Since the other video probably wont be back until Monday, here's a bonus.
@angelblanco-pc7 ай бұрын
pc
@goongleton7 ай бұрын
oh bloody hell. i could have watched it but decided to put it off. its all on me
@Evan376457 ай бұрын
I was watching the setup one then I watched something else came back and it was gone lol
@UsuallyLime7 ай бұрын
Nice. Hoping to see the other one too cause of the claim at the beginning that it's the wildest malware ever reviewed on this channel. Just wondering what it did.
@maxtech669997 ай бұрын
Great bonus. Thanks !
@elisa_54457 ай бұрын
They sent a malware to a channel that analyses malwares, genious idea
@redlionstudio27507 ай бұрын
yeah, that just shows how dumb scammers are XD but maybe this malware was redirected by a viewer?
@bombus_7 ай бұрын
yeah but what an own it'd be on the off chance they actually manage to infect the owner of a channel that analyses malware!
@Operative857 ай бұрын
@@redlionstudio2750 Scammers aren't dumb - but they always go for the dumbest targets. Remember those Nigerian Prince emails with terrible english? Those who respond to them prove that they have no knowledge about the scam or are dumb enough to believe anything, so those same people don't know that they're about to be scammed. That means those kinds of people won't report the scam, which will allow it to keep going for longer. Nigerian Prince scams have been estimated to have stolen more than a hundred million dollars over the past few decades, which means they've filtered their targets enough to keep milking them to this day. The only dumb people here are those who think that scammers are dumb. Always be on your toes.
@TheDZHEX7 ай бұрын
When the ruble is in rubble, they can get pretty desperate I guess lol
@CZghost7 ай бұрын
Yeah. And of course send it to someone who knows how to bypass Cloudflare's proxy, and therefore knows how to get to the real C2 server's IP address, and the best thing that person does is to send that IP address to their friends to have a little fun :D
@toxicisgaming7 ай бұрын
ah yes. sending a malicious file to a youtuber who investigates malware. very smart.
@avifcollective7 ай бұрын
getting linus tech tips flashbacks
@user-dw6fj1py1o7 ай бұрын
Nice!
@Minty_Meeo7 ай бұрын
Ah yes, the classic "hide extensions of known file types" attack. Microsoft is the worst for inventing that "feature".
@EricParker7 ай бұрын
I guess technically it's probably smarter not to put the fake pdf if people are not accustomed to seeing file extensions.
@kevkevpurple7 ай бұрын
My thoughts exactly. File extensions should be enabled by default, they’re not hurting anyone.
@CZghost7 ай бұрын
Microsoft did it in an attempt to prevent people from accidentally changing the file type by renaming the extension (which by design is fairly wrong in so many occasions, because file type should NOT be determined solely by its extension). Renaming a file to a different extension might cause it to break compatibility, so Microsoft by default hides extensions to prevent dumb users to rename program files for example (causing them to no longer work). It is dumb, not gonna lie. First of all, Microsoft assuming users are dumb they don't understand extensions, that's insulting. Second of all, it's a bad design. Unix-like OS doesn't determine the file type by its extension, rather does it through file header. If that file header might correspond to many file formats (example being text files, which do not actually have a header), then the file format might be determined by the file name extension (for example: C source code files). If Windows adopted this behaviour from Unix, then it would be so nice, and there would not be many issues with renaming a file extension. Fun fact: In Unix-like OS, the file doesn't even need an extension, it can be simply just "file" with no extension, and it will still function according to its file type that's associated with the header inside. As an example, many log files might be extension-less, C++ source code header files are sometimes files without an extension (remember writing "#include " in your C++ program? That file has no extension), and some programs (including Windows Copilot and Recall) have extensions from their log files removed (which on Windows it's more of a measure to prevent users from poking around and looking for stuff they're not supposed to be poking around). Also, Windows is fully capable of opening extensionless files. Of course, you won't be able to assign a permanent application to open them, but you can still open the file by manually selecting the editor that is designed to open that file (if you know the format of the file). Not only that, Windows Command Line is capable of dumping extensionless text files into the console, the same goes for Windows Powershell (or Powershell for those who installed the latest version), and of course Command Line and Powershell don't hide the file extensions even if that is enabled in Windows.
