Microsoft Teams: Malware Version

Поделиться
HTML-код
  • Опубликовано: 3 фев 2025

Комментарии • 103

  • @wolf1438
    @wolf1438 11 дней назад +107

    I will share this video next time when someone at work will ask me why the office employee cannot install programs on company computers on their own.

    • @aussiegruber86
      @aussiegruber86 11 дней назад +6

      I work in automation with PLCs etc and our OS is so locked down it takes weeks to have software installed to fix urgent repairs, literally to the point you have customers screaming at you……it’s an absolute joke, I understand that people are hopeless but when these big companies make these stupid blanket rules for engineering task it legit holds everyone back.
      I have even driven 6 hours to go home to grab a personal laptop so that I could flash a PLC card with the correct firmware.

    • @wolf1438
      @wolf1438 10 дней назад

      @@aussiegruber86 would you let some freshmen operator to configure PLC? Tinker with parameter. For example you got value 39 but, he likes rounded numbers so he change them to 40, even when he has warning sign right above PLC controller, DO NOT SET VALUE OVER 39! And as result it cause machine malfunction and several days out of order. What would you explain to the customers? "We let the control panel unlocked so when the alarm goes off, we don't have to input password several times a day?"

    • @defenderblack614
      @defenderblack614 6 дней назад

      😄 good one

  • @LockCarge
    @LockCarge 11 дней назад +20

    £3200 is a bit steep for a single user! I thought it would be a couple of hundred and was shocked to see the price of vm Ray!

  • @r3desired
    @r3desired 11 дней назад +5

    Good thing to note is that the real Microsoft Teams does not actually require UAC approval. But, I've also seen companies where the IT departments are the wild west so I wouldn't be surprised if some corporation ran this file lol.

  • @GerardPinzone
    @GerardPinzone 11 дней назад +110

    Can I ban all software signed in India? If so, how?

    • @mukeshsolanki7772
      @mukeshsolanki7772 11 дней назад +4

      why do u want to do so??

    • @GerardPinzone
      @GerardPinzone 11 дней назад

      @@mukeshsolanki7772 Why would I ever need to run software signed in India?

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 11 дней назад +17

      I'm not aware of anything like this, but there are two other approaches:
      1. Make manual control with HIPS/IPS/IDS utilities.
      2. Use firewall like Safing Portmaster to ban all traffic to any country that you don't like. It won't save you if bad actor will use VPN or server located in other countries, but it's at least something

    • @GerardPinzone
      @GerardPinzone 11 дней назад +12

      @@ТоварищКамрадовСоциалистКоммун I already block traffic by country. The question was, can we block signed applications by the country of origin of the certificate?

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 11 дней назад +1

      @@GerardPinzone the country of the origin of the certificate is the company that included this indian company in the trusted list. It should be seen if Leo would at 0:30 click on the company name and then press on 'details' button. That would reveal the CA data.
      About your question looks like rather no. You either use the normal list of CA, or you don't use it )
      In fact, the alternative to it is the web of trust.
      You can edit the CA list, but it's rather a manual control, not what you asked

  • @Steven-u5w
    @Steven-u5w 4 дня назад

    I truly appreciate everything. Put it into this channel. Very interesting and really do need to be aware and on top of the situation at all times it is very easily to get caught out

  • @mikumikupog
    @mikumikupog 11 дней назад +13

    That is pretty convincing.. signature would probably give it away for me

    • @lifelover69
      @lifelover69 10 дней назад +2

      Because of IT policy, I have to click that prompt so many times a day, so most people will not read the signature, especially under always-tight deadlines. IT preinstalls Teams via Intune, so this exact malware situation would not happen.

  • @13thravenpurple94
    @13thravenpurple94 11 дней назад +1

    Outstanding work on this video! I'm grateful for your dedication! 🌟

  • @peterwassmuth4014
    @peterwassmuth4014 11 дней назад +2

    Awesome! Thank you for Sharing! 💯✴

  • @anxiousfool
    @anxiousfool 11 дней назад +7

    Most importantly, I would not expect a UAC prompt when installing Teams, and so would be immediately suspect.

    • @fred-youtube
      @fred-youtube 11 дней назад +8

      However any software that installs for all users requires UAC, so not many else would be suspicious.

    • @itsbinoyghosh
      @itsbinoyghosh 11 дней назад

      Yup ​@@fred-youtube

    • @anxiousfool
      @anxiousfool 10 дней назад

      @ True! The official Teams installer installs in a user's appdata by default, and only will install for all users if you manually run the installer as an admin. That's why from my experience a Teams installer should only give a UAC prompt if I prompt it to do so.

