How YouTubers get Hacked: Redline Stealer

แชร์
ฝัง
  • เผยแพร่เมื่อ 1 ต.ค. 2024
  • A lot of large TH-cam channels were hacked recently to post crypto scams. They tried to hack me too with a 715 MB Redline Stealer. Here's the full story.
    Video sponsor: Intezer. Check out analyze.inteze...
    --
    Buy the best antivirus: thepcsecurityc...
    Contact us for an cybersecurity audit/test of your business: tpsc.tech/
    Sponsor: thepcsecurityc...
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 775

  • @randallvargas4457
    @randallvargas4457 2 ปีที่แล้ว +1394

    "Malware authors *hate* this secret trick!"
    Hilarious! Thank you for taking the time to help regular users, Leo.

    • @DemeDemetre
      @DemeDemetre 2 ปีที่แล้ว +5

      lol

    • @stylite1637
      @stylite1637 2 ปีที่แล้ว

      nah we don't hate these "sectret tricks" since we can hide absolutely everything and bypass every single antivirus

    • @RubenDeJong1603
      @RubenDeJong1603 2 ปีที่แล้ว +1

      they hate a rescue disc more

    • @stylite1637
      @stylite1637 2 ปีที่แล้ว +1

      @@RubenDeJong1603 we get to keep your informations '-'

    • @RealRandomSmart
      @RealRandomSmart 2 ปีที่แล้ว

      @@stylite1637 every single antivirus ? geez lol. wait.. are you a malware author lol

  • @HyperFire
    @HyperFire 2 ปีที่แล้ว +1587

    Imagine trying to hack someone named the pc security channel

    • @HanSDevX
      @HanSDevX 2 ปีที่แล้ว +234

      and get exposed step by step

    • @Mario583a
      @Mario583a 2 ปีที่แล้ว +34

      Leo: It sounded cool.

    • @Nogardtist
      @Nogardtist 2 ปีที่แล้ว +56

      its most likely a bot programmed to send malware to youtubers mail

    • @kyouhyung
      @kyouhyung 2 ปีที่แล้ว +29

      @@Nogardtist yeah, they could easily compile a script that crawls TH-cam for channels over certain subscriber threshold, and set up a pipeline that compiles the malware and emails with the channel name and send them to the channel's email. Perhaps the initial mail and the reply sent by the channel was the trigger that fires up the pipeline. Obviously they want to minimize the number of specimens sent out instead of spamming them all over the place and risk them being automatically flagged.

    • @Nogardtist
      @Nogardtist 2 ปีที่แล้ว

      @@kyouhyung wont making verified email by the brand or company with a mark or something to easier filter out these parasites
      then lets say a newcomer starts their channel most tutorials or guides are either wasting time or useless they dont give all the problems and tips a creator might face like quality of the videos why algorithm hates small creators ironically they say most updates are for smoll creators safety there bigger problems then the dislike ratio and its comment bots and fake sponsors then what google themselves provide with search results but asking google or youtube directly most likely gonna feel like talking to the void or a bot imagine if in youtube studio there was an option to directly talk them instead relaying on other sites for a chance to get a respond

  • @Draxis32
    @Draxis32 2 ปีที่แล้ว +944

    The cheeky scammers be like:
    "Hey we found this *PC SECURITY CHANNEL* let's try to fish him in!"
    I would like to have the boldness of these people at least once in my life!

    • @lIli-ht4hw
      @lIli-ht4hw 2 ปีที่แล้ว +17

      @@synthlord6575 how is it cringe

    • @zsi
      @zsi 2 ปีที่แล้ว

      This thread is cringe.

    • @dealsanddiecast
      @dealsanddiecast 2 ปีที่แล้ว +6

      @@synthlord6575 I’m confused how you’re confused

    • @zUltra3D
      @zUltra3D 2 ปีที่แล้ว

      Lmao

    • @nlx78
      @nlx78 2 ปีที่แล้ว

      On the other hand, they say a professional cook does not really likes to cook at home on his spare night, you sometimes hear. Or in the case of Seinfeld when he had girlfriends that was a masseuse, but she refused to give him a neck massage. Meanwhile Kramer did get one I believe... th-cam.com/video/zLo3kbggWZs/w-d-xo.html

  • @mudi2000a
    @mudi2000a 2 ปีที่แล้ว +352

    A "contract" that has a size of 750MB should always be a red flag.
    Regarding the behavioral protection, we have this at work, I'm a developer and it blocks a lot of completely legit tools.

    • @4.0.4
      @4.0.4 2 ปีที่แล้ว +5

      They hope you don't notice because it's packed so small.

    • @_auser_
      @_auser_ 2 ปีที่แล้ว +5

      Talking about a 700mb "word document", is it a good idea to just make a text file just 500mb and just shatters anyone with potato pc when opening it, aka spam E since why not, notepad did crash me at 250mb since my pc isn't the greatest as well, but it's funny and i did ruin my friend's pc, don't worry nothing is damaged the cpu is just broken. This reply is really long and probably as long as 1 paragraph of a wikipedia page

    • @_auser_
      @_auser_ 2 ปีที่แล้ว +2

      Did my TH-cam just crashed?

