This STEALER Infects Discord

  Рет қаралды 22,036

Eric Parker

Eric Parker

3 күн бұрын

I take a look at a technique known as "Discord Injection" where a stealer can be built into discord.
Official Discord Server - / discord
Follow me on X - / atericparker
Disclaimer: The content in this video is for education and entertainment purposes to showcase the dangers of malware & malicious software. I do not encourage any form of illegal hacking, nor do I encourage the usage of game cheats, cracks or hacks.
(C) Eric Parker 2024

Пікірлер: 171
@NickAc
@NickAc 2 күн бұрын
One funny thing you can do with discord webhooks if they're present, is to _just_ delete them lmao
@ENNEN420
@ENNEN420 2 күн бұрын
Another funny thing you can do with bots is you can kick them from your server! Silly, huh?
@NickAc
@NickAc 2 күн бұрын
@@ENNEN420 yeah that sure is fun and silly, but before you do that, make sure to use that same bot to infiltrate the server, and hopefully report the owner. although I wouldn't trust Discord's T&S team to actually do anything. It's also possible using the webhook URL to see the user who created it lmao
@electricz3045
@electricz3045 Күн бұрын
That won't Work If the attacker Setup a custom Domain with PHP Backend to do the requests behind the scencrs and Not forwarding it If It's a webhook delete request
@NickAc
@NickAc Күн бұрын
@@electricz3045 yep, that's true! but if we take a moment to think about the target "audience" for these kinds of things, I feel like you'll be coming across a lot of people who don't bother to even do that. for example, in the Hypixel (a Minecraft server with different games) skyblock (one of their games) community, there's a lot of scams involving utility mods that "supposedly" help the player. a while back I remember browsing across a dozen KZfaq videos about said mods (sorted by upload date), and after reversing the code, it was mostly the same 2 jars (so two different grabbers), just with different webhooks
@goingcrazy-mg9sf
@goingcrazy-mg9sf Күн бұрын
​@@electricz3045most cases skids dont modify code, incapable of it
@truckerbug
@truckerbug Күн бұрын
"Growtopia? I don't know what that is.. *sounds* like it's marijuana related..."
@feefre
@feefre 2 күн бұрын
It terminating itself when detecting tokenprotector is really weird, you would think it would just laugh at it but actually "helping" it to work by not activating doesnt make any sense
@Sypaka
@Sypaka Күн бұрын
if i did read the code correctly, its the other way around. this malware kills any blacklisted process, the tokenprotector too.
@tryrexman8627
@tryrexman8627 2 күн бұрын
open-source malware is kind of based
@root_binary
@root_binary 2 күн бұрын
true
@jimmlmao
@jimmlmao 2 күн бұрын
im still waiting for GNU stealer
@W0lfCL
@W0lfCL Күн бұрын
​@@jimmlmaogst/gstr?
@tryrexman8627
@tryrexman8627 Күн бұрын
@@jimmlmao BSD Borrower
@jimmlmao
@jimmlmao Күн бұрын
@@tryrexman8627 KRetrieve
@notBeWitchy
@notBeWitchy 2 күн бұрын
Growtopia is a prolific MMO known for hacking and real world trading. I was involved with the real world trading scene for a while until the ingame inflation made it unbearable. Surprised it tried to password grab it. Bit of a throwback because I haven't heard of it for years.
@lg-nathan84
@lg-nathan84 Күн бұрын
Also Gambling on the game ofcorse
@notBeWitchy
@notBeWitchy Күн бұрын
@@lg-nathan84 thats tied to the real world trading... basically irl gambling but accessible to the youth! lovely..
@Mario-sn5qr
@Mario-sn5qr Күн бұрын
Lmao yea I was surprised to see it mentioned here. I loved playing it when I was younger but ofc it got ruined
@cluelessnova
@cluelessnova Күн бұрын
My childhood game... 22yo now. Sad to see it dying
@notBeWitchy
@notBeWitchy Күн бұрын
@@cluelessnova Last time I touched it was in the summer of 2020. It was always not a great game, from mediocre content creation somehow garnering hundreds of thousands of subscribers because someone was rich ingame to culture (racism, sexism, homophobia, etc running rampant) to botting wise it was problematic. I am glad I distanced myself from it the moment there was extremely rapid inflation (going from 10% inflation in 3 months to 100% inflation in 2 months). In total I got like 4k profit with 20k turnover. Not a bad journey..
