Ryuk Ransomware: Live Demo and Analysis

แชร์
ฝัง
  • เผยแพร่เมื่อ 12 พ.ย. 2024

ความคิดเห็น • 155

  • @kamranrasheed4180
    @kamranrasheed4180 3 ปีที่แล้ว +81

    Legends and kids are still waiting for Kaspersky vs Bitdefender 2021

    • @the-Gammaron
      @the-Gammaron 3 ปีที่แล้ว

      Lol

    • @pushpendramishra2297
      @pushpendramishra2297 3 ปีที่แล้ว

      Yes😂

    • @the-Gammaron
      @the-Gammaron 3 ปีที่แล้ว +1

      @Heberth R. Kaspersky.. that will take even longer. Sometimes it can take 4 hours to full scan PC.

    • @kamranrasheed4180
      @kamranrasheed4180 3 ปีที่แล้ว +2

      @Heberth R. Yeah bitdefender scans are very deep and complex compared to Kaspersky

    • @username-uq6zq
      @username-uq6zq 3 ปีที่แล้ว

      Lol yes

  • @akixvagymarinene2834
    @akixvagymarinene2834 3 ปีที่แล้ว +7

    One of the best malware analysis channels out there!

  • @mooselexus
    @mooselexus 3 ปีที่แล้ว +4

    Yes, please!, I would also, like to see , how effective a trial of cynet that is against your ransomware?
    When you get a second...... would like to see.
    Kind regards,

  • @TheCerbron
    @TheCerbron 3 ปีที่แล้ว +7

    WHAT A TIME TO BE ALIVE

    • @banana_squared
      @banana_squared 3 ปีที่แล้ว

      1000 pp

    • @-wokhead
      @-wokhead ปีที่แล้ว

      Oh MY god its a stop sign

    • @-wokhead
      @-wokhead ปีที่แล้ว

      Finding nemo

  • @admrotob
    @admrotob 3 ปีที่แล้ว +10

    Good analysis and demo of this new variant. Thanks for the intelligence 👍

  • @dend1
    @dend1 3 ปีที่แล้ว +13

    Ryuk did nothing wrong, aside from that whole bringing the death note into the human world thing 😁

  • @Milos.L
    @Milos.L 3 ปีที่แล้ว +2

    Heck yeah! Glad to see your cnannel growth 🙌

  • @Enforcedcraft
    @Enforcedcraft 3 ปีที่แล้ว +3

    Nice. Good content as always. Appreciate it.

  • @waw4428
    @waw4428 3 ปีที่แล้ว +3

    Awesome. Question: couldn't ransomware be significantly mitigated if normal windows users had a function to not allow common extension (exe, pdf, jpg, word, etc) to be modified or deleted/replaced on a large scale? I mean, most of the files attacked are very know/common extensions and files that 99.9% of people would never even think about changing the extension or deleting/replacing on a massive scale.

  • @mannym8ker
    @mannym8ker 2 ปีที่แล้ว

    Thanks for this vid man, I work with malware analysis and was looking for this.

  • @MomentsInTrading
    @MomentsInTrading 2 ปีที่แล้ว

    A company I used to work for got hit with this just a couple of months ago. (I’m watching this to learn what they went through). The whole company was pretty much shut down for a few weeks because of this.

  • @ayden8901
    @ayden8901 3 ปีที่แล้ว +5

    Absolutely love your content :)

  • @charleh.
    @charleh. 3 ปีที่แล้ว +31

    Ryuk sounds like an edgy teen name

    • @ae8177
      @ae8177 3 ปีที่แล้ว +19

      it is name from death note

    • @erenyeagersasageyo
      @erenyeagersasageyo 3 ปีที่แล้ว +7

      @@ae8177 Shinigami 🔥

    • @erenyeagersasageyo
      @erenyeagersasageyo 3 ปีที่แล้ว +1

      Rudgard

    • @ae8177
      @ae8177 3 ปีที่แล้ว

      @@erenyeagersasageyo what

    • @avidcracksmoker
      @avidcracksmoker 3 ปีที่แล้ว +1

      @@ae8177 Ryuk is a Shinigami or demon

  • @Bean_consumer7
    @Bean_consumer7 3 ปีที่แล้ว +13

    What happens if u r in the process of getting infected / getting a virus to run for a few seconds but it doesn't complete what it is supposed to ( like encryption ) and u immediately force shutdown your pc?

