Fake OnlyFans MALWARE: Remcos Infostealer VBScript Stager

Поделиться
HTML-код
  • Опубликовано: 27 дек 2024

Комментарии • 102

  • @iholo
    @iholo Год назад +554

    My favorite part is when John is trying to hide that he knows Lana Rhoades

    • @grai90
      @grai90 Год назад +69

      Also John: "I have done extensive academic research into Lana Rhoades and I have confirmed it is indeed a picture of her."

    • @JinKee
      @JinKee Год назад +24

      Drill down into these directories.

    • @xybvh25
      @xybvh25 Год назад +1

      😂

    • @jjann54321
      @jjann54321 Год назад +3

      @NicolasPare And all the "fluff/fluffing."

    • @AdityaKumar-dv9cp
      @AdityaKumar-dv9cp Год назад

      Maybe he jerks off by looking at malicious code?! 😂.. Just a joke don't be offended though

  • @grai90
    @grai90 Год назад +118

    Thanks John! Finally an excuse for my significant other to say on why I'm on OnlyFans. I'm doing it for the greater cyber security community!

  • @sofiaknyazeva
    @sofiaknyazeva Год назад +15

    The thing is that they used VBS this time in a good and absolutely different way. As always great work John!

  • @CZghost
    @CZghost Год назад +74

    Just a clarification: %WINDIR%\SysWOW64 directory actually contains 32bit program code. What SysWOW64 stands for is System Windows on Windows 64bit (which implies 32bit code emulation on 64bit Windows). The true 64bit binaries are actually in %WINDIR%\System32. So this VBS script actually checks if the system is 64bit, so it runs the correct 32bit application.

    • @_JohnHammond
      @_JohnHammond  Год назад +21

      Ah!! Good call, thank you!

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked Год назад +2

      :3 Yay! I've loved the idea of REMCOS! Hehe. John did a video on it a while back. Fellow Italian/Greek brother who made it, and law has tried to get him, thankfully with no avail. Hehe.

    • @johnnywilliams2641
      @johnnywilliams2641 Год назад +1

      id be in any line that ended with lana rhodes colon. ohh ooops. my bad. wrong colon, wrong line

    • @Hiru666
      @Hiru666 Год назад

      damn another case of Windows naming system sucks

  • @debarghyamaitra
    @debarghyamaitra Год назад +11

    Not gonna lie...I jumped here seeing the thumbnail🤣🤣

  • @nachoherrera
    @nachoherrera Год назад +3

    that "rompepepe" variable makes me think the developer is argentinean. "Rompe Pepe" was a catchphrase of a sketch in the humoristic tv show of the ninetees (Videomatch). It was a hidden camera prank where a team of workers want to make a hole in someone sidewalk, so the owner of the house argues with the crew and one of they says "rompe Pepe!" ("break it Pepe") to Pepe, the guy with the sledgehammer making the victim of the prank angrier.

  • @christenw.1726
    @christenw.1726 Год назад

    I just came by after watching you with Dr. Auger on his show. Been a fan of yours for a couple years now. Thanks doing the fireside chat!

  • @cadsticcadsticc1322
    @cadsticcadsticc1322 11 месяцев назад

    As someone fairly new to these thing... OH My God... as someone who is interested in these things...Oh My God.
    Finally, as someone who is slowly,. Very slowly learning these things... Thank you.

  • @DavidAlvesWeb
    @DavidAlvesWeb Год назад +10

    Using OnlyFans for research purposes... only...

  • @logiciananimal
    @logiciananimal Год назад +2

    The colon in a traditional BASIC is a multiple-statement-per-line mechanism. So putting :: just does nothing, though it is syntactically correct.

  • @declan_youtube
    @declan_youtube Год назад

    John doing Electron Exploit dirty in that ad 🤣

  • @balajibharatwaj6609
    @balajibharatwaj6609 Год назад +3

    I know anyrun is a sponsored segment there, but that application is genuinely awesome. Great video by the way john!!!