@epicMinemenner
@epicMinemenner 2 күн бұрын
"The most powerful stealer" *It can't even grab Discord tokens correctly.* (I know it from one person that I've targeted and took down their stealers)
@thatoneglitchpokemon
@thatoneglitchpokemon Күн бұрын
Mama Mia! My Italian countryball collection is at a-risk!
@truckerbug
@truckerbug Күн бұрын
at 8:04 at the top of cmd prompt you can see it says "isVM: no" xD
@MysLouis
@MysLouis 2 күн бұрын
stealers are getting more and more popular bc of ppl stupidity
@master-og5kg
@master-og5kg Күн бұрын
You got one info wrong. Blank grabber injects itself into Discord only for capturing discord related data like added payment data, changed password and Login token. It does not use discord injection to get presistence on the system and uses like most stealer the auto start folder to stay on the system. If you remove the stealer from the auto start folder, the stealer is also gone, and only the discord injection stays, which keeps montioring discord for passwords, payment info and new tokens.
@qoombert
@qoombert 2 күн бұрын
maybe it's called "Blank Grabber" because it puts the data in a folder with an invisible name.
@UCILaGtQaYAh3wnkvg4Rxzqg
@UCILaGtQaYAh3wnkvg4Rxzqg Күн бұрын
im pretty sure its supposed to be named after the username of the creator, blank-c
@qoombert
@qoombert Күн бұрын
@@UCILaGtQaYAh3wnkvg4Rxzqg Oh, that makes sense
@mori0
@mori0 Күн бұрын
as far as i know "John-PC" is some kind of Sandbox from i think it was Avast
@KoDi82
@KoDi82 2 күн бұрын
thanks for getting rid of the background music again
@yonice
@yonice 2 күн бұрын
man what are you talking about. The background music kinda perfects it. I'm sad he changed to this from his last couple uploads.
@atl6s
@atl6s Күн бұрын
@@yonice got his ass 🤣
@OliversTech
@OliversTech 2 күн бұрын
10:25 there's just a rarreg.key file right there lmao (winrar activator)
@Sypaka
@Sypaka Күн бұрын
They even give a free WinRAR key. how nice of them.
@jackprower2602
@jackprower2602 2 күн бұрын
was not expecting to see growtopia mentioned. it was a fairly popular indie mmo that got bought out by ubisoft and ran into the ground. even if this stealer is from a while back its odd t o see something spesifically check for a game so niche. great video
@notBeWitchy
@notBeWitchy 2 күн бұрын
definitely a throwback from when i played it back in like 2020
@mpkhd
@mpkhd 2 күн бұрын
Id love to see a video on setting up a new Windows PC and the best programs to keep it safe. Your expertise would be super helpful, especially for those just starting out with IT and PCs. There arent many legit videos on that topic, so yeah.
@rnts08
@rnts08 2 күн бұрын
If you're not on linux already, you've already lost. Windows only belongs in controlled environments such as VMs.
@thetrueshadow9227
@thetrueshadow9227 2 күн бұрын
There is a reason I am not on Linux at least for me there are some games that don't work on Linux and some software that does support Linux entirely for example here is a software that doesn't support Linux that I use wallpaper engine, and a game example is dark and darker these don't work and probably will never maybe dark and darker but I will have to see, and some games detect VM's and whatnot so its impossible to run a VM to play some games that only support windows plus EPIC Games not supported so... I can't make games nor is RPG maker another program I frequently use (sorry for the rant on this)
@mpkhd
@mpkhd 2 күн бұрын
@@thetrueshadow9227 Yeah, compatibility issues ARE a real hassle. Thanks for sharing your experience!
@skver
@skver 2 күн бұрын
"most powerful" :^)
@corewwwi
@corewwwi 2 күн бұрын
you mean Shouko :^)
@manan67891
@manan67891 2 күн бұрын
the John's are celebrating right now
@Lexencore
@Lexencore 2 күн бұрын
The stealer has a new github which is where it is continued btw
@ForLost929q
@ForLost929q Күн бұрын
Thank you so much for making the video❤
@dragon.7191
@dragon.7191 2 күн бұрын
stealer infects discord? yeah they tend to do that
@thetrueshadow9227
@thetrueshadow9227 2 күн бұрын
Could you make a video on how to protect browser cookies and or session tokens?
