Reverse Engineering a Windows XP NET Worm

Sdílet
Vložit
  • čas přidán 26. 06. 2024
  • What does the "CONHOZ" Worm Really do?
    Official Discord Server - / discord
    Follow me on X - / atericparker
    Network Dynamic Analysis: 0:00
    Testing the C2 server: 4:18
    What is it? 8:09
    Decompilation & Source Analysis: 10:49
    IP Analysis (Shodan): 16:57
    Disclaimer: The content in this video is for education and entertainment purposes to showcase the dangers of malware & malicious software. I do not encourage any form of illegal hacking, nor do I encourage the usage of game cheats, cracks or hacks.
    Cracks are sometimes shown to highlight the dangers of software piracy, my content is not intended to teach anybody how to pirate, or maliciously hack.
    More Malware Investigation Videos:
    → The latest "NORD" Malware - Nordsecured: • The latest 'NORD' Malw...
    →🧧VIRUS WARNING🧧 NEW Optifine for Minecraft 1.16 SCAM: • 🧧VIRUS WARNING🧧 NEW Op...
    → The wilkreate CZcams stealer virus that started this whole trend: • Fake sponsor DESTROYS ...
    (C) Eric Parker 2024
  • Věda a technologie

Komentáře • 105

  • @glassbunnyy
    @glassbunnyy Před 8 dny +113

    dude. the consistency is incredible. every video you put out is interesting as fuck.

    • @Chrisfishem
      @Chrisfishem Před 8 dny +11

      Ong mf has me watching him on lunch 😭🙏🏻

    • @iBob4G
      @iBob4G Před 7 dny

      guys fucking relax damn. 😮‍💨🙄 These guys titties are hard

  • @etchickadee
    @etchickadee Před 8 dny +71

    THE RETURN OF CONHOZ AT LAST

    • @Margen67
      @Margen67 Před 6 dny

      Chickadees need CUDDLES

  • @JaYco1777
    @JaYco1777 Před 8 dny +30

    CONHOZ is literally an opp to eric parker lol.

  • @Higherthanozone
    @Higherthanozone Před 8 dny +14

    Eric. You run a great channel and great content. You give me danooct1 vibes. Asmr basically with incredibly intriguing and entertaining content. Don't know how I wasn't subscribed the last couple videos I've watch but im always tuning in. Thank you for being you and uploading these videos. Stay blessed

    • @igemily
      @igemily Před 8 dny +6

      comparing him to danooct1 is honestly the most accurate way of describing him wow

    • @ChandravijayAgrawal
      @ChandravijayAgrawal Před 8 dny +1

      I think both could be same person, since danooct1 stopped uploading 3 months ago and eric started 1 month ago

    • @igemily
      @igemily Před 8 dny

      @@ChandravijayAgrawal I really doubt that's the case but it's still interesting to see their similarities

    • @tl1882
      @tl1882 Před 7 dny

      @@ChandravijayAgrawal nah eric started years ago

    • @EricParker
      @EricParker  Před 7 dny +5

      DanOOCT's first video came a month after my 8th birthday.

  • @ChandravijayAgrawal
    @ChandravijayAgrawal Před 8 dny +4

    windows xp still look good, i think even after 1000 years people will see windows xp and say what an awesome looking operating system it was

  • @Chris-lw5po
    @Chris-lw5po Před 8 dny +7

    Thanks for uploading videos like this. I only knew about the recent WiFi vulnerability because of your videos.

    • @mcslave3
      @mcslave3 Před 8 dny

      Same here. It ultimately ended in me having to upgrade to windows 11 but the alternative would be a vulnerable computer

    • @prikolica3567
      @prikolica3567 Před 7 dny

      @@mcslave3 microsoft released an update for all versions from windows server 2008 to win 11

  • @mirrorportal1587
    @mirrorportal1587 Před 8 dny +6

    Great video Eric. I’d like to ask one thing: are you still planning on exposing 7/Vista, or any specific OS for that matter to the internet? Or testing exploits on those versions?

  • @giakhanhvn2mc
    @giakhanhvn2mc Před 8 dny +5

    that thumbnail caught me offguard lmfao

  • @naveen-
    @naveen- Před 8 dny

    incredible videos man you've been on a roll.!

  • @aaesth
    @aaesth Před 8 dny +6

    the conhoz chronicles

  • @Dmpawl758
    @Dmpawl758 Před 7 dny +2

    Post more bro on viruses and exploits like executors as those are very interesting the executors could be used for roblox/ other games

  • @cyalata
    @cyalata Před 8 dny

    Love the vids keep it up!

  • @dioboi-gr9sp
    @dioboi-gr9sp Před 8 dny +8

    Thanks for uploading amazing videos man, you are so underated! keep up the great work. Do you plan to make a video on Vape V4?

