The World's Worst Botnet Just Got Stronger

  Рет қаралды 191,809

Mental Outlaw

Mental Outlaw

2 жыл бұрын

Emotet, One of the world's worst Malware/Botnet has been around for years, but its ramped up again after law enforcement took down their infrastructure and already has more than 130000 machines in 179 different countries compromised.
Subscribe to me on Odysee
odysee.com/@AlphaNerd:8
₿💰💵💲Help Support the Channel by Donating Crypto💲💵💰₿
Monero
45F2bNHVcRzXVBsvZ5giyvKGAgm6LFhMsjUUVPTEtdgJJ5SNyxzSNUmFSBR5qCCWLpjiUjYMkmZoX9b3cChNjvxR7kvh436
Bitcoin
3MMKHXPQrGHEsmdHaAGD59FWhKFGeUsAxV
Ethereum
0xeA4DA3F9BAb091Eb86921CA6E41712438f4E5079
Litecoin
MBfrxLJMuw26hbVi2MjCVDFkkExz8rYvUF
Dash
Xh9PXPEy5RoLJgFDGYCDjrbXdjshMaYerz
Zcash
t1aWtU5SBpxuUWBSwDKy4gTkT2T1ZwtFvrr
Chainlink
0x0f7f21D267d2C9dbae17fd8c20012eFEA3678F14
Bitcoin Cash
qz2st00dtu9e79zrq5wshsgaxsjw299n7c69th8ryp
Etherum Classic
0xeA641e59913960f578ad39A6B4d02051A5556BfC
USD Coin
0x0B045f743A693b225630862a3464B52fefE79FdB
Subscribe to my KZbin channel goo.gl/9U10Wz
and be sure to click that notification bell so you know when new videos are released.

Пікірлер: 595
@iskamag
@iskamag 2 жыл бұрын
>the world's worst botnet big tech sobbing in corner
@mateusvmv
@mateusvmv 2 жыл бұрын
the world's worst botnet are those youtube comment reply bots ^^
@getawayunclejohn7107
@getawayunclejohn7107 2 жыл бұрын
Finally it's here
@titaniumtemplar3560
@titaniumtemplar3560 2 жыл бұрын
@@getawayunclejohn7107 fuck man at last it’s here after all that waiting.
@hectorcanizales5900
@hectorcanizales5900 2 жыл бұрын
@@getawayunclejohn7107 yeah man, oh my God I can't believe we're being saved by the Lord Jesus Christ. /s I wonder if the bots will follow/reply to our conversation.
@lVlonkberry
@lVlonkberry 2 жыл бұрын
@@hectorcanizales5900 Actually some Telegram promo bots are setup to reply with a random text, sticker, gif or even a voice message within ~30s-3m of being mentioned. It's annoying AF, but at the same time hilarious whenever they start "talking" to each other.
@Aranimda
@Aranimda 2 жыл бұрын
Imagine all these smart light bulbs, TVs and fridges getting out of support in a few years and getting a second life in a botnet attacking the Pentagon without the user ever noticing.
@jacobeii
@jacobeii 2 жыл бұрын
getting ddosed by a few first gen Amazon alexas
@gabrielem_
@gabrielem_ 2 жыл бұрын
I'm working at a cybersecurity company in a team that deals with botnets actually and I can tell you that bots are knocking at the door of your devices every few minutes, continuously. It's just that, if your device is not the type of device targeted by the bot, is not vulnerable to the type of payload the bots comes knocking with or is protected in any way, then the door simply doesn't open. There's not that many ip addressed in total, and a botnet comprised of a few dozen thousand devices runnings bots that are trying to propagate themselves by sending multiple payloads to random ips all over the world every second is enough to cover the whole range of existing ips and reach essentially every device connected to the internet multiple times per day. All of these bulbs, smart tvs, smart fridges, conventional routers, smart security cameras that generally stay connected to the internet all the time without someone constantly investigating what's running on inside them are the ideal and the preferred targets of such attacks.
@marcin6386
@marcin6386 2 жыл бұрын
@@gabrielem_ woooaaahh.... zero-trust firewall on every ip!
@badradish2116
@badradish2116 2 жыл бұрын
one can only dream X'D
@paltaSass
@paltaSass 2 жыл бұрын
I remember a talk about using blockchains to create networks of smart devices that self correct changes to firmware through consensus. It's definitely a big worry that not enough manufacturers address.
@rbdm
@rbdm 2 жыл бұрын
The only good part of distro hopping, wiping your drive every few days to weeks
@prakharmishra3000
@prakharmishra3000 2 жыл бұрын
kzbin.info/www/bejne/opTXkIF4eN-Jgbs Finally it's here
@lochrowley9997
@lochrowley9997 2 жыл бұрын
kzbin.info Finally it's here.
