Birele Ransomware

แชร์
ฝัง
  • เผยแพร่เมื่อ 16 ก.ย. 2024
  • I take a quick look at a new version of another file encrypting ransomware trojan. Unlike previous versions, this one leaves (nearly) no way to decrypt your files without the correct password.

ความคิดเห็น • 160

  • @marimeme
    @marimeme 9 ปีที่แล้ว +63

    A ransomware
    that actually
    delivers

    • @marimeme
      @marimeme 8 ปีที่แล้ว +1

      If I knew myself, but this comment is old.

    • @marimeme
      @marimeme 8 ปีที่แล้ว

      Just forget it, this comment is old.

    • @TomatoFriesLAN
      @TomatoFriesLAN 7 ปีที่แล้ว

      I read it as a haiku, thank god I renewed my bamboozle insurance yesterday.

    • @youtube.commentator
      @youtube.commentator ปีที่แล้ว +1

      @@marimeme indeed, it is

    • @getthepartystarted1247
      @getthepartystarted1247 ปีที่แล้ว

      @@youtube.commentator yes it is very old indeed

  • @satanmaizono790
    @satanmaizono790 7 ปีที่แล้ว +12

    "And of course, we have a JPG."
    "CRAZY RUSSIAN PORN"
    Rogueamp, you classy, classy, man.

  • @silasreel1801
    @silasreel1801 10 ปีที่แล้ว +55

    I'll send them BankInfo.txt.exe.

    • @toadette2097
      @toadette2097 9 ปีที่แล้ว

      yea

    • @DannyProto
      @DannyProto 8 ปีที่แล้ว

      Wow wasnt expecting to see a toontown fan like me here XD

  • @xander2698
    @xander2698 10 ปีที่แล้ว +32

    NOOOOOOO! The scry computr ting rooned me shmexy pr0nz!

  • @airee8724
    @airee8724 8 ปีที่แล้ว +18

    This ransomware is now obsolete.
    The IP the webserver this runs on (37.221.162.51) is now no longer available.
    If you really want to, I suppose you can route 37.221.162.51 to localhost in your hostsfile. I got a sample of this is and this is quick fix as it will not encrypt anything if it can't properly send the code.

    • @kuhascoat
      @kuhascoat 4 ปีที่แล้ว +6

      I can respect that.
      Won't encrypt if it can't make sure it can unencrypt.

  • @will5459577
    @will5459577 8 ปีที่แล้ว +13

    "CRAZY RUSSIAN PORN" 😆 fucking brilliant!!

    • @NascarWWE636
      @NascarWWE636 7 ปีที่แล้ว

      i get that reference 😂😂😂

  • @ThePuffin77
    @ThePuffin77 9 ปีที่แล้ว +32

    Change all files to .mp3

    • @ThePuffin77
      @ThePuffin77 9 ปีที่แล้ว

      *****
      I mean before.

    • @ThePuffin77
      @ThePuffin77 9 ปีที่แล้ว

      +minerinnorway norsk gaming For this occasion before he runs the virus.

    • @tmurfinmurfin584
      @tmurfinmurfin584 8 ปีที่แล้ว +2

      +ThePuffin77
      What a smart idea!
      because then this may happen:
      Russian.exe INFECTED
      fakeimagedisquised.mp3 SAFE!

  • @douro20
    @douro20 11 ปีที่แล้ว +1

    Birele uses AES. And I'd imagine it is implemented properly without any vunerabilities.

  • @Pipe0481
    @Pipe0481 9 ปีที่แล้ว +13

    Send them/him a txt with the Rick roll url

  • @anentityshroudedinmystery.8037
    @anentityshroudedinmystery.8037 7 ปีที่แล้ว +3

    what is the OS used in this video?
    is this Windows 7 with the Windows 2000 interface?

  • @trit136
    @trit136 9 ปีที่แล้ว +12

    What if you have the internet disconnected so the server does not receive the password?

    • @airee8724
      @airee8724 8 ปีที่แล้ว +7

      +don brathuhn It doesn't work. This person has the decency to not fuck you if they make no money from you.
      This is obsolete, so it doesn't matter either way. (operating server 37.221.162.51 is now shut down)

    • @smasher4291
      @smasher4291 7 ปีที่แล้ว

      what if you get it, but have internet off, then restart and turn it on?

    • @cetusophetus5590
      @cetusophetus5590 5 ปีที่แล้ว +1

      @@smasher4291 please try that and let us know

  • @nightshademagia
    @nightshademagia 8 ปีที่แล้ว +1

    So basically WireShark (or any packet analyzer) toasts this ransomware through and through.