    • @kjellbeats
      @kjellbeats 3 ปีที่แล้ว +1

      Good question

    • @mrpro2264
      @mrpro2264 3 ปีที่แล้ว

      some file encrypted and some will be safe i guess (I am not sure because i am not try that but i tell you what i expect 😉

    • @davidoff5898
      @davidoff5898 3 ปีที่แล้ว +7

      Most ransomware drops an autorun file to prevent shutdown from interrupting the encryption process, so it will restart once the PC is turned on again. (Maybe I made some grammatical mistakes, English is not my first language)

    • @kjellbeats
      @kjellbeats 3 ปีที่แล้ว +3

      @@davidoff5898 makes sense. Your didn’t make any grammatical mistakes as far as I can tell, but I‘m not English either.

    • @Bean_consumer7
      @Bean_consumer7 3 ปีที่แล้ว

      @@davidoff5898 Ok thanks

  • @Henk717
    @Henk717 3 ปีที่แล้ว +2

    Given i designed Pictolocker as a proof of concept to fool common misconceptions i also made it work on network locations first. Not this aggressive since that would have been slower and i also needed to be able to control it but it would work from drive Z to C. It really helps the ransomware and its why i advocate for tripwire files on the network that shut the network drive down if deleted.
    Kinda surpriced they still go with the file extension and ransomnote mechanic though since that makes it much easier to block against it. It makes me wonder what this ransomware does if the file extension is blocked. Will it just delete the files or would it be a means of stopping it?
    I also was curious about the worm effect which you unfortunately didn't demonstrate.

  • @HTBLuVA
    @HTBLuVA 3 ปีที่แล้ว +3

    I added my smb shared folders to the Windows Defender Ransomware protected access feature. Will this help? I added them on every computer that has access to these folders.

  • @gec929
    @gec929 3 ปีที่แล้ว +2

    Hey, thanks for this vid! I have 2 questions: If a system infected by ransomware like Ryuk trying to encrypt files or infect other computers on the network, but these other computers are protected by strong antivirus and antimalware software, would the ransomware still be able to encrypt files or infect the other computers on the network? Can Ryuk spread from cell phones to computers on a network? Thanks in advance!

    • @johnwig285
      @johnwig285 ปีที่แล้ว

      It depends on how the antivirus & ransomware work. Typical antivirus works detects ransomware based on its signature & behaviour. I cant rmbr but there's a paper specifically talking abt the loopholes.

  • @mooselexus
    @mooselexus 3 ปีที่แล้ว +5

    Hi,
    Can you test you K7 Ultimate Security Infiniti Edition.
    When you get a second , would greatly appreciate......
    Also, could do review on Ransomware Rewind Software<
    Please!
    Kind regards,

  • @mrpro2264
    @mrpro2264 3 ปีที่แล้ว +7

    new video 👍👍

  • @coolnetthere2791
    @coolnetthere2791 3 ปีที่แล้ว

    @ThePCSecurityChannel If you don't mind me asking, out of all of the ransomware tests you did, which one would you recommend for consumers?

  • @bobanpetrovic2634
    @bobanpetrovic2634 3 ปีที่แล้ว +16

    Please test avast free again, it haves free ransomware shield now.

    • @ultralaggerREV1
      @ultralaggerREV1 3 ปีที่แล้ว

      Really?!

    • @bobanpetrovic2634
      @bobanpetrovic2634 3 ปีที่แล้ว

      @@ultralaggerREV1 yes

    • @BlueV1
      @BlueV1 3 ปีที่แล้ว

      Im pretty sure it had ransomware shield in his last test. I could be wrong though been a while since i watched it.

    • @bobanpetrovic2634
      @bobanpetrovic2634 3 ปีที่แล้ว +3

      @@BlueV1 it didnt, it was like 6-8 months ago, when it didnt have it

  • @عطاءالرحمن
    @عطاءالرحمن 3 ปีที่แล้ว +1

    Hello. I want to get your opinion on which antivirus should I install on my pc. I use windows defender only. My usage is medium and i don't want that antivirus which takes a lot of processing power and ram...

  • @ConservativeCoinCollector
    @ConservativeCoinCollector 3 ปีที่แล้ว

    Another ransomware I don't need to worry about thanks to Malwarebytes.

    • @Wahinies
      @Wahinies 3 ปีที่แล้ว

      True because Malwabytes real time protection slows the computer down so much, not much else can run

    • @SaadKhanUnited
      @SaadKhanUnited 2 ปีที่แล้ว

      In another video, Ryuk was able to shutdown Malwarebytes immediately and go on with the encryption process as usual.

