Malware Analysis & Threat Intel: UAC Bypasses

jh.live/anyrun-ti || ANYRUN has just released their latest Threat Intelligence feature set, and it is super cool to track and hunt for malware families or observed tradecraft -- try it out! jh.live/anyrun-ti
Learn Cybersecurity - Name Your Price Training with John Hammond: nameyourpricetraining.com
📧JOIN MY NEWSLETTER ➡ jh.live/email
🙏SUPPORT THE CHANNEL ➡ jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
🌎FOLLOW ME EVERYWHERE ➡ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/discord ↔ jh.live/instagram ↔ jh.live/tiktok
💥 SEND ME MALWARE ➡ jh.live/malware
🔥KZread ALGORITHM ➡ Like, Comment, & Subscribe!

Пікірлер: 67

  • @IAmmlskOG
    @IAmmlskOG2 ай бұрын

    dude you move through this file like butter

  • @nickadams2361

    @nickadams2361

    2 ай бұрын

    he did it before, this is a planned demo. Normal stuff you should be able to do at work

  • @user-sx4zy5hn2f

    @user-sx4zy5hn2f

    2 ай бұрын

    ​@@nickadams2361😊😊😊😊😊😊😊😊😊

  • @IOwnThisHandle

    @IOwnThisHandle

    20 күн бұрын

    It is rehearsed

  • @hedgehogform
    @hedgehogform2 ай бұрын

    VSCode has a powershell formatter

  • @HachikoTanuki

    @HachikoTanuki

    2 ай бұрын

    I feel like such a casual that I know none of the tools John is using, while VSCode is too casual for John to know it has a Powershell formatter 😭

  • @markcentral
    @markcentral2 ай бұрын

    Thanks for the video. Is the anyrun segment part of a sponsored deal? If not, I would have preferred you continued to demonstrate how to deconstruct the malware locally. There's a lot of educational value and wisdom potential being lost by moving things to an online platform that requires a subscription vs local

  • @gabriell4815162342
    @gabriell48151623422 ай бұрын

    I love your videos, as a foreigner and because I don't speak native English, I feel very comfortable and can understand everything because of the calm and concise way you speak. In addition to practicing my English, I learn a lot about cyber security

  • @Alfred-Neuman

    @Alfred-Neuman

    2 ай бұрын

    I learned English by watching lot of KZread videos like this. If you are curious enough and/or determined, you'll be able to write some English poetry pretty soon. ;D

  • @severinghams

    @severinghams

    Ай бұрын

    @@Alfred-Neuman I don't understand foreigners' fascination with English poetry. Why is poetry something that so many non-English speakers flock to when they learn English? Why not debate, or music, or popular speeches, or literature- why _specifically_ poetry? What is so special about poetry?

  • @Alfred-Neuman

    @Alfred-Neuman

    Ай бұрын

    @@severinghams How many languages do you speak outside of English?

  • @Supstone8519
    @Supstone85192 ай бұрын

    Very insightful. Thank you for doing this video.

  • @Adkali
    @Adkali2 ай бұрын

    Love the threat analysis using the dynamic analysis. Again, thanks john for another fun schooling video

  • @PMM619
    @PMM6192 ай бұрын

    hey fan from Morocco, all the love !!

  • @valk9789
    @valk97892 ай бұрын

    Treat at the end~ love John's laugh😅❤

  • @cypher2226
    @cypher22262 ай бұрын

    I didn't know about that UAC bypass

  • @antifreeze44
    @antifreeze442 ай бұрын

    You're take on the Apex stuff was AWESOME, thanks John!

  • @Streetrack
    @Streetrack2 ай бұрын

    I really like this one!!

  • @k.g.c.karunathilaka9781
    @k.g.c.karunathilaka97812 ай бұрын

    Thanks

  • @Duy1P3
    @Duy1P32 ай бұрын

    I'd really like to see your homelab setup and see how you run things and do your investigations and with what tools and stuff.

  • @YuKonSama
    @YuKonSama2 ай бұрын

    I kind of like the sublime approach to clean the sample up but I also would be interested into automating stuff like this (guess R.E.M has tools for this). For example, deleting variables that are assigned but never used should be a pretty easy task.

  • @memeconnect4489
    @memeconnect44892 ай бұрын

    a lot of danish words in that code

  • @7YBzzz4nbyte

    @7YBzzz4nbyte

    2 ай бұрын

    Seems to be fluff to obfuscate the code itself. Seems like Danish-inspired gobbledegook, words stacked without meaning, though a scanner would not know (at least not before AI). 😮

  • @ShayBlez
    @ShayBlez2 ай бұрын

    Never thought Id see Bonzi Buddy again.. XD

  • @capability-snob
    @capability-snob2 ай бұрын

    What was the intended use of this .ini file and the class named by the guid?

  • @carsonjamesiv2512
    @carsonjamesiv25122 ай бұрын

    NICE!😃

  • @Carambolero
    @Carambolero2 ай бұрын

    Nice start, but next time if you want to promote a tool, just go to the point and state it in the Title. Tx.

