Fake CAPTCHA Runs Malware
Key Takeaways
The video analyzes a fake CAPTCHA malware that uses PowerShell and social engineering to infect users, with tools such as VirusTotal, Twitter, and Sublime Text used for analysis and tracking.
Full Transcript
our security operations center has recently seen a number of investigative cases where the origin and start of malicious code that runs seemingly comes from absolutely nowhere and this is encoded Powershell it's a small oneliner to kick things off but there wasn't a clear starting process or persistence mechanism or initial access Vector other than just explore. exe like your desktop we could see the process invocation and the commands that were ran but where did this all kind of come from so our sock analyst dug a little bit deeper and took a look in the users's web browser history it seems like this poor user the victim the Target in this case was unfortunately following through a redirect chain all online maybe from a ad or popup or something that just flew open on their browser and maybe accidentally clicked it one way or another I don't know somehow they landed at TPB proxy ninja whatever somehow leading to The Pirate Bay and this was a redirect right this is a 302 HTTP 302 to send you to another site now better ad system apparently and I've redacted some of the breadcrumbs here that might be unique identifiers for the victim I can't say I don't know for sure if they are or not this is all looking back in retrospect but just to be safe I wanted to redact a couple of those bits and then it brings them to a download step.com with a notion of verify you are human finally bringing them to another location the final ending destination a static page posing as a fake capture at human human verification 4. bcn.net verify you are human now we can try and take a look at this see if this is still live currently it's a defanged URL with x in replace of https a couple Square braces around some important tidbits here but we could replace those and open that up in our web browser see if it's still online pasting in this URL we can see if that brings us to the page but oh okay thanks bunny net has taken it down and that seems to be the case for a lot of these that we've uncovered and that's a good thing right hey the malware the Halo the Stager has been taken offline but I do have a saved copy of what that page looked like and I wanted to show it to you cuz it's a little bit interesting and we can have some cool conversations from it so if I open up that index.html just the static page that this was present in we can see that this is a fake capture right verify you are human please verify that you are human to continue with the classic I'm not a robot button and if we were to click on this it gives us some verification steps that aren't like the usual oh click them number of buses or motorcycles you see now it's actually press the Windows button and r on your keyboard press contrl V and then press enter um now I'm sure a lot of you that watch this channel probably know what this is and what this does but for an unsuspecting innocent user maybe they don't know so if I were to follow those steps if I hold down the windows key and press the letter r on my keyboard you can see we open up the Run dialogue box if I press control V on my keyboard to paste this in looks like a whole lot of nonsense but look I didn't put that in my clipboard this is all base 64 and and encoded command to run with Powershell that is our Stager now if I were to hit enter here this would invoke whatever the next stages pull down some malware and invoke ultimately an information stealing malware family isn't this a little cutesy though like I know it's dumb I know it's the attack Vector of copy and paste but literally it that's what it is and it may very well work so let's dig into how this happens and then what happens if I actually close this out and get back to the original page I'll just F5 to refresh I can hit control U on my keyboard or right click to view the page source and this gives us the flat static HTML honestly you know it might look better in uh Sublime Text but that doesn't matter here we see a lot of cascading stylesheets just some CSS static boilerplate stuff that isn't all that interesting just necessary for the display of the page here HTML which is nothing fancy just the exact steps and a div that's displayed little popup modal but here's the JavaScript here's the client side code that runs dynamically and let me zoom in a little bit so you can see this because this is where we get to some sweet stuff you know what I will bring this into Sublime Tech so we get some better syntax highlighting there take a look at this verify function know that it's built but then at the very bottom actually code that runs will grab the element of the verify button by its ID and then add an event listener when it's clicked on it calls this verify function now here's what it does defines text to Copy being the Powershell payload that we just saw and it creates a text area element on the document on the web page just momentarily like a temp text area after it adds this code and command the text to copy as the text area's value it adds it to the document selects all the data and then runs this document. EXA command copy now I don't know I think apparently from what