How YouTubers get Hacked: Redline Stealer

  Рет қаралды 396,423

The PC Security Channel

The PC Security Channel

2 жыл бұрын

A lot of large KZfaq channels were hacked recently to post crypto scams. They tried to hack me too with a 715 MB Redline Stealer. Here's the full story.
Video sponsor: Intezer. Check out analyze.intezer.com/
--
Buy the best antivirus: thepcsecuritychannel.com/buy
Contact us for an cybersecurity audit/test of your business: tpsc.tech/
Sponsor: thepcsecuritychannel.com/spon...

Пікірлер: 771
@randallvargas4457
@randallvargas4457 2 жыл бұрын
"Malware authors *hate* this secret trick!" Hilarious! Thank you for taking the time to help regular users, Leo.
@DemeDemetre
@DemeDemetre 2 жыл бұрын
lol
@stylite1637
@stylite1637 2 жыл бұрын
nah we don't hate these "sectret tricks" since we can hide absolutely everything and bypass every single antivirus
@RubenDeJong1207
@RubenDeJong1207 2 жыл бұрын
they hate a rescue disc more
@stylite1637
@stylite1637 2 жыл бұрын
@@RubenDeJong1207 we get to keep your informations '-'
@RealRandomSmart
@RealRandomSmart 2 жыл бұрын
@@stylite1637 every single antivirus ? geez lol. wait.. are you a malware author lol
@HyperFire
@HyperFire 2 жыл бұрын
Imagine trying to hack someone named the pc security channel
@HanSDevX
@HanSDevX 2 жыл бұрын
and get exposed step by step
@Mario583a
@Mario583a 2 жыл бұрын
Leo: It sounded cool.
@Nogardtist
@Nogardtist 2 жыл бұрын
its most likely a bot programmed to send malware to youtubers mail
@kyouhyung
@kyouhyung 2 жыл бұрын
@@Nogardtist yeah, they could easily compile a script that crawls KZfaq for channels over certain subscriber threshold, and set up a pipeline that compiles the malware and emails with the channel name and send them to the channel's email. Perhaps the initial mail and the reply sent by the channel was the trigger that fires up the pipeline. Obviously they want to minimize the number of specimens sent out instead of spamming them all over the place and risk them being automatically flagged.
@Nogardtist
@Nogardtist 2 жыл бұрын
@@kyouhyung wont making verified email by the brand or company with a mark or something to easier filter out these parasites then lets say a newcomer starts their channel most tutorials or guides are either wasting time or useless they dont give all the problems and tips a creator might face like quality of the videos why algorithm hates small creators ironically they say most updates are for smoll creators safety there bigger problems then the dislike ratio and its comment bots and fake sponsors then what google themselves provide with search results but asking google or youtube directly most likely gonna feel like talking to the void or a bot imagine if in youtube studio there was an option to directly talk them instead relaying on other sites for a chance to get a respond
@mudi2000a
@mudi2000a 2 жыл бұрын
A "contract" that has a size of 750MB should always be a red flag. Regarding the behavioral protection, we have this at work, I'm a developer and it blocks a lot of completely legit tools.
@4.0.4
@4.0.4 2 жыл бұрын
They hope you don't notice because it's packed so small.
@_auser_
@_auser_ 2 жыл бұрын
Talking about a 700mb "word document", is it a good idea to just make a text file just 500mb and just shatters anyone with potato pc when opening it, aka spam E since why not, notepad did crash me at 250mb since my pc isn't the greatest as well, but it's funny and i did ruin my friend's pc, don't worry nothing is damaged the cpu is just broken. This reply is really long and probably as long as 1 paragraph of a wikipedia page
@_auser_
@_auser_ 2 жыл бұрын
Did my KZfaq just crashed?
@HuntingKingYT
@HuntingKingYT 2 жыл бұрын
@@_auser_ at least ur reply isnt tons of E's
@_auser_
@_auser_ 2 жыл бұрын
@@HuntingKingYT but its as big as one wikipedia paragraph
@Draxis32
@Draxis32 2 жыл бұрын
The cheeky scammers be like: "Hey we found this *PC SECURITY CHANNEL* let's try to fish him in!" I would like to have the boldness of these people at least once in my life!
@lIli-ht4hw
@lIli-ht4hw 2 жыл бұрын
@@synthlord6575 how is it cringe
@zsi
@zsi 2 жыл бұрын
This thread is cringe.
@DealsAndDiecast
@DealsAndDiecast 2 жыл бұрын
@@synthlord6575 I’m confused how you’re confused
@zUltraXO
@zUltraXO 2 жыл бұрын
Lmao
@nlx78
@nlx78 2 жыл бұрын
On the other hand, they say a professional cook does not really likes to cook at home on his spare night, you sometimes hear. Or in the case of Seinfeld when he had girlfriends that was a masseuse, but she refused to give him a neck massage. Meanwhile Kramer did get one I believe... kzfaq.info/get/bejne/sLKfZs6TzM27iqc.html
@jackfishthe6th373
@jackfishthe6th373 2 жыл бұрын
I did not know about the large file trick to evade detection! Now I understand the real reason to be wary of large downloaded/unknown files.