  • @jappanjyot794
    @jappanjyot794 3 ปีที่แล้ว +3

    I jave deleteted windscribe but i checked task manager and it is showing windscribe in startup can i fix it ??

    • @BlueV1
      @BlueV1 3 ปีที่แล้ว

      @Diego Carlos Shut up

  • @unlydoors4u
    @unlydoors4u 2 ปีที่แล้ว

    I almost fell asleep watching this on bed

  • @insert-yes
    @insert-yes 3 ปีที่แล้ว +6

    Hi, love your vids. Also I am early

  • @busyhacker63
    @busyhacker63 3 ปีที่แล้ว

    Nice video, I just like to ask if you have a memory sample or can image one for memory forensics and behavioral analysis

  • @arthurkeech
    @arthurkeech 3 ปีที่แล้ว

    The IPs listed are the entire private IP zone. Nothing to actually do from a networking perspective. A proper EDR solution like SentinelOne or Sophos InterceptX will prevent these attacks effectively. Cloud integration is essential for all AV systems

  • @MrMgrPL
    @MrMgrPL 3 ปีที่แล้ว

    Hi, can you test backup solutions against ransomware? Specially the Widows native backups.

  • @OthmanAlikhan
    @OthmanAlikhan 3 ปีที่แล้ว

    Thanks for the video =)

  • @ecu4321
    @ecu4321 3 ปีที่แล้ว +1

    Can you try testing a trial if cynet and see how effective that is against any ransomware?

  • @sachink9075
    @sachink9075 3 ปีที่แล้ว +2

    Can you do a demo on medusalocker ransomware?

  • @al-ihsan-institute
    @al-ihsan-institute 3 ปีที่แล้ว +1

    no body is talking about that ryuk is from death note man. damn. don't you guys watch death note.

  • @xiaomi_grus_ita3587
    @xiaomi_grus_ita3587 3 ปีที่แล้ว

    But why this demos are without windows defender? Can we try to see a demo of a system updated?

  • @gibranhaekal5399
    @gibranhaekal5399 ปีที่แล้ว

    How you got malware to analyze?? Isnt it dangerous?

  • @Eww...NotTheHumansAgain
    @Eww...NotTheHumansAgain 3 ปีที่แล้ว

    Sh*t, Kira is attacking!

  • @danteoffline1198
    @danteoffline1198 3 ปีที่แล้ว +2

    BiG FAN SIR .....

  • @TheTunesinmyhead
    @TheTunesinmyhead 3 ปีที่แล้ว +1

    what happens with hidden and read only folders?

  • @tar3712
    @tar3712 3 ปีที่แล้ว +1

    Still waiting for Kaspersky vs bitdefender

  • @SafYounes
    @SafYounes 3 ปีที่แล้ว

    I somehow got infected with a rw, a .cadq encryption. I believe it is an online encryption, any chance of having +200 GB of files back?

  • @awhvex7188
    @awhvex7188 3 ปีที่แล้ว +1

    wouldnt this be linked to EternalBlue?

  • @HowardTse
    @HowardTse 3 ปีที่แล้ว +3

    *Imagine forgetting to run everything in a virtual machine then realizing that your PC is infected....*

  • @schrodinger_wave5933
    @schrodinger_wave5933 3 ปีที่แล้ว

    Waiting for Anti Virus /Anti Malware review for vintage laptop , have low hardware specs just don't know which to choose K9 antivirus or F-Secure Antivirus.

    • @BlueV1
      @BlueV1 3 ปีที่แล้ว

      Have you considered kaspersky at all?

    • @schrodinger_wave5933
      @schrodinger_wave5933 3 ปีที่แล้ว

      @@BlueV1 i don't think kaspersky will work fine on laptop with 2 GB ram and intel pentium dual core processor.

    • @BlueV1
      @BlueV1 3 ปีที่แล้ว

      @@schrodinger_wave5933 I dont know about K9 but kaspersky is much lighter than F secure. I once tested how many antiviruses I could put on a single vm before it was unusable, i almost had to uninstall f secure because it was taking up over a gig of ram on a 4 gig vm. Maybe I got a memory leak or something butit was also using way more CPU up to 30% on a 3 core.

    • @sudonsudo4632
      @sudonsudo4632 3 ปีที่แล้ว

      @@BlueV1 Kaspersky cloud free has a firewall?