I've heard this is like a deprecated thing but still works right as all deprecated things sometimes usually do I have config I'm at you now this will literally copy data into your clipboard so that if you were to press contrl + V or paste in the copy and paste process now you've got whatever the website staged for you it cleans it up and then it just makes this display so that is a tiny cutesy harness just to be able to get malicious code into your clipboard and literally social engineer en lure the victim into pasting that in all in a dumb stupid verify your human capture would you fall for that I know maybe you wouldn't but is there anyone that you know that would fall for that but let's grab this base 64 encoded data and then really see what it is let me hop into C linkx just so I have a quick and easy Bas 64 command so if I were to Echo this out and paste it pipe it into our BAS 64 tacd to decode it we can see ooh it runs MSHA so that Microsoft hypertext application interpreter with a link URL here so an external resource to click1 bcdn n/ Giga gigachad look at that now the last that I saw this was offline or at least not serving the mshta payload anymore but I do want to tell the rest of the story and give more kudos to our security Operation Center and sock analysts back in our notes and forgive me I realize these are just notes we'll get into a little bit more fun sexy showcase a little bit later but after it reaches out with MSHA to that click one bcdn giga it ends up pulling down a binary and an executable that'll drop a training manager Enterprise .exe into their local temporary directory in app data local that is apparently LMA stealer the info stealing malware that I was alluding to later but it actually injects into a native Windows binary to look a little bit more innocent or presume innocent right with bit Locker to go I don't know if you've ever seen this but this is a real thing on your Windows system and I'll use the uh run dialogue box with the windows key and R just to get to that directory super quick there is literally genuinely a bit Locker too. XE that ships with Windows after you drill down to that final payload like the lumma stealer and the executable itself beyond the fishing lure social engineering copy pasta look virus total can tell you quick and easy hey this thing is Bad News Bears this is lumus dealer this is everything that might be seeing you can see some of the details other info for it relations or Behavior Uh that actually has a different domain or URL where that was coming from and previous submission Community notes all in the mix here like hey this is a Lama stealer over and over and over again but that was a bit of a lackluster demo would like to Showcase a little bit more and there's more to chat about here actually uh recently I was tagged in this post or this little tweet over on Twitter where Muhammad says look this is an interesting Vector have you ever seen this before and he know it's me uh including this exact same verify your human silly capture fake copypaste lure and scam that ends up loading llama stealer as we've observed somehow some way this post like explodes that's got like 300,000 views and 3,000 likes so that's cool and I noted look we saw the exact same thing and I was trying to decide look is this something that we should put in a video because it's copy paste it's not like the coolest most elite tradecraft here is the screenshot though of all the notes that I was sharing with you just a moment ago and again all Kudos and credit to our security Operation Center sock analysts that were digging into this doing the real work with all that said I do want to extend an extreme amount of kudos to seriously all these sock analysts that do incredible work day in and day out so with that please let me tell you about the sponsor of today's video and a super cool event that they've got going on sock analyst Appreciation Day Security operation Center analysts are too often overworked and underappreciated they're doing the most impactful cyber security work but they're never in the Limelight so to help celebrate those sock analyst rock stars dvo is hosting the fourth annual sock analyst appreciation R it's all to pay some long du kudos to our world sock analysts and to encourage organizations to improve their job satisfaction and mental well-being the online event is completely free and open to anyone and everyone live on October 16th it is packed full with career focused sessions preventing burnout secrets to success day in the life details for analysts and researchers and so much more I'll even be speaking on the rapid response efforts during the connectwise screen connect exploitation I'd love to see you there if you are a security Operation Center analyst or you're fascinated by the work and you want to become one you should absolutely tune in to the sock and appreciation it's completely free and it's a day dedicated to celebrate you and your great efforts sign up for the sock analyst Appreciation Day on October 16th with my link below in the video description jh. liveo huge thanks to dvo for sponsoring this video all right now back at it and I don't mean to be just scrolling through Twitter here but I do really want to call out a lot of the community collaboration and just really cool insights that get to chime