  • @holyjewel
    @holyjewel 11 ปีที่แล้ว

    I really enjoy watching these types of videos in the morning, generally while drinking a Monster, or Redbull. Except, it's 1PM. I overslept, I'm too fucking sick to go to the store to get anything, and it would taste like shit, most likely. Sorry for telling you all my whole life story.

  • @_chirp_6108
    @_chirp_6108 8 ปีที่แล้ว +2

    someone needs to make a virus that pops up Rickroll every 2 seconds

  • @dleedirector9831
    @dleedirector9831 11 ปีที่แล้ว

    In case you haven't found it yet, it was Desktop Defender 2010.

  • @mockingbird667
    @mockingbird667 11 ปีที่แล้ว +1

    It wouldn't make any difference. Create a text file, put words in it. Then, change it's extenstion to something like .data, or like in the video, .txt.crypt. If you try to open it with Notepad, it'll show the file's contents just fine.

  • @Strattou
    @Strattou 11 ปีที่แล้ว

    you did it, amp. you did the thing. i'm so proud of you.

  • @Yognaught0me
    @Yognaught0me 11 ปีที่แล้ว

    avast covered that voice with "AVAST HAS SUCCESSFULLY UPDATED!"

  • @OGitsjayce
    @OGitsjayce 11 ปีที่แล้ว

    both of these are system processes that are essential for your computer to run. do NOT end their processes or system trees.

  • @Abca209
    @Abca209 11 ปีที่แล้ว

    So rogue's been listening to some Jim Jones

  • @clem5858
    @clem5858 11 ปีที่แล้ว

    Wow, that's one hell of a trojan 0.0

  • @webbadger08
    @webbadger08 11 ปีที่แล้ว

    Your user icon is a work of art

  • @Pazzknallie
    @Pazzknallie 11 ปีที่แล้ว

    I miss Chad Warden. BALLIN.

  • @thedivinityman
    @thedivinityman 11 ปีที่แล้ว

    This is why I ghost copy my drive to a redundant RAID server every night, you can build one for just backups, ghost copies etc. for less than $200 then if your computer gets ransomed, you just re-install and and since it is a ghost copy restore it to right before your machine was ransomed

  • @JangoPeppers
    @JangoPeppers 11 ปีที่แล้ว

    1:14 Ballin. Jarl Ballin.

  • @zeyfuller
    @zeyfuller 11 ปีที่แล้ว

    Those are so mainstream now that that isn't really a safe assumption.

  • @fusiongamesstudios
    @fusiongamesstudios 11 ปีที่แล้ว

    What you could do is disassemble the file and find out how it works. Then find where the data is in memory and then execute the file through preferably a debugger and you shall find the key. Although regular execution would not work because it will only be in memory a fraction of a second dependant on speeds and opcodes.

  • @yosteryosher
    @yosteryosher 11 ปีที่แล้ว +1

    YESSS GIMME DAT CRAZEEEE RUSSUAANNN PPOOORRRNNNNNNNNÑ

  • @clem5858
    @clem5858 11 ปีที่แล้ว

    Yeah, I love when I see your new videos in my sub box

  • @nesbroslash
    @nesbroslash 11 ปีที่แล้ว

    Those text files made me laugh pretty hard.

  • @bcordone
    @bcordone 11 ปีที่แล้ว

    Which ransomware was that fake AV that made your computer lock up, flashed the screen red, and played this annoying electrical sound through the speakers? I remember seeing it on Rogueamps channel.

  • @TheSteamGamer99
    @TheSteamGamer99 10 ปีที่แล้ว

    wouldn't there be a key to use, it needs a key to encrypt it right? decompiling it might help us

  • @edison700
    @edison700 11 ปีที่แล้ว

    hmm, maybe it also effect program because it think it might have to do with a problem you are trying to resolve, point still stands system restore should not effect pictures, documents, music, etc

  • @HellShiner
    @HellShiner 10 ปีที่แล้ว

    We Fly High You know this. You watch Chad Warden before this video xD?

  • @ALLENWinWizzy2
    @ALLENWinWizzy2 11 ปีที่แล้ว

    So the amp found out about chad warden now lol.

  • @UwUshun
    @UwUshun 11 ปีที่แล้ว

    I went to the destination IP that the .php file lies on in an attempt to see how it does it, but it asks for a log on, with the description being "bit-coin mining proxy". huh
    needless to say I couldn't log-in, and it booted me to a page saying "Sorry, I don't know you."