    • @HuntingKingYT
      @HuntingKingYT 2 ปีที่แล้ว +2

      @@_auser_ at least ur reply isnt tons of E's

    • @_auser_
      @_auser_ 2 ปีที่แล้ว +1

      @@HuntingKingYT but its as big as one wikipedia paragraph

  • @jackfishthe6th373
    @jackfishthe6th373 2 ปีที่แล้ว +201

    I did not know about the large file trick to evade detection! Now I understand the real reason to be wary of large downloaded/unknown files.

    • @dp6123
      @dp6123 2 ปีที่แล้ว +5

      You mean those GB's of torrent download files? This is why torrent is dead.

    • @anonymousarmadillo6589
      @anonymousarmadillo6589 2 ปีที่แล้ว +22

      @@dp6123 Lol

    • @jmbkpo
      @jmbkpo 2 ปีที่แล้ว +2

      @@dp6123 Lol

    • @LordFlaggy
      @LordFlaggy 2 ปีที่แล้ว +1

      @@dp6123 Lol

    • @reymarckessaguirre5082
      @reymarckessaguirre5082 2 ปีที่แล้ว

      @@dp6123 Lol

  • @WilliamDye-willdye
    @WilliamDye-willdye 2 ปีที่แล้ว +203

    If your sponsor can analyze compressed files, I suggest they change their "file too big" dialog to tell the user to try compressing the file and resubmitting.

    • @Steveson
      @Steveson 2 ปีที่แล้ว +1

      i actually got hacked few days, ago and my mc afe subscription got over, and i was pretty much downloading a filmora file, and dont know what had happend, my yt an all other accs got data breached online :/, i deleted that file, but im still scared

    • @ananthakrishnanj
      @ananthakrishnanj 2 ปีที่แล้ว +1

      @@Steveson lol who told download cracked

    • @investfoxy
      @investfoxy 2 ปีที่แล้ว +2

      @@Steveson Immediately change your google and other necessary passwords like Facebook, netbanking passwords, etc

  • @RockTheCage55
    @RockTheCage55 2 ปีที่แล้ว +337

    Would be interesting to see what happens when you actually execute it with different AVs (especially windows defender :) )

    • @joemama3372
      @joemama3372 2 ปีที่แล้ว +10

      Try it and tell us! 😉

    • @whocares7078
      @whocares7078 2 ปีที่แล้ว +6

      Windows defender is shit
      You sadly are fucked if you solely rely on anything microsoft makes XD

    • @KyngD469
      @KyngD469 2 ปีที่แล้ว +58

      @@whocares7078 cringe

    • @richards1213
      @richards1213 2 ปีที่แล้ว +1

      Happend to me you don't want that 😅

    • @idkmanreal0008
      @idkmanreal0008 2 ปีที่แล้ว +26

      @@whocares7078 windows defender is honestly underrated because most people think that Microsoft software is pure trash.

  • @108kitsune
    @108kitsune 2 ปีที่แล้ว +14

    Lots of facecam lately interesting change

  • @CaptainXLAB
    @CaptainXLAB 2 ปีที่แล้ว +179

    Another short trick you can use without hex editor, is to compress the exe by using Windows's built in NTFS compression. If it's full of zeros, the file size should show Size 700MB or whatever, and then Size on Disk will be something around 100 KB. I'm quite sure that the zip file in that download is also a few 100 KB as well due to compression, and 4 files more than 700 MB each in a zip which is barely a few KB is also a dead giveaway of something being very wrong. Nice video as always :D

    • @joemama3372
      @joemama3372 2 ปีที่แล้ว +7

      Great tip! Thank you!

    • @themasterofdisastr1226
      @themasterofdisastr1226 2 ปีที่แล้ว +22

      The ZIP-Archive he downloaded was shown as only ~400 kb, which was a pretty clear indicator the the file was bloated w/o any other tricks.

    • @rockon7478
      @rockon7478 2 ปีที่แล้ว

      @@themasterofdisastr1226 yo bro

    • @SmoggyLambGG
      @SmoggyLambGG ปีที่แล้ว +1

      VirusTotal still wouldn't take the file in regardless of compression tactics.
      Besides that, the original zipped files are still encrypted.

    • @goldenhate6649
      @goldenhate6649 ปีที่แล้ว +2

      The point isn’t to get the antivirus to find it. The point is to be able to see its a bloated file which is a dead giveaway of a virus program. An executable shouldn’t compress very much as it should have lots of important, non-compressing calls

  • @lokelaufeyson9931
    @lokelaufeyson9931 2 ปีที่แล้ว +125

    First rule of security: Dont open EXE files unless they are from a trusted source. If something feels strange or wrong, its usally something bad. Say no thanks and cancel/X out.

    • @RubenDeJong1603
      @RubenDeJong1603 2 ปีที่แล้ว +7

      or/and DELETE! 🗑

    • @irpnet
      @irpnet 2 ปีที่แล้ว +10

      @@RubenDeJong1603 My first rule of security is: unless it came with Windows, don't trust it! And even if it did, still don't!!

