Somebody emailed me a trojan virus

Поделиться
HTML-код
  • Опубликовано: 21 янв 2025

Комментарии • 1,7 тыс.

  • @bogxd
    @bogxd  5 месяцев назад +2367

    Also, I just realised that you can reduce email spam by around 70-80% by scrolling back up to SMASH the like button

  • @M249-z2s
    @M249-z2s 5 месяцев назад +6838

    This turned from a video about viruses to an virtual box ad.

    • @vaakdemandante8772
      @vaakdemandante8772 5 месяцев назад +120

      more like a Windows installation tutorial, which is crazy because the OS installer should not require one

    • @sspnlgaming7844
      @sspnlgaming7844 5 месяцев назад +7

      thats the point

    • @JmKrokY
      @JmKrokY 5 месяцев назад +3

      🗿

    • @Manny73211
      @Manny73211 5 месяцев назад +29

      they deserve the promo

    • @laupoke
      @laupoke 5 месяцев назад +6

      That's not the type of tool that would make any sense being advertised on youtube

  • @billyjhamlin
    @billyjhamlin 5 месяцев назад +953

    Congratulations on getting me to watch a 14 minute long ad for VirtualBox!

    • @normalgamer-wf5in
      @normalgamer-wf5in 29 дней назад +4

      lol

    • @daapz
      @daapz 23 дня назад +5

      Especially when instead all that deleting and cloning it would've been a lot more productive to make a snapshot of the clean state and then just revert to that.

  • @RishabhBohra13
    @RishabhBohra13 5 месяцев назад +3635

    I live in india, Zomato is a legit company, and really big like doordash, this person is definitely pretending to be them.

    • @HaryanviKashmiri
      @HaryanviKashmiri 5 месяцев назад +209

      same here, zomato doesn’t even work in europe.

    • @zerokun2655
      @zerokun2655 5 месяцев назад +140

      I mean, definitely. He even showed the stock value of the company in the video, so it's real. Just like Sony Vegas is

    • @flipflops99
      @flipflops99 5 месяцев назад +40

      ya dont say?

    • @Rusty01
      @Rusty01 5 месяцев назад +28

      @@flipflops99 fr like bro saying it like it wasnt obvious they are prentended

    • @asadfarraj
      @asadfarraj 5 месяцев назад +3

      It is a multinational company if I remember correctly

  • @TerraGreen1
    @TerraGreen1 5 месяцев назад +685

    A couple years ago I fell for one of these emails on an old channel from some one pretending to be from a mobile game. After opening it, within a few hours my channel had been converted into some fake scam uploading videos about cracked editing softwares trying to spread the trojan to my audience. It was a pain to get the channel back as pretty much all my emails had been hacked and I had no proof of even owning the channel 😂. I had to completely wipe my computer and go through tons of email recovery steps. It's crazy how they're still around, and it's a good thing you made a video about this as you probably saved at least a couple youtubers from falling for it.

    • @thegrungler_real
      @thegrungler_real 5 месяцев назад +16

      Huge fan of your channel! Hope this never happens again

    • @SillyStarCat
      @SillyStarCat 2 месяца назад +5

      I remember this happened to an artist named sonadrawsstuffyt

    • @zallax-07
      @zallax-07 2 месяца назад

      Can you gimme a shout-out?

    • @twotruckslyrics
      @twotruckslyrics Месяц назад +2

      @@SillyStarCatthe elon musk live streams…

    • @SillyStarCat
      @SillyStarCat Месяц назад

      @@twotruckslyrics oh god

  • @AmartyaAnand
    @AmartyaAnand 5 месяцев назад +4023

    Plot twist: this whole video was a virtual box promo 🗿

    • @ElishaPervezORG
      @ElishaPervezORG 5 месяцев назад +17

      bruhhh :-:

    • @sauliusvitkauskas8741
      @sauliusvitkauskas8741 5 месяцев назад +35

      VMware is better

    • @ElishaPervezORG
      @ElishaPervezORG 5 месяцев назад

      @@sauliusvitkauskas8741 Both are pretty good but still not 100% safe

    • @Russian95_
      @Russian95_ 5 месяцев назад

      @@sauliusvitkauskas8741 true

    • @TheosTechTips
      @TheosTechTips 5 месяцев назад

      @@sauliusvitkauskas8741 No way lol. Broadcom sucks. Open-source FTW!