    • @the-Gammaron
      @the-Gammaron 6 дней назад

      Problem is, you can't really expect the ordinary user to notice and remember such tiny details ​@@anxiousfool

  • @Vik-005
    @Vik-005 7 дней назад +2

    Microsoft has office in India yet this happens so it means, its a partnership and w11 and recall and account to logged in without logging out deliberately shouts same.

  • @russellhltn1396
    @russellhltn1396 11 дней назад +4

    Question: what happens if the users don't have admin rights? That's the way we do it at my company.

  • @xgui4-studios
    @xgui4-studios 11 дней назад +7

    the code signing practice is corrupted

  • @xypha85
    @xypha85 10 дней назад +2

    Weird question i guess. Is it the fact i grew up in the 90s as in internet kid that makes me inclined to matter go to an official source or not use it. If a email comes through for anything i always open the site myself. I treat it the same as that if my calls me. I hang up and dial back to my bank so i know its really the bank because i dialled them. Hadnt really thought about it in years till i watched this, its just been habit since i can remeber.

  • @MikesRecordBox
    @MikesRecordBox 11 дней назад +6

    What happens if you already have teams installed?

  • @empmachine
    @empmachine 9 дней назад

    BonziBuddy comeback time!!

  • @RezaQin
    @RezaQin 8 дней назад

    Just another reason why I've only ever gotten a virus by clicking things I shouldn't have...

  • @vpx23
    @vpx23 11 дней назад +1

    According to the systray icon it's also the old Teams version, not New Teams. ^^

  • @foqsi_
    @foqsi_ 11 дней назад +1

    Hey! I'm starting a malware analysis course in school. The professor has provided a zipped malware folder on the portal. However, there are no instructions other than do not unzip. I know to not mess with it on my local machine, but I enabled sandbox mode on my PC, but I'm not entirely sure how sandbox works. Is it possible the virus could leak to my local machine from the sandbox?

    • @Ohem1
      @Ohem1 11 дней назад +1

      I've had the same thought about VMs

  • @mazharul3132
    @mazharul3132 11 дней назад +1

    What will a good behavioral protection AV do in this situation?

  • @06dogb
    @06dogb 11 дней назад +1

    Surprised people would even need something to install teams. Thought it was automatically installed on windows by default or even if not included it auto installs every time I put fresh Win11 on a PC and connect to internet.

  • @IamLookingforWoody_________786
    @IamLookingforWoody_________786 11 дней назад +1

    Nice video😘💐👌🏼.

  • @VORTEX_OMB
    @VORTEX_OMB 7 дней назад

    1:09 WHAT WE COULD IMAGINE?
    IMAGINE IF NINJA GOT A LOOOOOW TAPER FAADE
    🗣🗣🗣🗣

  • @Furtivexx
    @Furtivexx 11 дней назад +1

    Do you happen to have an installer for the John miner? Aka ReaItekHD bitcoinminer that blocks a lot of AV software?
    Know what I’m referring to?

  • @Daeva83B
    @Daeva83B 8 дней назад

    I think i got hacked, not sure how exactly, still figuring that out. Using ubuntu clamscan now to scan and figure out the infection.
    Either game mods, or in my crusade on twitter, because a guy sended me a soundfile, he was pretending to be elon, and I said proof it and without thinking i clicked on the play button.
    My pc is still scanning for the infection and i just wanna identify it. I want to know what it is.
    Thank you btw, your videos informed me well.

  • @paullopresti9568
    @paullopresti9568 9 дней назад

    Is there any recent malware on Pot Player or VLC media player. I downloaded both and something made my laptop and router unusable. USB ports don't work. Command prompt doesn't work. Can't open file Explorer, and it won't let me wipe the drive. Router won't connect to the internet. I tried to log onto the router, but my password didn't work. I did a factory reset, and the default user/password doesn't work. I also tried everything in safe mode. Any ideas on what to do?