    • @Ethorbit
      @Ethorbit 2 ปีที่แล้ว +14

      First rule of security: don't store your precious data on Windows

    • @shib5267
      @shib5267 2 ปีที่แล้ว +2

      first rule of security: just don't

    • @greenicalgaming
      @greenicalgaming 2 ปีที่แล้ว +2

      First rule of security: n o

  • @Aci_yt
    @Aci_yt 2 ปีที่แล้ว +35

    I fell for one of these once, kind of sad this has become such a popular thing now..

    • @jello3064
      @jello3064 2 ปีที่แล้ว +3

      did you actually run the file or no

    • @Aci_yt
      @Aci_yt 2 ปีที่แล้ว +3

      @@jello3064 yes, but it wasn't a contract like here, but instead a game demo

    • @pengwino828
      @pengwino828 2 ปีที่แล้ว +3

      @@Aci_yt Any game that comes with no textures are dll files are fake because then it couldn't display anything

    • @Aci_yt
      @Aci_yt 2 ปีที่แล้ว +2

      @@pengwino828 it supposedly was the installer

    • @pengwino828
      @pengwino828 2 ปีที่แล้ว +1

      @@Aci_yt wow, they really thought that far ahead. At least you got your channel back.

  • @suhail-msk
    @suhail-msk 2 ปีที่แล้ว +7

    Didn't expect your face reveal

  • @SriHarshaChilakapati
    @SriHarshaChilakapati 2 ปีที่แล้ว +35

    That's an interesting trick you showed there! I've seen people embedding malware in bmp images and share a screensaver which will load executable from this bmp image, but this just blasting the size with zeroes is totally new. A question though: when you just select the zeroes and simply delete them, wouldn't that render the PE file invalid? Won't moving the offsets cause issues with the loader?

    • @randomdude12370
      @randomdude12370 2 ปีที่แล้ว +3

      I'm not qualified to answer, but guess would be because it's essentially dead space, it shouldn't effect the program, which is why he just did a general delete of the zeros and didn't fine time it

    • @inwoner7190
      @inwoner7190 2 ปีที่แล้ว +3

      @@randomdude12370 It must be for the same reason they could add all the zeros just in that place, the program is behaving the same anyway

    • @blogspoto
      @blogspoto 2 ปีที่แล้ว +3

      The zeros were after the main PE sections, in between let's say the .rsrc section and the overlay(the zeros could also be in the overlay or in their own custom named section) and they don't affect any offsets as no code or data points to that zero section, and the overlay is mostly for display(most RedLine payloads use corrupted certificates from big companies to try to further deceive the user into executing the payload). Any other offset used by the program's internals is calculated at runtime with regard to the image base and different srctions in the PE.

  • @ardeof
    @ardeof ปีที่แล้ว +3

    I'm curious, since when did Antivirus decide not to scan a file based on size? I remember scanners taking HOURS to scan. Why did they shuffle to "oh 10 minute scans are superior, even if we miss the actual virus"?

    • @KillerSkullX
      @KillerSkullX 4 หลายเดือนก่อน

      I was wondering that too

  • @AtariKafa
    @AtariKafa 2 ปีที่แล้ว +3

    best antivirus is yourself...

  • @Alberos
    @Alberos 2 ปีที่แล้ว +15

    Wow, this is the oldest trick in the book and it still work.... Changing the icon of an exe to something like Word or folder. Windows hiding the known file extension by default doesn't going to help either. And now we are starting to have people that doesn't even know what is "drive" and "file" is...... things are about to get worst from here haha

    • @4.0.4
      @4.0.4 2 ปีที่แล้ว +2

      Zoomers are the new Boomers. We gotta help them so they have basic tech skills and aren't vulnerable.

    • @Yousie6
      @Yousie6 2 ปีที่แล้ว

      thats implying the mid 2000's weren't god awful haha
      limewire ruined so many pcs

    • @nettack
      @nettack 2 ปีที่แล้ว

      Adding to the IT illiteracy comes, that people just want to monetize themselves on YT without merit or talent on "character" alone. And who can blame them, once the Pauls succeeded with this crap. Be vigilant, but if you get screwed over, maybe it's time for a real job.

  • @jubrajtoolsie680
    @jubrajtoolsie680 2 ปีที่แล้ว +11

    The part where he got rid of the blank spaces which were only there to fill space to make the malware undetectable was mind blowing!

  • @Voreoptera
    @Voreoptera 2 ปีที่แล้ว +7

    You barely explained why no one would notice that the docx file is an exe file, especially if it show file extinctions is enabled(hate Microsoft for disabling this by default). The attackers did not even bother adding docx to trick some users.

    • @Mario583a
      @Mario583a 2 ปีที่แล้ว +6

      It's part Microsoft - part stupid people renaming the file _including_ the extension and complaining why Office won't load their files.

  • @silentmajority8518
    @silentmajority8518 2 ปีที่แล้ว +7

    Thanks for this video. I was wondering HOW ON EARTH these ppl got around 2FA recently. Now I know. Great info.

    • @Mario583a
      @Mario583a 2 ปีที่แล้ว +1

      And knowing is half the battle.