@atsizbalik7 ай бұрын
@@kevkevpurple the little timmy would get scared after seeing the .exe file format
@lritzdorf7 ай бұрын
@@CZghostExcellent point about protecting users from themselves - you just know someone's going to rename a JPEG to PNG and expect it to work. On the other hand, even with file extensions shown, you get a warning popup if you attempt to edit the extension - which is all that should really be needed, Microsoft!
@guila7677 ай бұрын
The malware appears to be sending compressed files with your browser DB to steal your logged sessions. If you look at the packages sniffed in the proxy, they send multipart form data with a file attached. The files have a PK header, which could be a ZIP file. Have you tried to take a look at it? Would be cool if we can see what exactly they are scrapping from victim PCs
@POLARTTYRTM7 ай бұрын
I keep asking WHO is behind this Tesla scam, because it is so widespread it CANNOT be a single person, it has to be an enormous group trying to do something that has nothing really to do with crypto. One of the things people used to do a long time ago, and still do, is taking channels with a noticeable following and selling them for a fairly good amount of money, same goes for game accounts.
@YaySyu7 ай бұрын
It's going to be the same scam run by different people. Best you can do is keep track of crypto wallets and the transactions they make
@EricParker7 ай бұрын
Many different groups.
@POLARTTYRTM7 ай бұрын
@@YaySyu probably. There are also known market places where you can buy youtube channels, they go up in value a lot depending on what you are looking for, for example channel age, number of subscribers, monetization, etc. Game accounts because of in-game valuable items, account age, no restrictions in place, hours played, rank. Many variables.
@zchen277 ай бұрын
I wouldn't be surprised if the entire thing is sold as a Malware As A Service package. The stealer, the C2 servers, the crypto filler content when they do get access.
@СергейДаниленко-в3э7 ай бұрын
Lots and lots of groups from CIS. You can check out some Russian formus like Lolzteam, many of them do this collectively. But Lumma is kinda expensive, so there could be a more profession team.
@TheRealScottMusic7 ай бұрын
Eric you are criminally underrated you make some great cyber security content which I constantly find myself coming back to
@sudalie79143 ай бұрын
I came here because one of my favorite channels got hacked to stream live debate. I'm bummed about it. He's recently uploaded and I was looking forward to watch the video once I got time. And the channel's actually from Japan and uploaded calming videos of mini gardens, forests, etc. This situation is frustrating...
@lkn900l7 ай бұрын
Funny thing that, if you copy Firefox appdata file with passwords and logins, and then paste it to another PC with fresh Firefox, it will have all the passes from copied one. I guess this virus uses this vulnerability.
@average2bpvp3326 ай бұрын
this is not a vuln, its a feature. firefox stores cookies in the appdata folder
@diogenessinopeus5 ай бұрын
I used to work at Microsoft and received a case from a client complaining about this and how O365 sessions remain active. It is not a product vulnerability but rather a human one. In order to gain that level of access, it means that there are a serious of actual security problems in your infrastructure like lack of execution policies and security training for the personel. In other words if an attacker can get its hands on your sessions and cookies, your security infrastructure is full of holes.
@DamageXYZ397 ай бұрын
That fucking restart at 10:33 scared the shit out of me. I thought I restarted my own pc
@l8wt57 ай бұрын
Would be interesting to see if Smart App Control in Windows 11 can protect against these stealers. It should only allow "known reputable apps" to run, but I haven't seen anyone test that yet. It does have some false positives, but in an environment where security really matters, it might be a good idea to enable it if it does block these threats.
@EricParker7 ай бұрын
Will try it.
@opposite3427 ай бұрын
7:59 correct me if I'm wrong but MingW is a c compiler for windows. I think it uses gcc which is why it shows gnu here.
@sfisher9237 ай бұрын
Acai's OBS Plugin Incident was a different approach that ended up with the same So anyone watching his streams on Twitch this is why chat has to remind him to not download any executables past 9pm his time (US Eastern)
@marqueemoon32207 ай бұрын
I tried searching for it on YT and google and can’t find it, do you have a link for it?