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 8 дней назад

      solving an issue starts from localizing it. First to do is to find out what doesn't work. It's not likely that both your gadget (PC?) and router are affected because of possible malware. If you don't have any other PCs, get a linux from your flash stick, load from it, and check if router is OK.
      Oh, you don't have any linux on a flash drive? what a shame

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 8 дней назад

      it might be that your system doesn't work properly. You need first to stop using your possibly infected system and find something that you can rely on. If not another laptop, then at least another system loaded from it. Desirably some linux from a flash drive. Ask your friends/ neighbors to make it for you

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 8 дней назад

      when router will be working again, fix your laptop. Safe way is to reinstall your system. Your laptop may have a system backup sector, you can use it to restore your system

  • @reasonabledoubt-z9q
    @reasonabledoubt-z9q 10 дней назад

    Is an antimalware like Bitdefender effective at analyzing attachments and executable? It does have a function to do this

  • @NO-END
    @NO-END 11 дней назад +3

    What 4 AV engines detected it??

    • @imgamerful
      @imgamerful 10 дней назад

      I'm willing to bet Bitdefender or ESET caught it. Maybe Kaspersky too

  • @graysonpeddie
    @graysonpeddie 11 дней назад +4

    You can have your computer infected with malware in Windows 11 as you would in Windows Vista and 7 which are two of my favorite operating systems of all time. Even as far back to Windows XP. It does not matter which version of Windows you are in if you are not vigilant at all.

    • @imgamerful
      @imgamerful 10 дней назад

      Unironcially I still use windows xp. Despite being cautious I'm sure my PC is infected, due to there being no decent or working anti viruses for it.

  • @Audulf-of-Frisia
    @Audulf-of-Frisia 11 дней назад +20

    I wish you would a few episodes on mobile threats for Android.

    • @animeworld2005
      @animeworld2005 11 дней назад +3

      Mobile threats are very rare if you not download any apks from anywhere

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 11 дней назад

      yep, as long as you stick to the app store, you are pretty safe

    • @lukamanevski
      @lukamanevski 11 дней назад

      What about clicking on links​@@ТоварищКамрадовСоциалистКоммун

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 11 дней назад

      @@lukamanevski links are normally processed by browsers, so it's about how secure the browser is. If you are interested in just security, staying with google products, including chrome, is a safe side. You can still ramp up your security by using some extensions for security and privacy. The top 3 of them: uBO, noscript, bitwarden or keypassxc

    • @1nwb-4dnws
      @1nwb-4dnws 11 дней назад

      AppManager using virustotal, still need to check the repo manually tho eg false positive solved in breeze weather

  • @ppiero7
    @ppiero7 9 дней назад

    👍👍👍

  • @ProtoType4588
    @ProtoType4588 11 дней назад +1

    even if its the business i do not care emails with attachments standardly gets verified in a vm if its a well known program i will download it from the source itself people go ow but it aint as convenient...are you that lazy to open the browser and find microsoft teams on the microsoft site heck why even a browser run the windows store instead it also has microsoft teams

  • @ConfuseDoc
    @ConfuseDoc 11 дней назад +2

    Hello what antivirus software do you use personally?Thanks for reply 🙂

    • @Fugalism
      @Fugalism 11 дней назад

      Microsoft's Defender is fine. Just don't open executables you shouldn't be opening to begin with.

    • @bomlife1572
      @bomlife1572 11 дней назад +7

      @@Fugalism "Just don't open executables you shouldn't be opening to begin with." lol

  • @ethimself5064
    @ethimself5064 11 дней назад +2

    Seems like my Comment disappeared. I believe it was noteworthy

  • @FSK1138
    @FSK1138 11 дней назад +5

    ? . it is not from microsoft ...? why would you run this ?? just download teams from Microsoft .😆

    • @IgnacioGouk
      @IgnacioGouk 11 дней назад +8

      The level of tech illiteracy in the average office would blow your mind..

    • @eainen
      @eainen 11 дней назад +3

      perhaps consider watching the video

  • @Nippell
    @Nippell 11 дней назад +3

    nice 20 seconds of the video bro❤

  • @mackjsm7105
    @mackjsm7105 11 дней назад

    TY bd

  • @LaProUserniere
    @LaProUserniere 11 дней назад

    Versions:
    Team personal
    Team proffesional
    Random asian team..

  • @preveenramcharan
    @preveenramcharan 10 дней назад +1

    The worst thing to do on Windows 11: align the icons to the left 🤦‍♂

  • @iamwitchergeraltofrivia9670
    @iamwitchergeraltofrivia9670 11 дней назад +1

    Hhahahaha more malware update not new

  • @lewiskelly14
    @lewiskelly14 10 дней назад

    Half baked video

  • @ooparkeroo
    @ooparkeroo 11 дней назад

    first

  • @patriotic1526
    @patriotic1526 9 дней назад

    goons. thats how