@ahmedabd2259
@ahmedabd2259 2 жыл бұрын
Use a live os with persistent
@xCwieCHRISx
@xCwieCHRISx 2 жыл бұрын
​@@ahmedabd2259 make your own live os with your custom os settings. A bit of a hassle to update things but would be safe
@GabrielTobing
@GabrielTobing 2 жыл бұрын
I love how your comment got 3 bots XD
@manitoba-op4jx
@manitoba-op4jx 2 жыл бұрын
every windows user should have show file extensions enabled in file explorer. just saying
@PWN_Nation
@PWN_Nation 2 жыл бұрын
this...
@JamesWilson01
@JamesWilson01 2 жыл бұрын
Agreed, but .lnk extensions are still hidden. It's only the little arrow on the icon that gives it away. Very clever to put powershell code in there now I think about it.
@r0e404
@r0e404 2 жыл бұрын
@@mr.serious707 lol thx for the good explanation
@TrggrWarning
@TrggrWarning 2 жыл бұрын
@@mr.serious707 thanks for showing us bob
@TsarBlyatinum
@TsarBlyatinum 2 жыл бұрын
@@mr.serious707 the IT guy in our school made our teacher delete files in her hard drive because a program said "out of memory" 😭😭😭 (I didn't say it meant ram because I don't like her anyway she deserved it + the IT guy should have known better)
@apIthletIcc
@apIthletIcc 2 жыл бұрын
ISP's once hit by this, will be the next frontier for massive attacks that stem from the backdoors left by these malware.
@MrSongib
@MrSongib 2 жыл бұрын
Is it works that way? Most of the time social engineering is the way to go. (It's basically scamming people to think something else) and a lie is the most underrated thing in this world. XD
@puffpuffpass3214
@puffpuffpass3214 2 жыл бұрын
Maybe buying a bag of ICP isn't such a bad idea after all then. The only problem is ICP being a decentralized internet with good speeds. It already takes a good amount of time to send transactions imagine video files or games lol
@s4ms3piol30
@s4ms3piol30 2 жыл бұрын
Redditors
@apIthletIcc
@apIthletIcc 2 жыл бұрын
@@s4ms3piol30 I barely use reddit but good job spotting a profile pic I guess.
@apIthletIcc
@apIthletIcc 2 жыл бұрын
@@puffpuffpass3214 not sure what u mean by icp all I think of when I see or hear icp is insane clown posse.
@Zephyr-tg9hu
@Zephyr-tg9hu 2 жыл бұрын
Malware is constantly evolving. The traditional viruses we once knew are no longer as common, but phishing and social engineering will always be a weakness, and the only way to protect against it is by spreading awareness. Thank you.
@lubu4u312
@lubu4u312 2 жыл бұрын
Computer worms have used network and emails to spread since the mid 90s. This is just the latest model. I'm not worried. Not the first time the world has over blown a computer virus. Still waiting for CIH to end all computers....
@ghostface5559
@ghostface5559 2 жыл бұрын
you say that but Zeus is a core program in a lot of nasty malware.
@anthonyr.589
@anthonyr.589 2 жыл бұрын
Gator don't play no games.
@haxorinjector4186
@haxorinjector4186 9 ай бұрын
Yo thats correct what ya said
@pixelplanet142
@pixelplanet142 2 жыл бұрын
I'm running a small company and i got an email as a RE from an actual past customer, well written, even refering to the purchase and an macro-xml attached with supposed payment info. It was malware like you describe it. The email probably automatically created by a bot that reads the context out of past emails. And the origin was from some hacked server of some company from Saudi Arabia. They are getting smarter with the email text, and this is how they get people.
@Affax
@Affax 2 жыл бұрын
I usually laugh at people who fall for this stuff (even if I shouldn't.. not everyone can be that tech literate) But that is just on a next level, I guess you just hope your AV might have some behaviour blocking stuff that gets alerted I wonder when they start using AI to write personal spearfishing emails to *everyone* based on their social media...
@ziyaddossri1821
@ziyaddossri1821 2 жыл бұрын
How did you know the origin of the attack? Is your past customer/client from Saudi Arabia?
@pixelplanet142
@pixelplanet142 2 жыл бұрын
​@@ziyaddossri1821 i mean the server that sent the email. It is in the email headers. Even if the email address is something different, the origin server is there. It was a wordpress website of a company that most likely got hacked and their servers used for sending those mail.
@fuckingpippaman
@fuckingpippaman 2 жыл бұрын
thats scary
@TheMohawkNinja
@TheMohawkNinja 2 жыл бұрын
Might be worth pointing out that while classic anti-virus is pretty much useless against anything made in the past 10 years, as I understand it, EDR solutions (and their derivatives) should be effective against most modern threats due to the fact that they look at program behavior, not just file hashes.
@Loremips9966
@Loremips9966 2 жыл бұрын
Classic antivirus also look at program behavior. There are still evasion techniques that will work for a while then you need to find something else
@Avengerie
@Avengerie 2 жыл бұрын
Can antivirus programs look through obfuscated code? Or do they detect signs of obfuscation and this is a red flag in and of itself?
