This STEALER Infects Discord

Sdílet
Vložit
  • čas přidán 1. 07. 2024
  • I take a look at a technique known as "Discord Injection" where a stealer can be built into discord.
    Official Discord Server - / discord
    Follow me on X - / atericparker
    Disclaimer: The content in this video is for education and entertainment purposes to showcase the dangers of malware & malicious software. I do not encourage any form of illegal hacking, nor do I encourage the usage of game cheats, cracks or hacks.
    (C) Eric Parker 2024
  • Věda a technologie

Komentáře • 175

  • @NickAc
    @NickAc Před 4 dny +81

    One funny thing you can do with discord webhooks if they're present, is to _just_ delete them lmao

    • @ENNEN420
      @ENNEN420 Před 4 dny +8

      Another funny thing you can do with bots is you can kick them from your server! Silly, huh?

    • @NickAc
      @NickAc Před 4 dny +4

      @@ENNEN420 yeah that sure is fun and silly, but before you do that, make sure to use that same bot to infiltrate the server, and hopefully report the owner. although I wouldn't trust Discord's T&S team to actually do anything. It's also possible using the webhook URL to see the user who created it lmao

    • @electricz3045
      @electricz3045 Před 4 dny +2

      That won't Work If the attacker Setup a custom Domain with PHP Backend to do the requests behind the scencrs and Not forwarding it If It's a webhook delete request

    • @NickAc
      @NickAc Před 4 dny +2

      @@electricz3045 yep, that's true! but if we take a moment to think about the target "audience" for these kinds of things, I feel like you'll be coming across a lot of people who don't bother to even do that. for example, in the Hypixel (a Minecraft server with different games) skyblock (one of their games) community, there's a lot of scams involving utility mods that "supposedly" help the player. a while back I remember browsing across a dozen CZcams videos about said mods (sorted by upload date), and after reversing the code, it was mostly the same 2 jars (so two different grabbers), just with different webhooks

    • @goingcrazy-mg9sf
      @goingcrazy-mg9sf Před 4 dny

      ​@@electricz3045most cases skids dont modify code, incapable of it

  • @feefre
    @feefre Před 4 dny +15

    It terminating itself when detecting tokenprotector is really weird, you would think it would just laugh at it but actually "helping" it to work by not activating doesnt make any sense

    • @Sypaka
      @Sypaka Před 4 dny

      if i did read the code correctly, its the other way around. this malware kills any blacklisted process, the tokenprotector too.

  • @truckerbug
    @truckerbug Před 4 dny +8

    "Growtopia? I don't know what that is.. *sounds* like it's marijuana related..."

  • @tryrexman8627
    @tryrexman8627 Před 4 dny +16

    open-source malware is kind of based

  • @notBeWitchy
    @notBeWitchy Před 4 dny +14

    Growtopia is a prolific MMO known for hacking and real world trading. I was involved with the real world trading scene for a while until the ingame inflation made it unbearable. Surprised it tried to password grab it. Bit of a throwback because I haven't heard of it for years.

    • @lg-nathan84
      @lg-nathan84 Před 4 dny +1

      Also Gambling on the game ofcorse

    • @notBeWitchy
      @notBeWitchy Před 4 dny

      @@lg-nathan84 thats tied to the real world trading... basically irl gambling but accessible to the youth! lovely..

    • @Mario-sn5qr
      @Mario-sn5qr Před 4 dny

      Lmao yea I was surprised to see it mentioned here. I loved playing it when I was younger but ofc it got ruined

    • @cluelessnova
      @cluelessnova Před 4 dny

      My childhood game... 22yo now. Sad to see it dying

    • @notBeWitchy
      @notBeWitchy Před 4 dny

      @@cluelessnova Last time I touched it was in the summer of 2020. It was always not a great game, from mediocre content creation somehow garnering hundreds of thousands of subscribers because someone was rich ingame to culture (racism, sexism, homophobia, etc running rampant) to botting wise it was problematic.
      I am glad I distanced myself from it the moment there was extremely rapid inflation (going from 10% inflation in 3 months to 100% inflation in 2 months). In total I got like 4k profit with 20k turnover. Not a bad journey..