  • @koshkamatew
    @koshkamatew 2 ปีที่แล้ว +1

    Real VS Fake NordVPN Sponsorship mail

  • @ADVANCEDLEVELAUTO
    @ADVANCEDLEVELAUTO 2 ปีที่แล้ว +1

    Wow! Great video! My channel was recently hacked because I opened an attachment similar to this one. I posted a video a few days ago explaining how it happened and how I was able to get my Gmail account back the same day. Crazy stuff! I’m way more cautious now.

  • @yssjc1414
    @yssjc1414 2 ปีที่แล้ว +9

    The ".scr" file, like in 1:53, was used to hack the crypto assets of streamers here in the Philippines.

    • @Mario583a
      @Mario583a 2 ปีที่แล้ว +3

      I always knew something was off with that Pipe Dream screensaver....

    • @AlfiesFuntime
      @AlfiesFuntime 2 ปีที่แล้ว

      That's a screensaver file...

    • @AlfiesFuntime
      @AlfiesFuntime 2 ปีที่แล้ว

      @@nevergonnagiveyouup4189 I didnt know that, I thought they were limited to animations

    • @AlfiesFuntime
      @AlfiesFuntime 2 ปีที่แล้ว

      Oh gosh does that username have RTL in it or something?
      Edit: it only appears weird on mobile

    • @user-0r67h2wdhu
      @user-0r67h2wdhu 2 ปีที่แล้ว

      @@AlfiesFuntime why did you write backwards

  • @YellyClips
    @YellyClips 2 ปีที่แล้ว +6

    i got attacked by this malware. the guy used my discord and took 200$ from my 13 year olds account and then i got mad(he didnt know i was a linux guy :) )so i just reverse shelled him and deleted almost all files on his pc.lol revenge

  • @alipetuniashow
    @alipetuniashow 2 ปีที่แล้ว +8

    Thanks for the video, it really helps with malware analysis for beginners

  • @xelspeth
    @xelspeth 2 ปีที่แล้ว +5

    If only there was some sort of checkbox you had to click on files before they are allowed to execute and otherwise warn you that they don't have permissions to be executed so you can't mistake an executable with a word document icon for a word document 😔

  • @t3true-games
    @t3true-games 2 ปีที่แล้ว +3

    They hacked a gaming channel I know the guy he had over 1million subs! And it went to this crypto videos.. He was able to get it back like 2 weeks later tho. But that sucks!

  • @imtheconstitution1190
    @imtheconstitution1190 2 ปีที่แล้ว +3

    Looking at the name of the virus at 6:37 this is a Chinese god’s name, “yanluowang” 閻羅王, a god that manages afterlife world for mortals ( sort of similar to Hades)

  • @Shocker99
    @Shocker99 2 ปีที่แล้ว +5

    Have you just started to make these types of videos?
    I don't know why but it feels like you have more credibility because of them. I've watched some of your Antivirus A vs Antivirus B type videos in the past and always wondered if it was unbiased or paid by a company content.

  • @kastrodyll1724
    @kastrodyll1724 2 ปีที่แล้ว +10

    i wonder how the executable would perform on virustotal after you removed the unnecessary parts.

    • @kastrodyll1724
      @kastrodyll1724 2 ปีที่แล้ว +2

      i just tried to download the file myself, but theyve changed the 7zip password. No chance to extrakt the file. Maybe ill try it with bruteforce attack.

    • @paullombardi9506
      @paullombardi9506 2 ปีที่แล้ว

      Hi can you tell me how you downloaded the file ?????

    • @paullombardi9506
      @paullombardi9506 2 ปีที่แล้ว

      I want to put it through virus total

    • @kastrodyll1724
      @kastrodyll1724 2 ปีที่แล้ว +1

      @@paullombardi9506 just copy the link seen in the Video

    • @fade6052
      @fade6052 2 ปีที่แล้ว

      @@kastrodyll1724 how was your test? Is it detected?

  • @ayden8901
    @ayden8901 2 ปีที่แล้ว +8

    What antivirus do you personally use? Of course I've seen your tier list but I'm super curious to know what you use on your machine

    • @elevul
      @elevul 2 ปีที่แล้ว

      Linux probably

    • @spritzerland658
      @spritzerland658 ปีที่แล้ว +1

      @@elevul huh???????????

  • @naeroforceofficial
    @naeroforceofficial 2 ปีที่แล้ว +1

    I GOT IT, I GOT EXACTLY THIS! Do I need to worry if I didn’t open it? I just unzipped and when I saw the file was 750MB i just WIPED it out of existence

    • @SpeedsterBlur
      @SpeedsterBlur 2 ปีที่แล้ว +1

      You're fine as long as you didn't run the file.

  • @damienmcgirl3577
    @damienmcgirl3577 ปีที่แล้ว +11

    Im honestly just a hacker for fun (i love finding the security breaches in computers and whatnot, its like an advanced puzzle that always changes) and these videos not only help my skills but they also help me patch up and make my systems better

    • @cadmanfox6874
      @cadmanfox6874 ปีที่แล้ว

      @@Kanyesouth436 I doubt he hacks other peoples systems, this is actually pretty common. Pretty sure they're called white-hat hackers. But if he actually does hack other people, he can gtfo of civilization.