@dp6123
@dp6123 2 жыл бұрын
You mean those GB's of torrent download files? This is why torrent is dead.
@anonymousarmadillo6589
@anonymousarmadillo6589 2 жыл бұрын
@@dp6123 Lol
@jmbkpo
@jmbkpo 2 жыл бұрын
@@dp6123 Lol
@LordFlaggy
@LordFlaggy 2 жыл бұрын
@@dp6123 Lol
@reymarckessaguirre5082
@reymarckessaguirre5082 2 жыл бұрын
@@dp6123 Lol
@WilliamDye-willdye
@WilliamDye-willdye 2 жыл бұрын
If your sponsor can analyze compressed files, I suggest they change their "file too big" dialog to tell the user to try compressing the file and resubmitting.
@Steveson
@Steveson 2 жыл бұрын
i actually got hacked few days, ago and my mc afe subscription got over, and i was pretty much downloading a filmora file, and dont know what had happend, my yt an all other accs got data breached online :/, i deleted that file, but im still scared
@ananthakrishnanj
@ananthakrishnanj 2 жыл бұрын
@@Steveson lol who told download cracked
@investfoxy
@investfoxy Жыл бұрын
@@Steveson Immediately change your google and other necessary passwords like Facebook, netbanking passwords, etc
@lokelaufeyson9931
@lokelaufeyson9931 2 жыл бұрын
First rule of security: Dont open EXE files unless they are from a trusted source. If something feels strange or wrong, its usally something bad. Say no thanks and cancel/X out.
@RubenDeJong1207
@RubenDeJong1207 2 жыл бұрын
or/and DELETE! 🗑
@irpnet
@irpnet 2 жыл бұрын
@@RubenDeJong1207 My first rule of security is: unless it came with Windows, don't trust it! And even if it did, still don't!!
@Ethorbit
@Ethorbit 2 жыл бұрын
First rule of security: don't store your precious data on Windows
@shib5267
@shib5267 2 жыл бұрын
first rule of security: just don't
@greenicalgaming
@greenicalgaming 2 жыл бұрын
First rule of security: n o
@CaptainXLAB
@CaptainXLAB 2 жыл бұрын
Another short trick you can use without hex editor, is to compress the exe by using Windows's built in NTFS compression. If it's full of zeros, the file size should show Size 700MB or whatever, and then Size on Disk will be something around 100 KB. I'm quite sure that the zip file in that download is also a few 100 KB as well due to compression, and 4 files more than 700 MB each in a zip which is barely a few KB is also a dead giveaway of something being very wrong. Nice video as always :D
@joemama3372
@joemama3372 2 жыл бұрын
Great tip! Thank you!
@themasterofdisastr1226
@themasterofdisastr1226 2 жыл бұрын
The ZIP-Archive he downloaded was shown as only ~400 kb, which was a pretty clear indicator the the file was bloated w/o any other tricks.
@rockon7478
@rockon7478 2 жыл бұрын
@@themasterofdisastr1226 yo bro
@SmoggyLambGG
@SmoggyLambGG Жыл бұрын
VirusTotal still wouldn't take the file in regardless of compression tactics. Besides that, the original zipped files are still encrypted.
@goldenhate6649
@goldenhate6649 Жыл бұрын
The point isn’t to get the antivirus to find it. The point is to be able to see its a bloated file which is a dead giveaway of a virus program. An executable shouldn’t compress very much as it should have lots of important, non-compressing calls
@jubrajtoolsie680
@jubrajtoolsie680 Жыл бұрын
The part where he got rid of the blank spaces which were only there to fill space to make the malware undetectable was mind blowing!
@RockTheCage55
@RockTheCage55 2 жыл бұрын
Would be interesting to see what happens when you actually execute it with different AVs (especially windows defender :) )
@joemama3372
@joemama3372 2 жыл бұрын
Try it and tell us! 😉
@whocares7078
@whocares7078 2 жыл бұрын
Windows defender is shit You sadly are fucked if you solely rely on anything microsoft makes XD
@KyngD469
@KyngD469 2 жыл бұрын
@@whocares7078 cringe
@richards1213
@richards1213 2 жыл бұрын
Happend to me you don't want that 😅
@dangerr_xlmao1317
@dangerr_xlmao1317 2 жыл бұрын
@@whocares7078 windows defender is honestly underrated because most people think that Microsoft software is pure trash.
@DarkDonnieMarco
@DarkDonnieMarco 2 жыл бұрын
I learned more about malware analysis in this video than the entire module on it in my masters in cybersecurity
@Shocker99
@Shocker99 2 жыл бұрын
Have you just started to make these types of videos? I don't know why but it feels like you have more credibility because of them. I've watched some of your Antivirus A vs Antivirus B type videos in the past and always wondered if it was unbiased or paid by a company content.
@108kitsune
@108kitsune 2 жыл бұрын
Lots of facecam lately interesting change
@SriHarshaChilakapati
@SriHarshaChilakapati 2 жыл бұрын
That's an interesting trick you showed there! I've seen people embedding malware in bmp images and share a screensaver which will load executable from this bmp image, but this just blasting the size with zeroes is totally new. A question though: when you just select the zeroes and simply delete them, wouldn't that render the PE file invalid? Won't moving the offsets cause issues with the loader?