in from other people across the Internet it's a team effort after all and there are a lot of different names or whatever different parties or groups called different malware strains and threats whatever Andre Northern over at proof Point says these are called click fix one of the major clusters that I track uh super sweet Mage back and forth and some folks saying hey look yep saw that just a few weeks ago way back on August 20th who said what who's always sharing some really cool stuff includes the very very same lus Steeler with a power shell dropper and even any run link to include so way back on August 20th you can see this Russian Panda seeing the same maybe some folks decoding that Bas 64 squib dooo who we've had on this channel in a video before actually notes hey this is actually apparently tracked as em and Hall includes a orange cyber defense blog so we can take a look at that one a little known loader Distributing commodity info Steelers worldwide commodity that's totally right I'll include the links for this and all the things that I referen in the video description so you can dig down into it a little bit more if you'd like I certainly don't mean to drag us down the rabbit hole for each and every one of these my good friend Jamie Williams over at unit 42 shares the same looks like unit 42 is tracking this just as well they have a pretty cool write up or at least some of the indicators of compromise that show this and look at all the pictures here like they have a S3 bucket that hosts this same exact setup Powershell code that's copy and pasted and communication back and forth over wire shark they show if you take a look at unit 42's link they do have some cool indicators of compromise here this is less of a blog post but more just kind of data dump sharing some of the sweet stuff that they've seen uh did want to get that out if it's interesting or worthwhile for you J Minton who I work with Huntress notes it's kind of similar to this clear fake campaign uh he's actually got a video over on it note that is clear fake though separate different not LL stealer that we've been digging into right now and I know everyone's going to laugh like oh hang on a little bit of a insane asylum setion uh Paradox here there's John there's John Bido token confirms and sees look I've noted that with LMA Steeler all in the action uh some other folks had a cool write up and blog post uh did want to give a shout out to ton Moy who has a sweet article on it the anatomy of a l sealer attack via fake capture Pages really cool because you do get to see some other indicators to compromise or other domains other little artifacts of their infrastructure where you see the same campaign okay now I promise I'm going to get off Twitter but I did want to show you this sweet forensic artifact that another cooworker of mine another teammate at Huntress had shared this is Mike and he says look if you've got an adbl alert for some malicious Powershell with no apparent intrusion take a look at the Windows registry you might be able to see in that user Hive current user if you are locally logged in as that or hku whatever Sid or just the NT user. software Microsoft Windows current version Explorer run mru and you can see if they fell for that capture fake little scam copy paste into the win plus r run dialogue box back in our Windows world if we were to follow through following these verification steps actually copy pasting the malicious payload in we'd be able to see that in back in our registry editor let me get to Reg edit or we could use regge cool right which I would totally recommend link to that on the desktop well let's take a look at my current user software Microsoft Windows this registry path and see if we have a note not that I am logged in as myself so current user is fine but if you needed to you could go to hku rather than hkcu let me paste this in and you can see just about everything that I've ran previously note this mru list value is the one that actually indicates what order you ran each of these in and they're all noted with whatever A B C D going down the list of the alphabet I guess but C being first in our mru list yeah we just ran regit it as you can see cue that follows well remember I use that to open up the bit Locker Discovery volume contents folder these all end with a SL1 trailing but you could see just about all the history and maybe the malicious Powershell command for a victim user sock analyst triage if you're trying to dig into someone that fell for this I think that's a neat little forensics breadcrumb hope that's helpful to you now Mike had shown this to me with another example and another investigative case where we saw this popped in a poor user they included a different encoded Powershell command syntax here so I did want to dig into that one this is the encoded pow shell that was ran for that scenario so let's copy that and see what we can do with it nothing special here let's just B 64 decode as usual paste that in B 64 minus D and with that ooh little bit more Powershell actually being executed ex that invoke expression Alias iwr that invoke web request and a new little lure here we're pulling down an a. text let's see if this is still live let me curl that and it is okay so a little bit more Powershell here for us we've got a web cine object created