    • @damienmcgirl3577
      @damienmcgirl3577 ปีที่แล้ว

      @americanketchup4340 don't bother, these guys are idiots. It's not worth your time trying to explain it

    • @Kanyesouth436
      @Kanyesouth436 ปีที่แล้ว

      @americanketchup4340 ye

  • @ifur
    @ifur 2 ปีที่แล้ว +36

    I love how calm you are while dealing with malware

    • @orbitalonyx
      @orbitalonyx 2 ปีที่แล้ว +8

      For real if I get a virus I would probably breakdown or something idk I have bad anxiety lol

    • @kamilo1175
      @kamilo1175 2 ปีที่แล้ว +6

      He was probably in a VM

    • @orbitalonyx
      @orbitalonyx 2 ปีที่แล้ว +4

      @@kamilo1175 yeah most likely pretty much every person that deals with stuff uses vm

    • @malwaretestingfan
      @malwaretestingfan 2 ปีที่แล้ว +2

      @@kamilo1175 Indeed, or he's just experienced, or even both.

    • @roguewasbanned4746
      @roguewasbanned4746 2 ปีที่แล้ว +1

      @@orbitalonyx I trust people and download files all the time, and that’s why I get nervous even when I know someone is on a VM. I do creative projects with people, so you just have to hope no one gets hacked or sends anything malicious 🙃

  • @satinfoil
    @satinfoil 2 ปีที่แล้ว +1

    well, any sane person would automaticly know that a document in the form of an exe is malishous. But thanks anyway!

  • @CeilingPanda
    @CeilingPanda 2 ปีที่แล้ว +7

    Yes please more of these, even if I'm quite techy it's super good to have these types of videos to send to others! :)

  • @aayushkarulkar107
    @aayushkarulkar107 2 ปีที่แล้ว +4

    Me seeing Mrwhosetheboss channel in the thumbnail: "Wait what He's Channel got hacked!!!!!???" After all UK's Largest Tech youtuber

    • @talksalot7562
      @talksalot7562 2 ปีที่แล้ว

      I mean.. he got hacked a few years ago-

    • @talksalot7562
      @talksalot7562 2 ปีที่แล้ว

      but I'm shocked that he is on the thumbnail on this vid...

  • @Stoner_mtl
    @Stoner_mtl 2 ปีที่แล้ว +3

    that's why you need second opinion scans like Hitman Pro Alert

  • @Nullifys
    @Nullifys 2 ปีที่แล้ว +4

    So this is what security research is. I like this alot

  • @RickOShay
    @RickOShay 2 ปีที่แล้ว +1

    You'd have to be especially stupid to download a 750 MB exec file that claims to be a simple contact file !! One could say - so stupid that you shouldn't actually own a computer.

  • @Reeegon
    @Reeegon 2 ปีที่แล้ว +1

    would you recommend the google usb stick for access and security?

  • @DarkDonnieMarco
    @DarkDonnieMarco 2 ปีที่แล้ว +7

    I learned more about malware analysis in this video than the entire module on it in my masters in cybersecurity

    • @KillerSkullX
      @KillerSkullX 4 หลายเดือนก่อน

      Is it really that easy to study cyber security?

  • @rayrussell6258
    @rayrussell6258 2 ปีที่แล้ว +5

    if the security systems we use are limited in size of file it scans, then why don't they break down the file into smaller chunks, to be scanned. Surely they could design something that deletes all the repetitive zeros, and then put files back together, before scanning. (similar to how you manually did it)
    I'm not a programmer, but that seems like the way to eliminate scammers like this.

    • @tronghungnguyen8716
      @tronghungnguyen8716 2 ปีที่แล้ว

      A single repeatitive 0s is easy but once it gets to repeatitve sequence that just impossible to split and detect easily

    • @rayrussell6258
      @rayrussell6258 2 ปีที่แล้ว

      @@tronghungnguyen8716 to my thinking, not really;
      break it into equal parts, doesn't matter where the zeros are, then look for all zeros in each part. When done, put it back together and run the scan. Just like he did manually.

    • @rayrussell6258
      @rayrussell6258 2 ปีที่แล้ว

      @@Emilia-fl5ii I'm not a programmer, but I still say you can break any file apart anywhere you like, scan the smaller files, and then put them back together again. If he could do it manually, it can be done in whatever software code they used, and look for patterns. Whether or not they used 0's or "junk" might make it harder to figure out the malicious intent, it doesn't stop the ability to do the scan; he said file size is preventing the scan, so that's where I said it should start, rather than leaving users totally exposed. As with most things new, people lose sight that you can't take step 2 until you take step 1.