@lyndon22747 ай бұрын
can you do a video on Valorant's anticheat software vanguard?
@tribes2archivist7 ай бұрын
Controlled folder access says "unauthorised changes" in the description, so it defends against suspicious, high entropy writes that you would see when a file is encrypted for ransomware, nothing else.
@JoCaTen7 ай бұрын
Awareness of these things must be brought. We must raise awareness, we can't just keep loosing our channels just like that.
@frstwhsprs7 ай бұрын
The hacker who wanted to hijack Eric Parker's channel to promote Tesla bullshit: "GOD DAMMIT, WHERE IS HIS CHANNEL"
@HoonzoDarkspawn7 ай бұрын
You should have responded that the download didn't work and that you would like a new link to see what else they would send you.
@CopyrightedCup7 ай бұрын
Why don't anti-virus software auto flag reading of cookies in browsers? I can only think of one scenario where it could be useful and that would be installing a new browser and moving all your data over. Or if anything detect the behavior of copying and sending of the cookies file over the internet. I can't think of a use for it not being flagged.
@pi_xi18 күн бұрын
8:00 This was compiled using MinGW, which is a Unix environment for Windows. This was not cross-compiled on Linux.
@thesketchboysgaming77527 ай бұрын
Actually 2 of the biggest gaming channels in sweden got hacked exactly like this today with tesla lives running on the channels.
@YumiizArts7 ай бұрын
This actually happened to me. Got a sponsorship from Stray (the game). Turned out to be a fake PDF. I ended up contacting KZbin via Twitter.. The hacker hacked my entire gmail account and locked me out entirely haha. Thankfully, KZbin did help me get my KZbin and gmail account back. Safe to say I invested in safety precautions and a key.
@devilcookie99247 ай бұрын
hi, Eric. what happened to the activator video? did you delete it or YT did?
@EricParker7 ай бұрын
Taken down by KZbin, I appealed.
@devilcookie99247 ай бұрын
@@EricParker it seems YT has keyword filters for the subject of video. thanks for reply!
@EricParker7 ай бұрын
Yeah, since covid they started allowing AI to take down videos without review, sometimes it gets it wrong. On balance it is a good thing.
@gozuken89857 ай бұрын
@@EricParker are you going that upload that video again? KZbin or on another platform?
@pi_xi18 күн бұрын
8:22 The file signature starts with PK, so it is probably a ZIP file. This does not have to do anything with encryption.
@pi_xi18 күн бұрын
This is clearly a stealer, it copied your firefox SQLite database (which contains information like cookies and stored passwords), information about installed software, Discord tokens etc. The Cyrillic word "Приват" is literally "Privat", maybe part of some session ID used in this API
@teamruddy6117 ай бұрын
Did you report the website the data was sent to as malicous, so it could be taken down?
@xXball_smasherXx7 ай бұрын
you're right, one could notify cloudflare for abuse and boom, cloudflare protection gone from the site
@baribari10007 ай бұрын
hope you're near Las Vegas! going to def con sure sounds like a lot of fun
@KC-ew6okАй бұрын
If I opened this and nothing happened, how can I eliminate this virus from my pc
@TheCynicalCommentator2 ай бұрын
The first warning signs comes from the company they’re impersonating. Why would Netflix sponsor a channel on a competitors platform?
@maxniftynine7 ай бұрын
Do a video on the new windows WiFi vulnerability
@kiendra7 ай бұрын
Canadian endermanch
@meiduyomada51556 ай бұрын
I just fell for this exact thing but I was using a Mac and used 3rd party apps to unzip and clicked all the files and even used another app to open the exe. Please give me any advice will it also affect my WiFi network
@efg7867 ай бұрын
sorry if you’ve been asked this before, but what is the software you use to monitor network traffic? i’m interested in downloading it, i thought it might be glass wire because that’s the only application i’ve heard that does something like this but im not sure
@EricParker7 ай бұрын
mitmproxy. The setup I use is a wireguard VPN outside the VM. It can either be a second VM or the host (don't do if the host is windows).