  • @Hotrod6045
    @Hotrod6045 11 ปีที่แล้ว

    We fly high
    No lie
    You know dis
    BALLIN

  • @skepticmisfit2
    @skepticmisfit2 11 ปีที่แล้ว

    i think you should put that code in the description so that people can remove it easily.
    and also, gr8 files

  • @shadowdanman1000
    @shadowdanman1000 11 ปีที่แล้ว

    WOMAN IM LOOOOORD OF THE RINGS

  • @TheGrandMaster110
    @TheGrandMaster110 9 ปีที่แล้ว

    Ballin'.

  • @MartijnvanBerkel
    @MartijnvanBerkel 11 ปีที่แล้ว

    I wonder how it can display "Password accepted". Does it check with the server? A file that it decrypts with known contents to test the password? Or is the password still saved on the system?

  • @ZeStealthyPwn
    @ZeStealthyPwn 11 ปีที่แล้ว

    Where would you generally get infected by a ransomware? Would the person who made it have disguised it as something too good to be true and sent it to you?

  • @zzoinks
    @zzoinks 7 ปีที่แล้ว

    Would it be possible to decrypt a file by comparing the encrypted version to the unencrypted version the criminal sends you?

  • @4pThorpy
    @4pThorpy 11 ปีที่แล้ว

    What would happen if this was run on a machine without an internet connection? I doubt files are being uploaded to a server and changed there, or you could just send huge files at the server constantly, the encryption has to be in that exe, surely? which would mean someone like xylitol could make a fix with a bit of ollydbging.

  • @gab1527
    @gab1527 5 ปีที่แล้ว

    that ransom ware kills safe mode as well though!!!!

  • @InternetKilledTV21
    @InternetKilledTV21 11 ปีที่แล้ว

    Wouldn't you think that the packet that sends the password would use SSL to prevent people from using sniffers to get the password?

  • @Obito313
    @Obito313 11 ปีที่แล้ว

    Who ever said I was a white hat D: I am curious to see if I can reverse engineer it, I mean I have several books on cryptology and I am currently developing a system of encryption, but I need something which seems like a challenge :3

  • @TheTechyButterfly
    @TheTechyButterfly 10 ปีที่แล้ว

    That is very cool that you can use wireshark for anything

    • @TheTechyButterfly
      @TheTechyButterfly 10 ปีที่แล้ว

      So? Aren't you a fan of something too?

    • @lyrareal
      @lyrareal 9 ปีที่แล้ว +2

      ***** Why are you criticising her for liking Roblox? Is it because you hate Roblox? I could also say that your grammar is bad, as that "sentence" - if I could even call it that - doesn't make sense AT ALL. Roblox also has nothing to DO with WireShark. Come on, at least step up your game a little bit. Or are you just gonna write another complaint comment, with your one subscriber (probably you) and your 10 views?

    • @TheTechyButterfly
      @TheTechyButterfly 9 ปีที่แล้ว

      HashtagBenches Thank you. You didn't have to stand up for me.

    • @lyrareal
      @lyrareal 9 ปีที่แล้ว

      Roblox TheTechyButterfly Eh, no problem.

    • @HackaseSky
      @HackaseSky 8 ปีที่แล้ว +1

      +HashtagBenches This is the internet. Don't take what people say to heart

  • @norunepole
    @norunepole 11 ปีที่แล้ว

    ballin

  • @JazzyTheRabbit
    @JazzyTheRabbit 9 ปีที่แล้ว

    I heard on Britc09's site there is a decryption tool

  • @SlamTF2
    @SlamTF2 11 ปีที่แล้ว

    Check Google. I'm pretty sure it is a rogue so go on google or something and look it up. Generally when you type in the name of a rogue everything that comes up is warnings and bad reviews from websites like BleepingComputer.

  • @Gameboygenius
    @Gameboygenius 11 ปีที่แล้ว

    I wonder if it's using RC4 or some other weaksauce crypto with an identical keystream for every file. In that case if you have a backup of any of the files, you can recover the keystream, up to the size of that file, with some xor action. Then xor the keystream with the ciphertext to get back you precious crazy Russian porn.

  • @metalboySK1
    @metalboySK1 11 ปีที่แล้ว

    Where do you get these ransomwares and rogues? I would like to try some of them on my VM.