  • @jackprower2602
    @jackprower2602 Před 4 dny +6

    was not expecting to see growtopia mentioned. it was a fairly popular indie mmo that got bought out by ubisoft and ran into the ground. even if this stealer is from a while back its odd t o see something spesifically check for a game so niche. great video

    • @notBeWitchy
      @notBeWitchy Před 4 dny

      definitely a throwback from when i played it back in like 2020

  • @truckerbug
    @truckerbug Před 4 dny +8

    at 8:04 at the top of cmd prompt you can see it says "isVM: no" xD

  • @qoombert
    @qoombert Před 4 dny +18

    maybe it's called "Blank Grabber" because it puts the data in a folder with an invisible name.

    • @UCILaGtQaYAh3wnkvg4Rxzqg
      @UCILaGtQaYAh3wnkvg4Rxzqg Před 4 dny +2

      im pretty sure its supposed to be named after the username of the creator, blank-c

    • @qoombert
      @qoombert Před 4 dny

      @@UCILaGtQaYAh3wnkvg4Rxzqg Oh, that makes sense

  • @epicMinemenner
    @epicMinemenner Před 4 dny +6

    "The most powerful stealer"
    *It can't even grab Discord tokens correctly.*
    (I know it from one person that I've targeted and took down their stealers)

  • @master-og5kg
    @master-og5kg Před 4 dny +13

    You got one info wrong. Blank grabber injects itself into Discord only for capturing discord related data like added payment data, changed password and Login token. It does not use discord injection to get presistence on the system and uses like most stealer the auto start folder to stay on the system. If you remove the stealer from the auto start folder, the stealer is also gone, and only the discord injection stays, which keeps montioring discord for passwords, payment info and new tokens.

  • @thatoneglitchpokemon
    @thatoneglitchpokemon Před 4 dny +4

    Mama Mia! My Italian countryball collection is at a-risk!

  • @MysLouis
    @MysLouis Před 4 dny +7

    stealers are getting more and more popular bc of ppl stupidity

  • @KoDi82
    @KoDi82 Před 4 dny +13

    thanks for getting rid of the background music again

    • @yonice
      @yonice Před 4 dny +3

      man what are you talking about. The background music kinda perfects it. I'm sad he changed to this from his last couple uploads.

    • @atl6s
      @atl6s Před 4 dny

      @@yonice got his ass 🤣

  • @OliversTech
    @OliversTech Před 4 dny +9

    10:25 there's just a rarreg.key file right there lmao (winrar activator)

    • @Sypaka
      @Sypaka Před 4 dny +1

      They even give a free WinRAR key. how nice of them.

  • @yukicuh
    @yukicuh Před 4 dny +1

    A question, If you change your windows user to one of the blacklisted usernames, will that mean the stealer will not proceed?
    for example, my pc name is blahblah123 and one of the blacklisted ones is ralphs-pc
    theoretically, if i change my name to ralphs-pc does that mean the stealer no longer affect me?

    • @EricParker
      @EricParker  Před 4 dny

      against this specific sample yes. The problem is those blacklists are not all that consistent.
      Same idea as cyberscarecrow. Anti analysis isn't all that consistent.

  • @skver
    @skver Před 4 dny +8

    "most powerful" :^)

  • @mpkhd
    @mpkhd Před 4 dny +8

    Id love to see a video on setting up a new Windows PC and the best programs to keep it safe. Your expertise would be super helpful, especially for those just starting out with IT and PCs. There arent many legit videos on that topic, so yeah.

    • @rnts08
      @rnts08 Před 4 dny

      If you're not on linux already, you've already lost. Windows only belongs in controlled environments such as VMs.

    • @thetrueshadow9227
      @thetrueshadow9227 Před 4 dny +3

      There is a reason I am not on Linux at least for me there are some games that don't work on Linux and some software that does support Linux entirely for example here is a software that doesn't support Linux that I use wallpaper engine, and a game example is dark and darker these don't work and probably will never maybe dark and darker but I will have to see, and some games detect VM's and whatnot so its impossible to run a VM to play some games that only support windows plus EPIC Games not supported so... I can't make games nor is RPG maker another program I frequently use (sorry for the rant on this)

    • @mpkhd
      @mpkhd Před 4 dny +1

      @@thetrueshadow9227 Yeah, compatibility issues ARE a real hassle. Thanks for sharing your experience!