@itsqbobby
@itsqbobby 2 жыл бұрын
@@Avengerie some antiviruses do flag positive for obfuscated code
@tomomei
@tomomei 2 жыл бұрын
@@itsqbobby which ones
@HAJDERx
@HAJDERx 2 жыл бұрын
@@tomomei nearly every av flags obfuscated executables as malware, even Windows defender
@unicorn_tamer
@unicorn_tamer 2 жыл бұрын
The most important thing in cyber security: "Double check, before you double click" XD
@Minty_Meeo
@Minty_Meeo 2 жыл бұрын
Antivirus isn't enough, you need Protogent.
@henzou13
@henzou13 2 жыл бұрын
deeta recovery software
@robertpaws
@robertpaws 2 жыл бұрын
The only antivirus you need
@Ralofguy
@Ralofguy 2 жыл бұрын
I am Proto, your security is my motto.
@fofopads4450
@fofopads4450 2 жыл бұрын
Is just another corporate AV, they probably have their own botnet within it.
@ReconScammers
@ReconScammers 2 жыл бұрын
@@fofopads4450 it's a joke. legitimate antivirus software but from past testing of it by KZbinrs it wasn't good at least back then.
@agentflemme
@agentflemme 2 жыл бұрын
Is it possible to block any cmd/powershell instances if it isnt run as admin ? It could block this kind of malware as you'll need to agree running powershell, which is much more "suspicious" than running some random document, i think
@mgh7634
@mgh7634 2 жыл бұрын
it's actually very easy to skirt admin requirements in powershell with -ExecutionPolicy Bypass and other such methods. And most malware scripts are made to do exactly that or to find ways to manipulate files and data that don't typically trigger user access controls, of which you'd be surprised at how much you can get away with without such privileges.
@xfaraday2433
@xfaraday2433 2 жыл бұрын
I think it's possible to block this through windows group policy which wouldn't even allow PowerShell or cmd to be opened at all
@maximilian200057
@maximilian200057 2 жыл бұрын
@@mgh7634 Where does one learn how to do such things?
@wrockd
@wrockd 2 жыл бұрын
@@mgh7634 "ExecutionPolicy" Bypasses don't exactly bypass Admin Privileges, they simply bypass the "GUI only", "Signature only" and "Admin Only" *Restrictions* and a few other restrictions, and many legit scripts use it too. Even MS has stated explicitly on its docs that it is not an security feature and even mentioned a bypass method themselves. And, there aren't any Admin Bypass/Privilege Escalation going on here either, Botnets could perform their function with Non elevated Privileges just fine, as they just need to sit on the computer and constantly scan for a connection request for the payload. And In the first place you don't even need Admin privileges for most of the Malwares, for the most part it's some Ransomware or System Sabotage kind of malware only which requires modifying System files and/or Locking you out of system components or the system itself. Most of the Spywares, Botnet and the similar ones could perform all the tasks(logging keystrokes, accessing webcam, performing operations on the network stack and accessing personal files) without Admin Privileges as these are pretty common things. The only thing that it may need higher privileges for is reading from restricted memory addresses, in which case they could exploit some other elevated process and inject arbitrary code in their memory address/stack which contains the execution flag using some UAF Vulnerability, but generally privilege escalation is avoided as it's unnecessary and not always successful to perform.
@JamesWilson01
@JamesWilson01 2 жыл бұрын
@@maximilian200057 John Hammond has analysed malware that bypasses execution policies easily by using this flag. It's not designed to be a security measure in the first place.
@dodjo_cat
@dodjo_cat 2 жыл бұрын
We should really start teaching basic internet protection in school. Depending on career choice a mandatory periodic briefing of new threats in the are of expertise would also be worth considering.
@lubu4u312
@lubu4u312 2 жыл бұрын
Step 1: change the default password Step 2: see step 1
@thomas.thomas
@thomas.thomas 2 жыл бұрын
Only thing we learned is how to make a good password and that you shouldn't use them twice, that's it lol
@haifutter4166
@haifutter4166 4 ай бұрын
Actually quite easy to implement since ICDL (International Computer Driving License) already exists. It was part of my job training.
@kernelcortex
@kernelcortex 2 жыл бұрын
Normal users actually concern about security. But at last, they'll turn it off for convenience and think it's a solution to make things working.
@karamelapple8007
@karamelapple8007 2 жыл бұрын
English?
@NameTheUnnamed12
@NameTheUnnamed12 2 жыл бұрын
@@karamelapple8007 normal people don't actually care about security that much, if an antivirus etc slows their stuff they'll turn it off and assume that any problem it gave went away
@kernelcortex
@kernelcortex 2 жыл бұрын
@@NameTheUnnamed12 My friend using Android phone and said he does installed 3rd party malware scanner. 🤣 When I asking PC people like... Hey, do you download pirate software for personal use?. Mostly said no. They're worried about virus will going to ruin their machines. But They'd rather installed free to use softwares without much worry in mind.
@jesscorbin5981
@jesscorbin5981 2 жыл бұрын
Sometimes they are so bizarre that it bypasses your brain completely. I got one saying it had my tax return from England. It doesn't apply to me either.
@ThomasBomb45
@ThomasBomb45 2 жыл бұрын
Dude it's free money 🤡
@jesscorbin5981
@jesscorbin5981 2 жыл бұрын
@@ThomasBomb45 no way, fr?!