@vladik_yt31867 ай бұрын
When hackers sent malware to PC Security Channel i laughed, now i question their IQ level
@chri-k7 ай бұрын
It's likely automatic
@vladik_yt31867 ай бұрын
@@chri-k Ye but still pretty funny Btw on which ending did you finished oneshot? Besides Solstice
@chri-k7 ай бұрын
@@vladik_yt3186 I don't even remember anymore due to seeing so many let's plays of it. I think it broke the sun?
@vladik_yt31867 ай бұрын
@@chri-k Good boi
@kavylavx7 ай бұрын
hell- classic. also funfact no one watched the full vid yet. glad i dont do sponsorships. edit: woah i was 1st (actually before eric)
@ranelaan767Ай бұрын
Corn flake
@bltfireburstAU6 ай бұрын
this was interesting since my channel was hacked and turned into a tesla account about a year ago. cool stuff man
@EchoPlaynomicsАй бұрын
Very nice sir. Thank you for the relaxed walk-through on this file.
@KamsPoliticalPredictions6 күн бұрын
Considering two channels i follow just recently got hit by the Ripple hack, this needs to blowup
@NullPointer7 ай бұрын
8:14 zip files always start with PK, so those are all non encrypted zip files
@gyroninjamodder7 ай бұрын
8:43 PK header is a zip file
@AdrX0037 ай бұрын
Sadly ive seen two channels that i had set the bell on with this happening to them. got a vid notification that i clearly had not subscribed before
@greatvegetables7 ай бұрын
One of my favorite things about these videos is how in most of his Windows VMs he sets the username to Lain
@gh22865 ай бұрын
surely there is no way you can accidently run a bunch of vms running that program in a loop to spam the api
@Electro-tw9um7 ай бұрын
The zip file should have the MOTW. Why doesn't it? If it did, SmartScreen would block the unknown executable.
@tomatobrush32837 ай бұрын
At 70 mb that is a RAT for sure.
@JoshuaPeisach7 ай бұрын
Man I need to look at those obvious spam emails in VMs now
@fawad4bros5 ай бұрын
Can anyone tell which tools are being used in the video ?
@tee_the_vee7 ай бұрын
not the polish email adress
@skzulka7 ай бұрын
you are so clever! great works man
@chiesatonaka8776 ай бұрын
Funny enough, the video "recommended" next to this one while watching it was one of those sloppy Ripple ads.
@eggs45617 ай бұрын
Was looking for a video like this after Nexus got hacked.
@PlanetHarpion5 ай бұрын
I got a fake ripple ad before the video started.
@BlueIsLeet7 ай бұрын
dont pull a LTT and have it happen to you now lol
@Demonyclub5 ай бұрын
Hello,this is my hacked channel😢😢(1 day ago)
@xxxxxx3q7 ай бұрын
2:48 lain mentioned
@freenull7 ай бұрын
Is Lumma sold with domains, too? Because this .shop domain is the same pattern as the one from your "Tracking Malicious "Tutorials" on KZbin" video, and the API is the same. Was thinking it may be the same actors, but I guess it might also be a full package you get from them?
@EricParker7 ай бұрын
API and the software is the same, AFAIK you set it up on your own domain / server. Most stealer sites look roughly the same, many will also feature a special useragent to make DoS'ing it a bit trickier.
@vincent.7z7 ай бұрын
Day 1 of asking Eric to collab with The PC Security Channel because they sound like the same person
@electrolyteorb7 ай бұрын
TPSC sounds more "bright"
@vincent.7z7 ай бұрын
@@electrolyteorb and eric sounds like tpsc with a voice changer
@washere34327 ай бұрын
Love the recent videos!!! Keep it Upppp!!!