  • @HarryDoesTech
    @HarryDoesTech 2 месяца назад +173

    Nice folder called "STOP READING MY FOLDER NAMES". Gotta love that!

  • @falxie_
    @falxie_ 5 месяцев назад +5602

    Running suspicious software in a VM helps but doesn't completely remove any risk. The virus could steal any credentials present in the VM and potentially probe at your home network if you don't have it isolated.

    • @randomgamingin144p
      @randomgamingin144p 5 месяцев назад +677

      also often the software can detect a VM so you have to use qemu-kvm and trick it into thinking its not running on a VM, or hyper-v might work

    • @phr3ui559
      @phr3ui559 5 месяцев назад +60

      are there any tutorials on this

    • @phr3ui559
      @phr3ui559 5 месяцев назад +40

      @@randomgamingin144pcan you link a tutorial

    • @zakariya2011_
      @zakariya2011_ 5 месяцев назад +143

      Uhh if you run VMware the vm's network connection will be isolated

    • @redlionstudio2750
      @redlionstudio2750 5 месяцев назад

      @@randomgamingin144p or sandbox

  • @DomenLo
    @DomenLo 5 месяцев назад +193

    This part {something|something else} is actually spintax, not personalization. It randomly picks one of the options inside the squiggly brackets (separated by a pipe), making the text unique enough that it doesn't trigger spam filters.
    Btw - in virtualbox you could also create snapshots and revert back to one pre-test, this way you dont need to delete and re-clone the installation.

  • @gFamWeb
    @gFamWeb 5 месяцев назад +1244

    Clarification on virtual machines: some clever viruses can detect and potentially even escape virtual machines (although the latter is rare)

    • @siphovundla5057
      @siphovundla5057 5 месяцев назад +120

      That is what wacatac is doing, it first scans to see if its on a VM and if it is then it wont run any further malware

    • @Fuzzbuzzhuzzruzzluzz
      @Fuzzbuzzhuzzruzzluzz 5 месяцев назад +76

      I mean 6 out of 100 malware can do this. Your just better off playing the unlucky jackpot if that happens. But some people use web virtual machines

    • @thmUNIX
      @thmUNIX 5 месяцев назад +55

      QEMU/KVM is rarely detected, because VirtualBox and VMware are the most popular VMs out there. btw, even in VBox & VMware you can via Registry Editor, I believe, edit sys info so that it would look like to malware that it's a real PC

    • @ZarakKhan-h3j
      @ZarakKhan-h3j 5 месяцев назад

      @@siphovundla5057 wacatac isnt even a malware lol. its the ai scanned malware.

    • @dvorakgigachad1444
      @dvorakgigachad1444 5 месяцев назад

      @@Fuzzbuzzhuzzruzzluzz VM escapes are very very rare and haven't happened in many years

  • @nanomachines2954
    @nanomachines2954 4 месяца назад +162

    9:04 it's not "HTML". H here stands for 'heuristic' and ML means machine learning. Means this virus was detected not by checking it's signature but by scanning its behavior using machine learning (AI).

    • @thelastdirewolf3587
      @thelastdirewolf3587 3 месяца назад

      What it was detected with ml because it said that was the detected file

  • @CrimesAnatomy
    @CrimesAnatomy 5 месяцев назад +1749

    Hey Bog, this is hilarious, I got a recent email just like this. You did well turning this into a video to educate people. Because I installed it and now everyone know my true identity and Gotham will never be safe again.

    • @kwe_
      @kwe_ 5 месяцев назад +15

      😭

    • @MrBIizzard
      @MrBIizzard 5 месяцев назад +59

      Pack it up bruce wayne

    • @TimeisoutT
      @TimeisoutT 5 месяцев назад +4

      @@MrBIizzard MY NAME IS THE HULK!

    • @marekvojta9648
      @marekvojta9648 5 месяцев назад +7

      Well i hoped for some analysis of the virus like what it steal how it works etc.

    • @Mr.MessOpixels
      @Mr.MessOpixels 5 месяцев назад +3

      Gotta engage knightfall protocol now
      Edit: don’t forget about the 243 riddler trophies

  • @JohnJacobson555
    @JohnJacobson555 3 месяца назад +264

    I want you to know that this happened to my mother and I had to restart the PC from scratch and look for the programs and office keys to get it working again.