@AJ-po6up
@AJ-po6up 2 жыл бұрын
@@jesscorbin5981 Yes, next time click it pls! 🙃 claim your free money!!
@lucasm20
@lucasm20 2 жыл бұрын
The consequences of Microsoft being lazy and letting macros do whatever they want really won't ever die, will they? At the very least they could have a macOS style permissions pop up to confirm that you want to run an unknown script (including from a shortcut), showing the script source in question as well for the user to see. But alas, another good day to be a Linux user.
@shotnothing3419
@shotnothing3419 2 жыл бұрын
I don't think they are lazy. They have huge incentives to make windows secure and an army of well paid devs and specialists working on that. The issue is balancing the need for legacy stuff to work vs writing off things that were mistakes in the first place (e.g. macros). To be fair, we have the power of retrospect and software development was different in the past. In a bid to offer the most feature rich and competitive product, some boo-boos were made and they are paying for it now.
@lucasm20
@lucasm20 2 жыл бұрын
@@shotnothing3419 I meant being lazy when they first implemented macros. Yes, it's easy to be critical in retrospect, but I don't think it absolves them of it either, if a mistake of the past still affects us today, it's still a mistake.
@shotnothing3419
@shotnothing3419 2 жыл бұрын
@@lucasm20 oh in that case I agree, although recklessness to deliver the most competitive product back then was also probably significant
@toquita3d
@toquita3d 2 жыл бұрын
I completely disagree that "antivirus won't do much". Just as malware changed since the 90's, so did AntiViruses and nowadays most have behavior analysis and core system protection built in, not to mention sandboxing unknown software. An antivirus alone can't protect from everything, but most come as a *package* containing not only signature-based analysis but a whole gamma of security tools to prevent this sort of thing.
@AwakenedPhoenix309
@AwakenedPhoenix309 2 жыл бұрын
But it's really best not to rely on an antivirus for that, especially given that these programs have a tendency to go to shit. Even Windows 11 does a lot to sandbox apps right in the OS, and you can't match the security of something like Fedora Silverblue.
@minhuang8848
@minhuang8848 2 жыл бұрын
@@AwakenedPhoenix309 Fair enough, but still, considering the ubiquity and prevalence of Windows machines, out-of-the-box security has gotten astonishingly good. It's kind of really difficult to demolish your setup if you have the slightest traces of common sense - which, of course, is a huge if. You might not match the security of commonly used distros, but the question is if you have to in the first place.
@minhuang8848
@minhuang8848 2 жыл бұрын
@@AwakenedPhoenix309 Fair enough, but still, considering the ubiquity and prevalence of Windows machines, out-of-the-box security has gotten astonishingly good. It's kind of really difficult to demolish your setup if you have the slightest traces of common sense - which, of course, is a huge if. You might not match the security of commonly used distros, but the question is if you have to in the first place.
@Jacobprogammer
@Jacobprogammer 2 жыл бұрын
No it really doesn't do anything.
@1996Pinocchio
@1996Pinocchio 2 жыл бұрын
There is antivirus software by default on any mac and windows machine. You don't need any additional software to keep out most of the viruses. Not sure about linux.
@KonEl-BlackZero
@KonEl-BlackZero 2 жыл бұрын
Bro, i just won 1 millon dollars and all i have to do is to fill the doc document attached to the mail.
@SahilFR
@SahilFR 2 жыл бұрын
😂😂💀💀
@jacobeii
@jacobeii 2 жыл бұрын
I'm a Nigerian prince give me 794.32 btc and I will promise to wire transfer double that into your account
@vincei4252
@vincei4252 2 жыл бұрын
All I'm hearing is don't use Windows and/or Microsoft office tools ... in addition to reducing your levels of trust. i.e. trust no one.
@dinamitemaster
@dinamitemaster 2 жыл бұрын
*Video:* There's this malware going around that requires you to be a complete idiot and open random files you get sent attached to suspicious looking emails *You:* So you're saying we shouldn't use Windows and Office? That's like burning down your house to kill a spider
@mathisblair2798
@mathisblair2798 2 жыл бұрын
Freedom lead the way. Amen.
@minhuang8848
@minhuang8848 2 жыл бұрын
Windows and MS is fine for safety's sake. Just don't be dumb and don't download random stuff.
@vocodabaddest
@vocodabaddest 2 жыл бұрын
@@minhuang8848 ? malware can get on your computer in more ways than downloads.
@3lH4ck3rC0mf0r7
@3lH4ck3rC0mf0r7 2 жыл бұрын
Mac OS and Linux malware exists, too. Also, some malware works on Wine. Using another OS isn't a silver bullet.
@coom07
@coom07 2 жыл бұрын
I hope u talk more about this topic
@dontaskiwasbored2008
@dontaskiwasbored2008 2 жыл бұрын
I'd like to know, why the fuck, in 2022, is it still possible for a Microsoft Office file to execute arbitrary commands on your computer? Oh wait, I just answered my own question.
