Тёмный

Malware beats Windows Defender: How you get hacked 

The PC Security Channel
Подписаться 527 тыс.
Просмотров 193 тыс.
50% 1

Опубликовано:

 

29 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 585   
@patagum8289
@patagum8289 8 месяцев назад
I could have sworn I've seen something like this before, but instead of a sponsorship, it was for discord game testing scams. Insane how widespread it's getting.
@Haorelian
@Haorelian 8 месяцев назад
Honestly, fell for one of those "Discord Game Testing" scams. Tried running the so-called "game," got hit with an error. Took me two days to realize it, checked all my accounts-no login, no spammy ads or malware. Lucky break, but still had to force logout and change all passwords. Lesson learned: steer clear of these scams, folks. A momentary lapse can lead to a world of trouble.
@user-jm8sy5ox2j
@user-jm8sy5ox2j 8 месяцев назад
Discord game sponsorships are different, they wanted you to run an actual exe which predictably gives you malware
@fireninja8250
@fireninja8250 8 месяцев назад
So I shouldn't advertise my game on discord?
@farhanrejwan
@farhanrejwan 8 месяцев назад
@@fireninja8250 perhaps you still can, just don't ask them to run an exe file right away, or at least tell them to do the testings in a virtual machine.
@dsfs17987
@dsfs17987 8 месяцев назад
what is insane that people will trust some random emails, not catch up on the weird email addresses, then download zip files, unzip them, and run additional programs requiring passwords - THAT is amazing, I mean - this isn't rm -rf and enter, there are red flags all through out that whole email convo, and still people fall for that crap
@SkoomaChugger
@SkoomaChugger 8 месяцев назад
this stuff really scares me cuz of how many older folks fall for this
@Pektar135
@Pektar135 8 месяцев назад
That’s why I installed Kaspersky on the pc from my grandmother
@freen1364
@freen1364 8 месяцев назад
So do kids
@nezu_cc
@nezu_cc 8 месяцев назад
older? I know people from almost every age group that have a high chance of falling for this and a lot of other seemingly easy to spot scams and malware. Not everyone is chronically online.
@ponponpatapon9670
@ponponpatapon9670 8 месяцев назад
@@nezu_cc true, only being chronically online can you spot malware hehe
@SkoomaChugger
@SkoomaChugger 8 месяцев назад
@@nezu_cc obviously dr obvious but older folks fall for way more often than anybody else
@harmonbrentdm
@harmonbrentdm 8 месяцев назад
How good is this with Malwarebytes..
@SireSquish
@SireSquish 8 месяцев назад
I have a dedicated folder for downloading any suspicious emails, and NTFS permissions are set to deny execute (ALL) in that folder. It's not much, but it's one extra onion layer.
@skyesky0
@skyesky0 8 месяцев назад
"My operating system is TempleOS"
@tonnentonie2767
@tonnentonie2767 8 месяцев назад
Can't hack the oracle
@wernerviehhauser94
@wernerviehhauser94 8 месяцев назад
GEOS 2.0
@wernerviehhauser94
@wernerviehhauser94 8 месяцев назад
@n0tjak I would argue that you haven't really understood the video. It is very likely that they also have a payload for Linux, which would be pretty easy to generate since the user is effectively executing it, Linux trusts the user (mostly) and there are less defense mechanisms on Linux against this type of attack (since it was increadibly rare in the past)
@flaskoflife9044
@flaskoflife9044 8 месяцев назад
LOOL
@DiabolicCrusher
@DiabolicCrusher 7 месяцев назад
FBI monkeys moment.
@bluecrest9762
@bluecrest9762 8 месяцев назад
This video makes it seem like you're discrediting Windows Defender, but you didn't really show whether other antiviruses can catch this thing. Code obfuscation techniques can disguise malware signatures, allowing them to evade some antivirus detection. You showed Norton giving a generic warning, but that's not the same as detecting the actual threat. It'd be good to see how some other antivirus programs handle this - does it sneak past them too? Maybe it's an issue for more than just Windows Defender. No antivirus is perfect, so comparing a few could give people a better idea of how hard this kind of attack is to catch.
@Bouwer2100
@Bouwer2100 8 месяцев назад
basically this
@tablettablete186
@tablettablete186 8 месяцев назад
Finally, someone with critical thinking
@OhHeyItsShan
@OhHeyItsShan 8 месяцев назад
Thank you! He also spotted the email header was not genuine and at 1:30 you can see so many grammar mistakes in the email - "All right, let's get to jobs" - JOBS? / "read WITH the Magix contract" - WITH? (common when it's scammers, not the case when its from a legit company like Magix). Those should have been enough signs to stop in his tracks without pursuing this anything further.