    • @MarkUSAfreedom
      @MarkUSAfreedom 3 месяца назад +1

      where did you get them?

    • @JohnJacobson555
      @JohnJacobson555 3 месяца назад +2

      I checked many sites and in the end I leaned towards BNH Software and in the end everything turned out well.

    • @MarkUSAfreedom
      @MarkUSAfreedom 3 месяца назад +1

      I asked you because lately I'm very distrustful of download sites

    • @JohnJacobson555
      @JohnJacobson555 3 месяца назад +1

      I think that's normal

  • @LocksDE
    @LocksDE 5 месяцев назад +811

    Hey Bog if you see this, in the future DO NOT connect a ethernet cable or Wi-Fi they can infect your router.

    • @norav69
      @norav69 5 месяцев назад +103

      More than infecting your router they can take the public IP from the internet connection of the pc, taking public informations. Most "routers" that we use in our houses do not have any computation power and decision making capabilities, everything is done by the ISP. In general yes tho, it's better to disconnect the internet connection from a virus testing virtual machine

    • @Follina.
      @Follina. 5 месяцев назад +54

      @@norav69 The greatest risk I see is if you have a router with the default password the malware might be able to log into it and turn on port forwarding on your devices, then send your IP to an attacker, so if you then ran a service thinking it'd only be accessible locally, you might end up exposing yourself to the internet

    • @fabienso5889
      @fabienso5889 5 месяцев назад +42

      ​@@norav69
      Oh no they can take my PUBLIC ip whatever are they gonna do
      Yeah nothing that's right
      Network access might start becoming dangerous if you have fully unprotected devices like a camera or a washing machine on your network
      But let's be honnest most viruses you get are just interested in grabbing your passwords and access token

    • @somedude8728
      @somedude8728 5 месяцев назад

      @@fabienso5889 Can't wait for a virus to overtake random unprotected printeris

    • @dvorakgigachad1444
      @dvorakgigachad1444 5 месяцев назад +4

      anyrun is a good way to do that stuff safely

  • @CLOYO
    @CLOYO 5 месяцев назад +83

    6:23 If there's spelling and grammar mistakes then there's definitely something wrong in my opinion.

  • @biscottimuncher
    @biscottimuncher 5 месяцев назад +68

    Running Procdot to capture all system changes in a network isolated environment, or even better, running it in a cloud SAAS like joesandbox could be a really cool follow up video! Following the exfiltration of whatever the bad actor/hacker wanted in a safe environment is always a blast, plus seeing what happens as a granular level is super cool! Awesome video!

  • @Humtog
    @Humtog 5 месяцев назад +48

    Hi, I also got exact same Zomato impersonating email. Same text. And same second reply. At approx same time as you.
    I also realized something is off, when I saw the email itself. Then after downloading and seeing the exe file, I became sure. I did not even extract it.
    I think the ploy here is to get the login/password details of youtubers. Maybe possible to copy a Chrome session that has the user already logged in?
    I had put a hidden mailtracker in my reply to their last email. And they did not even open the mail to check what it is about!

  • @Spectrulight
    @Spectrulight 5 месяцев назад +533

    3:39 my bad for reading your folder names

    • @pizzaman1720
      @pizzaman1720 5 месяцев назад +4

      Lol

    • @JosGeerink
      @JosGeerink 5 месяцев назад +2

      I don't get it?

    • @GlowBerryPumpkin
      @GlowBerryPumpkin 5 месяцев назад +6

      ​@@JosGeerink3:41

    • @ZRIstruck
      @ZRIstruck 4 месяца назад +4

      My bad, too.

    • @its_air7
      @its_air7 4 месяца назад +1

      why is the pfp a pic of someone on the moon

  • @rustlr
    @rustlr 5 месяцев назад +28

    "Now imagine if I opened this on my actual computer, not a virtual machine."
    Your Windows Defender on your actual computer would have blocked and quarantined it as well.

    • @Lucy-bx7si
      @Lucy-bx7si 3 месяца назад +25

      but windows defender will not 100% protect you from these viruses.