@wrockd
@wrockd 2 жыл бұрын
Maybe because Macros exist and have a valid usecase for anyone who doesn't want to spam the same shid like a 1000 times in a Word or Excel document?
@amongsussyballs
@amongsussyballs 2 жыл бұрын
@@wrockd I feel like Microsoft should make people read the dangers of allowing macros before that are able to enable them
@wrockd
@wrockd 2 жыл бұрын
@@amongsussyballs Agreed, Ngl given that most of the common MS Office users don't pay much attention to *small* Dialogues and just hit OK, because of how common and mostly non important/relevant these dialogues are. Even I think that they should show a big dialogue with a big *"WARNING"* Flashing in Red on top and then the dangers mentioned in bold, it will hugely prevent this stuff. Also with the disclaimer that "If they have received it from Email, most likely it's a Virus"
@shotnothing3419
@shotnothing3419 2 жыл бұрын
uhm how have you answered your own question?
@frenchmarty7446
@frenchmarty7446 2 жыл бұрын
It's both hilarious and sad that Microsoft is doing most of the social engineering for these hackers simply by having confusing "warnings" and not having secure ways to even preview a document.
@midge9740
@midge9740 Жыл бұрын
the thing is they DO have a secure way to view the document. as long as u dont enable editing u can see the entire document, u just cant change anything (which is kinda the definition of previewing). the warnings that u saw were part of the document, made to look like they were part of the program. that was REAL social engineering done by the hackers behind the malware.. not microsoft.
@joeldoxtator9804
@joeldoxtator9804 2 жыл бұрын
My email account is 20 years old and I have never gotten an attachment e-mail. Guess i just don't frequent sites that give away your e-mail information.
@JamesWilson01
@JamesWilson01 2 жыл бұрын
Makes no difference if one of your friends' emails gets hacked. You just publicly revealed you have no friends! 😉 /JOKE
@Bryophytan
@Bryophytan 2 жыл бұрын
@ladawg81 if they try to befriend you, they must be trying to social engineer you! Dinner for 1 is cheaper anyway...
@AJ-po6up
@AJ-po6up 2 жыл бұрын
@ladawg81 pity is just another tool in the playbook of using people for personal gain.
@LungCancer420
@LungCancer420 2 жыл бұрын
As always, thank you for this amazing content
@kamekaze997
@kamekaze997 2 жыл бұрын
Dude the way you share tech/hacker news is phenomenal keep that shit up. Can’t wait to see this channel blow the f_ck up
@khall187
@khall187 2 жыл бұрын
Already is! Worst "critisim" is I prefer it at 1.25x speed but cmon... That's nbd cuz 90% of videos are better at 1.25. Great content!
@TheSuperBoyProject
@TheSuperBoyProject 2 жыл бұрын
H*ck
@karamelapple8007
@karamelapple8007 2 жыл бұрын
It's not
@mrnickisntaprick
@mrnickisntaprick 2 жыл бұрын
Thanks brother. I see some older folk falling for this like usual. Much love.
@vladislavkaras491
@vladislavkaras491 2 жыл бұрын
Thanks for the news!
@bradkaral1188
@bradkaral1188 Жыл бұрын
A very well-explained, well-narrated video. Thanks.
@171151
@171151 2 жыл бұрын
So this was EMOTET, thank you for the heads up!! I´ve been seen this ones for the las two months at my workplace, the warning has alredy been sent througth the company but maybe a refresh on them would be nice.
@MisterS.
@MisterS. 2 жыл бұрын
Thanks for the advice mr outlaw
@david3552
@david3552 2 жыл бұрын
Great content, as always
@fish3977
@fish3977 2 жыл бұрын
me, copy pasting any command I see on linux forums to try and fix the issue of the day: "who would be so stupid as to download a file they get mailed?"
@lowwastehighmelanin
@lowwastehighmelanin 2 жыл бұрын
The amount of emails we're getting at work about DON'T OPEN THAT is getting exhausting. I work at a health insurance company and it's getting really bad. We have sensitive data to worry about, our IT is worn out, people are quitting. This is insanity.
@royalxd
@royalxd 2 жыл бұрын
quitting because of spam emails 🥱
@AJ-po6up
@AJ-po6up 2 жыл бұрын
@@royalxd Hello and welcome to my article and TED talk about How spam emails gave me PTSD!
@MisterMosfet
@MisterMosfet 2 жыл бұрын
@@royalxd more like dumb staff
@johnsmith8981
@johnsmith8981 2 жыл бұрын
Sooo many older folks are running Win 7 while using their ISP's email (which has no spam filters or protections of any kind and hasn't been updated since like 2008) and leave their computer on all day.
@PatchCornAdams723
@PatchCornAdams723 2 жыл бұрын
Bro your channel has reignited my love for computers.
@stonetrench117
@stonetrench117 2 жыл бұрын
The start of your videos always make me feel so hopeless! Keep it up,
@puffpuffpass3214
@puffpuffpass3214 2 жыл бұрын
You and Muta should of collabbed on this. I could see you two doing some amazing collabs
@jegga9199
@jegga9199 2 жыл бұрын
Thank you carl shwob very cool!
