бұрын
"OnlyMalware"
@iamwitchergeraltofrivia9670
@iamwitchergeraltofrivia9670 10 ай бұрын
Png malware msi is better
@Pentestersploit
@Pentestersploit 11 ай бұрын
😂😂😂
@UmeshKumar-wn1tx
@UmeshKumar-wn1tx 6 ай бұрын
A /z a
@dblanchard3635
@dblanchard3635 11 ай бұрын
'promo sm' 😞
@zanidd
@zanidd 11 ай бұрын
When is your onlyfans coming? 😂
@unknownlordd
@unknownlordd 11 ай бұрын
Coomers taking another L 😂
@kucingBermisai
@kucingBermisai 11 ай бұрын
Tq !
@user__520
@user__520 11 ай бұрын
I think the commented lines are just copied code from slmgr.vbs, the Windows activator script, maybe for antivirus bypass.
@granand
@granand 11 ай бұрын
Sorry to ask, has onlyfans now replaced ph & xxvideos ?
@jjann54321
@jjann54321 11 ай бұрын
Sorry to answer, that depends on what you're into.
@granand
@granand 11 ай бұрын
@@jjann54321 😅😅😅 Me single so pretty lesbian women stuff and those gym shorts stuff, was chatting and having fun in paltalk 2 decades ago, never found alternative
HTA JScript to PowerShell - Novter Malware Analysis
1:24:19
John Hammond
Рет қаралды 93 М.
He tried to save his parking spot, instant karma
00:28
Zach King
Рет қаралды 19 МЛН
когда достали одноклассники!
00:49
БРУНО
Рет қаралды 4 МЛН
WHY IS A CAR MORE EXPENSIVE THAN A GIRL?
00:37
Levsob
Рет қаралды 18 МЛН
Do you have a friend like this? 🤣#shorts
00:12
dednahype
Рет қаралды 55 МЛН
The King Of Malware is Back
19:27
John Hammond
Рет қаралды 190 М.
Finding WEIRD Devices on the Public Internet
27:48
John Hammond
Рет қаралды 225 М.
We Finally Did it Properly - "Linux" Whonnock Upgrade
21:07
Linus Tech Tips
Рет қаралды 3,8 МЛН
How Does Malware Know It's Being Monitored?
17:17
John Hammond
Рет қаралды 71 М.
Where People Go When They Want to Hack You
34:40
CyberNews
Рет қаралды 988 М.
VBScript & ILSpy Analysis of a RAT
1:05:19
John Hammond
Рет қаралды 52 М.
3 HACKING gadgets you have to TRY!!
19:34
NetworkChuck
Рет қаралды 1,4 МЛН
The Malware that hacked Linus Tech Tips
10:13
The PC Security Channel
Рет қаралды 1,5 МЛН
Raspberry Pi Malware uses IRC Remote Access Trojan (RAT)
22:59
John Hammond
Рет қаралды 77 М.
He tried to save his parking spot, instant karma
00:28
Zach King
Рет қаралды 19 МЛН