@slpyOb
@slpyOb 2 күн бұрын
the true best way to protect yourself is to not download sketchy files and listen to windows defender/smartwall when they warn you 😊
@fraze912
@fraze912 2 күн бұрын
@@slpyOb WD is the easiest AV to bypass even Malwarebytes is even more easier to bypass
@thetrueshadow9227
@thetrueshadow9227 2 күн бұрын
I use brave though so its chromium based and I like brave
@thetrueshadow9227
@thetrueshadow9227 2 күн бұрын
When I got hacked windows never told me anything, and how I got hacked was from remote desktop and UAC bypass by a GitHub (file from git pulling) now has been taken down and I've always scanned files but now since that happened I scan my computer at least 4 times a week even when download from official sites like Microsoft just in case 😁
@thequiet8572
@thequiet8572 2 күн бұрын
@@thetrueshadow9227brave sucks. Watch Someordinarygamers video on it.
@obviouslyaxo
@obviouslyaxo 2 күн бұрын
I like waking up 10 minutes earlier (so I can eat breakfast) the Eric posts. W MORNING
@STEALT_BLADE
@STEALT_BLADE 2 күн бұрын
Eric, on a old cd from a old czech click! Magazine i found a trojan, if i send it to ya will you review it?
@ENNEN420
@ENNEN420 2 күн бұрын
If he doesn't see this comment, I'd email them asking if they want it
@EricParker
@EricParker Күн бұрын
That could be interesting, you can send via email. Is possible that it's a false positive.
@STEALT_BLADE
@STEALT_BLADE Күн бұрын
@@EricParker eset flags it as a trojan, it even shows the trojans name but i dont remember it, btw the cd is from 2006
@yukicuh
@yukicuh 2 күн бұрын
A question, If you change your windows user to one of the blacklisted usernames, will that mean the stealer will not proceed? for example, my pc name is blahblah123 and one of the blacklisted ones is ralphs-pc theoretically, if i change my name to ralphs-pc does that mean the stealer no longer affect me?
@EricParker
@EricParker 2 күн бұрын
against this specific sample yes. The problem is those blacklists are not all that consistent. Same idea as cyberscarecrow. Anti analysis isn't all that consistent.
@TheGoldenGear
@TheGoldenGear 18 сағат бұрын
Hey Eric, I know this is not at all related to this video, But it would be cool if you could show off how to hide a virtual machine from programs that it is a virtual machine. I am using windows and am trying to run Fortnite on an emulator but EAC prevents the use of virtual machines.
@EZX280
@EZX280 18 сағат бұрын
He made a video a little while back on this. For your use case, give up. EAC is kernel level, and spoofing it would be hell (and would 100 % get your account banned)
@TheGoldenGear
@TheGoldenGear 15 сағат бұрын
@@EZX280 Not for my account
@CozyHQ
@CozyHQ Күн бұрын
Hey, thanks for making a video on this, I'm the server manager for a server with over 130k members on Discord, we experience the problem of members being sent viruses and the biggest amount of them are blank-grabber. We usually delete the webhook on it by simply getting the webhook from the code of the virus.
@yukicuh
@yukicuh Күн бұрын
what server?
@microcybs
@microcybs Күн бұрын
they really said "Most Powerful"
@swardmasteryu
@swardmasteryu 2 күн бұрын
oh yt notifications actually works
@obviouslyaxo
@obviouslyaxo 2 күн бұрын
FOR REAL
@Nubs2112Official
@Nubs2112Official Күн бұрын
not the browser history 😭we must leave
@Rekz_devexpoa
@Rekz_devexpoa Күн бұрын
Hi eric I haven’t been here for too long, but I can already say your channel is the best on KZfaq. I enjoy your content a lot and it’s great that you’re posting more frequently.
@Souverx_
@Souverx_ Күн бұрын
i wanna know what software you use to check the internet stuff that happens, if you even use one, of course
@ysfchn
@ysfchn 22 сағат бұрын
The software that is shown in the video is the web interface of "mitmproxy" software.