@ecwnikos
@ecwnikos Жыл бұрын
thank you.
@namenlosNamenlos
@namenlosNamenlos 2 жыл бұрын
Thanks!
@poisenbery
@poisenbery 2 жыл бұрын
The government will only contact you in 2 ways: Written mail Law Enforcement at your door
@Elrog3
@Elrog3 2 жыл бұрын
or a third option.. direct withdrawal from your bank account
@samuelhaidar2580
@samuelhaidar2580 2 жыл бұрын
You’ve encountered an emotet. I chose you virtual machine! Virtual machine use close. Critical hit. Emotet fainted. Exp 434
@John3_16_
@John3_16_ 2 жыл бұрын
Great video m8!
@thechadbuddha
@thechadbuddha 2 жыл бұрын
back in the day the reasons you know you had a virus was because the anti virus software didnt work anymore xD
@DragonOfTheSkies
@DragonOfTheSkies 2 жыл бұрын
Oh hell not again…… I had to deal with emotet a lot a few years ago (I’m a sys admin) and it was already a pain in the ass back then. Guess I’m gonna start drinking again
@lever1209
@lever1209 2 жыл бұрын
here's my hot take, don't use the blacklist for websites, use a whitelist
@proloycodes
@proloycodes 2 жыл бұрын
duh
@anneonymous4884
@anneonymous4884 Жыл бұрын
The IRS always sends stuff as physical mail. If it's urgent, it'll be certified.
@bancodrut
@bancodrut 2 жыл бұрын
woaw , have to love coincidences ! I just did all this with examples almost identical for a Crisis Management simulation in a competition (for cybersec newbies). You are doing such a great public service showcasing this ! I firmly believe everyone should be aware of this sort of cyber security risks as ANYone could be an attack vector at some point.
@reviloplays2143
@reviloplays2143 Жыл бұрын
i'd use a bot net to not harm but to find.
@Zycoreination
@Zycoreination 2 жыл бұрын
Things like this is why I keep reminding my parents not to click things they don't know what it is and be suspicious in general when checking mail, visiting websites or getting spam texts...
@tomasgorda
@tomasgorda 2 жыл бұрын
Great video m8 👍
@JohnMushitu
@JohnMushitu 2 жыл бұрын
Emotet sounds like some Egyptian pharaoh's name
@victims5820
@victims5820 2 жыл бұрын
All it takes to infect hundreds of thousands of computers is being nice and kind to people wishing them good day. Although, not gonna lie, the virus part is pretty rude.
@AnkitAnubhav
@AnkitAnubhav 2 жыл бұрын
Just few days ago,the attack vector has changed. Instead of document macros, they are shipping shortcut files. These are shortcuts to launch powershell in hidden mode, and call code to download and execute a malicious payload. And the attachment is a mere 1200 bytes.
@maotseovich1347
@maotseovich1347 2 жыл бұрын
I actually have seen excel sheets like that where there's no data and just a prompt telling you to enable macros. Our corporate parent company's data department does daily data distributions in them. I'm still terrified every time I click "enable". The company my wife works for sends out anti-phishing training emails every few months that are intended to look like newsletters where the content is just links to pages that ask for your username and password, and forward your details to the company's IT team for internet security training. My company's actual newsletters are just collections of links that take you to pages that ask you to log in with your username and password to view that particular piece of newsletter content. It's like they're training us to compromise ourselves.
@WaffleStomper69
@WaffleStomper69 2 жыл бұрын
Guys, I wouldn't worry about EMOtet too much. This type it thing is almost always just a phase. It will grow out if it.
@QDSGames
@QDSGames 2 жыл бұрын
Lol, good one. 😂
@nocultist7050
@nocultist7050 2 жыл бұрын
Yep recently go a mail like this. Marked as spam instantly.
@chaos0987654321
@chaos0987654321 2 жыл бұрын
How can you tell if a reimaging device, such as a drive copier would be safe to use to as a faster reformat of a system
@akirathearchibald7958
@akirathearchibald7958 2 жыл бұрын
At this point you cant really use any gadgets at all
@TiagoTiagoT
@TiagoTiagoT 2 жыл бұрын
It's not a zero-day, it's a many-years....
@leshommesdupilly
@leshommesdupilly 5 ай бұрын
Everyone gangsta til the toothbrushes turn evil
@okiguessineedahandle
@okiguessineedahandle 2 жыл бұрын
once i was checking out some malware sample someone had emailed me (i think maybe in 2017/18?), because I like to pull things apart, except when i right clicked to rename it from a exe type to a harmless type my mouse glitched and right clicked again (good old Logitech double click problem), pressing the "Open" button and ran the malware, i hit the power switch a few seconds later, and I then had to wipe everything and swap out all of my passwords. Later analysis of the malware that I did showed it was mostly just a botnet zombie so wasn't actively going after harvesting any of my data, thank f...
@TheNeonLynx
@TheNeonLynx Жыл бұрын
Honestly e-mail attachments on my end have only ever been opened when we had through a different means of communication confirmed that there would be an email with an attachment sent. I believe that is the optimal courrse of action. If it is something regularly done in a company then have some form of internal code that has to be checked before anything is downloaded. Never Download/open attachments you have not beforehand confirmed that you would receive.