    • @rayrussell6258
      @rayrussell6258 2 ปีที่แล้ว

      @@Emilia-fl5ii Well, look back then; the original poster broke the file apart, eliminated the 0's, put it back together, ran the virus scan on smaller file, all that manually.
      I read what you say, and see nothing you say that overrides what he did manually, meaning it should be possible to replicate his manual process. I wish he would come back in to the thread and get in this discussion with you. As I said, I'm not a programmer. However, on my job, I was usually the designated spec writer, working with programmers, who automated our manual reports. We never found anything that couldn't be done with software. Took time occasionally to get the right software, but nothing stopped us.
      I think this situation is a hole not being fixed. It's fixable, somehow.
      Address further questions to the original poster please, not me. You two can talk it out, I'll read your discussion with him.

    • @rayrussell6258
      @rayrussell6258 2 ปีที่แล้ว

      @@Emilia-fl5ii Again, I said talk the technicals with the original poster, not directly to me.
      But from my point of view, if someone can do it manually, then it's do-able with programming. At least it would make it more difficult for the hacker to do mischief. Enough said.

  • @Eirexeyes
    @Eirexeyes ปีที่แล้ว +1

    It's really annoys me that these helpful channels are not boosted by TH-cam rather than all of the dumb political stuff..

  • @LNDFHACKER
    @LNDFHACKER 2 ปีที่แล้ว +1

    And the ZIP is encryped so AV software would have trobule analyzing it...

  • @joeyr3349
    @joeyr3349 2 ปีที่แล้ว +1

    any unknown email in my inbox.... "STRAIGHT TO BIN"

  • @thrices4372
    @thrices4372 2 ปีที่แล้ว +3

    Can you tech us the best practice on how to make a virtual window to test virus and malware.

  • @lolobke
    @lolobke 2 ปีที่แล้ว +1

    Can you get the malware from watching TH-cam video’s?

  • @memetech-
    @memetech- 2 ปีที่แล้ว +1

    man, all that blank space is really taking up a lot of space. it's really important though...

  • @xerox8080
    @xerox8080 2 ปีที่แล้ว +2

    Why does Windows allow users to hide all file extensions while these are very important. That's a real stupid decision from Microsoft imo....

  • @aimannizam4505
    @aimannizam4505 2 ปีที่แล้ว +1

    Yep, every hacker is made, THEY LITERALLY HACK ALL MY FRIENDS ACCOUNT THO IN THE SAME DAY

  • @walshar2705
    @walshar2705 2 ปีที่แล้ว +1

    I thought a famous TH-camr would comment here and say "Hey that's what I did!"

  • @lumixanbgaming
    @lumixanbgaming 2 ปีที่แล้ว +2

    you know this is frustrating stuff, i really thought they would use some insane exploits or sth. But if they only send an .exe file and youtuber click it.... idk This is the most ridiculous thing ever
    imagine clicking uknown .exe files in 2022 :D I mean their social engineering/phishing email is fucking bad

  • @lewiskelly14
    @lewiskelly14 2 ปีที่แล้ว +1

    Why did you use different online services before and after removing the middle space????

  • @BasedF-15Pilot
    @BasedF-15Pilot ปีที่แล้ว +1

    Based on the train reflection in your mirror you live in Boston, or the UK also has some silver trains with 2 windows per car.

  • @tophitter9323
    @tophitter9323 2 ปีที่แล้ว +1

    Something like this kinda happened to me, I got my account stolen, and they just liked all their videos using my account

  • @thegreatboomhauer6794
    @thegreatboomhauer6794 2 ปีที่แล้ว +4

    this is your best video, actually showing us the forensics of a malware. WOW

  • @kyouhyung
    @kyouhyung 2 ปีที่แล้ว +3

    Gotta have to admit, that file size trick was quite clever.

  • @Adrain45175
    @Adrain45175 2 ปีที่แล้ว +2

    What about free/open source HIDS vs this types of malwares? It works better than regular av?

  • @LynKazoyuu
    @LynKazoyuu 2 ปีที่แล้ว +3

    How about the discord stealers , it's really getting annoying

  • @kenpachizaraki4184
    @kenpachizaraki4184 2 ปีที่แล้ว +1

    Would deleting the file, and doing a system restore to revert back be sufficient in ridding the threat? Im trying to avoid a clean wipe.
    Edit: actually, i extracted the contents, saw an .exe but ever ran it though. There's no reason a company offer should supply an exe.

  • @slogadin
    @slogadin 2 ปีที่แล้ว +1

    Dude this literally happened to me how would I make my pc safe PLSSSSSSSSSSSSSS help

  • @zangizangidze8787
    @zangizangidze8787 2 ปีที่แล้ว +1

    guys!!!
    i found muta's brother.

  • @Fantasy2k
    @Fantasy2k 2 ปีที่แล้ว +2

    thanks for the info

  • @someuser4166
    @someuser4166 2 ปีที่แล้ว +1

    Malwarebytes can scan big files if you right click on them and tell it to

  • @cestmamin
    @cestmamin 2 ปีที่แล้ว +2

    This is Cyber Security class in a TH-cam video

  • @x-gamer2478
    @x-gamer2478 2 ปีที่แล้ว +5

    appreciate how much effort he puts into the content for us❤

  • @tomato-fh1qb
    @tomato-fh1qb 2 ปีที่แล้ว +1

    How about Posting the file Link in Virus total

  • @Stuff1646
    @Stuff1646 2 ปีที่แล้ว +4

    I suffered from the exact same malware tho instead of exe, the attacker had used chrome extension that had great reputation, and reviews so were hard to determine if it was malicious or not. Oddly enough after 2 months it had remotely installed redline stealer along with some other nasties and later on kicked off the chrome store.