@randomdude12370
@randomdude12370 2 жыл бұрын
I'm not qualified to answer, but guess would be because it's essentially dead space, it shouldn't effect the program, which is why he just did a general delete of the zeros and didn't fine time it
@inwoner7190
@inwoner7190 2 жыл бұрын
@@randomdude12370 It must be for the same reason they could add all the zeros just in that place, the program is behaving the same anyway
@blogspoto
@blogspoto 2 жыл бұрын
The zeros were after the main PE sections, in between let's say the .rsrc section and the overlay(the zeros could also be in the overlay or in their own custom named section) and they don't affect any offsets as no code or data points to that zero section, and the overlay is mostly for display(most RedLine payloads use corrupted certificates from big companies to try to further deceive the user into executing the payload). Any other offset used by the program's internals is calculated at runtime with regard to the image base and different srctions in the PE.
@Alkaris
@Alkaris 2 жыл бұрын
You can take this to a Linux machine and run an audit on the EXE file itself and examine its contents all just the same with a disassembler tool for reading Windows EXE files. It be a safer environment for scanning them too, or inside of a VM works also. Also I think its foolish for AVs to have a file size limit for scanning files if you can just bloat the file with zeros to bypass scanning checks.
@monchete9934
@monchete9934 2 жыл бұрын
They do it because scanning huge data takes longer and it's vulnerable to zip bombs or people sending huge packets to cause a server outage
@jugertmucoimaj9017
@jugertmucoimaj9017 2 жыл бұрын
its a pain in the ass to develop a code to scan large files, the thing is even malware coders evade bloating with gibberish data since they are heavier to transport, you can easily write a way less file to transport easy and do what it has to do being fast and delete itself.
@adriancoanda9227
@adriancoanda9227 2 жыл бұрын
most have such limit but it can be disabled actually that setup is for low performance hardware imagine if you would remove the limmit a pc with a 1 5 ghz and 4 ram would become unresponsive freze on high end flagships you will have diffrent features than on low resources so most infected machines are those that are not that performant, on high end hardware you will have hardware av wich will bloch the execution if the code is not a standard behavior rootkit won't even run at boot times due to secure boot deep is als there and on some motherboards they have also a special procesor for pre processing the code and only valide code is passed to main cpu such configuration is bulet prof
@suhail-msk
@suhail-msk 2 жыл бұрын
Didn't expect your face reveal
@thegreatboomhauer6794
@thegreatboomhauer6794 2 жыл бұрын
this is your best video, actually showing us the forensics of a malware. WOW
@ToddSweeney341
@ToddSweeney341 2 жыл бұрын
Thanks for the post Leo.First Time giving a post on your channel.One of the best Security Channels
@BurhanRana
@BurhanRana 2 жыл бұрын
Straight away subscribed. This is the first video i watched from you and loved it.
@Aci_yt
@Aci_yt 2 жыл бұрын
I fell for one of these once, kind of sad this has become such a popular thing now..
@jello3064
@jello3064 2 жыл бұрын
did you actually run the file or no
@Aci_yt
@Aci_yt 2 жыл бұрын
@@jello3064 yes, but it wasn't a contract like here, but instead a game demo
@pengwino828
@pengwino828 2 жыл бұрын
@@Aci_yt Any game that comes with no textures are dll files are fake because then it couldn't display anything
@Aci_yt
@Aci_yt 2 жыл бұрын
@@pengwino828 it supposedly was the installer
@pengwino828
@pengwino828 2 жыл бұрын
@@Aci_yt wow, they really thought that far ahead. At least you got your channel back.
@bennysh
@bennysh 2 жыл бұрын
I had no idea about the size limit. thanks for the heads up.
@RyanCGames
@RyanCGames 2 жыл бұрын
That's very interesting that they stuffed the file with 0's to inflate the size! A bit clever, but not clever enough to trick you! Also, cool to see you also using a Shure MV7 since I got the silver one on Black Friday!
@Alberos
@Alberos 2 жыл бұрын
Wow, this is the oldest trick in the book and it still work.... Changing the icon of an exe to something like Word or folder. Windows hiding the known file extension by default doesn't going to help either. And now we are starting to have people that doesn't even know what is "drive" and "file" is...... things are about to get worst from here haha
@4.0.4
@4.0.4 2 жыл бұрын
Zoomers are the new Boomers. We gotta help them so they have basic tech skills and aren't vulnerable.
@Yousie6
@Yousie6 2 жыл бұрын
thats implying the mid 2000's weren't god awful haha limewire ruined so many pcs
@nettack
@nettack 2 жыл бұрын
Adding to the IT illiteracy comes, that people just want to monetize themselves on YT without merit or talent on "character" alone. And who can blame them, once the Pauls succeeded with this crap. Be vigilant, but if you get screwed over, maybe it's time for a real job.
@kyouhyung
@kyouhyung 2 жыл бұрын
Gotta have to admit, that file size trick was quite clever.
