How to make your malware HARD to detect
17:21
Пікірлер
@kickeddroid
@kickeddroid Күн бұрын
100%
@novianindy887
@novianindy887 Күн бұрын
any specific course or tutorials on how the malware evade the EDR?
@mostafaabdallazidan6264
@mostafaabdallazidan6264 Күн бұрын
Great video as usual, looking forward to getting into the more advanced stuff.
@kvancaydn231
@kvancaydn231 2 күн бұрын
You are just looking from your angle. Your malware has to run completely once, but defender has to defend against you, but also for the phishing but also for the web attacks but also for the physical attacks, but also for the data exfil by a disgruntled employee. I am not underestimating difficulties of your tasks but the success of defenders is rely on mostly luck😅
@mostafaabdallazidan6264
@mostafaabdallazidan6264 2 күн бұрын
Excellent point
@thejonte
@thejonte 2 күн бұрын
Crypto miner malware use Monero because it's one of the cryptocurrencies that aren't way more efficient on GPUs. Therefore CPU monero mining is more profitable.
@brendanj2403
@brendanj2403 3 күн бұрын
I could build the most advanced shit in python. Compile time to an exe is 2 mins and on top of it, the file size is 30x, memory usage is higher and overall compute is slower. I won’t say what I’ve built but polling for requests is a bad implementation, just use sockets bro. Oh and screw python I should probably learn rust. Lol
@worldadmin9811
@worldadmin9811 3 күн бұрын
good on you. itd be reckless to do so
@DietChugg
@DietChugg 3 күн бұрын
I think that is very wise. Thank you for not doing something just because people ask you to do it.
@mycelia_ow
@mycelia_ow 3 күн бұрын
Especially true considering how AI large language models are being used to lower the barrier of entry for black hat activities even further. Having good source code would make it far too easy.
@KillianTwew
@KillianTwew 3 күн бұрын
I could be wrong, but I think posting the source would legally be distribution and I'm sure they could find a judge somewhere to hold the distributor accountable for the crimes committed.
@valhalla_dev
@valhalla_dev 3 күн бұрын
I doubt it would stick unless they managed to show intent, but I am both not a lawyer and not willing to risk it for internet points
@benjamindominguez2638
@benjamindominguez2638 3 күн бұрын
Sleeper build fs
@user-iz1nx2qd6r
@user-iz1nx2qd6r 3 күн бұрын
your channel is very comfy. thanks
@user-iz1nx2qd6r
@user-iz1nx2qd6r 3 күн бұрын
nice videos bro. thanks.
@Red4mber
@Red4mber 4 күн бұрын
A wise choice :D That's precisely the reasons why when I wanted to learn some specific techniques I made a maldev library and not just straight up click and run malware, because I need something public to look for a job ^^ and also I guess I could reuse it later but that was secondary
@itzhexen0
@itzhexen0 4 күн бұрын
I have liked your video.
@kickeddroid
@kickeddroid 4 күн бұрын
I have liked your comment!!!!!
@meanjellybean8963
@meanjellybean8963 4 күн бұрын
Just started watching my dude. Nice. Like your logic. People underestimate learned experience.. when redoing a project after a year of working through and making all those micro corrections, will help set you into the next level of programming. Also Rust is life!
@catlover.triangleheadprod4887
@catlover.triangleheadprod4887 4 күн бұрын
Its like asking someone why they dont hand out nukes instead of telling people about how they work and how to protect against them. Because its a bad idea.
@YellowSnow575
@YellowSnow575 5 күн бұрын
1st
@JasonKaler
@JasonKaler 3 күн бұрын
4st
@thesupernoob8340
@thesupernoob8340 3 күн бұрын
8rd
@lollol-js8bj
@lollol-js8bj 5 күн бұрын
Cool POC. Nice video 👍
@grsnvin4773
@grsnvin4773 6 күн бұрын
This is so cool you should consider making a series coding a rat from scratch
@deathgod4nubis
@deathgod4nubis 7 күн бұрын
bro doesn't only build malware, he also builds muscles.