    • @joemama3372
      @joemama3372 2 ปีที่แล้ว

      Wow... From a Chrome Extension that seemed legitimate and good reviews..
      I'm often suspicious of Extensions for browsers, Google Office and MS Office products..

    • @Stuff1646
      @Stuff1646 2 ปีที่แล้ว

      @@joemama3372 Should also be suspicious about PlayStore apps as Google doesn't do good job when it comes to auditing.

    • @Fatman305
      @Fatman305 ปีที่แล้ว +1

      Which is why I trust only extensions that have been available for 2+ years, and have plenty of downloads and plenty of reviews. Very easy to get a few hundred fake reviews.

  • @Trizic_
    @Trizic_ 2 ปีที่แล้ว

    Just saw 2 TH-cam accounts get hacked by crypto hackers who's uploading or livestreaming crypto stuff.

  • @sebf98s90fh2
    @sebf98s90fh2 2 ปีที่แล้ว +1

    finally some coverage on this shit show

  • @lewiskelly14
    @lewiskelly14 2 ปีที่แล้ว +1

    So many problems in this video

  • @tahafayed4843
    @tahafayed4843 2 ปีที่แล้ว +1

    are you using a filter or is your skin just so smooth?

  • @javiTests
    @javiTests 2 ปีที่แล้ว +4

    Thank you for sharing! Quick question... How would they bypass the 2-factor authentication? Even if they force you to log in again, steal passwords and the 2-factor value, when they go and use those credentials they will need to type another 2-factor value, right? That they don't have... 🤔

    • @flyhtz
      @flyhtz 2 ปีที่แล้ว +5

      u log in and it makes a cookie and when u exploit a cookie by injecting it (if u really wanna know and want an example id look up how to log into discord using discord token its the exact same) because when u inject a cookie the device/account thinks: "oh hey i know this one he doesnt need to do 2FA cuz i trust him :D"

    • @nickwoodward819
      @nickwoodward819 2 ปีที่แล้ว +1

      but that trust wouldn't extend to sensitive operations like password changes? So how would they steal the account/lock you out?

    • @javiTests
      @javiTests 2 ปีที่แล้ว

      @@flyhtz Aren't cookies linked to specific devices? If not, yes, that's quite a big security hole!

    • @flyhtz
      @flyhtz 2 ปีที่แล้ว

      @@nickwoodward819 no it would not but as soon as they have the cookie they can change the password and email

    • @flyhtz
      @flyhtz 2 ปีที่แล้ว

      @@javiTests they are not they are linked to browsers so u can inject them

  • @monkeyrobotsinc.9875
    @monkeyrobotsinc.9875 2 ปีที่แล้ว +1

    beauty face on level 10? LOL

  • @investfoxy
    @investfoxy 2 ปีที่แล้ว

    Being a crypto TH-camr I am very familiar with all these spam messages. I must admit I have been a Victim of a trojan attack once and ever since I have never got scammed because I have learned from being hacked. Can you tell me how can a .src file stole my crypto wallet keys?

  • @alvaro_rm_07
    @alvaro_rm_07 2 ปีที่แล้ว +2

    Love your videos

  • @xdkrazycamy7978
    @xdkrazycamy7978 2 ปีที่แล้ว +1

    DOES ANYBODY KNOW HOW TO REMOVE IT, I’M IN BIG TROUBLE!! I heard it takes security card info, IP Adresses and steals lots of money. Please help! 😥

    • @digima3972
      @digima3972 2 ปีที่แล้ว

      I'll do my best to steal you

    • @cosmicdust632
      @cosmicdust632 2 ปีที่แล้ว

      Run a scan with malwarebytes

  • @JustAPersonWhoComments
    @JustAPersonWhoComments ปีที่แล้ว

    A hacker starts a TH-cam channel.
    Gets 200K subscribers in 5 hours.

  • @elishatech4600
    @elishatech4600 2 ปีที่แล้ว +1

    I have never seen yo face 💖💖🔥

  • @Diarmuhnd
    @Diarmuhnd 2 ปีที่แล้ว +1

    Thanks for the info digital science guy on the PC Security Channel
    (sorry, don't know your name or nickname)
    Have fun and be safe.

  • @YANCEYLIFTS
    @YANCEYLIFTS 2 ปีที่แล้ว

    I got hacked in december but luckily i got it back they were able to look at my ip address being signed in from a diffrent state . crazy thing about it is i didnt even click any emails or download and malware

  • @ccjack431
    @ccjack431 2 ปีที่แล้ว +1

    Browser privacy please

  • @4restknight404
    @4restknight404 2 ปีที่แล้ว +1

    Classic Client-Side Attack,but the payload is tenderness not so nasty:)))

  • @thebritishindian1
    @thebritishindian1 2 ปีที่แล้ว +3

    Great explanation, thanks. Given the size limitation of virus checkers, how can you check those big applications that you download from genuine companies, just in case they’ve been compromised without knowing?
    It would’ve been great if you could have executed the file anyway and showed how the virus checker would’ve handled it.