  • @efficiencyvi8369
    @efficiencyvi8369 5 месяцев назад +57

    As long as it is a cookie cutter trojan and windows defender is on it is no big deal. It gets dangerous when it is tailored for your device and antivirus doesn't detect it.

  • @XJ9LoL
    @XJ9LoL 4 месяца назад +42

    0:29 nope, broken english = its a phish.

    • @johnsilvrr
      @johnsilvrr 4 месяца назад +3

      God I had such a crush on that pfp when I was a kid

    • @user38526
      @user38526 23 дня назад

      ​@johnsilvrrI still do 😋🤤

  • @karmapawsnplay9701
    @karmapawsnplay9701 5 месяцев назад +336

    good thing you oppened the trojan in a virtual machine. BUT I don think you have properly isolated virtualbox! You might have to check your main desktop! it might have leaked! Be safe!

    • @toreopp
      @toreopp 5 месяцев назад +34

      He didn't run the file. He's fine.

    • @redlionstudio2750
      @redlionstudio2750 5 месяцев назад +16

      i think it's just some cheap stealer, so nothing to worry about

    • @RealMol
      @RealMol 5 месяцев назад +24

      ​@toreopp this is true, he ran the file on his vm. But he didn't completely isolate his vm from his host machine by disabling all network connections. Most viruses can escape the vm by hopping to the host machine through the network.

    • @pancak3
      @pancak3 5 месяцев назад +64

      @@RealMol this is false.

    • @somedude8728
      @somedude8728 5 месяцев назад +47

      @@RealMol They aren't able to escape, they can however gain access to unprotected devices on the network.

  • @smittywerbenjj1
    @smittywerbenjj1 5 месяцев назад +18

    Windows has a optional feature called "Windows Sandbox".
    It does exactly what you did with your clone of a clone of a virtual machine, where it gives you a disposable virtual Windows Machine.
    Its pretty good & safe and doesn't use as much space as VirtualBox.

    • @johnandericadventures
      @johnandericadventures 5 месяцев назад +3

      "it's pretty good & safe"
      someone has never encountered a piece of malware not coded by a 7 year old

    • @speedstyle.
      @speedstyle. 5 месяцев назад +14

      @@johnandericadventures Please do show me this malware that can escape from an airgapped Hyper-V sandbox. Would be handy for taking down Azure

  • @jan_harald
    @jan_harald 4 месяца назад +42

    protip: don't keep cloning the machines, use snapshots!
    you take a base snapshot, then do shady stuff, and revert back to previous snapshot, it's pretty simple

    • @subbastionbastion2167
      @subbastionbastion2167 8 часов назад

      If you want to take 30 min every time and restore doesn't actually restore everything the malware is still there half the time.

  • @rossberget
    @rossberget 2 месяца назад +8

    5:36 whoo trojan virus ladies and mentelgen got me cracked up 😂

  • @zerrrp
    @zerrrp 5 месяцев назад +75

    3:40 love the "STOP READING MY FILE NAMES" folder 🤣🤣🤣🤣

  • @tylerebowers
    @tylerebowers 5 месяцев назад +33

    Booting in a VM is sure safer EXCEPT WHEN THAT VM IS CONNECTED TO THE INTERNET!

  • @Lampe2020
    @Lampe2020 5 месяцев назад +65

    5:46 You can also create a snapshot of the VM in VirtualBox and restore it after you're done, that way you don't have to have multiple VMs.

  • @FanixeyReam
    @FanixeyReam 2 месяца назад +7

    9:38 this gives "I always come back" vibes

  • @mokumoki
    @mokumoki 5 месяцев назад +4

    Regarding the unattended file, it’s a cool feature for most people as it will setup Windows for you automatically without any user interaction (hence, unattended). The reason you get the license key error is when you are adding new VM you did not add a license key. You can use KMS Generic key which you can get from Microsoft documentation and put it in during VM creation. On the other hand, if you want to set it up manually, just check “Skip unattended installation” when creating VM.
    *Unattended installation is quite common in most type 2 hypervisors (Virtual Machine software) like VMware Workstation and Parallels, and for most major OS, so it’s quite easy to setup a VM with minimal effort.
    Another few things I would like to mention is you can learn more about snapshotting in VM, so you can avoid the part where you delete and clone your VM. Also you don’t have to remove floppy to solve the mount error, it is complaining no bootable device found is because you didn’t press any key when booting from the ISO.

