#🔒 how to set up this rat detector

152 messages · Page 1 of 1 (latest)

ancient kite
steel helmBOT
#

@ancient kite

Python help channel opened

Remember to:

  • Ask your Python question, not if you can ask or if there's an expert who can help.
  • Show a code sample as text (rather than a screenshot) and the error message, if you've got one.
  • Explain what you expect to happen and what actually happens.

:warning: Do not pip install anything that isn't related to your question, especially if asked to over DMs.

mild meadow
#

Just don't run sketchy files? pithink

#

This is slow, it's silly, and it's not well written.

#

It isn't particularly surprising that this isn't working.

#

@plain maple

ember mulch
edgy current
#

yeah, this is no protection, just ignore it and dont open or run files

plain maple
ancient kite
#

??????

#

im scareed

mild meadow
#

Did you run something silly?

ancient kite
#

last year yes

ember mulch
#

you don't have to be scared it's just particularly bad code lol

#

fck didn't mean to resend that

ancient kite
#

this

#

i got ratted

#

by that

#

last year

#

now this year

#

im running it on dummy laptop

mild meadow
#

Ok, and you're worried that the malware is still present?

ancient kite
#

hence my name poop

#

this is not a official acc

#

yall can steal it if u want

#

idc

mild meadow
#

Oh wait, you're trying to run the RAT? pithink

ancient kite
#

rat me

#

go ahead

#

yes

#

i ran it

#

i found out

mild meadow
#

Why?

ancient kite
#

it cannot steal from firefox

#

but every other browser it can

ancient kite
#

that empyrean exe is a python file that can be renamed to like "discord updater" and people would download it

#

then get ratted

#

i want to detect it

#

before the logging happens

#

i want to scan the file with steal eyes

#

and then expose the ratter

mild meadow
#

You should leave that to the people who do this professionally instead.

ancient kite
#

tell me what this is

#

or means

#

please

mild meadow
#

It's just bad code, the repository you linked is not how this is done.

ancient kite
#

what does the bad code do

mild meadow
#

Bad as in... not malware but poorly written.

plain maple
ancient kite
#

so what does it do at the end of the day

plain maple
#

🗿

ancient kite
#

im good now bro

ember mulch
ancient kite
#

i wiped my os

ancient kite
mild meadow
ancient kite
#

what does it check

#

pls tell me

plain maple
mild meadow
#

Dude-- holy shit relax lol.

ancient kite
mild meadow
#

As everyone in this thread has told you, without us spelling it out in painful detail, this application will not prevent the execution of stealers on your host.

ancient kite
#

its a dud

#

???

plain maple
#

PUC - Practically useless code

mild meadow
#

It... does some things. But not anything that's going to be useful for you.

plain maple
#

I just made that acronym up fwiw

mild meadow
#

There's a plethora of things on the internet that claim they prevent <x> but only really work once and awhile.

#

Instead of focusing on... whatever it is you're doing, just focus on not running sketchy crap off the internet.

#

(Like stealer-detectors written by malware authors.)

mild meadow
#

Perhaps you should learn Python instead of using us as a service to explain code to you. pithink

plain maple
ancient kite
#

i would think its a normal day in the park convo

#

not a service

mild meadow
#

It looks for malicious 'strings' in files. It creates a 'risk score' based on the links in that file.
It also reads the index.js file, and tries to detect webhooks written to the index.js for Discord.
It then looks in the user's startup folder for files with webhooks in them.

ancient kite
#

for this

#

so if i put that against empyrean logger would it detect it

mild meadow
ancient kite
#

damn it

#

im trying to set it up

#

and test

mild meadow
#

You need to learn more about what you're doing before you continue doing what you're doing.

#

(And to be clear, I cannot teach you.)

ancient kite
#

well i know how the logger works

#

i ratted myself lol

mild meadow
#

You might be the single sketchiest person I've met in Python Discord thus far.

#

Why are you trying to detect these? I don't understand.

#

Why are you playing with RAT's?

#

Just don't run them.

#

It's that easy.

ancient kite
mild meadow
#

Okay well you're not going to do it with a Webhook.

ancient kite
#

they send me sketchy file then i check it before running

mild meadow
#

There's tools that do this that don't... suck.

ancient kite
#

like this?

plain maple
#

A good tool is typically common sense, it'll help prevent a lot of headaches.

mild meadow
#

Iunno, I've never looked at that before.

#

Looks terrible though.

ancient kite
#

but like

#

i want to expose these ratters

mild meadow
#

So go learn Cybersecurity concepts and malware analysis first.

#

This is not the way to start.

plain maple
#

How did you get infected in the first place? 👀

mild meadow
ancient kite
#

i was dumb

plain maple
mild meadow
#

based and malware-pilled.

plain maple
#

Honestly, real

plain maple
ancient kite
mild meadow
#

It is a VM built with tools to support dynamic and static analysis of malware.

lethal sorrel
#

if you're interested in being able to tell what a program does, you might want to try learn about malware analysis

plain maple
ancient kite
#

i see

#

so there is no simple program to just run it in

lethal sorrel
#

it looks like you're trying to find pre-built tools that will give you a yes or no whether a file is a rat

#

yeah

mild meadow
#

Correct.

#

There are some tools that get close.

#

VirusTotal etc.

#

But they ultimately rely on dynamic analysis-- and are evaded commonly.

ancient kite
#

bro i have used virustotal and that shit confuses me i dont know how to read it nor what to look for

mild meadow
#

That's why I keep telling you to study it if you want to learn more about it 🥴

ancient kite
#

alright

#

sorry yall

mild meadow
#

You're fine-- to be clear that's my blog. I work in this field; I've been doing this for a hot minute now, and I'm still learning every day. You're not going to succeed if you come in running prebuilt tools, and more importantly, it's dangerous to you as the end user.

If you want somewhere to start, look into regex and YARA.

ancient kite
#

alright

lethal sorrel
#

if you're interested in reverse engineering malware, there are a bunch of challenge sites online that have files you can practice with

#

but you'll need to learn how to use tools

ancient kite
#

i see

plain maple
#

You may also want to be familiar with several programming/scripting languages so you're able to read and understand what the malware is doing.

ancient kite
ancient kite
#

ok

stable abyss
#

what you need is a deratification machine alla

steel helmBOT
#
Python help channel closed

This help channel has been closed and it's no longer possible to send messages here. If your question wasn't answered, feel free to create a new post in #1035199133436354600. To maximize your chances of getting a response, check out this guide on asking good questions.