@jasongo3793
@jasongo3793 8 месяцев назад
And where is the VirusTotal scan of the exe file? That way we can see how the other antiviruses works against this threat.
@Pewafamath
@Pewafamath 8 месяцев назад
It seems pretty crazy that a recently downloaded application doing a specific action like, grab session tokens, wouldn't alert ~something~. I understand(glad even) them not scanning a file with a password but I can't think of many things that would do that specific action.
@mollthecoder
@mollthecoder 8 месяцев назад
There's legit reasons for this, like if you're changing browsers and use its "import browser data" functionality. Although I do agree that there should be more in place to prevent these, it is a very fine line with high stakes, that must be tread carefully.
@theoldtruth1196
@theoldtruth1196 8 месяцев назад
Indeed. I wonder why windows didn't say anything at all about running the unknown .exe?
@niccis1982
@niccis1982 8 месяцев назад
@@theoldtruth1196 because it's not using administrator rights thus not requiring an Okay by the user and also not a certificate to show it's from a reputable source.
@erikkonstas
@erikkonstas 8 месяцев назад
​@@niccis1982They're talking about SmartScreen, not UAC.
@gabrielandy9272
@gabrielandy9272 8 месяцев назад
don't the passwords are stored incrypted by some form? i understand cookies being not, but hmm?
@AllExistence
@AllExistence 8 месяцев назад
Listen guys, never ever run or open any files that are password protected. There is almost no reason to encrypt stuff like that other than malware or personal data.
@liforra
@liforra 8 месяцев назад
Except if its expected to trigger antiviruses, like pirated software would
@AllExistence
@AllExistence 8 месяцев назад
@@liforra Unless you antivirus triggers at hacktools, or keygens, it's probably for a good reason.
@fraznofire2508
@fraznofire2508 8 месяцев назад
@@liforra pirated software does not mean you should interact with it. Pirated content is infected more often than not
@liforra
@liforra 8 месяцев назад
@@fraznofire2508 honestly that is incorrect, i do actuallx pirate software and honestly, as long as youre a bit careful its really not that bad, but dont open isos those are suspicious because thexre usually not used as archive
@gizmowizard352
@gizmowizard352 8 месяцев назад
As a experienced hacker, I must say that never ever open any file without checking with a reliable AV(not including Windows Defender).Even if it looks a like a legit Microsoft Windows file, still check it.We learnt that lesson with NoEscape.exe, which looks like Windows Defender itself.
@tiagoferreira086
@tiagoferreira086 8 месяцев назад
Oh man how much i laugh when you said that the criminals are discussing about win11 being spyware and don't like competition 🤣🤣🤣 that's absolutely hilarious
@markusTegelane
@markusTegelane 8 месяцев назад
This is why we should always right click on a downloaded file and see properties to confirm that a file is what it claims to be (e.g. a PDF shouldn't be identified as an executable program)
@youdontneedmyrealname
@youdontneedmyrealname 8 месяцев назад
Show file extensions should be on by default.
@raylopez99
@raylopez99 8 месяцев назад
And don't enter a "password" to "unlock" a file.
@youdontneedmyrealname
@youdontneedmyrealname 8 месяцев назад
@@raylopez99 password protect files are actually quite common. You just REALLY need to know where it's coming from, and best case scenario is you can open and edit it in a secure virtual environment.
@raylopez99
@raylopez99 8 месяцев назад
​@@youdontneedmyrealname Yeah I've played around with type 2 virtual environments but I've never had a legitimate password protected file sent to me for business, and I've worked in Silicon Valley on multi-billion dollar deals back in the days (90s and 00s). Maybe it's different now, I dunno I'm retired.
@youdontneedmyrealname
@youdontneedmyrealname 8 месяцев назад
@@raylopez99 I work with medical records in my industry so encryption is a requirement for HIPAA compliance.
@nezu_cc
@nezu_cc 8 месяцев назад
this is a very effective way to get around not only Defender but also all the other sandbox-based solutions because what it effectively does is use the password you type in as the decryption key. Many sandboxes will try to interact with UI elements so a simple message box is not enough but asking for user input is because no sandbox out there will know the password. And the reason why it doesn't trip afterward is that defender does the bulk of its scanning before the file is run with only minimal heuristics at runtime.
@wannabedal-adx458
@wannabedal-adx458 8 месяцев назад
But if you open this file in a sandbox, won't that still protect your system? Isn't that the purpose of a sandbox?