@plogiii
@plogiii 20 сағат бұрын
And wireshark
@Souverx_
@Souverx_ 17 сағат бұрын
oh, thanks
@cluelessnova
@cluelessnova Күн бұрын
It's sad seeing all the bots in Growtopia. Shame Hamumu hates the game so we wont see Seth and Hamumu working on it after they sold the game to Ubisoft Abu Dhabi..
@Limetable
@Limetable 2 күн бұрын
@NoTextToSpeech your time
@poomanhighlights
@poomanhighlights Күн бұрын
fr i didnt see ur comment, but i said he should try to do a collab lol
@aWeirdNickname
@aWeirdNickname 2 күн бұрын
Bro chill with the uploads
@hhhhhhhhhhhhhhhhhhhhhh
@hhhhhhhhhhhhhhhhhhhhhh Күн бұрын
The Discord uninstaller does rather messy uninstallations, so simply just uninstalling Discord might've worked for this stealer, but more nefarious stealers might persist in a file that doesn't get wiped by the uninstaller. Would definitely recommend deleting the discord folders in "%AppData%" *AND* "%LocalAppData%" (Discord stores stuff in both these locations).
@someguy9175
@someguy9175 Күн бұрын
Even then, it would need to hook itself back into discord so it could be executed again... Maybe the malware could make a task to reinstall itself once the uninstaller is executed and then delete said task once discord is back on the machine but it's definitely not that stealthy.
@hhhhhhhhhhhhhhhhhhhhhh
@hhhhhhhhhhhhhhhhhhhhhh Күн бұрын
@@someguy9175 As I said, Discord's uninstaller is messy and leaves lots of files behind that the malware can inject to and will allow it to persist past a regular uninstallation. The index.js file shown in the video isn't the only file that can be injected to.
@thatoneglitchpokemon
@thatoneglitchpokemon Күн бұрын
Genius! I'm going to get my cookies deleted and have to log in every time! Bravo, bravo.
@KZA1234
@KZA1234 2 күн бұрын
babe, wake up eric parker posted a video
@Sypaka
@Sypaka 2 күн бұрын
Jo, buddy. This discord stealer is using almost the same code to bypass UAC as the malware in the other video of yours called "Remote Control Any PC With Discord". but instead of an "If/else", it's using "case". And now I am trying to block any outside access to my "%localappdata%\discord" directory, brb. I wonder, if I can pull that off.
@prodfulcrum16
@prodfulcrum16 2 күн бұрын
I was just playing growtopia and the servers went down lol
@jeevacation
@jeevacation 2 күн бұрын
That game is still alive??
@taahaseois.8898
@taahaseois.8898 2 күн бұрын
@@jeevacation It indeed is, filled with bots from Indonesia on other third world countries.
@prodfulcrum16
@prodfulcrum16 2 күн бұрын
@@jeevacation The servers are constantly down and flooded with bots, the game's currency is fucked and inflation is pretty bad, over 80% of active players are bots or casino hosters and the devs don't give a fuck, since the game is owned by Ubisoft, since 2017.
@jeevacation
@jeevacation Күн бұрын
@prodfulcrum16 yeah it was good when S&H had it, ubisoft ruined it by milking it. I remember seeing new locks all the time lol I think I first played it in '15 or '16
@prodfulcrum16
@prodfulcrum16 Күн бұрын
@@jeevacation yeah, it brings me a tear imagining how the game was around 2013-2016, since I started playing in 2013 christmas being 7 years old :D
@DominykasPc
@DominykasPc 2 күн бұрын
haha blank grabber detected
@sendevia
@sendevia 2 күн бұрын
please use dark mode
@JessicaFEREM
@JessicaFEREM 2 күн бұрын
no it's less readable
@Shleepy27
@Shleepy27 2 күн бұрын
lol fr, my eyes are already itchy cuz im sick.
@sendevia
@sendevia 2 күн бұрын
@@JessicaFEREM the windows is zooming like 150% rn
@austist
@austist 2 күн бұрын
@@JessicaFEREM mfr got astigmatism and making it our problem.
@rnts08
@rnts08 2 күн бұрын
Got to get uses to those flashbangs somehow.
@Jackss0n
@Jackss0n 2 күн бұрын
What anti malware/virus program do you use or suggest?