@CeilingPanda
@CeilingPanda 2 жыл бұрын
Yes please more of these, even if I'm quite techy it's super good to have these types of videos to send to others! :)
@joemama3372
@joemama3372 2 жыл бұрын
Agree! More!
@silentmajority8518
@silentmajority8518 2 жыл бұрын
Thanks for this video. I was wondering HOW ON EARTH these ppl got around 2FA recently. Now I know. Great info.
@Mario583a
@Mario583a 2 жыл бұрын
And knowing is half the battle.
@ifur
@ifur 2 жыл бұрын
I love how calm you are while dealing with malware
@orbitalonyx
@orbitalonyx 2 жыл бұрын
For real if I get a virus I would probably breakdown or something idk I have bad anxiety lol
@kamilo1175
@kamilo1175 2 жыл бұрын
He was probably in a VM
@orbitalonyx
@orbitalonyx 2 жыл бұрын
@@kamilo1175 yeah most likely pretty much every person that deals with stuff uses vm
@malwaretestingfan
@malwaretestingfan 2 жыл бұрын
@@kamilo1175 Indeed, or he's just experienced, or even both.
@roguewasbanned4746
@roguewasbanned4746 2 жыл бұрын
@@orbitalonyx I trust people and download files all the time, and that’s why I get nervous even when I know someone is on a VM. I do creative projects with people, so you just have to hope no one gets hacked or sends anything malicious 🙃
@Diarmuhnd
@Diarmuhnd 2 жыл бұрын
Thanks for the info digital science guy on the PC Security Channel (sorry, don't know your name or nickname) Have fun and be safe.
@ChodaBoyUSA
@ChodaBoyUSA 2 жыл бұрын
Is this threat part of your test suite? If not, do you plan to add it? It would be nice to know how well the big name security products handle it. Would any antivirus software have protected those KZfaqrs?
@SCH4LK
@SCH4LK Ай бұрын
really interesting video. Really really awesome. If I want to investigate these type of malware do you recommend doing it in a safe environment like tailsOS or a VM in a VM?
@harrisonnjenga777
@harrisonnjenga777 2 жыл бұрын
I wondered for long when you would put a face behind the brilliant work you do and you did.Thanks alot for the tip
@GeorgeMcCoy
@GeorgeMcCoy 2 жыл бұрын
This is one of the best KZfaq videos that I've seen in a long time. Thanks for sharing this.
@ayden8901
@ayden8901 2 жыл бұрын
What antivirus do you personally use? Of course I've seen your tier list but I'm super curious to know what you use on your machine
@elevul
@elevul 2 жыл бұрын
Linux probably
@spritzerland658
@spritzerland658 Жыл бұрын
@@elevul huh???????????
@thebritishindian1
@thebritishindian1 2 жыл бұрын
Great explanation, thanks. Given the size limitation of virus checkers, how can you check those big applications that you download from genuine companies, just in case they’ve been compromised without knowing? It would’ve been great if you could have executed the file anyway and showed how the virus checker would’ve handled it.
@goldenhate6649
@goldenhate6649 Жыл бұрын
Pup finders tend to do a better job at this. Most antivirus’s now are just bloatware sadly.
@GrenPara
@GrenPara 2 жыл бұрын
Good video, thanks for making it. Where do you get pestudio from?
@ADVANCEDLEVELAUTO
@ADVANCEDLEVELAUTO 2 жыл бұрын
Wow! Great video! My channel was recently hacked because I opened an attachment similar to this one. I posted a video a few days ago explaining how it happened and how I was able to get my Gmail account back the same day. Crazy stuff! I’m way more cautious now.
@tvathome562
@tvathome562 2 жыл бұрын
Love this kind of content how to actually analyse, run sandboxes and what antiviral software to use.
@jamesedwards3923
@jamesedwards3923 2 жыл бұрын
You explained it well. So I have a question. Avast or Malware Bytes? I prefer Malware Bytes.
@alipetuniashow
@alipetuniashow 2 жыл бұрын
Thanks for the video, it really helps with malware analysis for beginners
@BasedF-15Pilot
@BasedF-15Pilot Жыл бұрын
Based on the train reflection in your mirror you live in Boston, or the UK also has some silver trains with 2 windows per car.
@SealedSaucer
@SealedSaucer 2 жыл бұрын
I got 2 of these mails the previous month. And one today. Was wondering what was happening and then this video popped up in my recommendations.Thanks man, really appreciate it.
@blakegriplingph
@blakegriplingph 2 жыл бұрын
Which reminds me... Ever since mods for the indie beat-em-up game Sifu came out, there's been a rash of scam channels taking advantage of people's gullibility by posting videos purporting to offer skin mods for the game, only for the link to be a scam site leading to what may be malware similar to this.
@ardeof
@ardeof Жыл бұрын
I'm curious, since when did Antivirus decide not to scan a file based on size? I remember scanners taking HOURS to scan. Why did they shuffle to "oh 10 minute scans are superior, even if we miss the actual virus"?
@jhudieltheone308
@jhudieltheone308 2 жыл бұрын
When KZfaqrs got hacked. The Hacker Takes Control of their KZfaq Channel and Stream Cryptocurrency Scams. So that's why youtubers are getting really hacked. thanks for this very informative video.