we can see it's grabbing a URL with a Dango do zip peculiar uh staging that in our temporary directory oh look at that actually sorry uh the digital ocean little droplet that's kind of Hosting this and not to say it's a droplet but some way to host some files up there anyway stores it in our temporary directory in a zip archive downloads it ends up extracting it with expand archive and then stages this setup.exe it's kind of funny to note this is totally an active campaign like I wanted to see this and I kind of tested it last night you can see it was downloading a pelt Gon Do zip and would actually work with a setup.exe without a hyphen there from the same sort of stage or that same IP address and file but we might very well have different things and maybe the setup or setup with a hyphen could be another payload all with the same behavior I wonder if we could try and track those down let's go ahead and see if Dango is still working for us let me W get that yep pulled that down let me stage that into another directory and then I can extract this and oh there is a lot of stuff there okay this is all the very same as to what I saw just previously with the um Pelt gone one if we were to upload Pelt gon or Dango into a quick and easy online sandbox for some rapid analysis let me put that on the desktop I'll include the whole zip so we have all the file Contents I like to use Windows 11 and let's amp up the duration here with that let's try to do some quick Scrappy analysis totally pressing the Easy Button letting the sandbox cover it all here but now that that's starting to fire off we should be able to see here's WinRAR actually working with this let me extract this all to my desktop we can put it in the exact same folder it'll get all the file contents that we just saw as we extracted a moment ago uh a little bit of an error there whining but that's just WinRAR kind of getting staged find now double click on our setup.exe and I don't know how well you can see it there is a little python icon there so odd that it errors at least gives some error message but it's still doing stuff setup.exe is now firing off Str strcmp exe a more.com being staged we can see some connections back and forth here and oh searchindexer.exe kind of being created but what will that do that is one of the natural native Windows binaries right a lot like our bit Locker to go and uhoh oh okay tracking down lumma stealer with our yaah rules big thanks and we can see yep okay even a configuration that it might be able to extract out all the same do shop domains that we saw previous just as well with one of those other artifacts and domains that it took a look at so we didn't have to work too hard here look obviously our online sandbox is helping save the day but if we were to dig into this it's certainly going to do some of the info stealer malware like stuff I did just want to show you that chain I don't think we need to drill down into it but I thought o neat uh injecting into yet another Windows native binary like we saw with our bit Locker to go actually kind of staging some other things in between it like our more.com in this case like our Str strcmp getting dropped into some app data files and folders locations here you can see in the connections and HTTP requests even the uh searchindexer.exe executable the one that looks real legitimate native because it's built into Windows is the one that's trying to communicate with this dotshop random domain obviously exfiltrating data back and forth we can upload Dango dotzip to see the new Stager or whatever other payload came through but I'm going to assume it's probably the very same I don't think there's going to be too much variation in what it's doing here let me extract all this super easy we can just get the same files on our desktop just so we have all of the things that it might have used for its own execution start our setup.exe yeah this also does more.com as an intermediary ooh bacterium punch. a3x isn't a3x is that that's not Auto hotkey though is it that's that's like ahk or something whoa llama of course once again do they have new domains here can we see that uh CFG oh no same exact ones in the config bacterium punch. a3x is still an executable file it probably just yeah ends up being ran as an exe oh and a quick by the way another individual over on the Twitter verse had seen this exact same lumma stealer Stager same sort of setup with Pelt gon sdrc and pxc search iner the same thing that we just saw in the very first one they note PS persistence in run mru I'm not sure so much as persistence other than you opening the Run dialog box again maybe it's still being in your history you need to naturally hit enter on that so not I wouldn't say persistent per se but at least some of the forensic artifacts with that some of the cool chatter and conversation that came from this alongside their any run analysis also notes the very same and then uh they posted my thing and I did want to show you this I know the video is already crazy long but I thought it's neat and I hope you think it's cool too so this was an insomnia project the other day I just thought a lot of the chitchat around this was kind of cutesy I know it's kind of silly being a copy Pac lure but you know what it's obviously apparently working and this is Albin centered around