@Comeatm3br0
@Comeatm3br0 2 жыл бұрын
Group policy and powershell shouldn’t be available for anyone other that specific users, general customers should not have a need for them.
@phillipanselmo8540
@phillipanselmo8540 2 жыл бұрын
bruh what????? powershell may be a shit shell but only relying on cmd would be hell
@Astroqualia
@Astroqualia 2 жыл бұрын
Need to have individual and dev versions of windows, dev versions would be much less locked down. They could even make a super secure, but still usable version of "security windows", couldn't they?
@real1cytv
@real1cytv 2 жыл бұрын
Yeah sure, I'm committing tax fraud, get a suspicious email and then I call the IRS to ask them: "Hey are you investigating me yet?"
@ASDASD-zh7vx
@ASDASD-zh7vx 2 жыл бұрын
Avoid downloading attachments from shady emails. Me: Jokes on you, i never read any emails.
@poketcg1592
@poketcg1592 2 жыл бұрын
Ive gotten so much more malware spam sent to me that passes google and my own custom filtering.
@lau5067
@lau5067 2 жыл бұрын
Double check before you double click - that's catchy!
@postbunnie
@postbunnie 2 жыл бұрын
Isn't that the name of the mummy guy in that old movie with Brendan Fraser? Looks like the curse of the mummy has been placed on a computer! Seems his soul is still wreaking havoc on people- so his style.
@cornevandervyver3301
@cornevandervyver3301 2 жыл бұрын
Crowdstrike Next Gen AV uses indicators of attack and don't need signatures. Traditional AV is useless. They also record all the telemetry so you know when and how it tried.
@d21852
@d21852 2 жыл бұрын
Once emotet includes a few zero days in their infection methods you won't be able to stop it with being more computer literate, I'm guessing that's not happening due to the amount of work to maintain it; Stay smart, but don't think it will protect you from all hackers
@potatofrogs5999
@potatofrogs5999 2 жыл бұрын
Avast freaks out if some program tries to run powershell scripts. I noticed it while installing MTGO.
@chrishears
@chrishears 2 жыл бұрын
What if right clicking and looking at the source code was the way to activate malware? Oooo scary! Love your work o/ Thanks for all this phish!
@Elrog3
@Elrog3 2 жыл бұрын
The malware doesn't just get to decide on its own how it gets activated. It has to work with whatever software the computer is already running.
@chrishears
@chrishears 2 жыл бұрын
@@Elrog3 Wasn't being serious. Joke...but thanks for being a logical thinker.
@adrianalexandrov7730
@adrianalexandrov7730 Жыл бұрын
Yeah, looking at the file won't hurt your computer. ...except for that 0-day windows backdoor where just preview was enough )))
@samuelbirdwell3167
@samuelbirdwell3167 2 жыл бұрын
Lol, you guys still connect your PCs to the internet?
@ZaHandle
@ZaHandle 2 жыл бұрын
^^ He sent this via pigeons
@artfol2
@artfol2 2 жыл бұрын
I worked in a company that would shutdown your machine if you saved a file as an executable. Their machines had 16 gigs of RAM and 1/4 of it was filled with anti virus and monitoring stuff.
@HotShotMechPilot
@HotShotMechPilot 2 жыл бұрын
I only open attachments from moms in offshore casinos. Pretty sure I'm safe.
@PopeMical
@PopeMical 2 жыл бұрын
If these attacks use powershell to install, could you just disable powershell? Obviously it would be better to not download and run random attachments without checking if they are legit, I'm just curious if disabling poweshell would work.
@chanerubin2287
@chanerubin2287 2 жыл бұрын
In some cases, you can get pawned just by opening a folder with a malicious .lnk file in it.
@gravityhorse4781
@gravityhorse4781 2 жыл бұрын
"Double-check before you double-click." Also solid dating advice.
@JamesWilson01
@JamesWilson01 2 жыл бұрын
A Ukrainian researcher recently made it FOSS I think 😉
@ZaHandle
@ZaHandle 2 жыл бұрын
Based researcher ignores war
@unclebenny9028
@unclebenny9028 2 жыл бұрын
Your grandparent's computer will eventually destroy the world... LOL
@rogo7330
@rogo7330 Жыл бұрын
I like how you named Windows shortcuts "programs". Because they are scripts, not just a symbolic link to a file.
@nashaut7635
@nashaut7635 2 жыл бұрын
> more than 130000 [...] I am pretty much amazed of such a low number, I really expect[ed] way more than that...
@bradweir5579
@bradweir5579 2 жыл бұрын
Just call the IRS. Navigate a convoluted speech recognition menu that will send you to the right option 50% of the time. Wait on hold for 2 hours before getting disconnected... Repeat...
@Renopus
@Renopus 2 жыл бұрын
10:01 For a momento thought that was Yettel, heh.