@nezu_cc
@nezu_cc 8 месяцев назад
@@wannabedal-adx458 I'm not talking about the sandboxes that a user might use (like sandboxie), I'm talking about the automated malware analysts sandboxes that run the sample in a clean VM each time and record everything the sample is doing (like cape sandbox).
@SetSubarashii
@SetSubarashii 8 месяцев назад
Ways to prevent getting hacked Step 1: Don't Open Emails lul
@niezzayt3809
@niezzayt3809 8 месяцев назад
when you tell the sender what kind of Operating System you have, like you might say Windows 11, you move to another Operating system, like Linux but in dual boot mode. And then open the Emails from there.
@tezcanaslan2877
@tezcanaslan2877 8 месяцев назад
@@niezzayt3809use some locked down system like ios to open mails
@Alextelefoon
@Alextelefoon 8 месяцев назад
It can also with other files and with BROWSER EXTENSIONS.
@cpufrost
@cpufrost 8 месяцев назад
Use a whitelist, anything not on it is quarantined in a folder that only reads text/headers. Relying an security software to protect you is like relying on a gun safety to protect you from an armed robber. And it slows the fsck out of your computer, wasting resources and power.
@niezzayt3809
@niezzayt3809 8 месяцев назад
@@cpufrost using "Whitelist" is still equal to "relying on" certain algorithm-which you might see it as software. Whenever dealing with Emails, it's not only about security. It's about Social Engineering. How you manipulate your recipient is more important than the contents of the Email itself. By pretending to lowering your guard can reveal the other party's true intentions. Therefore, if a malware was designed to attack certain OS, it is way simpler to just open it in another OS where the malware is completely useless.
@Capt-Intrepid
@Capt-Intrepid 8 месяцев назад
NO. That's not a PDF. That's an executable (application).exe The icon is a pdf. But the file extension is .EXE !!! 2:08
@FrostlifeV
@FrostlifeV 8 месяцев назад
Did you even watch the whole thing, it's literally written there by him.
@Capt-Intrepid
@Capt-Intrepid 8 месяцев назад
@@FrostlifeV That's not what he said at 2:08
@tablettablete186
@tablettablete186 8 месяцев назад
​@@FrostlifeVOP is right
@jaydoubleyou780
@jaydoubleyou780 8 месяцев назад
Yes, I thought I was losing it, video should be corrected. He makes it seem like a PDF will execute if you put the password in and steal your cookies. I literally had to freeze it a few times to make sure it was an EXE and not a PDF when it's listed in the zip folder as an application and Leo said it was a PDF. I was like what exploit is this in PDF I have to look out for now? Also wish he stressed how every time you use windows to make sure file extensions are not hidden. It happens, still love the Channel.
@balsalmalberto8086
@balsalmalberto8086 8 месяцев назад
​@@jaydoubleyou780 exactly this. the filename is shown by norton and has exe extension. if It's a PDF exploiting software than it can be mitigated .. Anybody knowledgeable about computers should know never to run stray executable from random person. micrsoft makes it too easy for malicious to prey on the unsuspecting because they hide the file extension by default and again by not flagging an executable that grabs browser data as unexpected and possible harmful behavior. MS hates nirsoft tools but a random executable has free reign to do basically the same thing so it seems.
@FadedKai
@FadedKai 8 месяцев назад
First red flag was the Email it was set from.
@kbhasi
@kbhasi 8 месяцев назад
Some e-mail clients, particularly those made for mobile OSes (like iOS and Android) hide the sender e-mail address in order to provide what their UI/UX designers would see as a clean UI. However, many people who aren't tech-savvy, like my parents, wouldn't notice that it's possible to tap a not-so-obvious down arrow or the round profile picture to reveal the full e-mail address.
@EADYT
@EADYT 8 месяцев назад
I wonder, did other AVs caught it? I mean, Bitdefender/Kaspersky/ESET and such, using their behavioral model and other real time protection modules?
@FJB-bl8xg
@FJB-bl8xg 8 месяцев назад
Intune Windows Defender will block it with ASR Attack Surface Reduction.
@jorgitogaitan
@jorgitogaitan 8 месяцев назад
But the passwords only leaked if you saved them on the browser? Or are they being able to hit bitwarden and getting from the add-on??
@Krlowanigu-mg6eg
@Krlowanigu-mg6eg 8 месяцев назад
Good question
@yspegel
@yspegel 8 месяцев назад
But who wouldn't get seriously alarmed by a password protected file AND the password in the SAME attachment? That defeats the purpose of pw protection unless you want to bypass security.
