PowerShell CRYPTOSTEALER through DNS

Поделиться
HTML-код
  • Опубликовано: 8 май 2023
  • j-h.io/snyk || Try Snyk to find vulnerabilities in your own code and applications FOR FREE ➡ j-h.io/snyk
    🔥 RUclips ALGORITHM ➡ Like, Comment, & Subscribe!
    🙏 SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎 FOLLOW ME EVERYWHERE ➡ jh.live/discord ↔ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware

Комментарии • 73

  • @Aurem_YT
    @Aurem_YT Год назад +55

    Powershell is so cool, you never have to worry about installation. Makes it easier

  • @DS6Prophet
    @DS6Prophet Год назад +6

    John, you are an amazing Fella who always makes AAA+ quality videos! Huge props to you!! 😊

  • @justinpinson8575
    @justinpinson8575 Год назад +1

    Love this content! Thank you for the analysis as always ❤️

  • @manisharrora9525
    @manisharrora9525 Год назад +8

    Already stopped the same attack thanks for this. Also did the malware analysis of the .ps1 file.

  • @Lampe2020
    @Lampe2020 Год назад +17

    18:35

  • @stopper0203
    @stopper0203 Год назад +2

    Love these videos 😎!!

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Год назад

    Sho talented person.

  • @hyklmcjger9232
    @hyklmcjger9232 Год назад

    Great video! Almost went into the rabbit hole together with you :D

  • @muhammadtaha2578
    @muhammadtaha2578 Год назад

    love your videos sir

  • @DarkFaken
    @DarkFaken Год назад

    Thanks man!!

  • @allurbase
    @allurbase Год назад +3

    That UUID at the top of the script in the registry is probably to change the signature of the script.

  • @theblankuser
    @theblankuser Год назад

    Powershell stuff is interesting af

  • @luketurner314
    @luketurner314 Год назад

    13:01

  • @demotedc0der
    @demotedc0der Год назад

    aaawesome !!!

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Год назад

    Great master

  • @pdkama
    @pdkama Год назад

    thanks

  • @NederlandsPersoon
    @NederlandsPersoon Год назад +9

    uuh, wtf. I found this on a pc two weeks ago, 3 PowerShell files with a name of 4 random characters with the exact same contents. I correctly identified it as a virus and did some research, after deleting it there still remained some other parts which I could not find (I am a noob on this), so wiped everything. Amazing to see a video on it

  • @raiddesu9687
    @raiddesu9687 Год назад +5

    coolbase64 package for sublime would be useful for this kind of stuff since you do a lot of decoding ,you can just select and decode in sublime directly

  • @Sestain
    @Sestain Год назад

    I had this too and not sure where I had gotten it.

  • @mynamesaretakenwtf
    @mynamesaretakenwtf Год назад +12

    How are they injecting and running the PowerShell? It feels like we’re missing the initial attack.