@hahahahaha7237
@hahahahaha7237 2 күн бұрын
A user is the best anti virus.
@monkaSisLife
@monkaSisLife 2 күн бұрын
not downloading sketchy shit
@austist
@austist 2 күн бұрын
1.) dont be an idiot. 2.) windows defender 3.) seriously, just pay the fuck attention to what the fuck you're doing
@AOSP-is-still-Linux
@AOSP-is-still-Linux 2 күн бұрын
​@@hahahahaha7237 Single handedly the best response for this type of question.
@Jackss0n
@Jackss0n 2 күн бұрын
@@hahahahaha7237possibly the best answer I’ve ever seen to this question
@adam.maqavoy
@adam.maqavoy 21 сағат бұрын
*Discord* is a mine field of 'em. *Discords* not far from how *facebook* were in the early 2010 Nowadays.
@Saint.Scaramouche
@Saint.Scaramouche 2 күн бұрын
Hello! How does the NightfallGT/Lunar Grabber work? Nice vid btw
@_____666______
@_____666______ Күн бұрын
anyways to hide process hacker from another softwares ?
@Luna5829
@Luna5829 Күн бұрын
rename the process lol
@thatoneglitchpokemon
@thatoneglitchpokemon Күн бұрын
@@Luna5829 you got brains i could NEVER have guessed that
@mrx6555
@mrx6555 Күн бұрын
@@Luna5829 how you do that?
@kyo69420
@kyo69420 Күн бұрын
What the open source
@eHyp
@eHyp Күн бұрын
Thanks
@Playerk125
@Playerk125 2 күн бұрын
ntts mentionf letsy goo
@wlanverbot
@wlanverbot 2 күн бұрын
hey my hitmanpro scans when i boot up my pc tells me my userinit.exe file is suspicious and its 128kb large is that normal, if I scan it with something else it says its fine
@feefre
@feefre 2 күн бұрын
@@wlanverbot it should go away after a reboot, You can also check the details to see what is it being detected as and by what av motor if available
@eIixi
@eIixi 2 күн бұрын
you havent heard of growtopia??????
@electricz3045
@electricz3045 Күн бұрын
Not everybody in the Internet ist a 12 y old roblox kid. We have better things to do
@Floramene
@Floramene Күн бұрын
@@electricz3045 Growtopia was released in like 2012 though, lmao. And it was fairly popular up until around 2018-2020. The reason it was checking for passwords for that game was because the scene basically had a black market and irl trading scheme where accounts and stuff were being sold for real money. That's still going even today as far as I know.
@eIixi
@eIixi Күн бұрын
@@electricz3045 i'm not a 12 year old roblox kid and i've heard of it lol
@eIixi
@eIixi Күн бұрын
had you ever used android a few years back you'd have been recommended it
@freedustin
@freedustin Күн бұрын
This thumbnail AB testing is getting annoying. Saw this on my homepage earlier with a different more green thumbnail, but I didn't have much free time just setting up a playlist for the drive...now when I come back I have to scroll and scroll just to find out the green thumbnail I was looking for is gone and its white now. I didn't avoid clicking earlier because of the thumbnail, it was just a free time thing. But now YT takes this info as the new thumbnail got me to click.
@watercloud
@watercloud 21 сағат бұрын
Good vid
@Cybercerialdestroyer
@Cybercerialdestroyer Күн бұрын
Does this work on Linux?
@Floramene
@Floramene Күн бұрын
Stealers like this? Generally no, since they often rely on Windows specific DLLs via ctypes, or the win32 library for a lot of their functionality. But that doesnt mean Linux is safe from it. Someone absolutely could write a stealer that works in both places. It's just significantly less likely that you'd find one due to the nature of most Linux users literally never using random binaries lol In the eyes of most stealer devs, they find it easier to target more gullible and susceptible people (Windows Users) And not as worth it to target Linux which requires different methods for a lot of the same functionality, with diminishing returns.
@thatoneglitchpokemon
@thatoneglitchpokemon Күн бұрын
@@Floramene It's so dumb - right a stealer in Python, and they made it rely on ctypes. Whoever made this seriously denied the choice to make it crossplatform and still wrote it in Python lol
@poomanhighlights
@poomanhighlights Күн бұрын
You should try to collab with @NoTextToSpeech to explain this and how to detect it and how to avoid it, although he will probally make a video on his own as soon as he finds out about this stealer
@adamtso
@adamtso Күн бұрын
it's been out since 2021 lmao
@Visquint
@Visquint Күн бұрын
you avoid it by not downloading junk.