@3polygons
@3polygons 8 месяцев назад
You would be surprised...
@yspegel
@yspegel 8 месяцев назад
@@3polygons you're probably right and I shouldn't be surprised, knowing the average pc user.... but still
@A42yearoldARAB
@A42yearoldARAB 8 месяцев назад
Often video games have this, but still a video game should be much larger
@JJFlores197
@JJFlores197 8 месяцев назад
@@yspegel Have you ever worked in IT tech support? You would be surprised at the amount of people using computers who understand next to nothing about computers nor have any computer security training or knowledge. I work in school IT as an IT tech. We run several phishing campaigns per year and its astonishing how many people, even "higher ups" who fall for them. We've had several people flat out enter their email and password into one of our phishing campaigns because according to the email, they're supposed to "validate their account information".
@od1sseas663
@od1sseas663 8 месяцев назад
Does Kaspersky’s heuristics detect it?
@greghust8608
@greghust8608 8 месяцев назад
I'm actually curious to see if it gets detected by the modern antiviruses (Kaspersky, Malwarebytes, BitDefender etc).
@tybronx2446
@tybronx2446 8 месяцев назад
Boosting this, would like to know as well
@Lupinicus1664
@Lupinicus1664 8 месяцев назад
Good, clear information. Very helpful. Glad you stressed that Defender will not protect you completely (in fact no software will) and that you need 'situational awareness'.
@SartinPixel
@SartinPixel 8 месяцев назад
I once log in my school's computer (dumb move), after 15mn my account was logged in another country, that's how fast viruses steal the cookies and transform accounts into spammers. After that day, I never log on other people's computer even families.
@kbhasi
@kbhasi 8 месяцев назад
I'm guessing the school you attended used Windows but didn't use Active Directory with policies set to not allow users to run their own software. Also, it could've been possible that you attended that school at a time when they were still using Windows XP, because I know that one of the school PCs did get infected with malware that spread via USB flash drives and ran using an Autorun exploit that I think was patched out in Windows Vista or 7, and I only noticed the malware due to bad coding that saw it open another Windows Explorer (File Explorer) window with the folder pane open. I also did get my Facebook account hacked once (back before they added 2FA support), particularly with it sending and accepting friend requests with people I don't know in real life, but it turned out that some bullies looked at me typing my password, and I only found out that it was done by bullies when a classmate tipped me off in person. I then changed my password and remotely logged them out. I can only imagine where those bullies are now.
@NicolasDominique
@NicolasDominique 8 месяцев назад
I had such e-mails with the fake sponsorship. And I always wondered how it even works. Thanks for showing me that.
@godnessy
@godnessy 8 месяцев назад
Maybe talk to your sponsor and tell them to be a bit more clear on the pricing, god forbid let ppl know what it costs before registering.
@duplicake4054
@duplicake4054 8 месяцев назад
Bro really uses malware fake sponsors give him to test and make videos on. This is how you fight back.
@SuperFoxy8888
@SuperFoxy8888 8 месяцев назад
Best antivirus: common sense
@zoastro
@zoastro 8 месяцев назад
Does Kaspersky flag anything from that type of attack?
@tomschi9485
@tomschi9485 7 месяцев назад
*You're wrong: Microsoft Windows Defender has Data of many millions Windows Computer and they could easily recognize this malware.* OK: probably the first thousands computers would get infected, but for sure, M$ would be able to use this analytics data.
@BromTeque
@BromTeque 8 месяцев назад
I was consider trying out flare, but I can’t find any pricing… Like, do they actually provide prices anywhere? Because I sure as hell can’t find it, yet in their FAQ they state they have a "transparent pricing model". Cool cool, maybe add a link on that FAQ to prices? Makes it look sketchy as hell, so I’m out.
@UtherV
@UtherV 8 месяцев назад
Thanks for the concise but insightful video! Would it be possible to do an analysis of how this same scenario would play when passwords are behind browser's protections (Edge's Windows Hello or Firefox's Master Password) or when using Passkeys? Thanks!
@anywaytechreview
@anywaytechreview 8 месяцев назад
edge has windows hello? you mean to say microsoft edge wallet? windows hello is a windows feature not a microsoft edge feature
@defnotatroll
@defnotatroll 8 месяцев назад
@@anywaytechreview they mean that edge asks you to login using windows hello to reveal passwords
@moetocafe
@moetocafe 8 месяцев назад
To a wary user it doesn't look like big threat - there are multiple red flags. But many dumb office workers would potentially eat the bait.