@wolfbrave4866
@wolfbrave4866 2 жыл бұрын
Learning from your channel I use Intezer to analyze a small file with the extension .doc inside a password zip folder seems like it's a very popular technique of putting files inside a password lock zip file. Intezer reported the file as malicious. 🤣 Question can a windows type malware infected an android device if it's unpack using an android device? Yes it's the doc file but I did not execute or open it just extract and submit directly to intezer.
@tahafayed4843
@tahafayed4843 2 жыл бұрын
are you using a filter or is your skin just so smooth?
@jhawk3547
@jhawk3547 2 жыл бұрын
An awesome presentation! How is the 2FA data communicated back to them Leo?
@SidTheGeek
@SidTheGeek 2 жыл бұрын
Given the fact that so many people who are on YT are also not familiar with TECH and its related issues. hackers even can get a grip off experienced users
@lechendary
@lechendary 2 жыл бұрын
idk why but your mouse movement is satisfying
@himalayan_souls
@himalayan_souls 2 жыл бұрын
Very useful information! Thanks for sharing 🙂. Please make more videos like these in which you showed use of hex editor and studio thing in these situations or if there are any simple tool like these for analysis. If possible please also show any tool that can be used in linux and android app in which we can check which app is using internet from backend. Keep it up!🙏👍
@Daxter250
@Daxter250 2 жыл бұрын
this is like the lockpicking lawyer getting a package of a lock that says "unpickable".
@Voreoptera
@Voreoptera 2 жыл бұрын
You barely explained why no one would notice that the docx file is an exe file, especially if it show file extinctions is enabled(hate Microsoft for disabling this by default). The attackers did not even bother adding docx to trick some users.
@Mario583a
@Mario583a 2 жыл бұрын
It's part Microsoft - part stupid people renaming the file _including_ the extension and complaining why Office won't load their files.
@cestmamin
@cestmamin 2 жыл бұрын
This is Cyber Security class in a KZfaq video
@ScyHigh
@ScyHigh 2 жыл бұрын
Something I'm curious about, mainly with that scam in particular. Would the same thing happen with all the versions, regardless of sub count? do they all have the same code inside, just possibly inflated differently?
@alittax
@alittax Жыл бұрын
I'd like to ask you about this part: 2:10 When I download something, the first thing I do is right-click the file and have my antivirus (Bitdefender) scan it. Does this practice give me good enough protection if the file isn't password protected? Also, are you saying that a file above 700 MB is not automatically scanned by any locally installed antivirus program? Thank you.
@Fatman305
@Fatman305 Жыл бұрын
I'm pretty sure he was wrong about antivirus software skipping large exe's (or similar).
@dennisjungbauer4467
@dennisjungbauer4467 Жыл бұрын
I'm curious about how you can just remove data via hex-editing, especially in the middle of the file. My experience, at least with editing game files, has been that this will break things due to the offsets not being correct anymore. Is it just not a problem for analyzing the file and the program will actually not work anymore? I would expect there to be an offset specifying where the actual code starts as well.
@Stoner_mtl
@Stoner_mtl 2 жыл бұрын
that's why you need second opinion scans like Hitman Pro Alert
@F599
@F599 2 жыл бұрын
Hey, I have a quick question on a program that I've been using for a while its called Sandboxie and it's a program that runs other programs in a sandboxed environment, I would like to know if such a program could in theory protect most computers from unknown programs from my real machine. and maybe an opinion whoever used could help me also.
@demi1790
@demi1790 2 жыл бұрын
Hi sir. Can i ask some question regarding redline stealer. Does this malware exfiltrate datas from all IM clients that is installed in the PC or just some random im clients, and does it steal all the datas from desktop and documents folder? Hope to hear from you. Thank you
@menone8532
@menone8532 2 жыл бұрын
Leo, have you done a how to regarding running a vitural pc? If so I'm not finding a vid. Too many vids out there with the wrong info, missing info, ect. While I have built my own system's for 20 years, know networking well, this eludes me a bit. I've tried it, cant get it work.
@DenJaVlogs
@DenJaVlogs 2 жыл бұрын
thanks brother that was very informative. I just wanted to know will someone youtube be hacked even if they have a google key. Meaning you need to mandatorily connect your key(which is a USB) in order to open you youtube or gmail or facebook account
@Fatman305
@Fatman305 Жыл бұрын
Yes. If you execute malware they can hijack sessions, spy on you indefinitely, etc. That's how they defeated Linus's hardware keys.
@chupathingy5862
@chupathingy5862 Жыл бұрын
That's actually pretty genius, jamming a bunch of zeroes in the middle.
@S2eedGH
@S2eedGH 2 жыл бұрын
Great Content, I see Professional KZfaqr has compromised I don't know is it by this malware or not. My question is, if he was enabled 2FA does the attacker have the ability to bypass it?
@memetech-
@memetech- 2 жыл бұрын
man, all that blank space is really taking up a lot of space. it's really important though...