  • @Abukek133
    @Abukek133 5 месяцев назад +166

    "theres a .pl"
    Ok so its Polish
    "Its from the netherlands"

    • @vGermanK
      @vGermanK 4 месяца назад +4

      i was thinking the same think lol

    • @vGermanK
      @vGermanK 4 месяца назад +1

      thing*

    • @synvie-x
      @synvie-x 4 месяца назад +3

      as a polish person, i agree 😭

    • @uzzybuzzy-t5h
      @uzzybuzzy-t5h 4 месяца назад +3

      probably used a vpn

    • @agateophobiaaa
      @agateophobiaaa 4 месяца назад

      @@uzzybuzzy-t5h Polish domain (.pl) doesn't require you to have a polish citizenship. Also the information provided by WHOIS is supplied by the owner of the domain (it's whatever was used on domain's purchase), VPN has nothing to do with that.

  • @TheRealOderless635gnat
    @TheRealOderless635gnat 5 месяцев назад +11

    10:03
    Fun fact: if u have windows pro version, u can use windows sandbox too

  • @alijall
    @alijall 3 месяца назад +2

    I love that your videos don't have music. Very satisfying!

  • @27legend31
    @27legend31 5 месяцев назад +8

    Instead of cloning, you can use a snapshot to clone a vm at a point in time, so you can restore it back after running sketchy stuff

  • @JmKrokY
    @JmKrokY 5 месяцев назад +35

    7:57 Polish domain

    • @KRZYSZTOFMANIA
      @KRZYSZTOFMANIA 4 месяца назад +2

      Chciałem napisać 😅

    • @Maciurella
      @Maciurella 4 месяца назад +2

      nie wiem dlaczego, ale byłem przekonany, że oglądam Polski film a nie angielski, więc mnie to nie zdziwiło, czy ja już naprawdę nie odróżniam Polskiego od Angielskiego?! 😂 POLSKA GUROM 🇵🇱

    • @svijj_
      @svijj_ 4 месяца назад +1

      POLAND MENTIONED ☝️☝️☝️☝️🦅🦅🦅🦅🇵🇱🇵🇱🇵🇱🇵🇱🇵🇱🇵🇱🇵🇱💪💪💪💪💪💪💪

  • @natjoe4763
    @natjoe4763 5 месяцев назад +5

    this stuff is fascinating, seeing how security is exploited in different ways across different operating systems. particularly in windows and how its able to regen itself. so interesting

  • @Doctor_Ks
    @Doctor_Ks 5 месяцев назад +20

    4:33 insert vsauce music

  • @elbert5208
    @elbert5208 5 месяцев назад +24

    Try opening it without windows defender turned on

    • @AmartyaAnand
      @AmartyaAnand 5 месяцев назад +14

      💀💀

    • @zerokun2655
      @zerokun2655 5 месяцев назад

      Virtual machines are for cowards!

    • @mayoraeryn
      @mayoraeryn 5 месяцев назад +3

      Could be a cool video idea if he gets some really old laptop for super cheap

    • @Milkguy33
      @Milkguy33 5 месяцев назад

      he would get a trojan virus, nothing interesting

  • @leafve
    @leafve 5 месяцев назад +3

    I would recommend always turning off network connection from the virtual machine. As this way the malicious codes can infect your wifi and other devices connected in real-time.

  • @thmUNIX
    @thmUNIX 5 месяцев назад +6

    you know what, I was more interested in the Mac version of virus in the last email as it's a bit unusual. I downloaded it, and quick check of strings showed that it's definitely a stealer. Will try to reverse it later

    • @_invencible_
      @_invencible_ 5 месяцев назад +2

      yeah i thought he was going to show that one but he just showed the same windows virus twice 😒

    • @thmUNIX
      @thmUNIX 5 месяцев назад +2

      Ok, I digged a bit deeper, it's something reeeally interesting. Will completely reverse it and I guess upload a video on what it is

    • @thmUNIX
      @thmUNIX 5 месяцев назад +3

      well, just an upload to VT showed it's AMOS stealer (not 100% sure, maybe wrong detection & could be something different). So it seems that it's nothing incredibly new, but still interesting

  • @kylek29
    @kylek29 5 месяцев назад +4

    If you create a Linked Clone (this a snapshot that appears like a unique VM referencing the other) or a snapshot fork (checkpoint via the snapshot manager) you can reduce the VM's footprint by a lot. Utilizing checkpoints allows you to roll back the changes you made for the purpose of testing. Alternatively, if you enable the Hyper-V / Windows Sandbox in Windows Features, you gain access to a temporary VM clone built into Windows, it's a tad quicker to spin-up / get into, and can perform better.