@javiTests
@javiTests 8 месяцев назад
I've seen a few RU-vid channels that have been hacked with this method. I guess the best way of protecting against this is to never log in to RU-vid studio in the same computer that one uses to read the emails. Maybe a simple VM is enough, but definitely we need to be aware of these attacks.
@takuminightcore1886
@takuminightcore1886 8 месяцев назад
Appreciate the info I’m just curious will you be making an updated video of the best antivirus that you can get or has that not been changed since 2023 because I’m kind of curious to get an unbiased rating again instead of just going to some other places that they might be biasedespecially with free antivirus would be awesome too
@authurstretchygreenthing8464
@authurstretchygreenthing8464 7 месяцев назад
Ugh, more old people's computers for the meat grinder, I guess. Why don't these hackers get a damn life?
@portman8909
@portman8909 7 месяцев назад
A lot of old people are using Kaspersky thankfully
@pipjersey8303
@pipjersey8303 8 месяцев назад
all i need to do is read the third line of the email and i know, ''What is MAGIX? Is the easiest way to create music on a computer'' broken english is a immediate red flag, even without that thou i wouldn't open a link from an email i didn't know, especially if its just a bunch of random letters and numbers
@basharyasser5913
@basharyasser5913 8 месяцев назад
i tried to make an account via my hotmail & gmail accounts and the site said they dont accept addresses from them . what should I do?
@onomee130
@onomee130 8 месяцев назад
anything can beat windows defender
@mic27381
@mic27381 3 месяца назад
[I might be wrong!] When you download a file windows will mark it is from the web (aka. Not trustworthy) Since a few months/weeks ago windows did not flag files inside a zip downloaded.This changed!Meaning that as far as I know clicking in that fake pdf will trigger a popup.(Ofcourse this only happens when open/unzip it with windows directly not a 3rd party appl like winRAR or 7z, this might also be the reason windows added support for more file)
@bluntdocto2571
@bluntdocto2571 8 месяцев назад
I am working on my Secruity+ and the hacks nowadays are getting so good especially with AI this going be hard af job.
@notthetrueobserver
@notthetrueobserver Месяц назад
If one wall isn't enough. Than build multiple walls out of different material for each
@hectorj.romanp.
@hectorj.romanp. 8 месяцев назад
I wonder why you, being a security expert (no doubt about that), have the file extensions hidden.
@balsalmalberto8086
@balsalmalberto8086 8 месяцев назад
He's role playing as a dumb windows user. microsofts fault for setting up this type of attack.
@nathanwildthorn6919
@nathanwildthorn6919 8 месяцев назад
Great, _great_ video, Leo! 😊 Which (single) anti-malware anti-virus app would you recommend for use with Windows Defender?
@nathanwildthorn6919
@nathanwildthorn6919 8 месяцев назад
@XenoD2 Indeed, it does !
@fspeshalxo69
@fspeshalxo69 7 месяцев назад
hey , can you please have a video of this malware gets detected by other anti virus ? thinking about buying anti virus
@ObakuZenCenter
@ObakuZenCenter 7 месяцев назад
Paid versions often try to justify their cost by adding on features that aren't often all that useful. Try some of the free versions of antivirus solutions. In testing they are just as good as the paid versions often, just with less stuff added. It also means that you'll have at least some idea of how resource intensive an antivirus product is, or if you find it irritating, for example if there are a lot of false positives.
@jeremygeorgia4943
@jeremygeorgia4943 6 месяцев назад
How exactly does the file work? What does it do? Is there any way to detect it? Is it a PDF, or does it have multiple extensions? I typically ignore attachments, unless I absolutely know who sent the attachment and why. However, if I happen to have any weird PDF's on my system, I'd like to know about them. I don't have any password protected ones. I'm pretty sure about that.
@dannyd4339
@dannyd4339 8 месяцев назад
Bro talking about malware then he recommends you to install another kind of malware
@Electro-tw9um
@Electro-tw9um 8 месяцев назад
Are you claiming this malware bypasses SmartScreen?
@noelcie
@noelcie 8 месяцев назад
Damn, I did this attack over 15 years ago with a zip of "private images" of a popular guy in school. Every girl fell for it.
@alveera3610
@alveera3610 8 месяцев назад
PC security channel, do you recommend adding another antivirus software to wins antivirus system like $Norton or kapersky free edition?? Thanks for this info, look forward to your future videos! Now subscribed 👍🏼 Thanks again 💯
@MaiderGoku
@MaiderGoku 5 месяцев назад
If you're hacked it's your mistake not the os or Windows defender.