    • @goldenhate6649
      @goldenhate6649 ปีที่แล้ว +1

      Pup finders tend to do a better job at this. Most antivirus’s now are just bloatware sadly.

  • @DahoodRex
    @DahoodRex 2 ปีที่แล้ว

    Hackers: Oooh what is this channel lets watch it 5 mins later after watching the vid OMG LETS HACK AND TRY IT OUT
    Computer: BLOCKED... Not allowed
    Hacker: YOUUU COMPUTER SUCK I HATE YOU I SHOULD THROW YOU OUT!1
    cOMPUTER: YEETT
    Hacker: THATS WHAT YOU TAKE

  • @death_clan9123
    @death_clan9123 2 ปีที่แล้ว +1

    Guess I got hacked

  • @V34035
    @V34035 2 ปีที่แล้ว

    OHH So this is how it happened well F*, thx god I saved my acc in time

  • @TechX1320
    @TechX1320 2 ปีที่แล้ว +2

    I recently got hit in a very strange way. They changed my channel logo, they changed my channel name, they private it a bunch of random videos, not everything just a bunch of randomly picked ones, and then they started live streaming a crypto scam
    Strange thing though is my two-factor authentication was never triggered, and I looked at logged in devices on my Google account, and the only ones that were logged in were my personal computer, my work computer, and my cell phone. So I couldn't kick them off that way either. I have no idea how they got in. Hadn't recently downloaded anything that I would think would be malicious.

    • @TechX1320
      @TechX1320 2 ปีที่แล้ว

      @Appu26j wouldn't some sort of cookie stealer need to be used though? Work computer was a Mac, windows computer that was powered off since I wasn't home and an Android phone not rooted or anything sideloaded/modded apps

    • @TechX1320
      @TechX1320 2 ปีที่แล้ว

      @Appu26j at the time it occurred, the live stream they were doing I searched the title of and noticed there were about a dozen other TH-cam channels streaming the same thing. It was some Bitcoin scam.
      I could understand exploiting live streaming with something like somehow guessing the stream key, but it's so long and convoluted I highly doubt that. Also if you guess the stream key that doesn't give you access to change things like channel name private videos and change channel layout

  • @24kCookieMusic
    @24kCookieMusic 2 ปีที่แล้ว +1

    Mac users : oh how cute

  • @wolfbrave4866
    @wolfbrave4866 2 ปีที่แล้ว +1

    Learning from your channel I use Intezer to analyze a small file with the extension .doc inside a password zip folder seems like it's a very popular technique of putting files inside a password lock zip file. Intezer reported the file as malicious. 🤣 Question can a windows type malware infected an android device if it's unpack using an android device? Yes it's the doc file but I did not execute or open it just extract and submit directly to intezer.

  • @georgesenda1952
    @georgesenda1952 2 ปีที่แล้ว

    I get those promotional video emails constantly. I mark them spam.

  • @MoMo2o00
    @MoMo2o00 2 ปีที่แล้ว +1

    Did they really just try to hack THE pc security channel? Lol

  • @Eclypsee
    @Eclypsee 2 ปีที่แล้ว +2

    I know how redline works, i even have a client on my vm for testing. You know i just use it to analyse the compiled exe files, it is not hard to detect and all avs should be able to do the job, unless the creator modified it with a crypter, but it is unlikely. The file you tried seemed to be pumped to 715MB and the malicious code is like 350-700kb of that.

    • @sireopossom7860
      @sireopossom7860 2 ปีที่แล้ว

      Just be mindful that vm isn't safe.

    • @scootbmx01
      @scootbmx01 2 ปีที่แล้ว +1

      Didn't watch the video?

  • @LimE-iz1zb
    @LimE-iz1zb 2 ปีที่แล้ว

    Thumbnail:how youtubers get hacked
    Me:Oh cool A new tutorial XD

  • @1y3911
    @1y3911 2 ปีที่แล้ว +1

    I will never do it.

  • @jamesedwards3923
    @jamesedwards3923 2 ปีที่แล้ว +1

    You explained it well.
    So I have a question. Avast or Malware Bytes? I prefer Malware Bytes.

  • @fatrat600284
    @fatrat600284 10 หลายเดือนก่อน

    Hackers tries to hack The PC Security Channel
    Random hacker: "Why do i hear boss music?"

  • @silvaaa24
    @silvaaa24 2 ปีที่แล้ว

    Its sad but that scammers make a lot of money selling the hacked chanells...

  • @Sitharii
    @Sitharii 2 ปีที่แล้ว +1

    they tried to hack ... you ???
    *lol , tough luck on them* !!
    great analysis , thanks !!

  • @CertifyEdHub
    @CertifyEdHub ปีที่แล้ว

    I purchased the Express VPN along with the tor browser to go on the dark web, Some say I should downloading tails for extra security, would that be necessary. 🤔