@BlueIsLeet7 ай бұрын
"PK" prefix means its a zip file
@jellymemo6384Ай бұрын
Man wunba got hacked by ripple too just now
@Kimarnic7 ай бұрын
Of course Russian 🙄
@SynthwaveDuck7 ай бұрын
Miss your Activation exploit vid too bad YT censored
@dragonballandhonkaiimpact1022Ай бұрын
Variens KZbin channel just got hacked by ripple......😢
@FrancoisdifferentbreedАй бұрын
Yepp
@FrancoisdifferentbreedАй бұрын
Who is ripple and these kinds of groups need to get shut down and locked away forever. Kristen and reafe was hacked last week and their channel name was changed to ripple and all their videos were deleted and replaced with random videos by whoever ripple is.
@TheMeowthTeamV27 ай бұрын
I remember watching a video from 2009 called shreks crap or something it wasn't an sml video but it was funny but unfortunately it was deleted along with the channel and I never could watch the video again so all i have now is the memory of it
@tatsuyamashita7 ай бұрын
😔
@ManSoEpic5 ай бұрын
Eren Lenox got hacked by ripple today
@MrReeTart7 ай бұрын
Tristan Tate but computer science
@Spectrulight7 ай бұрын
That's exactly what I was thinking. Sounds so much like him.
@artman407 ай бұрын
How WHAT happens to my favorite KZbin Channels?
@isaackingvideos7 ай бұрын
Because of this. I will never login to my account to my computer again until Microsoft fixes this problem
@SlaveKGael7 ай бұрын
This definitely happend to quelaag
@blackbonnieiscool7 ай бұрын
They sent Mr. antivirus a malware and thought they will go unnoticed, *amatures*
@littlefire47Ай бұрын
Ripple got another, he was near 200 k but got hacked, rip ice711
@Pumbord_gamingАй бұрын
yes
@henrygoldberg12487 ай бұрын
I like your user name for your file
@Ratiqon7 ай бұрын
Oh eric my love i will die for you my lebron my pookie❤
@Phoenix_Enforcer16 ай бұрын
Nexus Flashbacks
@danieleditor4254Ай бұрын
Goddamn it. This happened to my channel. I feel so stupid.
@tubgold7 ай бұрын
smart..
@gyaltsengoh12593 ай бұрын
Hoplas2 fell for it
@WeencieRants7 ай бұрын
Another great video
@Triggs22106 ай бұрын
Thanks now I can show RZM 64😢
@ardwetha7 ай бұрын
If they got Linus tech tips like this, they should stop making videos asap.
@EricParker7 ай бұрын
It's actually easier (in general) to hack enterprises than random people. If you want to hack my channel you have to hack me, if you want to hack linus, there are 100 employees of varying levels of tech saviness that could be compromised.
@Kimarnic7 ай бұрын
@@EricParkerthis, they probably have editors that don't know about PCs but are great at editing videos
@angelblanco-pc7 ай бұрын
bro
@factswithlouis7 ай бұрын
classical scam now 😂
@Triggs22106 ай бұрын
I see now
@corewwwi7 ай бұрын
lain
@Stratxgy.7 ай бұрын
i love when elon gives free crypto!!!!!!!!11
@nicememes06767 ай бұрын
Hello
@lockout57317 ай бұрын
Above time this legand is talking about this Elon musk Tesla live stream scam about damn time
@user-dw6fj1py1o7 ай бұрын
Good Work!
@PABLOPeanutman7 ай бұрын
Hi eric
@RandomytchannelGD7 ай бұрын
hi
@88tx7 ай бұрын
bro just tried to base64 decode an encyrypted payload lmao
@丷7 ай бұрын
thats about as far as his malware analysis abilities go lol
@testtest-ez3mp7 ай бұрын
Yes, I cringe every time when I see that lol@@丷
@chri-k7 ай бұрын
where's the issue with that?
@88tx7 ай бұрын
@@chri-k you can tell just by looking at it that it's nowhere near base64. rookie mistake.
@chri-k7 ай бұрын
@@88tx It looks exactly like base64. In fact, there is a 99% chance that it is base64.
@asbfabfoaijfo87 ай бұрын
lain
@edwin3928ohd7 ай бұрын
Ween
@colinstech66016 ай бұрын
This happened to my channel
@vladwolfaction.7 ай бұрын
As russian i can say, we love Elon Musk. Thx for scam scheme.