@davenone8516
@davenone8516 2 жыл бұрын
Defender is a bit better than you give it credit for. Defender and other AV venders have heuristics engines, kernel level hooks, and windows subsystem shims that monitor all subsystem API calls. It isn't perfect, but most compromises are due to a failure to update or the deactivation of realtime protection features.
@glass7923
@glass7923 2 жыл бұрын
So how do we know it's 130,000 computers? How do you find that out?
@johandissmann9757
@johandissmann9757 Жыл бұрын
Pov: Your Wifi router is for some reason part of the meris botnet.
@johandissmann9757
@johandissmann9757 Жыл бұрын
Pov: no pov
@ytuser0110
@ytuser0110 2 жыл бұрын
High five to myself for having tactical lazyness and going to my e-mail only for 2 factor authentication.
@vaikjsf34a
@vaikjsf34a 2 жыл бұрын
"protected document" does not imply you cannot edit it... It implies that only you and the person who sent it to you can open the document. But of course the hacker can open it, they sent it to you.
@redemax
@redemax 2 жыл бұрын
Have you played the singularity game on Linux?
@RockAristote
@RockAristote 2 жыл бұрын
Does the process needs admin right to download something into system32 ?
@th1nhhdk
@th1nhhdk 2 жыл бұрын
Thank god i use Linux
@IgorBogdanoffs
@IgorBogdanoffs Жыл бұрын
Idk how anyone could fall for that bruh
@AntiWanted
@AntiWanted 2 жыл бұрын
Nice
@cherubin7th
@cherubin7th 2 жыл бұрын
Economics are funny for sure.
@kantraa
@kantraa 2 жыл бұрын
i was expecting or you to say twitter or google, the word "botnet" has been ruined for me
@tubbiele2
@tubbiele2 2 жыл бұрын
SMS too
@DukenukemX
@DukenukemX 2 жыл бұрын
I didn't hear any recommendations to use Linux. Not that Linux can't be infected but botnet hackers aren't going to make a tool for Linux which doesn't have many users. Also anyone smart enough to install Linux is usually smart enough not to give root access to anything. You may not be smart enough but thanks to all those Linux users they aren't going to fish for that one guy that might be smart enough to install and use Linux but dumb enough to give root access to their script.
@sawave1630
@sawave1630 2 жыл бұрын
nah. im sure newcomers to linux will not be very sesnsitive to security there just lucky that theres not much linux malware
@dltdev9006
@dltdev9006 2 жыл бұрын
Once userland is compromised you're toast as well
@ZaHandle
@ZaHandle 2 жыл бұрын
Take a shot every time he said “Linux”
@thefrogge
@thefrogge 2 жыл бұрын
@@ZaHandle helpp.ther.is.sjumpin he. Scheep
@brycem8161
@brycem8161 2 жыл бұрын
Most embedded iot devices run some flavor linux, it's actually a great target.
@-CRZY-
@-CRZY- 2 жыл бұрын
The name and the botnet alltogether remind me of an Episode from Rick and Morty
Can Paris fix its poop problem before the Olympics?
8:06
How to Actually Escape the Botnet
32:17
Mental Outlaw
Рет қаралды 506 М.
I Can't Believe We Did This...
00:38
Stokes Twins
Рет қаралды 86 МЛН
THEY WANTED TO TAKE ALL HIS GOODIES 🍫🥤🍟😂
00:17
OKUNJATA
Рет қаралды 20 МЛН
Самое Романтичное Видео ❤️
00:16
Глеб Рандалайнен
Рет қаралды 4,7 МЛН
The child was abused by the clown#Short #Officer Rabbit #angel
00:55
兔子警官
Рет қаралды 24 МЛН
Hacking Forum Raided By The Feds, Head Admin Arrested
17:56
Mental Outlaw
Рет қаралды 185 М.
The King Of Malware is Back
19:27
John Hammond
Рет қаралды 190 М.
An Analysis of Russian Cyber Attacks On Ukraine
14:45
Mental Outlaw
Рет қаралды 81 М.
How A Steam Bug Deleted Someone’s Entire PC
11:49
Kevin Fang
Рет қаралды 920 М.
Detect Hackers & Malware on your Computer (literally for free)
16:38
Mozi Malware - Finding Breadcrumbs...
50:16
John Hammond
Рет қаралды 198 М.
Virus investigations - Mylobot Proxy Botnet
14:19
Mental Outlaw
Рет қаралды 77 М.
These Keys Shouldn't Exist | Nostalgia Nerd
19:32
Nostalgia Nerd
Рет қаралды 648 М.
Avoiding FED Honey Pots and Entrapment
8:58
Mental Outlaw
Рет қаралды 504 М.
Worlds Dumbest Darknet Admin Gets Busted
14:54
Mental Outlaw
Рет қаралды 324 М.
Здесь упор в процессор
18:02
Рома, Просто Рома
Рет қаралды 171 М.
Опять съемные крышки в смартфонах? #cmf
0:50
Хотела заскамить на Айфон!😱📱(@gertieinar)
0:21
Взрывная История
Рет қаралды 6 МЛН
Мой инст: denkiselef. Как забрать телефон через экран.
0:54