@valhalla_dev
@valhalla_dev 6 күн бұрын
Gotta live long and prosper so I can write garbage code long into my 90’s
@deathgod4nubis
@deathgod4nubis 5 күн бұрын
@@valhalla_dev Hell yeah brother
@Dom-zy1qy
@Dom-zy1qy 7 күн бұрын
If you identify with being a "developer," then shipfast or other starter kits probably wouldn't be ideal for you in the long term. You could create your own starter kit, internal tools/scripts. Not only will you actually learn a lot more, but you'll be more proficient at using it. The way I see it; the stuff people typically build with starter kits (api wrappers) aren't going to really help anyone in any meaningful capacity. They just tax customers a considerable amount to display a UI. Because of this, the longevity of your product and likeliness to succeed and make a considerable amount of money is very slim. This is why the owner of Shipfast generates ~%90 of his income from selling his starter kit. Despite being a great marketer, very few people actually use his software. So may as well learn how to be "real" (not to gatekeep) developers and strive to make something meaningful and novel. Or, iterate and improve meaningful software, which is difficult. But when you repeatedly try to do something difficult, your capacity for learning in general will increase. Which is a pretty OP skill. Not to say you can't build a serious startup from a starter kit. Doing that just sounds like a Ship of Theseus situation though.
@valhalla_dev
@valhalla_dev 6 күн бұрын
This was a very good and well written comment. And FWIW I changed my tune on shipfast and might make another video on it
@user-nz9ip7tj4e
@user-nz9ip7tj4e 7 күн бұрын
what's the drawing program that you're using? cool video btw
@Antagon666
@Antagon666 7 күн бұрын
Yeah right. Cryptomining just "little" spins up the GPU and CPU. Also the best kind is the one which hides when you open task manager.
@SPYBORG_LIVE
@SPYBORG_LIVE 8 күн бұрын
Sir please make video about spyware which can run in android 12
@valhalla_dev
@valhalla_dev 7 күн бұрын
No
@SPYBORG_LIVE
@SPYBORG_LIVE 2 күн бұрын
@@valhalla_dev why
@laden6675
@laden6675 8 күн бұрын
Yikes, hope you're proud of yourself
@valhalla_dev
@valhalla_dev 8 күн бұрын
lol what
@NonsensGaming
@NonsensGaming 8 күн бұрын
you don't seem to know what the PE format or ELF format looks like if you can't even infer what include_bytes does if your first assumption is "end of the binary" ? did you ever open a executable in a static analysis software ?
@valhalla_dev
@valhalla_dev 8 күн бұрын
Hey there guy. I’m assuming you haven’t been around this channel much considering how rudely you started the convo. This is a channel where I learn alongside folks as I cover stuff. I don’t know everything and I don’t pretend to. If you would like expertise, I have a list of channels to share with you, because I’d rather you go and watch them than come into my comment section like this. Have a good one!
@meanjellybean8963
@meanjellybean8963 9 күн бұрын
Nice, good intro way to learn crypting.. i like the rust take in it...
@WANGLY
@WANGLY 9 күн бұрын
why did you choose to have the victim constantly reach out instead of have it listen for commands?
@betafruit
@betafruit 4 күн бұрын
Did you watch the video? He explains it at 1:54
@comosaycomosah
@comosaycomosah 9 күн бұрын
really been digging your videos lately
@Sidrobot
@Sidrobot 9 күн бұрын
Great video
@comosaycomosah
@comosaycomosah 9 күн бұрын
dope! speaking of dope that picture on your wall is really cool
@valhalla_dev
@valhalla_dev 9 күн бұрын
One of my favorite silent auction wins 😂
@AbelFikadu-lt1ei
@AbelFikadu-lt1ei 9 күн бұрын
Keep going, do not give up!!!
@blackhat6345
@blackhat6345 9 күн бұрын
are rats/trojans usually detected heuristically by anti virus programs nowadays?
@MyVlogTubes
@MyVlogTubes 9 күн бұрын
If they are released to the public then YES, the companies will take a sample and study and mark a signature to it and then sends a update to its Software and that way it will be detected. Private RAT/Trojans are not detected. the most hard one that are not detected are the one who are operating on root level!!!
@facts4647
@facts4647 8 күн бұрын
There are softwares like crypters which encrypt your RAT making your stub undetectable.
@blackhat6345
@blackhat6345 8 күн бұрын
@@facts4647 yeah im aware of that. i meant "private" rats such as this one.. don't they get detected based on their behavior by anti virus progs?
@facts4647
@facts4647 8 күн бұрын
@@blackhat6345 In this era of AI, I don't think it would be hard for an AV to detect if a code's gonna be malicious or not.