@MrKneeBeeYT
@MrKneeBeeYT 7 месяцев назад
show this to everyone who says Windows Defender is "unbeatable".
@robertroussakov9395
@robertroussakov9395 8 месяцев назад
lol @ making the user enter the password to decrypt the payload. never seen that one before
@urbanws1234
@urbanws1234 8 месяцев назад
Don’t trust anything.
@VeeTwoPointOh
@VeeTwoPointOh 8 месяцев назад
Jokes on them. I never check my email
@the_2663
@the_2663 8 месяцев назад
Thank you so much for your unbiased content. Please keep up the good work.
@panl8370
@panl8370 8 месяцев назад
can you make an updated 2024 version of "Free Security Tools Everyone Should Use" , and also test MiTeC Task Manager DeLuxe free?
@varniitprofessional
@varniitprofessional 7 месяцев назад
But Microsoft be like - Check out our AI tools.
@SumNumber
@SumNumber 8 месяцев назад
I have seen this password protected attacks in the past . At some point in the process people need to realize ,, " Wait a Minute ! " . I delete all these things without delay . I do not collaborate with any message that involves many steps or has links to the " Best new video " or " The great new shampoo " etc etc. I do not need an email to find out these things when there are hundreds of other avenues to use. :O) thanks for the share . ( The brain is meant to be used )
@88tx
@88tx 8 месяцев назад
u know ur av is shit when even norton beats it lol.
@roberthunter6927
@roberthunter6927 8 месяцев назад
A lot of password protected files are common, and legit. For example, you want to buy the electronic forms of journal article, textbook or novel. So the PDF or whatever might be zipped and password protected. If you want to earn some money as a writer, it does not make sense to give full free access to all. Not everyone is honest enough to donate towards costs, etc.
@mkumar04
@mkumar04 8 месяцев назад
with every day pass ,the chance of your pc infected in increasing , now it all need to open password protected zip file to get hacked 😫
@TheCocoaDaddy
@TheCocoaDaddy 8 месяцев назад
So, what other anti-malware tool(s) could have protected against this kind of threat, if any? Thanks for posting!!!
@draculemihawk10
@draculemihawk10 8 месяцев назад
Kaspersky and most likely Bitdefender
@alifsheikh4237
@alifsheikh4237 8 месяцев назад
​@@draculemihawk10i think you are talking about the premium plan of kaspersky, but what about the free plan?
@L2002
@L2002 8 месяцев назад
Well it's obviously not a pdf, it's an executable application, so don't open it
@A42yearoldARAB
@A42yearoldARAB 8 месяцев назад
those do not scan password protected files either do they?@@draculemihawk10
@kitsunekaze93
@kitsunekaze93 8 месяцев назад
make sure to check every file you download to make sure its actually what you think it is. dont run unknown filetypes, and REALLY dont run unknown exe files
@SireSquish
@SireSquish 8 месяцев назад
How come the actual password stealing payload didn't trigger the AV once it was decrypted and running?
@kbhasi
@kbhasi 8 месяцев назад
I believe it's because the malware exploits Windows Defender only scanning the file before running and initially running. The fake password prompt tricks the user into triggering the malware infection on command after Windows Defender had finished scanning.
@SireSquish
@SireSquish 8 месяцев назад
@@kbhasi Ah, that makes sense yeah.
@xjarhead1964
@xjarhead1964 8 месяцев назад
I used your link it says it doesn't except addresses from Yahoo or Hotmail!!! What?
@akhilsvarughese
@akhilsvarughese 8 месяцев назад
Same. Then noticed "cyber threat intelligence platform built for organizations". Use an email alias, works
@TheVideotoaster
@TheVideotoaster 8 месяцев назад
Does not accept email addresses from Rogers, Live, Yahoo. What good is it?
@dennywise153
@dennywise153 8 месяцев назад
"Name your operating system" is so sussy, why don't they just write an os detection code in their malwares?
@VoAviation
@VoAviation 8 месяцев назад
Because a Windows executable cannot be natively executed on Linux, and a Linux executable cannot be natively executed on Windows.
@solitary3767
@solitary3767 7 месяцев назад
can you explain@@VoAviation
@mkumar04
@mkumar04 8 месяцев назад
from now ,i will never open password protected zip files
@kimsena268
@kimsena268 8 месяцев назад
hi. dude, i always watch your video Leo. Plz update AVG or Avast signature! Compare with Windows defender :)
@Scav-Goblin
@Scav-Goblin 8 месяцев назад
Does Malwarebytes detect it?