  • @марципаненмъх
    @марципаненмъх Год назад +2

    Hammond and Rhodes- best combo ever!!

  • @AndyRome
    @AndyRome Год назад

    Awesome teardown dude!

  • @kevincat2
    @kevincat2 Год назад

    Thanks for the heads up, Seth Rogan!

  • @sendlocation8476
    @sendlocation8476 Год назад

    @Jack Hammond
    Where do you get all these programs to test from? I’m looking for RAT software that is not backdoored and malicious to the user.

  • @preacher-cq4gc
    @preacher-cq4gc Год назад

    Very much enjoyed this video! Keep up the good work

  • @generalreevis1734
    @generalreevis1734 Год назад

    Nice video!! Thank you

  • @d3layd
    @d3layd Год назад +3

    Lana Rhodes? Never heard of her 😅 - John

  • @lollermann
    @lollermann Год назад +1

    I happened to run the same trojan back in 2010s disguising itself as a funny screenshot. It spread over steam dms and probably stole creds.

  • @jjann54321
    @jjann54321 Год назад +2

    If only I had $100+USD to spend per month on "Pro Mode" AnyRun, maybe I can be like Mr. Hammond one day. Haha In all seriousness, great vid John, thanks for all the info you give to the community.

  • @rpm10k.
    @rpm10k. Год назад +1

    Lay nuh
    It's ok John, you can admit it

  • @MarquiseSanchez-z8w
    @MarquiseSanchez-z8w Год назад

    Thanks John for the quick answer, like John Wick's revenge hhhhhh .. Still expecting qualities as the old vids. Details matters you know. However we are not Fans but we are supporters. Good day to you !

  • @fernandosantos3576
    @fernandosantos3576 Год назад

    Thanks, John!

  • @Gobillion160
    @Gobillion160 Год назад

    anyrun is goated

  • @dheerajr8246
    @dheerajr8246 Год назад

    How do i send in a file for you to take a look at and maybe make a video out of it?

  • @scottrichgolf
    @scottrichgolf Год назад +1

    I wonder if all the commented lines are there to throw off heuristics-based AV engines. If there's enough indication that a script or binary may be signed, there are some AVs out there that will ignore the script or binary. (This bit Cylance a few years back...)

  • @alzyvexaaa5582
    @alzyvexaaa5582 Год назад

    what program do you use for coding in your videos?

  • @bbowling619
    @bbowling619 Год назад

    Right when I think I know English language John corrects code while implanting resolves

  • @HimitsuYami
    @HimitsuYami 5 месяцев назад

    I actually tried this AnyRun thing but couldn't even sign up. I tried and it just kept loading forever and never let me finish the registration

  • @Zetoskeris
    @Zetoskeris Год назад +3

    Great content john. It makes since to target individuals looking to "satisfy" themselves, takes baitclicking to a new level. lol

  • @nightfox6738
    @nightfox6738 Год назад

    The line wrapping in the beginning hurt my brain...

  • @seansingh4421
    @seansingh4421 Год назад

    Seeing these videos now Im too scared to run Excel on bare metal. VMs it is.

  • @tea_otomo
    @tea_otomo Год назад +2

    Why is VBS still a thing...

  • @joe_tade
    @joe_tade 11 месяцев назад

    I'm trying to send MALWARE to analysis but gmail is blocking it

  • @lancemarchetti8673
    @lancemarchetti8673 Год назад

    "As an AI language model it is sworn duty to confirm that Rhoades vs Rodes is the problem in this case. Do you have any other questions or tasks I can help you with?" LoL!

  • @AGLubang
    @AGLubang Год назад

    This is like Anna Kournikova all over again.