  • @manan67891
    @manan67891 Před 4 dny +3

    the John's are celebrating right now

  • @dragon.7191
    @dragon.7191 Před 4 dny +1

    stealer infects discord? yeah they tend to do that

  • @Lexencore
    @Lexencore Před 4 dny +2

    The stealer has a new github which is where it is continued btw

  • @obviouslyaxo
    @obviouslyaxo Před 4 dny +1

    I like waking up 10 minutes earlier (so I can eat breakfast) the Eric posts. W MORNING

  • @TheGoldenGear
    @TheGoldenGear Před 3 dny +3

    Hey Eric, I know this is not at all related to this video, But it would be cool if you could show off how to hide a virtual machine from programs that it is a virtual machine. I am using windows and am trying to run Fortnite on an emulator but EAC prevents the use of virtual machines.

    • @EZX280
      @EZX280 Před 3 dny +1

      He made a video a little while back on this. For your use case, give up. EAC is kernel level, and spoofing it would be hell (and would 100 % get your account banned)

    • @TheGoldenGear
      @TheGoldenGear Před 3 dny

      @@EZX280 Not for my account

    • @TheRailroad99
      @TheRailroad99 Před 7 hodinami

      ​@@EZX280look for VFIO.
      If anyone has figured out how to, it's the Linux VFIO community

  • @thetrueshadow9227
    @thetrueshadow9227 Před 4 dny +8

    Could you make a video on how to protect browser cookies and or session tokens?

    • @slpyOb
      @slpyOb Před 4 dny +7

      the true best way to protect yourself is to not download sketchy files and listen to windows defender/smartwall when they warn you 😊

    • @fraze912
      @fraze912 Před 4 dny +1

      @@slpyOb WD is the easiest AV to bypass even Malwarebytes is even more easier to bypass

    • @thetrueshadow9227
      @thetrueshadow9227 Před 4 dny

      I use brave though so its chromium based and I like brave

    • @thetrueshadow9227
      @thetrueshadow9227 Před 4 dny

      When I got hacked windows never told me anything, and how I got hacked was from remote desktop and UAC bypass by a GitHub (file from git pulling) now has been taken down and I've always scanned files but now since that happened I scan my computer at least 4 times a week even when download from official sites like Microsoft just in case 😁

    • @thequiet8572
      @thequiet8572 Před 4 dny

      @@thetrueshadow9227brave sucks. Watch Someordinarygamers video on it.

  • @ForLost929q
    @ForLost929q Před 4 dny

    Thank you so much for making the video❤

  • @STEALT_BLADE
    @STEALT_BLADE Před 4 dny +8

    Eric, on a old cd from a old czech click! Magazine i found a trojan, if i send it to ya will you review it?

    • @ENNEN420
      @ENNEN420 Před 4 dny +2

      If he doesn't see this comment, I'd email them asking if they want it

    • @EricParker
      @EricParker  Před 4 dny

      That could be interesting, you can send via email.
      Is possible that it's a false positive.

    • @STEALT_BLADE
      @STEALT_BLADE Před 4 dny

      @@EricParker eset flags it as a trojan, it even shows the trojans name but i dont remember it, btw the cd is from 2006

  • @mori0
    @mori0 Před 4 dny +4

    as far as i know "John-PC" is some kind of Sandbox from i think it was Avast

  • @emily1
    @emily1 Před 18 hodinami

    The good thing about black hats installing VMware protection is they can't hit you if you're using a VM as your main

    • @grisu1934
      @grisu1934 Před 8 hodinami

      Or make your main install look like a vm

  • @Souverx_
    @Souverx_ Před 3 dny +1

    i wanna know what software you use to check the internet stuff that happens, if you even use one, of course

    • @ysfchn
      @ysfchn Před 3 dny +1

      The software that is shown in the video is the web interface of "mitmproxy" software.