    • @dani-mb8ct
      @dani-mb8ct Před 8 dny

      what is he supposed to cover

    • @dioboi-gr9sp
      @dioboi-gr9sp Před 8 dny

      @@dani-mb8ct good point. although I was just curious to see what is terminated and executed when the cheat is ran or running. Basically just the behavior of the program

    • @macpc736
      @macpc736 Před 8 dny

      i would love to see this actually! even the ratted versions of the various cracks that have been released for vape.

    • @dioboi-gr9sp
      @dioboi-gr9sp Před 8 dny

      @@macpc736 fr. thinking about it though, the program is signed by the owner (Manth), its a paid client so there already getting some money out of it, and they would not want to ruin the reputation. Plus, its a registered company. off topic though, do you think mojang will come out with a global game anticheat?

    • @Kart
      @Kart Před 5 dny

      manthe hops through your screen in real life and hands you an electronic vaping device

  • @MfTrout
    @MfTrout Před 8 dny +1

    hey do you think you could make a video if you haven't already about kernel rootkits or just rootkits in general because i recently got one and would like to learn more about them

  • @Plasimticis
    @Plasimticis Před 8 dny +2

    LETS GO NEW VIDEO

  • @nick11927
    @nick11927 Před 8 dny

    Eric! Keep it up!

  • @LolsterYT
    @LolsterYT Před 8 dny +1

    Woooo new Eric vid

    • @LolsterYT
      @LolsterYT Před 8 dny +1

      I smile every time Eric uploads

  • @kavylavx
    @kavylavx Před 8 dny

    js woke up!! and you posted:D

  • @hamsterman5321
    @hamsterman5321 Před 8 dny

    do you have any tutorials or guides?

  • @bazeschool1958
    @bazeschool1958 Před 6 dny

    nice vid man

  • @nandgz
    @nandgz Před 6 dny

    You are my favorite tech CZcamsr, you helped me get safe on the internet.

  • @skver
    @skver Před 8 dny

    woah, another eric video

  • @silverwolfHSR
    @silverwolfHSR Před 8 dny +2

    hi, what happened to the windows activator vid? is it still under review by youtube?

    • @EricParker
      @EricParker  Před 8 dny +5

      CZcams really doesn't like anything tangentially related to piracy.
      They told me no, then they said disregard that they're gonna look deeper. If it goes nowhere I might release a very censored version of the video that shows only the payloads and not where they came from.

  • @Jono6321_true
    @Jono6321_true Před 8 dny

    Woohoo!

  • @alek002
    @alek002 Před 8 dny

    Will you do coverage on malware on windows 11 soon?

    • @EricParker
      @EricParker  Před 8 dny +9

      wdym.
      Vast majority of my videos are modern malware. Exposing newer versions of Windows to the internet (Even with firewall off) doesn't result in this type of thing.

  • @ChandravijayAgrawal
    @ChandravijayAgrawal Před 8 dny +1

    can you do some videos on windows 7 and windows 8, since many people still use those, since old PCs don't support windows 10+

    • @eDoc2020
      @eDoc2020 Před 4 dny

      Windows 10 has the same requirements as Windows 8, which includes almost all PCs less than 18 years old.

  • @PABLOPeanutman
    @PABLOPeanutman Před 7 dny

    i was wondering if you could make a video on project nova its a old fortnite project hosting type thing and people say its a trojan but i dont know and i want to play it but i dont want to get a virus or trojan

  • @wrathofainz
    @wrathofainz Před 6 dny

    He unblurred the thumbnail.
    Neat.

  • @toygoon_
    @toygoon_ Před 7 dny

    what language is used in the thumbnail?

  • @kiendra
    @kiendra Před 6 dny

    eric parker is parkin 🗣🗣🗣🗣🔥🔥🔥🔥

  • @leviathan7627
    @leviathan7627 Před 3 dny

    so basicly. from what im getting. its a 3-in-1 deal? like its a miner worm and proxy in 1?

  • @leroyjenkins1911
    @leroyjenkins1911 Před dnem

    I feel so incredibly smart, that I guessed right, that its probably EternalBlue, especially when you said it blocks of SMB. I am such a 1337 scr1p7 k1ddy

  • @imistrz
    @imistrz Před 2 dny +1

    7:47 Was that Endermans website???

  • @KarimSiuuu
    @KarimSiuuu Před 8 dny

    ERIC I LOVE YOU

  • @Mcblocky0
    @Mcblocky0 Před 8 dny

    New video!