  • @TheCanadianToast
    @TheCanadianToast 11 ปีที่แล้ว

    Here we go, more ransomware. :P

  • @mooselexus
    @mooselexus 11 ปีที่แล้ว

    Hi, keep up to date on this Birele Ransomware? Thanks!

  • @edison700
    @edison700 11 ปีที่แล้ว

    system restore has do with windows installation and registryl it doesn't touch your files

  • @mejftw
    @mejftw 11 ปีที่แล้ว

    system restore?

  • @HesitantSignal
    @HesitantSignal 9 ปีที่แล้ว

    Does it send out the password every time the informer starts?

  • @nabagaca
    @nabagaca 11 ปีที่แล้ว

    no matter what antimalware/antivirus program you use... there will always be ways around it. Its impossible to block every virus.

  • @DerpProductionz
    @DerpProductionz 8 ปีที่แล้ว

    Wait, couldn't you just get wire shark and run it again?

  • @MatMabee
    @MatMabee 11 ปีที่แล้ว

    I just got a Dell Dimension 3000 series with 600gb just for programming viruses, and Trojans. I spent $30 on the computer.

  • @thedivinityman
    @thedivinityman 11 ปีที่แล้ว

    I could install Linux, but I prefer to be productive. I am a certified Microsoft, apple, and GNU/Linux tech, and for productivity Windows is the best

  • @danielwickham3439
    @danielwickham3439 6 ปีที่แล้ว

    IT ISSSSSS FUCKED that was so funny

  • @neviemdopice
    @neviemdopice 10 ปีที่แล้ว

    what happens when you run it again? You could spam add.php to see what happens :)

  • @Obito313
    @Obito313 11 ปีที่แล้ว

    Do you know which type of encryption method it uses? This seems very interesting and I feel like I would like to take the challenge to decrypt it :) I mean pm me a link to where I can download this so I can take a crack at it :O

  • @vladdracula1485
    @vladdracula1485 10 ปีที่แล้ว +4

    but what happens if you get it and you send them a DDOS or SQL in that one file ur allowed to send them ?

    • @vladdracula1485
      @vladdracula1485 10 ปีที่แล้ว +2

      ***** but there antivirus or protection will block it and since they able to design something like this they r bound to be grey hat hackers so itll be easy for them to counter the roughe but SQL injects can bypass there defense systems, and denial of service will stop them from destroyin ur data for sendin them a Sql

    • @negativize_11
      @negativize_11 10 ปีที่แล้ว

      That Stupid Guy That Will Slap Your Face Send them the Fagot virus.
      It'll infect them AND call them a fagot at the same time.
      t-t-t-torture breaker

    • @radostin04wastaken
      @radostin04wastaken 10 ปีที่แล้ว

      if i will got infected with this i will send them the Gruel virus or the Internet Secururity rouge

    • @vladdracula1485
      @vladdracula1485 10 ปีที่แล้ว

      a good one would be the Trojan.zeroaccess, if you got experience with it. Because zeroacess basically sneakly gets into there sytem, deactivates internet security then it opens a backdoor and installs a tonne of other viruses which crashe there computer. With the backdoor u basically get control over the system and u can get the passkey to unlock ur system by urself from there computer :D

    • @mustangrt8866
      @mustangrt8866 10 ปีที่แล้ว

      I'd be sending something which can blow their machine up, with some kind of overflow

  • @SuperMewio
    @SuperMewio 11 ปีที่แล้ว

    Ctrl+F5 fixed it for me.

  • @St_Rizla
    @St_Rizla 8 ปีที่แล้ว

    all the test files are a reference to Chad Warden lol

  • @vinc544495
    @vinc544495 11 ปีที่แล้ว

    You wasn't first...I WAS!

  • @mikek17
    @mikek17 11 ปีที่แล้ว

    Dammit, i just recorded a whole video of this!

  • @AllHaiLKINGTIsHeRe3
    @AllHaiLKINGTIsHeRe3 11 ปีที่แล้ว

    Yeah, I'm sure.

  • @gampixi
    @gampixi 11 ปีที่แล้ว

    The code is different every time so it's no use.

  • @ReCkLeSsErr0r
    @ReCkLeSsErr0r 11 ปีที่แล้ว

    Looks like their getting their money through bitcoins... They are gonna be impossible to track down... Damn :(

  • @aten747official
    @aten747official 11 ปีที่แล้ว

    now that's just mean.