@SuqarSkllz
@SuqarSkllz 2 күн бұрын
yay
@domdomdomme1203
@domdomdomme1203 Күн бұрын
Very scary indeed. That’s why I always avoid logging into things I don’t really need on windows. Can’t steal login cookies or session tokens that don’t even exist 🤓
@Daniel99-j7l
@Daniel99-j7l 2 күн бұрын
15th
@budgetarms
@budgetarms Күн бұрын
1M subs soon
@Scy1hee
@Scy1hee 2 күн бұрын
w video
@_White_HvH_
@_White_HvH_ 2 күн бұрын
Why eric u looking forward to every thing im using :((
@white-ubermensch
@white-ubermensch 2 күн бұрын
you suck
@Mamikokh0
@Mamikokh0 2 күн бұрын
exposed
@Տupport
@Տupport Күн бұрын
Powerful, no kidding.
@gooniesfan7911
@gooniesfan7911 Күн бұрын
thanks andrew tate
@1haust
@1haust 2 күн бұрын
add some chill background music to these videos
@KoDi82
@KoDi82 2 күн бұрын
man what are you talking about. The background music kinda ruins it. I'm glad he changed back from his last couple uploads.
@SeamanLord
@SeamanLord 2 күн бұрын
It takes away from the minor mic cutouts that I live for
@Milk-rn5uq
@Milk-rn5uq 2 күн бұрын
zoomer
@1haust
@1haust 2 күн бұрын
@@KoDi82 it was just a suggestion as the context of these videos is interesting but the delivery can be rather boring, some sound other than plain talk definitely improves the atmosphere, though im not gonna argue with youtube comment warriors
@chairedge
@chairedge Күн бұрын
"Akeo Consulting" should be Rufus' signature. Growtopia is a pretty old mobile MMORPG acquired by Ubisoft who did not care enough to patch the issue that the "save.dat" (practically the login token) is saved in an unsecured state to the game directory. These accounts still sell for some money on the game's black market, so it makes some sense to have it check that way.
How much malware can you get from Fake Download Buttons in 2024?
18:35
What is the Smallest Possible .EXE?
17:57
Inkbox
Рет қаралды 159 М.
MEU IRMÃO FICOU FAMOSO
00:52
Matheus Kriwat
Рет қаралды 42 МЛН
МАМА И STANDOFF 2 😳 !FAKE GUN! #shorts
00:34
INNA SERG
Рет қаралды 4,3 МЛН
Haha😂 Power💪 #trending #funny #viral #shorts
00:18
Reaction Station TV
Рет қаралды 15 МЛН
I bought the World's RAREST Tech!
39:54
Mrwhosetheboss
Рет қаралды 1 МЛН
I Hacked Flappy Bird for Fun
7:16
Jack Harper
Рет қаралды 3,2 М.
Why Bridges Don't Sink
17:30
Practical Engineering
Рет қаралды 539 М.
I Hacked a Discord Bot, the Owner said this...
9:09
No Text To Speech
Рет қаралды 1 МЛН
Minecraft's Exploration Problem
29:49
JetStarfish
Рет қаралды 1,1 МЛН
Testing Laptops Properly is Really Hard
15:51
Linus Tech Tips
Рет қаралды 113 М.
This Discord Server Controls my PC (with Malware)!
8:07
No Text To Speech
Рет қаралды 1 МЛН
Making another pickproof lock (but better)
15:14
Works By Design
Рет қаралды 2,9 МЛН
The True History of Deep Dish Pizza
22:00
Tasting History with Max Miller
Рет қаралды 643 М.
Игровой Комп с Авито за 4500р
1:00
ЖЕЛЕЗНЫЙ КОРОЛЬ
Рет қаралды 1,8 МЛН
Hisense Official Flagship Store Hisense is the champion What is going on?
0:11
Special Effects Funny 44
Рет қаралды 2,5 МЛН
Как слушать музыку с помощью чека?
0:36
После ввода кода - протирайте панель
0:18
Up Your Brains
Рет қаралды 1 МЛН