  • @MrTomiCeZet
    @MrTomiCeZet Před 7 dny

    no one:
    eric having skype open: so i can also now uh lets just go to binaryninja

  • @MUFCTom
    @MUFCTom Před 8 dny +2

    Looking forward to u connecting to the North Korean 🇰🇵 intranet! :)

  • @johnhank6721
    @johnhank6721 Před 8 dny

    Damn ur active

  • @Fmgnio
    @Fmgnio Před 5 dny

    Can you do a video about this sketchy og fortnite emulator called "Project Nova"

  • @Graham6410
    @Graham6410 Před 7 dny +3

    I am surprised about how many companies still use a version of WinXP.

    • @kuil
      @kuil Před 6 dny +2

      if it is isolated from other computers, and works, why fix it?

    • @Graham6410
      @Graham6410 Před 5 dny +1

      @@kuil true, it's just the ones still connected to the internet I'd be worried about.

    • @dubl33_27
      @dubl33_27 Před 2 dny

      @@Graham6410 connected to the internet without protections in place*

  • @kevin.7z
    @kevin.7z Před 8 dny +1

    Day 3 of asking Eric to collab with The PC Security Channel because they sound like the same person

  • @DisloyalDesign
    @DisloyalDesign Před 6 dny

    Do bloxstrap next Idk if its trustworthy and itll be a fun vid

  • @Kamerzystanasyt
    @Kamerzystanasyt Před 8 dny +1

    127.0.0.1 kris.ru
    makes when you open kris.ru it will actually take you to localhost on your pc its used for cracking software

    • @EricParker
      @EricParker  Před 8 dny +1

      so it's likely then related to the 'helpful' functionality. Patching the worm after exploiting.

  • @mafusaku
    @mafusaku Před 8 dny

    hello eric, everyone here, we're now more educated.

  • @overhollgd
    @overhollgd Před 8 dny +2

    Please do roblox fake exploit analysis, Day 5 of asking.

  • @Jamesvarush
    @Jamesvarush Před 8 dny

    Early today

  • @Yadlina
    @Yadlina Před 8 dny +3

    smb-vuln-ms17-010 ?

  • @jeppe1774
    @jeppe1774 Před 8 dny

    the thumbnail is really cursed and invalid code, bruhh

  • @ltxr9973
    @ltxr9973 Před 8 dny

    Horst Connor?

  • @obviouslyaxo
    @obviouslyaxo Před 8 dny +1

    Hehe “conhoz” hehe

    • @EricParker
      @EricParker  Před 8 dny +2

      the "Microsoft Compilation" virus from the XP video

    • @obviouslyaxo
      @obviouslyaxo Před 8 dny

      @@EricParker I know it’s just funny

    • @goongleton
      @goongleton Před 8 dny +1

      the zoo pop up from the xp livestream

    • @obviouslyaxo
      @obviouslyaxo Před 8 dny

      @@goongleton OH GOD NO NO NO

  • @1338bubble
    @1338bubble Před 7 dny

    eric you need to higher moderators with an IQ at least in range of average

  • @hhhpestock951
    @hhhpestock951 Před 8 dny +1

    what do you mean by 'exposed XP to The Internet'?

    • @prikolica3567
      @prikolica3567 Před 7 dny +1

      he let an unupdated version of XP to connect to the internet with no firewall

    • @tl1882
      @tl1882 Před 7 dny

      no firewall

    • @EricParker
      @EricParker  Před 7 dny +1

      What I mean is having it's own IPV4 (ie could host anything it wants) with all ports open. This is an unusual desktop configuration these days, although in the 2000s it was more common.

  • @JamesnLollify
    @JamesnLollify Před 6 dny

    Copyright Microsoft Compilation

  • @CakeCh.
    @CakeCh. Před 5 dny

    ζ*(・ヮ・)*ζ

  • @itswilliamanimate
    @itswilliamanimate Před 12 hodinami

    don't give script kiddies ideas with that thumbnail

  • @nikos4677
    @nikos4677 Před 8 dny +3

    19 views in 30 seconds. Bro fell of

    • @sbob17
      @sbob17 Před 8 dny +10

      Well done. Clever and informative comment. 👏 👏 👏

    • @nikos4677
      @nikos4677 Před 8 dny +1

      @@sbob17 thank you. I try my best to broaden the video experience

  • @mrbub69
    @mrbub69 Před 8 dny

    can you make a video on minecraft rat mods? they can find every bit of information about your computer if you run the game and I think its interesting

  • @Yvellic
    @Yvellic Před 8 dny +2

    I’ve missed this type of malware showcases. Thank you Eric for bringing it back in style, favourite channels for it were Danoct1 and Rogueamp back in the day 🫡

    • @SoulcatcherLucario
      @SoulcatcherLucario Před 8 dny +1

      it's too bad rogueamp fell off, it's a good thing dan is still around though

    • @Yvellic
      @Yvellic Před 8 dny

      @@SoulcatcherLucario yeah agreed , would be nice for amp to comeback one day though.. he’s still got that sick attic fan footage 🤣