@TheawesomeMCB
@TheawesomeMCB 8 месяцев назад
That person person that got the details from that virtual machine is going to look at what they took and see that it was an blank virtual machine. Then they will see this video bringing more awareness. LOL
@nbrown5907
@nbrown5907 8 месяцев назад
You can see where your emails are coming from when you hover your mouse in Windows 11 with Xfinity and google email but not on the phone. Is there a way on Android to see what the sender id is? My relatives that use their phones a lot have run into trouble with email before on their phones.
@kbhasi
@kbhasi 8 месяцев назад
Assuming you mean the official Gmail app, then that, the official Outlook app, and Apple 'Mail' (iOS) hide the e-mail address and only show the sender name. The user is expected to tap on the round profile picture to the left or a not-so-obvious down arrow to reveal the full address.
@dg-hughes
@dg-hughes 8 месяцев назад
Well the Flare trial didn't go so well it refuses any gmail email address. Or hotmail, or Outlook, or Proton brb buying a server, installing Linux, and creating my own email server....
@balajisharathkumar9753
@balajisharathkumar9753 8 месяцев назад
nowadays brower protection and antivirus sepcific to avoid these malwares but even it in place they malwares get inside in enterprise but still siem tools might detect these hardware even in firewall dose these even those there will be detections or leftover might present , any way a great vidoe
@Generic_Handle4573
@Generic_Handle4573 8 месяцев назад
Screw this I’m downgrading to 98
@JJFlores197
@JJFlores197 8 месяцев назад
I myself am going to use 98 SE 😄
@UmVtCg
@UmVtCg 7 месяцев назад
0:35 Beeeeep ain't NEVER gonna happen.. Why open e-mail conversations you've not initiated yourself. Why do VM's and sandboxes exitst... Why click on links in e-mails. Why open password protected attachments, why open attachments at all... Why are people stupid...
@DunkelBisBunt
@DunkelBisBunt 8 месяцев назад
That's why I'd recommend a proper firewall (there are free ones) that catches every unusual outgoing connection and asks you if you want to allow it or not, because the most dangerous connections are not incoming but outgoing.
@01JakeGreen01
@01JakeGreen01 8 месяцев назад
Imagine opening unknown stuff on live system instead of Windows Sandbox / VMWare.....
@erikkonstas
@erikkonstas 8 месяцев назад
And then people say "you don't need to pay for no antivirus in 2024" 😂😂😂 like bruh, what I pay for is the HEURISTICS!!!
@OhHeyItsShan
@OhHeyItsShan 8 месяцев назад
1:30 The whole time you're going on about the innocence of links, you're forgetting one of the golden rules of scammers - bad English grammar! "All right, let's get to jobs" - JOBS? That makes no sense. That one line alone would be a red flag for me before I even bothered with the links. Magix may not have Microsoft or Google money but they are a well established company so could afford to hire people who can write legitimate emails with proper spelling and grammar. Going further in paragraph 2, "read WITH the Magix contract" - WITH? Again the English is poor enough to be a warning sign and given that there are so many grammar errors laced throughout the email, that should have been the red flag.
@creammando
@creammando 8 месяцев назад
Windows Defender has been shpwn to be bypassed easily that even a little kid can do it with enough understanding, i even bypassed windows defender
@D.von.N
@D.von.N 5 месяцев назад
Always suspicious of unexpected emails with links and attachments. Or being tagged by random profiles on social media asking me to contact them, or sharing link with me. And that includes private messages from my own contacts. Even a colleague sent me sms with a link, which I didn't click on until I had it confirmed from her it was genuine. Not being greedy and nosy pays off.
@CarlAlex2
@CarlAlex2 8 месяцев назад
So you get hacked by being stupid? View Emails as ASCII only, don't click on random links and attached files and if in the least amount of doubt and you still want to click or open, view the source of the Email first. Don't indulge in unneccesary risky behaviour just because you think some safety system will protect you.
@linuxandretrogamingfan3882
@linuxandretrogamingfan3882 8 месяцев назад
Use GNU/Linux then. problem solved. No viruses in 8 years of running GNU/Linux on all my computers. Non-free software is for jerks anyway
@ABC-o5n
@ABC-o5n 13 дней назад
Email. Ye Olde school attack vector, but still vulnerable thru its social aspect.
@wannabedal-adx458
@wannabedal-adx458 8 месяцев назад
Windows Defender doesn't use reputation scoring for looking at malware, because they know that Windows OS has a low reputation!! 🤣
@SpikyRoss
@SpikyRoss 8 месяцев назад
What kind of website is app flare? I was about to register but it doesn't even accept gmail address lol
@atussentinel
@atussentinel 8 месяцев назад
It'll be fun to reverse engineer the payload, any chance there will be a video about that?