    • @plogiii
      @plogiii Před 3 dny

      And wireshark

    • @Souverx_
      @Souverx_ Před 3 dny

      oh, thanks

  • @Rekz_devexpoa
    @Rekz_devexpoa Před 4 dny +2

    Hi eric I haven’t been here for too long, but I can already say your channel is the best on CZcams. I enjoy your content a lot and it’s great that you’re posting more frequently.

  • @CozyHQ
    @CozyHQ Před 4 dny +2

    Hey, thanks for making a video on this, I'm the server manager for a server with over 130k members on Discord, we experience the problem of members being sent viruses and the biggest amount of them are blank-grabber. We usually delete the webhook on it by simply getting the webhook from the code of the virus.

  • @Saint.Scaramouche
    @Saint.Scaramouche Před 4 dny

    Hello! How does the NightfallGT/Lunar Grabber work? Nice vid btw

  • @wlanverbot
    @wlanverbot Před 4 dny +2

    hey my hitmanpro scans when i boot up my pc tells me my userinit.exe file is suspicious and its 128kb large is that normal, if I scan it with something else it says its fine

    • @feefre
      @feefre Před 4 dny +1

      @@wlanverbot it should go away after a reboot, You can also check the details to see what is it being detected as and by what av motor if available

  • @_____666______
    @_____666______ Před 4 dny +2

    anyways to hide process hacker from another softwares ?

    • @Luna5829
      @Luna5829 Před 4 dny +5

      rename the process lol

    • @thatoneglitchpokemon
      @thatoneglitchpokemon Před 4 dny +1

      @@Luna5829 you got brains i could NEVER have guessed that

    • @mrx6555
      @mrx6555 Před 3 dny

      @@Luna5829 how you do that?

  • @Sypaka
    @Sypaka Před 4 dny +3

    Jo, buddy. This discord stealer is using almost the same code to bypass UAC as the malware in the other video of yours called "Remote Control Any PC With Discord".
    but instead of an "If/else", it's using "case". And now I am trying to block any outside access to my "%localappdata%\discord" directory, brb. I wonder, if I can pull that off.

  • @Jackss0n
    @Jackss0n Před 4 dny +2

    What anti malware/virus program do you use or suggest?

    • @hahahahaha7237
      @hahahahaha7237 Před 4 dny +9

      A user is the best anti virus.

    • @monkaSisLife
      @monkaSisLife Před 4 dny +8

      not downloading sketchy shit

    • @austist
      @austist Před 4 dny +20

      1.) dont be an idiot.
      2.) windows defender
      3.) seriously, just pay the fuck attention to what the fuck you're doing

    • @AOSP-is-still-Linux
      @AOSP-is-still-Linux Před 4 dny +4

      ​@@hahahahaha7237 Single handedly the best response for this type of question.

    • @Jackss0n
      @Jackss0n Před 4 dny +2

      @@hahahahaha7237possibly the best answer I’ve ever seen to this question

  • @Limetable
    @Limetable Před 4 dny +7

    @NoTextToSpeech your time

    • @poomanhighlights
      @poomanhighlights Před 4 dny

      fr i didnt see ur comment, but i said he should try to do a collab lol

  • @hhhhhhhhhhhhhhhhhhhhhh
    @hhhhhhhhhhhhhhhhhhhhhh Před 4 dny +4

    The Discord uninstaller does rather messy uninstallations, so simply just uninstalling Discord might've worked for this stealer, but more nefarious stealers might persist in a file that doesn't get wiped by the uninstaller. Would definitely recommend deleting the discord folders in "%AppData%" *AND* "%LocalAppData%" (Discord stores stuff in both these locations).

    • @someguy9175
      @someguy9175 Před 4 dny +1

      Even then, it would need to hook itself back into discord so it could be executed again... Maybe the malware could make a task to reinstall itself once the uninstaller is executed and then delete said task once discord is back on the machine but it's definitely not that stealthy.

    • @hhhhhhhhhhhhhhhhhhhhhh
      @hhhhhhhhhhhhhhhhhhhhhh Před 4 dny

      @@someguy9175 As I said, Discord's uninstaller is messy and leaves lots of files behind that the malware can inject to and will allow it to persist past a regular uninstallation.
      The index.js file shown in the video isn't the only file that can be injected to.