  • @allofabout7064
    @allofabout70642 ай бұрын

    I hope you discuss Qlin Ransomware, and how to overcome it (recovery)

  • @dipongkorroy6424
    @dipongkorroy64242 ай бұрын

    Love from Bangladesh ❤

  • @user-lq3tv4nd8w

    @user-lq3tv4nd8w

    2 ай бұрын

    Why did you bang ladesh tho, poor fella

  • @eikichi9050
    @eikichi90502 ай бұрын

    Hello Mr Hammond it is possible to defend against these type of attacks? Sorry for my english

  • @UnfiItered

    @UnfiItered

    2 ай бұрын

    If your end users don't use/run vbs/batch/PS1 scripts. You can make a group policy to require UAC to run them or disable them completely.

  • @user-yi4ef2gk1o
    @user-yi4ef2gk1o2 ай бұрын

    NICE this is really menace :)

  • @learnsomething564
    @learnsomething5642 ай бұрын

    First one ooooo now i have millions in my account

  • @johnvardy9559
    @johnvardy95592 ай бұрын

    I love y john

  • @JohnSmith-jc7dk
    @JohnSmith-jc7dk2 ай бұрын

    why vbs is required to deploy remcos and not deploying remcos directly?

  • @UnfiItered

    @UnfiItered

    2 ай бұрын

    Vbs was just a stager to build the powershell to run. Basically the hacker was trying to hide what they were doing behind a bunch of dead end code.

  • @U20E0

    @U20E0

    2 ай бұрын

    The point is that anyone who finds the malware but doesn't know how to handle this (including antiviruses) will likely not try to, which hopefully buys some more time before it gets logged into a malware registry. Inflated file sizes also stop VirusTotal and some antiviruses from analysing the file

  • @codytrout3257
    @codytrout32572 ай бұрын

    Pro tip- change the speed to slower if you cant keep up with the commands fully, yet, like me.

  • @mdfourhadkhan1842
    @mdfourhadkhan18422 ай бұрын

    ❤❤❤❤❤❤

  • @carteldebellamy677
    @carteldebellamy6772 ай бұрын

    Awesome video

  • @Hacker_Solo
    @Hacker_Solo2 ай бұрын

    Where can we obtain this sample for free

  • @RandomytchannelGD
    @RandomytchannelGD2 ай бұрын

    Hi

  • @psbharathkumarachari4005
    @psbharathkumarachari40052 ай бұрын

    hi man fan from india

  • @liljeep3631
    @liljeep36312 ай бұрын

    You guys use uac?

  • @UnfiItered

    @UnfiItered

    2 ай бұрын

    ? Everyone in the AD world uses UAC. You don't want your end users in a lower privilege group policy to just download and run anything without UAC. You're opening yourself up to so many threat vector by doing that.

  • @liljeep3631

    @liljeep3631

    2 ай бұрын

    @@UnfiItered vector these nuts

  • @UnfiItered

    @UnfiItered

    2 ай бұрын

    @@liljeep3631 okay, obviously you're a troll.

  • @liljeep3631

    @liljeep3631

    2 ай бұрын

    @@UnfiItered don’t need uac

  • @UnfiItered

    @UnfiItered

    2 ай бұрын

    @@nezu_cc other than stealing files via emails and accessing network, everything else should require UAC via group policy (cmd, pwsh, windows native file encryption tools, vbs, portable exe etc..). Even then, group policy should dictate which user have access to which network drive. Outlook is the only email client used. Attachment is disallowed unless sending to internal email.

  • @runandwin5396
    @runandwin53962 ай бұрын

    Chapters please?

  • @frinkifail7063
    @frinkifail70632 ай бұрын

    sure love assimilationist one hundred thirty nine

  • @SlipperyCarrot
    @SlipperyCarrot2 ай бұрын

    Whole lot of Danish word in that sample..

  • @bamboozledbamboozler
    @bamboozledbamboozler9 күн бұрын

    I... i got so fucking lost. To be fair idk shit but i still find coding nonsense interesting

  • @user-cz1lz5ye4i
    @user-cz1lz5ye4i2 ай бұрын

    mom

  • @user-cz1lz5ye4i
    @user-cz1lz5ye4i2 ай бұрын

    voice

  • @user-cz1lz5ye4i
    @user-cz1lz5ye4i2 ай бұрын

    @#

  • @Monothefox
    @Monothefox2 ай бұрын

    It's in Danish.

  • @iamwitchergeraltofrivia9670
    @iamwitchergeraltofrivia96702 ай бұрын

    Fucking intel

  • @user-cz1lz5ye4i
    @user-cz1lz5ye4i2 ай бұрын

    mobile no.

  • @radityaharya
    @radityaharya2 ай бұрын

    ur audio sounds weird

  • @nordgaren2358

    @nordgaren2358

    2 ай бұрын

    What's weird about it?

  • @user-cz1lz5ye4i
    @user-cz1lz5ye4i2 ай бұрын

    bhabhi