@SArthur221
@SArthur221 3 күн бұрын
@@facts4647 but it's compiled
@kartik1409
@kartik1409 10 күн бұрын
Please make some tutorial for this
@reijin999
@reijin999 5 күн бұрын
it's just system programming bro
@kickeddroid
@kickeddroid 10 күн бұрын
Another fire video!
@melancholydeath
@melancholydeath 11 күн бұрын
NjRAT >>>
@Felps1-q8e
@Felps1-q8e 11 күн бұрын
what software did you use to record this? i really liked it
@valhalla_dev
@valhalla_dev 11 күн бұрын
Join the malware research Discord: discord.gg/fngHNW9Bnd
@jaddion
@jaddion 11 күн бұрын
How would you go on integrating LLM use regarding coding? Like, prompting the AI to deliver the code you need... From my experience, I've been coding with LLMs and prompting it to generate what I want and although I learned a bit, I still haven't memorised programming language structures or be able to come up with a full fledged program from scratch...
@Red4mber
@Red4mber 12 күн бұрын
Good vid as always o/ If I may add, as i see it, a good way to balance difficulty to help you pick a project is to balance comfort and satisfaction. Learning new concepts is really gratifying but you still need enough comfort to avoid making the learning experience too painful. The harder the problem, the less comfy and the more satisfying it is, and vice versa. Some people can handle hitting their head on a brick wall until they finally get over it, it must be extremely satisfying but I for sure cannot do such a thing. On the flipside, you may be tempted to pick an easier, "comfier", project but it's not gonna really challenge you, so are you really gonna be satisfied of what you built ? This also takes into account that working on a subject you like will make it more comfortable, letting you tackle harder problems, and the opposite is true for subjects you don't really care about.
@valhalla_dev
@valhalla_dev 12 күн бұрын
Check out CodeCrafters: app.codecrafters.io/join?via=vikingSec
@Mrgodss43
@Mrgodss43 12 күн бұрын
What about Passive learning?
@damnsonwheredyoufindthis1878
@damnsonwheredyoufindthis1878 12 күн бұрын
What is that even mean 💀💀💀
@Ciborg085
@Ciborg085 11 күн бұрын
@@damnsonwheredyoufindthis1878 it's when you are a sleep with headphones while listening to a podcast about cybersecurity and the next day you are able to make zero day exploit
@georgeclooney6208
@georgeclooney6208 11 күн бұрын
You gotta be locked in to code bro, why skim through it?
@jaddion
@jaddion 11 күн бұрын
If by passive learning you mean reading books on coding and watching tutorials on coding but never actually spending time trying to code, its very inefficient imo. The more uncomfortable it is, the greater the reward, but the harder it will be. From my experience, passive learning was always very easy but not very rewarding, I found myself having to review back the knowledge multiple times.
@ghdshds1899
@ghdshds1899 12 күн бұрын
looks interesting, curious to see how this goes for you. i presume your main audience for revenue purposes is businesses but the name and marketing seems very oriented towards individual non-professionals, rebrand might be in order! as for the rewrite and stuff, i think your efforts are best placed putting together a really simple, functional and viable system, and focusing entirely on product and features. Hope the rewrite goes well, but don't sink too much time into deeper architectural problems. If you can slap this together as a basic python flask app, you should probably do that, focus on market fit and exposure, then worry about scale of any kind good luck!
@cristian505fr
@cristian505fr 13 күн бұрын
dear FBI this is just for educational purposes, i will never use this respectable man's video for bad purposes
@wtfdoiputhere
@wtfdoiputhere 14 күн бұрын
if this guy told you he needs to use your phone, DO NOT LET HIM interesting video btw i hope to see more from you man
@dllsmartphone3214
@dllsmartphone3214 14 күн бұрын
marketing is the most important, more then the product quality. your website is your weakest spot atm. and stay away from this AWS "thing"... 😂 good luck with your product bro. ❤
@clementamar3699
@clementamar3699 14 күн бұрын
Totaly agree all my family is in tech, and marketing is everything !
@kickeddroid
@kickeddroid 15 күн бұрын
Another banger
@0xMatticus
@0xMatticus 15 күн бұрын
Random question, do you stand on any sort of anti fatigue mat lol?
@valhalla_dev
@valhalla_dev 15 күн бұрын
No fatigue mat, but I do have a treadmill that goes under my desk to walk on!