He Sent Me Minecraft Malware (Java Deobfuscation)

preview_player
Показать описание


WATCH MORE:

🔥YOUTUBE ALGORITHM ➡ Like, Comment, & Subscribe!
Рекомендации по теме
Комментарии
Автор

Hey! Hypixel Skyblock YouTuber here,

Thanks for looking at this! The Hypixel community has been overwhelmed with fake mods, and session stealers for years.
I’m glad more people are looking at this, and helping to spread awareness about fake mods, and the dangers of them.

Love seeing stuff like this. Thanks for the fun watch!

Toadstar
Автор

Needed that sublime select thing at work today thank you

vanillarodent
Автор

Hey John! Thanks so much for looking at this sample I sent. Interesting to see how you did things differently and the same as I did in my initial analysis.

davidarthurcole
Автор

25:14 I've been rick rolled too much by now to recognize this regex.

Deftera
Автор

As a player of hypixel skyblock. RAT's are really common. You can find multiple in a week depending on what you do.

uxiii
Автор

best part was the indirect java roast (but loved the other two minutes as well)

rudigerheissich
Автор

"Java is just stupid and annoying." -John as well as every Java dev.

sojiro
Автор

Thought it was worth pointing out that Recaf is a good tool for those who decompile, deobfuscate, and reverse engineer java/minecraft mods. It allows you to rename variables, edit bytecode, and run methods with dummy inputs without ever even unzipping the jar

ffakkee
Автор

17:57 This is likely a decompilation error. I don't know why you're not using a proper IDE for this. Would probably chop about 15 minutes off the video length.

Sollace
Автор

25:21 Pizza Client is another minecraft mod for hypixel skyblock. It comes built in with a feature to protect against session id stealing which is when another mod like the one showcased steals the session id used to log into the users minecraft account. This string is there to find that part of the mod and presumably disable the feature in order to not get detected.

DChad-pt
Автор

Imagine spending this MUCH time making an info stealer to get people's lunar client accounts

MatinDevs
Автор

Spent 20 minutes doing nothing, then just uses ChatGPT and ends the video :/
Would've been more interesting to see some of the obfuscation techniques... I wish I could just access the code myself.

questwalkerko
Автор

Just using an actual Java IDE would probably make it much much easier LMFAO

GandhiTheDerg
Автор

"I do know maybe LITTLE bit about malware"
-John Hammond 2024

nemesician_
Автор

i assume that in "qolskyblockmod" the "qol" stands for "Quality of Life" as in useful additions that make it more enjoyable without making gameplay changes to the Skyblock mode that the mod is for.
some of the odd client names are most likely some obscure minecraft launchers i havent heard of before.
I do recognize essentials as a legitimate minecraft mod tho where they are probably trying to extract data from since its adding social mechanics like friends list, joining friends etc. like your used to from steam to the game.
I assume internal those systems store some data an info stealer would be interested in since the user basically already willingly gave those informations out.

ai-spacedestructor
Автор

OKAY JOHNNY YOU'RE GOING DOWN FOR CALLING JAVA STUPID (in all seriousness, great video, keep it up 😉)

ishino_ki
Автор

Hey man, JD-Gui is a pretty out of date decompiler. You should look into using a decompiler such as fern flower or vine flower (a fork of fern flower) instead which can (sometimes) be faster and provide more accurate and readable code

hydos
Автор

finally another malware deobfuscation video, they are so interesting

AACraft
Автор

I was once setting up my laptop to host a Minecraft server and I kid you not, it took 3 DAMN HOURS to get the correct version of java and their JDK's, JDE's. I was on like 10 Different websites. java is just so difficult to deal with so I can understand your struggle with javaFX and such stuff.

shadowplay
Автор

Not even Minecrafters are safe from malware....

callummcclure