  • @mustangrt8866
    @mustangrt8866 10 ปีที่แล้ว +1

    crack the program with a decompiler and get the key and the parameters

    • @atranshumanisttranshuman
      @atranshumanisttranshuman 10 ปีที่แล้ว

      ... It reads it off of a server, and sad server has authencaton. That wouldnt work.

    • @biigsmokee
      @biigsmokee 9 ปีที่แล้ว +3

      Mustang is right.
      The way this works is by generating a private seed to encrypt with, which is what that identification number is, so say each install's password seed is: identifiaction number + "xOdpdDFPG40fxZ", so if you decompiled it you could get the seed, and thus, the password.

    • @Happigail_Adams
      @Happigail_Adams 8 ปีที่แล้ว +1

      +.Float what's preventing this thing from having a preset pattern, if the password does not match the pattern, why interact with the server at all?
      or you can enter an incorrect password with the correct pattern, it would contact the server then realize it's the incorrect password.
      nothing is preventing the owner from keeping the key and the parameters on a private disposable server and sending it when the password is correct.

    • @biigsmokee
      @biigsmokee 8 ปีที่แล้ว

      Ticha360 What?

  • @thepirategamerboy12
    @thepirategamerboy12 11 ปีที่แล้ว

    So, we can still watch our porn videos. This Ransomware is somewhat nice, I guess.

  • @mooselexus
    @mooselexus 11 ปีที่แล้ว

    Try "Emsisoft Harasom Decrypter
    maybe it will Decryter this Ramsomware? Let me know? Write Emsisoft Anti Malware
    support for the Decrypter!

  • @stonecrestmovies
    @stonecrestmovies 11 ปีที่แล้ว

    Sup bitches. It's Chad Warden here.

  • @TheDesius
    @TheDesius 11 ปีที่แล้ว

    Good thing I run comodo
    No virus will ever come on my PC as long as I have comodo on it :) it has the best behavior blocker ever

  • @yadsmoodxD
    @yadsmoodxD 11 ปีที่แล้ว +2

    he said it generates a random password
    so there is no actual password

  • @samchem1020
    @samchem1020 10 ปีที่แล้ว

    $300 a lot of money to pay

    • @HackaseSky
      @HackaseSky 8 ปีที่แล้ว

      You're already stupid enough to download ransomware, right?

  • @thepirategamerboy12
    @thepirategamerboy12 11 ปีที่แล้ว

    Oh, I see it's a stupid program that throws up some random message boxes. How nice.

  • @caffeinepizza
    @caffeinepizza 11 ปีที่แล้ว

    good thing I run linux.

  • @mooselexus
    @mooselexus 11 ปีที่แล้ว

    in front of the tmp to download

  • @vinc544495
    @vinc544495 11 ปีที่แล้ว

    Nice :D

  • @thepirategamerboy12
    @thepirategamerboy12 11 ปีที่แล้ว

    What is this?

  • @Yognaught0me
    @Yognaught0me 11 ปีที่แล้ว

    idk 'bout rthdco.exe and smss.exe but if it is under the owner user etc. you MAAAAY wunna end the process

  • @GreenGuy9001
    @GreenGuy9001 11 ปีที่แล้ว

    That'sSomeCrazyPorn.jpg.jpg.. Wut.txt

  • @TheOnlyRounder
    @TheOnlyRounder 11 ปีที่แล้ว

    Lol porn.jpg on the desktop

  • @RetroPlus
    @RetroPlus 6 ปีที่แล้ว

    It's pronounced Baigh-real-ayyyyyyyyyyyy lmao

  • @MatMabee
    @MatMabee 11 ปีที่แล้ว

    Test.

  • @davidjl
    @davidjl 11 ปีที่แล้ว

    lol

  • @Kn270
    @Kn270 11 ปีที่แล้ว

    porn.jpg

  • @tamag9
    @tamag9 11 ปีที่แล้ว

    or just use Linux.

  • @clem5858
    @clem5858 11 ปีที่แล้ว

    Lol

  • @chezer9236
    @chezer9236 8 ปีที่แล้ว

    OMG jp file

  • @TheDesius
    @TheDesius 11 ปีที่แล้ว

    Can you send me a download link (in pm) to this virus so I can test it on a virtual machine

  • @vinc544495
    @vinc544495 11 ปีที่แล้ว

    Me 2

  • @lordcybertoolz2034
    @lordcybertoolz2034 3 ปีที่แล้ว

    *Jones_Tec* is reliable when it comes to recovery of files.he's a genius without any delay.

  • @mooselexus
    @mooselexus 11 ปีที่แล้ว

    Put in h ttps://