the conversation that we've been having lately it's nothing new right obviously this has seen over and over copy paste clipboard Shenanigans you could get anyone with this but I wanted to recreate it with what looks like a real legitimate capture not the O click button verify your human thing so this is me just kind of putting my hacker hat on I know little toy and trinket but I thought it might be neat uh if I actually go download this code it is something that's public on GitHub so you can play with it just as well if you would like with a recapture fish and let's go show it to you in action I'm going to end up serving this just with a super simple python HTTP server so it looks and simulates like oh some hosted things somewhere out on the internet you don't even have to have that it could just be the local index.html file because of the JavaScript that you saw in the client side code you could change that to run whatever you want but if I were to do some social engineering for a little I don't know pentest engagement red teaming work looks like I've got my I'm not a robot capture that looks as real as I could get it using the actual Google Images linking to the real privacy in terms and when we click the button here it says look complete these verification steps a little bit of a better display than what you saw in the malware and infection chain look press and hold the Windows key and R press contrl V press enter on your keyboard and you'll observe and agree I'm not a robot recapture verification ID 6119 so let me hit that Windows key in R I'll hit contrl V to enter that and I tried to hide this in a cutesy clever way where there is a comment ending or trailing for our malicious command in payload so that way when you paste it in you get the verification text just as you would see in that display and I don't know maybe that'll tricker fool user because they're entering that obviously if you were to move all the way back you can see the next stage in payload where'll use mshta the very similar way but if I enter on this uhoh now we get our recapture firing up trying to connect to a recapture server which it might fail to uh to keep up the charade Google icon but you saw my code EX ution little proof of concept we just popped open the calculator but then you could do whatever you want because you're just having code execution happen by tricking the user into literally copying and pasting dumb stupid cutesy but it would probably work don't forget if you were to hop on to the registry editor you should now be able to see that if I refresh this page there is R added in for my MSHA payload and everything that we just did with our I'm not a robot recapture verification don't forget yet that's a worthwhile forensic artifact and something that you as a security Operation Center analyst your sock analyst anyone else might be able to dig into to see some of these cases against lumma stealer or anything else uh using this fake capture scam lure social engineering with that my goodness this has been a longer video than I intended it to I'm sorry but I do want to showcase all those sweet things and help get some of that education and awareness out for you if you like the video please do all those YouTube algorithm things and please pretty please do give some love to our sponsors I I seriously genuinely hope you attend the security operations center analyst day from dvo I'll be giv a talk there and chatting a little bit about some other investigations we got to dig into some more rapid response stuff and it'll be a ton of fun so all right I'm done rambling I'll see you in the next video take care
Original Description
https://jh.live/soc || Join me for the SOC Analyst Appreciation Day! A completely FREE event on October 16th by DEVO! https://jh.live/soc
https://www.virustotal.com/gui/file/178d8523fa6e5560f59e75acb4d76e4a99d91c7bbf232e02c8763d7f62712d0c
https://x.com/aruhamm/status/1834284068227481682
https://x.com/g0njxa/status/1825940825400029483
https://www.orangecyberdefense.com/global/blog/cert-news/emmenhtal-a-little-known-loader-distributing-commodity-infostealers-worldwide
https://x.com/Unit42_Intel/status/1829178013423992948
https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2024-08-28-IOCs-for-Lumman-Stealer-from-fake-human-captcha-copy-paste-script.txt
https://www.youtube.com/watch?v=z8dLfnReg28
https://denwp.com/anatomy-of-a-lumma-stealer/
https://github.com/JohnHammond/recaptcha-phish
Learn Cybersecurity - Name Your Price Training with John Hammond: https://nameyourpricetraining.com
Learn Coding: https://jh.live/codecrafters
Don't listen to other "influencer" VPN crap -- host YOUR OWN: https://jh.live/openvpn
WATCH MORE:
Dark Web & Cybercrime Investigations: https://www.youtube.com/watch?v=_GD5mPN_URM&list=PL1H1sBF1VAKVmjZZr162aUNCt2Uy5ozAG&index=4
Malware & Hacker Tradecraft: https://www.youtube.com/watch?v=LKR8cdfKeGw&list=PL1H1sBF1VAKWMn_3QPddayIypbbITTGZv&index=5
📧JOIN MY NEWSLETTER ➡ https://jh.live/email
🙏SUPPORT THE CHANNEL ➡ https://jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ https://jh.live/sponsor
🌎FOLLOW ME EVERYWHERE ➡ https://jh.live/twitter ↔ https://jh.live/linkedin ↔ https://jh.live/discord ↔ https://jh.live/instagram ↔ https://jh.live/tiktok
💥 SEND ME MALWARE ➡ https://jh.live/malware
🔥YOUTUBE ALGORITHM ➡ Like, Comment, & Subscribe!
