Deciphering Obfuscated JavaScript Malware

preview_player
Показать описание
Do you like solving programming puzzles? Want to uncover what a malicious attacker is actually trying to do with their code?

In this video, we manually deobfuscate and Reverse Engineer an obfuscated JavaScript file. We look at a malicious loader file that downloads and executes a secondary AsyncRAT payload. You can follow along yourself with the video, by using the hash listed below!

---

File Hash: 978bf1471b3536dfdea854dd1c5d8ee63bdfbc8223c0254a92b183a711699a3a

---

Timestamps:
00:00 Intro to JavaScript Deobfuscation
06:03 Deeper Deobfuscation Techniques
12:02 Decoding Variables
18:00 Analyzing Obfuscated JS Function Calls
24:00 Uncovering Hidden Functionality
30:00 Reconstructing the Malicious Payload

---

LaurieWired Socials:

---
Intro Music Courtesy of Analog Summer:
Рекомендации по теме
Комментарии
Автор

I'm a backend dev and have never dug into malware analysis, but this video made the process look pretty fun and rewarding. I guess it is just a big dangerous puzzle

christopher
Автор

This is not really my area of interest specifically, although i follow various computer related content.
What actually shocked me, after watching several videos, is how orderly mind this lady has. Absolutely smooth speaking about complicated topics.
I envy that talent so much.

bartekklusek
Автор

holy effing sht. I literally just came across some heavily obfuscated js code that i am dying to reverse engineer and this vid came up. there is a god.

cusematt
Автор

I'm a complete code mong, so I'm trying to "hang around" with smart people to soak up as much as I can - hence, why I'm here.

Just to prove I was paying attention:
28:30
It looks like the integer returned was "1".
You went back to the code and typed "0".

Thanks for the walkthrough of what you're doing - Picked up a couple of tricks here.

digitalradiohacker
Автор

I did't need this but the explanation was so clear I kept watching

Jimbooos
Автор

These videos are really well made. I've tried to make educational content a few times before but never really landed on a good style or way to do things. You've inspired me to give it another shot

btdvids
Автор

Nice, I was looking for a nice detailed video that goes through such an annoying obfuscation in JavaScript. Thanks!

NatteeSetobol
Автор

One of my new favorite channels! I love the old school Tech Tv/G4 vibe of your set.

iss
Автор

Super neat video, really high level of production (also, 28:37, oopsie daisies the 1!) :P
Really awesome content, learnt a lot Laurie! Subbed :)

dblanque
Автор

The quality of these videos is just great, I'm not into JS at all, but it's well explained to follow along, nice! It all feels very much like security through obscurity, I predict this can be automated in the near future.

VincentGroenewold
Автор

You did a really good job with the style of your videos

sshiiden
Автор

@28:29 a little error here ;-) pasting 0 instead of the 1

ArjanvanVught
Автор

Awesome video Laurie, I learned a lot by watching your well explained videos. Thank you.

thediskostarz
Автор

This is so good I can't believe it exists, let alone such good content being free on YouTube.

Amazing work

shockinho
Автор

I absolutely love the way you break this down. Thank you!

viihnaNeverShutsUp
Автор

This was a lot of fun! What a cool breakdown.

UliTroyo
Автор

A lot of interesting insights, great job as usual!

DotDager
Автор

Clear, concise, and cool as hell. You picked a great code example!

mr.bulldops
Автор

This channel is really phenomenal. Everything from the technical aspect and way you break everything down in a clear and precise manner, the way you articulate yourself clearly, the synthwave color schemes and background setup is epic… I love all the things! Favorite channel lately :-)

You are very knowledgeable and talented and it shows. Thank you for sharing your knowledge!

nathaniellovely
Автор

I haven't done this type of stuff in forever. Great video and a fun romp through reverse engineering malware. Great Job, you've earned a new subscriber!

serpent