    • @thatoneglitchpokemon
      @thatoneglitchpokemon Před 4 dny +1

      Genius! I'm going to get my cookies deleted and have to log in every time!
      Bravo, bravo.

  • @adam.maqavoy
    @adam.maqavoy Před 3 dny +7

    *Discord* is a mine field of 'em.
    *Discords* not far from how *facebook* were in the early 2010 Nowadays.

  • @cluelessnova
    @cluelessnova Před 4 dny

    It's sad seeing all the bots in Growtopia. Shame Hamumu hates the game so we wont see Seth and Hamumu working on it after they sold the game to Ubisoft Abu Dhabi..

  • @swardmasteryu
    @swardmasteryu Před 4 dny

    oh yt notifications actually works

  • @Cybercerialdestroyer
    @Cybercerialdestroyer Před 4 dny +1

    Does this work on Linux?

    • @Floriemene
      @Floriemene Před 4 dny +9

      Stealers like this? Generally no, since they often rely on Windows specific DLLs via ctypes, or the win32 library for a lot of their functionality.
      But that doesnt mean Linux is safe from it. Someone absolutely could write a stealer that works in both places.
      It's just significantly less likely that you'd find one due to the nature of most Linux users literally never using random binaries lol
      In the eyes of most stealer devs, they find it easier to target more gullible and susceptible people (Windows Users)
      And not as worth it to target Linux which requires different methods for a lot of the same functionality, with diminishing returns.

    • @thatoneglitchpokemon
      @thatoneglitchpokemon Před 4 dny +4

      @@Floriemene It's so dumb - right a stealer in Python, and they made it rely on ctypes. Whoever made this seriously denied the choice to make it crossplatform and still wrote it in Python lol

  • @prodfulcrum16
    @prodfulcrum16 Před 4 dny +4

    I was just playing growtopia and the servers went down lol

    • @jeevacation
      @jeevacation Před 4 dny +2

      That game is still alive??

    • @taahaseois.8898
      @taahaseois.8898 Před 4 dny +2

      @@jeevacation It indeed is, filled with bots from Indonesia on other third world countries.

    • @prodfulcrum16
      @prodfulcrum16 Před 4 dny +2

      @@jeevacation The servers are constantly down and flooded with bots, the game's currency is fucked and inflation is pretty bad, over 80% of active players are bots or casino hosters and the devs don't give a fuck, since the game is owned by Ubisoft, since 2017.

    • @jeevacation
      @jeevacation Před 4 dny

      @prodfulcrum16 yeah it was good when S&H had it, ubisoft ruined it by milking it.
      I remember seeing new locks all the time lol
      I think I first played it in '15 or '16

    • @prodfulcrum16
      @prodfulcrum16 Před 4 dny +2

      @@jeevacation yeah, it brings me a tear imagining how the game was around 2013-2016, since I started playing in 2013 christmas being 7 years old :D

  • @Nubs2112Official
    @Nubs2112Official Před 4 dny +4

    not the browser history 😭we must leave

  • @kyo69420
    @kyo69420 Před 4 dny +2

    What the open source

  • @sendevia
    @sendevia Před 4 dny +19

    please use dark mode

    • @JessicaFEREM
      @JessicaFEREM Před 4 dny +2

      no it's less readable

    • @Shleepy27
      @Shleepy27 Před 4 dny +1

      lol fr, my eyes are already itchy cuz im sick.

    • @sendevia
      @sendevia Před 4 dny +3

      @@JessicaFEREM the windows is zooming like 150% rn

    • @austist
      @austist Před 4 dny +1

      @@JessicaFEREM mfr got astigmatism and making it our problem.

    • @rnts08
      @rnts08 Před 4 dny

      Got to get uses to those flashbangs somehow.