@ThatTransistorGuy
@ThatTransistorGuy Жыл бұрын
Antivirus programs should have options to prioritize detection accuracy, rather than performance. I think avast has some options to scan entire files, regardless of size (if my memory serves me well). If you guys are testing malware, make sure you use a low privilege standalone vm.
@Stuff1646
@Stuff1646 2 жыл бұрын
I suffered from the exact same malware tho instead of exe, the attacker had used chrome extension that had great reputation, and reviews so were hard to determine if it was malicious or not. Oddly enough after 2 months it had remotely installed redline stealer along with some other nasties and later on kicked off the chrome store.
@joemama3372
@joemama3372 2 жыл бұрын
Wow... From a Chrome Extension that seemed legitimate and good reviews.. I'm often suspicious of Extensions for browsers, Google Office and MS Office products..
@Stuff1646
@Stuff1646 2 жыл бұрын
@@joemama3372 Should also be suspicious about PlayStore apps as Google doesn't do good job when it comes to auditing.
@Fatman305
@Fatman305 Жыл бұрын
Which is why I trust only extensions that have been available for 2+ years, and have plenty of downloads and plenty of reviews. Very easy to get a few hundred fake reviews.
@kminek6548
@kminek6548 2 жыл бұрын
Your content is so helpful with avoiding any malware, I wish you get more subscribers and views so you reach to more people
@yssjc1414
@yssjc1414 2 жыл бұрын
The ".scr" file, like in 1:53, was used to hack the crypto assets of streamers here in the Philippines.
@Mario583a
@Mario583a 2 жыл бұрын
I always knew something was off with that Pipe Dream screensaver....
@AlfiesFuntime
@AlfiesFuntime 2 жыл бұрын
That's a screensaver file...
@AlfiesFuntime
@AlfiesFuntime 2 жыл бұрын
@@nevergonnagiveyouup4189 I didnt know that, I thought they were limited to animations
@AlfiesFuntime
@AlfiesFuntime 2 жыл бұрын
Oh gosh does that username have RTL in it or something? Edit: it only appears weird on mobile
@Ayaan13550
@Ayaan13550 2 жыл бұрын
@@AlfiesFuntime why did you write backwards
@TechXTech91
@TechXTech91 2 жыл бұрын
I recently got hit in a very strange way. They changed my channel logo, they changed my channel name, they private it a bunch of random videos, not everything just a bunch of randomly picked ones, and then they started live streaming a crypto scam Strange thing though is my two-factor authentication was never triggered, and I looked at logged in devices on my Google account, and the only ones that were logged in were my personal computer, my work computer, and my cell phone. So I couldn't kick them off that way either. I have no idea how they got in. Hadn't recently downloaded anything that I would think would be malicious.
@TechXTech91
@TechXTech91 2 жыл бұрын
@Appu26j wouldn't some sort of cookie stealer need to be used though? Work computer was a Mac, windows computer that was powered off since I wasn't home and an Android phone not rooted or anything sideloaded/modded apps
@TechXTech91
@TechXTech91 2 жыл бұрын
@Appu26j at the time it occurred, the live stream they were doing I searched the title of and noticed there were about a dozen other KZfaq channels streaming the same thing. It was some Bitcoin scam. I could understand exploiting live streaming with something like somehow guessing the stream key, but it's so long and convoluted I highly doubt that. Also if you guess the stream key that doesn't give you access to change things like channel name private videos and change channel layout
@gb-channel1880
@gb-channel1880 2 жыл бұрын
Good to know. I once programmed a logger for my pc when people who used to borrow my pc and I made it absolutely clear that I had installed a logger when they wanted to borrow my pc. After that no one borrowed my pc.
@RetNos0
@RetNos0 Жыл бұрын
lol
@kenpachizaraki4184
@kenpachizaraki4184 2 жыл бұрын
Would deleting the file, and doing a system restore to revert back be sufficient in ridding the threat? Im trying to avoid a clean wipe. Edit: actually, i extracted the contents, saw an .exe but ever ran it though. There's no reason a company offer should supply an exe.
@NickBush24
@NickBush24 2 жыл бұрын
Damn that's the mother of all NOP slides
@Adrain45175
@Adrain45175 2 жыл бұрын
What about free/open source HIDS vs this types of malwares? It works better than regular av?
@xelspeth
@xelspeth 2 жыл бұрын
If only there was some sort of checkbox you had to click on files before they are allowed to execute and otherwise warn you that they don't have permissions to be executed so you can't mistake an executable with a word document icon for a word document 😔
@nitheshhk2744
@nitheshhk2744 2 жыл бұрын
Thanks a lot very informative Please make a video on whether the pc has been already hacked or not How to find
@CoolJosh3k
@CoolJosh3k 2 жыл бұрын
I expect some antivirus software would check for padding with zeros (or similar patterns) right, then analyse the result after this is stripped away?
@imtheconstitution1190
@imtheconstitution1190 2 жыл бұрын
Looking at the name of the virus at 6:37 this is a Chinese god’s name, “yanluowang” 閻羅王, a god that manages afterlife world for mortals ( sort of similar to Hades)
@matiinb
@matiinb 2 жыл бұрын
One thing that is not good is that some people don't enable that checkbox for showing file extensions and when they download such a file, they say "Oh ok this is a normal Word document, isn't it?" and they open it...