    • @BlueV1
      @BlueV1 3 ปีที่แล้ว

      @@sudonsudo4632 I dont think so but I could be wrong I prefer to use comodo firewall anyway.

  • @kader8815
    @kader8815 ปีที่แล้ว

    where find the ransomware ? to try

  • @shy_sorai_vlogs
    @shy_sorai_vlogs 3 ปีที่แล้ว +1

    I came to the channel to see whether I could use only Windows Defender and if AVG was garbage. But I stay just for his voice, lol.

  • @amigotv4762
    @amigotv4762 3 ปีที่แล้ว

    I have a ransomware with an ft4eg extension, Sodinokibi (REvil) Ransomware , can you decode it, thanks

  • @kader8815
    @kader8815 ปีที่แล้ว

    any link for ryuk to do a lab ?

  • @KaranSingh-or7yy
    @KaranSingh-or7yy 3 ปีที่แล้ว +7

    *Please review ClamAV....* 🔥🔥

    • @Henk717
      @Henk717 3 ปีที่แล้ว +3

      ClamAV has always sucked. Its way worse than Windows Defender.

    • @Krisztian5HUN
      @Krisztian5HUN 3 ปีที่แล้ว +1

      ClamAV is always shit

    • @malwaretestingfan
      @malwaretestingfan 3 ปีที่แล้ว

      @@Henk717 It's in fact very old, it was maybe good in 2004 or 2005.

  • @tomnook9829
    @tomnook9829 3 ปีที่แล้ว

    So do they just write your pc in the death note ?

  • @rambegol868
    @rambegol868 ปีที่แล้ว

    where can i download ryuk virus?

  • @kungfupanda9327
    @kungfupanda9327 3 ปีที่แล้ว

    Can you do a Ransomware vs K7 Total Security??

  • @Sievart2
    @Sievart2 2 ปีที่แล้ว

    unrelated: it isn’t pronounced “rī-ük” it is pronounced “rē-ūk”

  • @michaelhill7774
    @michaelhill7774 3 ปีที่แล้ว

    MORE!

  • @supr-usr.1334
    @supr-usr.1334 3 ปีที่แล้ว +1

    Next vid avast vs ryuk

  • @Forp777
    @Forp777 3 ปีที่แล้ว +2

    Can you make video on safe vm to try.viruses?

    • @richardeliukas
      @richardeliukas 3 ปีที่แล้ว

      Virtualbox for free, vmware is paid, but bit better, and use vpn to try em

    • @Forp777
      @Forp777 3 ปีที่แล้ว

      What’s a good vpn that’s free or like cheap that works

    • @asil6077
      @asil6077 3 ปีที่แล้ว +1

      @@Forp777 Nord vpn or Proton vpn

    • @Henk717
      @Henk717 3 ปีที่แล้ว

      I can tell you the bare minimum to do it, but still recommend against it because one mistake and bad things can happen.
      1. VM software that supports spoofing, virtualbox is a good choice here.
      2. Some means of isolating your PC from the rest of the network. I use windscribe for this with its firewall set to block lan connections.
      3. A VPN to avoid getting your internet connection terminated when you get malicious activity going.
      4. Ways to keep the virus away from breaching your own data. This depends on the virus you want to play with. But with ransomware especially wormable ones you do NOT want any PC turned on with its valuable data connected.
      5. (Optional) a means of spoofing the VM so that the virusses will think its a real PC.
      6. (Only optional if you know for certain the sample can't breach VM's) Hardenend settings and updated vm software to prevent it breaching the vm.
      7. A great antivirus on the host pc to hopefully catch it if it does escape your VM.
      All in all if you plan on getting into this start easy. I always loved fake antivirus programs. Adware can be fun to watch to. Stuff you can really see happen but won't cause a big problem if it escapes your VM. Save ransomware and especially wormable ransomware until you are 1000% certain what you are doing and are 100% gauranteed not to make a mistake in your security.

    • @Forp777
      @Forp777 3 ปีที่แล้ว

      @@asil6077 ok sounds good

  • @johnsweda2999
    @johnsweda2999 3 ปีที่แล้ว

    Why can't you bash the encryption file all the decryption software on the internet just try each one find the matching code hey sesame back in

  • @Sky_2575
    @Sky_2575 3 ปีที่แล้ว

    bro hablas español o ingles buen video

  • @Laybaysb
    @Laybaysb 3 ปีที่แล้ว

    Can you make a video to how you test the av

  • @AlrekArinbjorn
    @AlrekArinbjorn 3 ปีที่แล้ว

    can I get a link to the virus total page for this?