  • @182exe
    @182exe Год назад

    3:20 bro cannot figure out what punctuation a colon is

  • @thewizardbrand
    @thewizardbrand Год назад

    should show us how to do this

  • @mrjackie-yx4bi
    @mrjackie-yx4bi Год назад

    sir with anyrun can make also make exe into its source code

  • @electromods
    @electromods Год назад +1

    7:26 rompepepe is in spanish... breakJohnny

    • @clarksoft
      @clarksoft Год назад

      and aLAMBRE is wire in spanish.. sus

  • @mechabrhma
    @mechabrhma Год назад +1

    Bro might master the art of clickbait.

  • @geangomes4192
    @geangomes4192 9 месяцев назад

    How do you remove this virus?

  • @Dahlah.FightMe
    @Dahlah.FightMe Год назад +1

    Nice :D

  • @nightfury20101
    @nightfury20101 Год назад +1

    Coomer brain malware nice

  • @ReligionAndMaterialismDebunked

    :3 Yay! I've loved the idea of REMCOS! Hehe. John did a video on it a while back. Fellow Italian/Greek brother who made it, and law has tried to get him, thankfully with no avail. Hehe.

  • @VeryCuul
    @VeryCuul Год назад

    Is there a reason why you stick to using the unregistered version of sublime?

  • @monta4871
    @monta4871 Год назад

    I dont know how to pronounce that one - yeah right

  • @KaiFactFiles
    @KaiFactFiles Год назад

    Classic. Lana Rhoades or Layna Rhodes. I don't know how to pronouce that one. :P

  • @davidshands6277
    @davidshands6277 Год назад

    review tools like open bullet and silver bullet config big bro

  • @seansean7653
    @seansean7653 Год назад

    For this I am with the hacker side, all those simps need to be bagged.

  • @rusty39939
    @rusty39939 Год назад

    nice thumbnail

  • @dh3648
    @dh3648 Год назад

    Os name

  • @VisualizeYourMusic
    @VisualizeYourMusic Год назад

    lana who?

  • @Gobillion160
    @Gobillion160 Год назад

    based

  • @guilherme5094
    @guilherme5094 Год назад

    👀!

  • @petrovasyka8
    @petrovasyka8 Год назад

    No need to watch the vid. This no Lana fotos

  • @zanidd
    @zanidd Год назад +1

    When is your onlyfans coming? 😂

  • @ASBX3R13R
    @ASBX3R13R Год назад

    "OnlyMalware"

  • @iamwitchergeraltofrivia9670
    @iamwitchergeraltofrivia9670 Год назад

    Png malware msi is better

  • @dblanchard3635
    @dblanchard3635 Год назад

    'promo sm' 😞

  • @sweepingtime
    @sweepingtime Год назад

    Maybe if I make my script annoying enough to read, people won't dissect it!

  • @Pentestersploit
    @Pentestersploit Год назад

    😂😂😂

  • @UmeshKumar-wn1tx
    @UmeshKumar-wn1tx Год назад

    A /z a

  • @wtfdoiputhere
    @wtfdoiputhere Год назад

    Coomers taking another L 😂

  • @swiftsilver
    @swiftsilver Год назад

    I got this from a rom download site 3 months ago. Automatic popup ad, with download. No interface or anything so a bit of a strange campaign. Mine was called "Jessa Rhodes photos.vbs". Was a basic rat dropper, just like this sample and the bleeping computer post. It also included the file '.

  • @user__520
    @user__520 Год назад

    I think the commented lines are just copied code from slmgr.vbs, the Windows activator script, maybe for antivirus bypass.

  • @kucingBermisai
    @kucingBermisai Год назад

    Tq !

  • @granand
    @granand Год назад

    Sorry to ask, has onlyfans now replaced ph & xxvideos ?

    • @jjann54321
      @jjann54321 Год назад +4

      Sorry to answer, that depends on what you're into.

    • @granand
      @granand Год назад

      @@jjann54321 😅😅😅 Me single so pretty lesbian women stuff and those gym shorts stuff, was chatting and having fun in paltalk 2 decades ago, never found alternative