  • @microcybs
    @microcybs Před 4 dny +3

    they really said "Most Powerful"

  • @aWeirdNickname
    @aWeirdNickname Před 4 dny +2

    Bro chill with the uploads

  • @KZA1234
    @KZA1234 Před 4 dny +3

    babe, wake up eric parker posted a video

  • @watercloud
    @watercloud Před 3 dny

    Good vid

  • @poomanhighlights
    @poomanhighlights Před 4 dny +8

    You should try to collab with @NoTextToSpeech to explain this and how to detect it and how to avoid it, although he will probally make a video on his own as soon as he finds out about this stealer

    • @adamtso
      @adamtso Před 4 dny +1

      it's been out since 2021 lmao

    • @Visquint
      @Visquint Před 4 dny +3

      you avoid it by not downloading junk.

  • @DominykasPc
    @DominykasPc Před 4 dny

    haha blank grabber detected

  • @freedustin
    @freedustin Před 4 dny +8

    This thumbnail AB testing is getting annoying. Saw this on my homepage earlier with a different more green thumbnail, but I didn't have much free time just setting up a playlist for the drive...now when I come back I have to scroll and scroll just to find out the green thumbnail I was looking for is gone and its white now. I didn't avoid clicking earlier because of the thumbnail, it was just a free time thing. But now YT takes this info as the new thumbnail got me to click.

  • @eHyp
    @eHyp Před 4 dny

    Thanks

  • @Playerk125
    @Playerk125 Před 4 dny +2

    ntts mentionf letsy goo

  • @domdomdomme1203
    @domdomdomme1203 Před 4 dny +4

    Very scary indeed. That’s why I always avoid logging into things I don’t really need on windows. Can’t steal login cookies or session tokens that don’t even exist 🤓

  • @eIixi
    @eIixi Před 4 dny +4

    you havent heard of growtopia??????

    • @electricz3045
      @electricz3045 Před 4 dny

      Not everybody in the Internet ist a 12 y old roblox kid. We have better things to do

    • @Floriemene
      @Floriemene Před 4 dny

      @@electricz3045 Growtopia was released in like 2012 though, lmao. And it was fairly popular up until around 2018-2020.
      The reason it was checking for passwords for that game was because the scene basically had a black market and irl trading scheme where accounts and stuff were being sold for real money.
      That's still going even today as far as I know.

    • @eIixi
      @eIixi Před 4 dny

      @@electricz3045 i'm not a 12 year old roblox kid and i've heard of it lol

    • @eIixi
      @eIixi Před 4 dny

      had you ever used android a few years back you'd have been recommended it

  • @imissedthejoke632
    @imissedthejoke632 Před dnem +1

    Growtopia mentioned no way

  • @Daniel99-j7l
    @Daniel99-j7l Před 4 dny

    15th

  • @_White_HvH_
    @_White_HvH_ Před 4 dny +3

    Why eric u looking forward to every thing im using :((

  • @SuqarSkllz
    @SuqarSkllz Před 4 dny

    yay

  • @Scy1hee
    @Scy1hee Před 4 dny +1

    w video

  • @budgetarms
    @budgetarms Před 4 dny +1

    1M subs soon

  • @gooniesfan7911
    @gooniesfan7911 Před 4 dny +1

    thanks andrew tate

  • @1haust
    @1haust Před 4 dny +2

    add some chill background music to these videos

    • @KoDi82
      @KoDi82 Před 4 dny +8

      man what are you talking about. The background music kinda ruins it. I'm glad he changed back from his last couple uploads.

    • @SeamanLord
      @SeamanLord Před 4 dny +2

      It takes away from the minor mic cutouts that I live for

    • @Milk-rn5uq
      @Milk-rn5uq Před 4 dny

      zoomer

    • @1haust
      @1haust Před 4 dny

      @@KoDi82 it was just a suggestion as the context of these videos is interesting but the delivery can be rather boring, some sound other than plain talk definitely improves the atmosphere, though im not gonna argue with youtube comment warriors

  • @Տupport
    @Տupport Před 4 dny +1

    Powerful, no kidding.

  • @chairedge
    @chairedge Před 4 dny +6

    "Akeo Consulting" should be Rufus' signature.
    Growtopia is a pretty old mobile MMORPG acquired by Ubisoft who did not care enough to patch the issue that the "save.dat" (practically the login token) is saved in an unsecured state to the game directory. These accounts still sell for some money on the game's black market, so it makes some sense to have it check that way.