@whatdoyouthinktodd
@whatdoyouthinktodd 2 жыл бұрын
So I'm not that tech savvy and you mentioned maybe Windows defender wouldn't be strong enough for other things may not be strong enough to figure out what's wrong with this file what would be what software do we need to have that would work do you have any suggestions anything will help thank you.
@Reeegon
@Reeegon 2 жыл бұрын
would you recommend the google usb stick for access and security?
@mdriz1353
@mdriz1353 Жыл бұрын
So, If hypothetically my dad opens such document while Bitdefender total Security is active, Shouldn't that stop it? I get it won't get scanned initially for being 750 Mb but as soon as it launches any decent Av should be able to stop it right?
@Akotski-ys9rr
@Akotski-ys9rr 2 жыл бұрын
I did not know that most anti viruses don’t scan large files but now that I think about it, it makes sense
@Nullifys
@Nullifys 2 жыл бұрын
So this is what security research is. I like this alot
@airfixer9461
@airfixer9461 2 жыл бұрын
Great video Leo, thanks for the warning 🙂
@ChiragHasyagar
@ChiragHasyagar 2 жыл бұрын
Do conventional Anti Virus software like Kaspersky/Bitdefender with malware protection not detect large files like this. Or is this for typical low level software only?
@Mario583a
@Mario583a 2 жыл бұрын
Oh, antiviral software do indeed detect this, it's just....if a file is behind a password protected thingy, no dice.
@rayrussell6258
@rayrussell6258 2 жыл бұрын
if the security systems we use are limited in size of file it scans, then why don't they break down the file into smaller chunks, to be scanned. Surely they could design something that deletes all the repetitive zeros, and then put files back together, before scanning. (similar to how you manually did it) I'm not a programmer, but that seems like the way to eliminate scammers like this.
@tronghungnguyen8716
@tronghungnguyen8716 2 жыл бұрын
A single repeatitive 0s is easy but once it gets to repeatitve sequence that just impossible to split and detect easily
@rayrussell6258
@rayrussell6258 2 жыл бұрын
@@tronghungnguyen8716 to my thinking, not really; break it into equal parts, doesn't matter where the zeros are, then look for all zeros in each part. When done, put it back together and run the scan. Just like he did manually.
@rayrussell6258
@rayrussell6258 2 жыл бұрын
@@Emilia-fl5ii I'm not a programmer, but I still say you can break any file apart anywhere you like, scan the smaller files, and then put them back together again. If he could do it manually, it can be done in whatever software code they used, and look for patterns. Whether or not they used 0's or "junk" might make it harder to figure out the malicious intent, it doesn't stop the ability to do the scan; he said file size is preventing the scan, so that's where I said it should start, rather than leaving users totally exposed. As with most things new, people lose sight that you can't take step 2 until you take step 1.
@rayrussell6258
@rayrussell6258 2 жыл бұрын
@@Emilia-fl5ii Well, look back then; the original poster broke the file apart, eliminated the 0's, put it back together, ran the virus scan on smaller file, all that manually. I read what you say, and see nothing you say that overrides what he did manually, meaning it should be possible to replicate his manual process. I wish he would come back in to the thread and get in this discussion with you. As I said, I'm not a programmer. However, on my job, I was usually the designated spec writer, working with programmers, who automated our manual reports. We never found anything that couldn't be done with software. Took time occasionally to get the right software, but nothing stopped us. I think this situation is a hole not being fixed. It's fixable, somehow. Address further questions to the original poster please, not me. You two can talk it out, I'll read your discussion with him.
@rayrussell6258
@rayrussell6258 2 жыл бұрын
@@Emilia-fl5ii Again, I said talk the technicals with the original poster, not directly to me. But from my point of view, if someone can do it manually, then it's do-able with programming. At least it would make it more difficult for the hacker to do mischief. Enough said.
@grast5150
@grast5150 2 жыл бұрын
Great Video. I always like to see new tools and products than what currently using.
@aayushkarulkar107
@aayushkarulkar107 2 жыл бұрын
Me seeing Mrwhosetheboss channel in the thumbnail: "Wait what He's Channel got hacked!!!!!???" After all UK's Largest Tech youtuber
@talksalot7562
@talksalot7562 2 жыл бұрын
I mean.. he got hacked a few years ago-
@talksalot7562
@talksalot7562 2 жыл бұрын
but I'm shocked that he is on the thumbnail on this vid...
@lewiskelly14
@lewiskelly14 2 жыл бұрын
Why did you use different online services before and after removing the middle space????
@ajaykumar1
@ajaykumar1 Жыл бұрын
1:18 here is, you can change ending the parameter of link where "?dl=1" to ''?dl=0" you can see the content of zip file on browser before download (I'm suggesting you, that you should use TOR browser)
@TzZek
@TzZek 2 жыл бұрын
What interface are you using with the MV7?