  • @scooter8853
    @scooter8853 3 ปีที่แล้ว

    Hey leo!

  • @thebritishindian1
    @thebritishindian1 3 ปีที่แล้ว

    Thanks for the video. Would be good to get your thoughts on the hack of Acer Corporation’s systems which has been in the news.

  • @737u
    @737u 3 ปีที่แล้ว +4

    Ayo osu player ransomware?

    • @zazaeater43
      @zazaeater43 3 ปีที่แล้ว

      yes

    • @-wokhead
      @-wokhead ปีที่แล้ว

      Oh my god its a stop sign

  • @niteshchaudhary4585
    @niteshchaudhary4585 3 ปีที่แล้ว

    can it encrypt linux file system also ?

    • @antiransomware
      @antiransomware 3 ปีที่แล้ว

      Had the same issue until someone recommended me to *roticman* on Instagram and he did fixed mine successful.

  • @gtb733
    @gtb733 3 ปีที่แล้ว

    Please could you do a McAfee test for 2021

  • @Nicecube3D
    @Nicecube3D 3 ปีที่แล้ว

    I got hit by ryuk last years the only thing i can say is Webroot is a piece of shit ... badactor disabled Windows Defender and Webroot hasn't seen anything at all. Very funny to see in webroot no threat detected when my computer is completely encrypted ...

  • @jibinjoseph5133
    @jibinjoseph5133 3 ปีที่แล้ว +1

    0:05, It's pronounced R-ee-uk, not Riek!

    • @user-mk2su9fd2v
      @user-mk2su9fd2v 3 ปีที่แล้ว

      Who cares

    • @jibinjoseph5133
      @jibinjoseph5133 3 ปีที่แล้ว +1

      @@user-mk2su9fd2v The majority of anime fans who are aware of the significance, except you

    • @-wokhead
      @-wokhead ปีที่แล้ว

      ReeYouKay

  • @dogscangame
    @dogscangame 2 ปีที่แล้ว

    Malwarebytes gets terminated by ryuk

  • @redeyes057
    @redeyes057 3 ปีที่แล้ว

    i thought deathnote but its ok

  • @Virlo
    @Virlo 3 ปีที่แล้ว +1

    Best antivirus without sponsor is...?

  • @rajlohith3648
    @rajlohith3648 3 ปีที่แล้ว +2

    it's ruyuk not "riuk"

  • @Mfti
    @Mfti 3 ปีที่แล้ว +2

    1 view and 9 likes 😕

    • @ethimself5064
      @ethimself5064 3 ปีที่แล้ว +3

      TH-cam can be slow to update things like this

  • @HelloHi-eu5rk
    @HelloHi-eu5rk 3 ปีที่แล้ว

    death note???

  • @fulygon
    @fulygon 3 ปีที่แล้ว

    ReeyouKay

  • @doritoman8918
    @doritoman8918 3 ปีที่แล้ว

    Hi

  • @mrpro2264
    @mrpro2264 3 ปีที่แล้ว

    test mcafee please pro

  • @junior-ky1mz
    @junior-ky1mz 3 ปีที่แล้ว

    Better call the L

  • @0mkar_
    @0mkar_ 3 ปีที่แล้ว

    try Net Protector Anti virus

  • @-wokhead
    @-wokhead ปีที่แล้ว

    National geographic god dammit

  • @the-Gammaron
    @the-Gammaron 3 ปีที่แล้ว +1

    Hehe

  • @redrid3rballistikspreeeeee434
    @redrid3rballistikspreeeeee434 2 ปีที่แล้ว

    young Jamie &&&&&&& redban &&&&&&&& & XENA &&&& Joey Diaz

  • @doritoman8918
    @doritoman8918 3 ปีที่แล้ว

    First

  • @AnglOsAxOn2
    @AnglOsAxOn2 3 ปีที่แล้ว

    Appreciate the content, but it must have been aimed at those already PC literate.

  • @redrid3rballistikspreeeeee434
    @redrid3rballistikspreeeeee434 2 ปีที่แล้ว

    9004 HANFORD ave HESPERIA

  • @ytrazerpg3d537
    @ytrazerpg3d537 3 ปีที่แล้ว +1

    Hi