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from John Hammond · John Hammond · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
Tutorials? MySQL connection with PHP and Bash!
John Hammond
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
JavaScript Splits The URL!
John Hammond
HTML Tables in Python!
John Hammond
HTML, Net Shares, GML!
John Hammond
Python 08 Programming Style and Comments
John Hammond
Python 26 Object Oriented Programming
John Hammond
75 Python Tutorials, Out Now!
John Hammond
Batch 14 Mathematical Expressions
John Hammond
Batch 85 Array Append
John Hammond
Batch 86 Array Count
John Hammond
Batch 87 Array Index
John Hammond
Batch 88 Array Insert
John Hammond
Batch 89 Array Remove
John Hammond
Batch 90 Array Reverse
John Hammond
Python [colorama] 00 Installing on Linux
John Hammond
Python [colorama] 09 Cursor Position
John Hammond
Python [hashlib] 02 Algorithms
John Hammond
Python 00 Installing IDLE on Linux
John Hammond
Python [pygame] 11 Rectangular Collision Detection
John Hammond
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
Python [XML-RPC] 01 Research
John Hammond
Python [pyenchant] 03 Personal Word Lists
John Hammond
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
Python 04: PEP8 Coding
John Hammond
Python Challenge! 17 COOKIES
John Hammond
Google CTF 2016: Ernst Echidna
John Hammond
Google CTF 2016: Spotted Quoll
John Hammond
Google CTF 2016: Can you Repo It?
John Hammond
Google CTF 2016: No Big Deal
John Hammond
Google CTF 2016: In Recorded Conversation
John Hammond
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
Homemade CTF Challenge: 04 "UPX"
John Hammond
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
Juniors CTF 2016 :: Six Strange Tales
John Hammond
Juniors CTF 2016 :: Lost Code
John Hammond
Juniors CTF 2016 :: Here Goes!
John Hammond
Juniors CTF 2016 :: Southern Cross
John Hammond
Juniors CTF 2016 :: Clone Attack
John Hammond
Juniors CTF 2016 :: Dirty Repo
John Hammond
Juniors CTF 2016 :: Hackers Blog
John Hammond
Juniors CTF 2016 :: Voting!!!
John Hammond
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
Juniors CTF 2016 :: Stop Thief!
John Hammond
Juniors CTF 2016 :: ROFL
John Hammond
Juniors CTF 2016 :: Restriced Area
John Hammond
Juniors CTF 2016 :: Oh SSH!
John Hammond
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
HackCon CTF 2017 "Bacche" Challenges
John Hammond
More on: AI Security
View skill →Related Reads
📰
📰
📰
📰
Kimi-K3 and GPT-5.6 Are This Powerful. Can Ordinary People Make Money Finding Vulnerabilities Too?
Medium · Cybersecurity
What is tcpdump?
Medium · Cybersecurity
Python Web Penetration Testing — Day 5: Password Testing
Medium · Programming
Python Web Penetration Testing — Day 5: Password Testing
Medium · Cybersecurity
🎓
Tutor Explanation
DeepCamp AI