@sa8212
@sa8212 Жыл бұрын
Hello, Unfortunately, I fell victim to one similar large size file, do you know what i supposed to do to overcome such condition? Currently, to remedy this problem, I've used (McAfee stinger+windows defender system) and both detected some high threats and either remove or quarantined those viruses. Do you think that would be enough? Thanks
@javiTests
@javiTests 2 жыл бұрын
Thank you for sharing! Quick question... How would they bypass the 2-factor authentication? Even if they force you to log in again, steal passwords and the 2-factor value, when they go and use those credentials they will need to type another 2-factor value, right? That they don't have... 🤔
@flyhtz
@flyhtz 2 жыл бұрын
u log in and it makes a cookie and when u exploit a cookie by injecting it (if u really wanna know and want an example id look up how to log into discord using discord token its the exact same) because when u inject a cookie the device/account thinks: "oh hey i know this one he doesnt need to do 2FA cuz i trust him :D"
@nickwoodward819
@nickwoodward819 2 жыл бұрын
but that trust wouldn't extend to sensitive operations like password changes? So how would they steal the account/lock you out?
@javiTests
@javiTests 2 жыл бұрын
@@flyhtz Aren't cookies linked to specific devices? If not, yes, that's quite a big security hole!
@flyhtz
@flyhtz 2 жыл бұрын
@@nickwoodward819 no it would not but as soon as they have the cookie they can change the password and email
@flyhtz
@flyhtz 2 жыл бұрын
@@javiTests they are not they are linked to browsers so u can inject them
@YANCEYLIFTS
@YANCEYLIFTS 2 жыл бұрын
I got hacked in december but luckily i got it back they were able to look at my ip address being signed in from a diffrent state . crazy thing about it is i didnt even click any emails or download and malware
@frankbaron1608
@frankbaron1608 2 жыл бұрын
wasn't there a jump instruction in there or does the malware just passthrough all the nops?
@fatrat600284
@fatrat600284 5 ай бұрын
Hackers tries to hack The PC Security Channel Random hacker: "Why do i hear boss music?"
@LLoydL
@LLoydL 2 жыл бұрын
I have a question..sorry I'm no expert..but let's just say I have subscribed to a decent/topnotch AV software..say, Kaspersky..and the noobest of all noob/stupid mind that I have still went for the executable..would the AV slap my wrist and stop me from running the disguised malware?
@thrices4372
@thrices4372 2 жыл бұрын
Can you tech us the best practice on how to make a virtual window to test virus and malware.
@AtariKafa
@AtariKafa 2 жыл бұрын
best antivirus is yourself...
@ITSN3GAN
@ITSN3GAN 2 жыл бұрын
hey, question for you, real great content by the way. I was one of the content creators hacked by basically this same thing. I wiped my computer and i HOPE i got it all lol wondering what I can do to make sure I'm safe, I am so paranoid now and it has been a stressful situation. Thanks
@ITSN3GAN
@ITSN3GAN 2 жыл бұрын
@Appu26j I didn't do it on purpose lol I was one of the content creators that was tricked by the collaboration proposal emails about doing an ad for a game (more than 15k content creators got hit) Normally I ignore spam but this one seemed legit as the last one that seemed sketchy was legit and made a decent amount of money from doing it so it seemed like it was possibly real .......... Guess it wasn't 🤣
The Latest YouTube Malware Scam
27:09
John Hammond
Рет қаралды 114 М.
Malware in Google Ads: Fake OBS, VLC, Notepad++
9:56
The PC Security Channel
Рет қаралды 240 М.
Когда на улице Маябрь 😈 #марьяна #шортс
00:17
Teenagers Show Kindness by Repairing Grandmother's Old Fence #shorts
00:37
Fabiosa Best Lifehacks
Рет қаралды 40 МЛН
Surprise Gifts #couplegoals
00:21
Jay & Sharon
Рет қаралды 33 МЛН
NO NO NO YES! (50 MLN SUBSCRIBERS CHALLENGE!) #shorts
00:26
PANDA BOI
Рет қаралды 92 МЛН
Is Valorant Spyware?
8:15
The PC Security Channel
Рет қаралды 668 М.
FAKE Sponsors are trying to get YouTubers HACKED!
7:17
No Text To Speech
Рет қаралды 192 М.
Top 5 Most Dangerous Ransomware
13:12
The PC Security Channel
Рет қаралды 205 М.
This Discord Server Controls my PC (with Malware)!
8:07
No Text To Speech
Рет қаралды 996 М.
Fake OBS Studio Hack Targeting YouTubers
31:19
John Hammond
Рет қаралды 347 М.
discord's dumbest update...
10:37
No Text To Speech
Рет қаралды 220 М.
Simple Javascript Decoding and C2 Extraction (Redline Stealer)
4:43
СЛОМАЛСЯ ПК ЗА 2000$🤬
0:59
Корнеич
Рет қаралды 2,5 МЛН
Он Отказался от БЕСПЛАТНОЙ видеокарты
0:40
ЖЕЛЕЗНЫЙ КОРОЛЬ
Рет қаралды 2 МЛН
The power button can never be pressed!!
0:57
Maker Y
Рет қаралды 44 МЛН
🤖Вернулись в ПРОШЛОЕ🤪
0:28
Demin's Lounge
Рет қаралды 60 М.