@antimsm6705
@antimsm6705 8 месяцев назад
you seriously need to enable your file extensions in the names of the files, this is the first thing you do when reinstalling windows
@markszili2577
@markszili2577 8 месяцев назад
This is just an advertisement, and provides false information about Windows, Office and Edge browser protection, Windows and Edge have user customisable features that can be turned on free of charge and prevent demonstrated situation from happening. How about be honest and truthful and show people how they can enable Windows, Office and Edge security settings, for free. instead of making click bait headlines to sell your sponsors product.
@IGoTNoAiMBoT
@IGoTNoAiMBoT 8 месяцев назад
Good thing i never read my mails
@captaindunsell8568
@captaindunsell8568 8 месяцев назад
When will windows implement black boxing or sand boxing of applications… POS OS
@Ashi13ff
@Ashi13ff 4 месяца назад
some time ago I click on the pdf attachment of a scam email, I had avast av back then, It said it was pishing virus, but when I clicked on the pdf It automatically open on microsoft edge. after some time I reseted the pc and changed all my passwords, Am I safe? sorry for bad english
@presicion25
@presicion25 6 месяцев назад
Flare wont accept any of my email address so I guess i cant use the free trial. Looks like an interesting platform though.
@iceManSwag
@iceManSwag 8 месяцев назад
The reason I dont use default antivirus or firewall. No matter how much good I hear about Defender. I have nothing against it but because it's default security for the masses.
@DianaProudmoore
@DianaProudmoore 8 месяцев назад
Bro, I always disable my windows defender after fresh installing my OS(Win7 Ult, btw) since it's basically useless~ Not worth the ram space~ I also disable windows update after getting the essential updates that my pc needs~
@JaiRudraNath
@JaiRudraNath 8 месяцев назад
What if all apps use One Time Password that changes every time and sent to your mobile as text message .. unless they hack your phone which is bit difficult, the computer info will be useless ..
@iPhoneAppReviewer
@iPhoneAppReviewer 6 месяцев назад
Why are you promoting a sponsor that doesn't permit regular users to register for their service and making it look like you can just use their service for personal use?
@Munkhbayarkhavtgai
@Munkhbayarkhavtgai 8 месяцев назад
My RU-vid account is gone after fking hacker was awable to get into my RU-vid account i had 5k followers now everything is gone 😢
@L2002
@L2002 8 месяцев назад
That's literally a basic skill, always check the file type of downloaded file. Exectuable? Don't open it
@cheezchris
@cheezchris 8 месяцев назад
Isn't it common knowledge not to click links from email? Let alone download it. Been on pc for 30 years, this is like a blast from the past. lmao I always scan my pc and clean it before using any sensitive account online. Then erase it thoroughly when im done. And neve save their passswords.
@hades_0606
@hades_0606 7 месяцев назад
There a lot people saying windows defender are enough u don't need any antivirus..😂😂😂😂😂
@ChuckHL
@ChuckHL 8 месяцев назад
No disrespect to the video maker but it clearly said on the zip file it was an application. So even after it got extracted, it is not a PDF. They made an app that it uses the PDF icon to make it look like a PDF but it still is an app. It was never a PDF... Reason why i always tell people to make sure windows shows the extension of files even if its well known extensions.
@xAgallochx
@xAgallochx 8 месяцев назад
in order for the file to get flagged by defender AV you also need to enable automatic sample submission as well as cloud delivered protection. If you have them disabled then you either have poor security knowledge or you're just spreading bullshit information trying to make it look like defender is bad.
Далее
Crypt | Bypass Windows Defender
1:32
Просмотров 237
How you get Hacked: what attackers use today
9:02
Просмотров 172 тыс.
Best Antivirus/EDR vs Unknown Ransomware
11:38
Просмотров 104 тыс.
The Anti-Virus Tier List
9:38
Просмотров 1,2 млн
How to not get hacked: real example
13:55
Просмотров 416 тыс.
Rootkit
10:20
Просмотров 1,5 тыс.
Hacking Windows TrustedInstaller (GOD MODE)
31:07
Просмотров 650 тыс.
How to Crack Software (Reverse Engineering)
16:16
Просмотров 566 тыс.
How bad is Windows spying?
13:13
Просмотров 194 тыс.
How you get hacked: Undetected Malware
10:01
Просмотров 68 тыс.