Fake DMCA MALWARE Scam

Fake DMCA MALWARE Scam

🎙 John Hammond 👥 2.2M 📅 November 6, 2025 ⏱ 19 min 👁 39K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

phishingDMCAmalwareinfostealersocial engineering

Summary

John Hammond analyzes a phishing email disguised as a DMCA takedown notice. The email contains a link to a fake DMCA reporting website (dmca-security.com) that prompts the user to download a ‘report package’, which is actually a malicious executable. Hammond dissects the website, revealing it is likely AI-generated with fake contact details and no real functionality. He then downloads the executable in a sandbox (Any.Run) and observes it dropping an infostealer (Rhadamanthys) and setting up persistence via scheduled tasks. He also traces the infrastructure using VirusTotal and Shodan, uncovering a network of related domains and exposed backend code (server.js) that confirms the scam’s operation. The video emphasizes the importance of recognizing phishing attempts and the technical details of malware analysis.

120 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into a real-world phishing campaign, demonstrating the entire attack chain from email to malware execution. The argumentation is solid, based on direct observation and analysis. Hammond’s step-by-step approach is logical and educational, showing how to safely investigate suspicious emails and websites. He also highlights the use of open-source intelligence (OSINT) tools to pivot and uncover related infrastructure, adding depth to the analysis. The collaboration with a colleague from Huntress adds credibility and shows the importance of community sharing in cybersecurity.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates scientific rigor by using reputable tools and methodologies for malware analysis. The author clearly explains each step and provides evidence for his claims. However, he does not cite formal sources, relying instead on his own analysis and tools. The title accurately reflects the content, and the video stays on topic. The description includes affiliate links, but they are clearly marked and do not detract from the content. The video does not include a formal bibliography, but the tools used (Any.Run, VirusTotal, Shodan) are well-known and reliable.

189 words

Title / Content Match

The title accurately reflects the content: the video dissects a fake DMCA takedown notice that leads to malware.

Quality & Reliability

8/10

The video provides a detailed, hands-on analysis of a phishing campaign, demonstrating the malicious infrastructure and malware behavior. The author uses reputable tools (Remnux, Any.Run, VirusTotal, Shodan, Censys) and collaborates with a colleague from Huntress, enhancing credibility. However, the analysis is informal and lacks formal citations, and some claims are based on assumptions (e.g., AI-generated website).

Key Moments

Cited Sources

Concurring Sources

  • VirusTotal — Used to analyze the malicious domain and IP addresses.
  • Shodan — Used to discover exposed ports and services on the attacker's infrastructure.
  • Censys — Used to search for exposed server.js files and other backend data.

Contribution & Novelties

The video provides a practical, real-world example of a phishing campaign that uses a fake DMCA takedown notice to distribute malware. It offers a detailed walkthrough of the analysis process, from identifying the phishing email to tracing the infrastructure and malware behavior. The collaboration with a colleague and the use of OSINT tools adds a collaborative and investigative dimension. The video also highlights the use of AI-generated content in phishing attacks, a growing trend.

Pour aller plus loin :

  • Rhadamanthys Stealer — Malpedia entry on the infostealer observed in the video.
  • Phishing — Wikipedia article on phishing, providing background on the attack vector.
  • Any.Run — Interactive malware sandbox used in the video for dynamic analysis.

115 words

Radar Profile

The radar profile shows high scores in information quantity and quality, indicating a detailed and informative analysis. The technical level is moderate, suitable for viewers with some cybersecurity knowledge. The overall reliability is high due to the use of reputable tools and methodologies.

Reliability 8/10

💬 Sur les 0 commentaires analysés, aucune tendance n'a pu être dégagée.