  • @abhishek_patra_
    @abhishek_patra_ 5 месяцев назад +236

    Bro I'm from India 🇮🇳 and Zomato is an Indian food company.... It doesn't work outside of India .... Why Zomato would promote anything outside India 😂😂 .....

    • @sebastianbauer4768
      @sebastianbauer4768 5 месяцев назад

      So why are they trying to trick people into installing malware on their machines? Even worse why don’t they support Linux? /jk

    • @GOLDEN-z7x
      @GOLDEN-z7x 5 месяцев назад +9

      It has many services outside India

    • @ashishjadhao115
      @ashishjadhao115 5 месяцев назад +16

      They are outside India aswell...atleast in usa and use since like 2016

    • @charmingotter976rr
      @charmingotter976rr 5 месяцев назад

      so its kinda like just eat/grubhub/uber eats but in india

    • @vikaspoddar001
      @vikaspoddar001 5 месяцев назад +3

      ​@@ashishjadhao115 they have stopped operating outside india

  • @This77577
    @This77577 5 месяцев назад +3

    Someone: sending an email to sponsor a company
    Bog: ends up sponsoring/recommending oracle virtualbox😊

  • @that_guy1211
    @that_guy1211 5 месяцев назад +4

    you can also do this with Triage, it's what NTTS uses, and it's a website that gives you a x/10 score on how bad the malware actually is, virustotal is also a pretty good scanner

    • @its_air7
      @its_air7 4 месяца назад +1

      Btw NTTS Means "No Text To Speech"

    • @aaaaaaaaaaaahreuagh
      @aaaaaaaaaaaahreuagh 14 дней назад

      @@its_air7 no one cares lmao

  •  4 месяца назад +3

    "woo, trojan virus ladies and mentalgen" 🤣🤣🤣🤣

  • @alba4k
    @alba4k 5 месяцев назад +18

    I almost lost my steam account to a similar scam a few days ago. Only realised there was something fishy going on before typing in the sms verification code

    • @bindogaming791
      @bindogaming791 2 месяца назад

      I almost lost my steam account by some person pretending to be a steam admin and that I was about to get banned. I didn’t fall for it I only gave him my email and he wanted verification code, but when I checked email to change password. Which made me suspicious. He has my email though and is that a problem?

  • @Tobiasxdful
    @Tobiasxdful 5 месяцев назад +1

    Please do an iWork vs Office. ❤ I've never seen anyone doing an in depth comparison between Apple and Microsoft in this area. Great videos. Thanks 👌

  • @nithinsvarrier670
    @nithinsvarrier670 5 месяцев назад +5

    From windows 11, You can use Windows Sandbox, which is essentially a VM for these files, It under the hood uses HyperV and is usually more performant than virtualbox

    • @machieu
      @machieu 5 месяцев назад

      Yeah it's just a random window that when you close it goes like bye bye

  • @fddarwish3391
    @fddarwish3391 13 дней назад

    Thank you for making this video. It was educational and entertaining whilst giving us advice and warning through your experience. I'm glad you knew all of this earlier and didn't slip up. Once i got my computer infected with malware, trust me it was hard and a long process, even with my Kaspersky antivirus. Eventually, I also had to reset all my passwords. Back then i was careless, but these types of videos can prevent from others doing the same mistake. It was also nice of you to learn something and on the go shared it with us. 😊

  • @barnknee7847
    @barnknee7847 5 месяцев назад +10

    Man keep doing these,really loving your work so far

    • @bogxd
      @bogxd  5 месяцев назад +1

      Cheers!

  • @AdammtheBiker1-uc9zq
    @AdammtheBiker1-uc9zq 23 дня назад

    I cannot understand why some people would put such a nasty malware inside there. It a nightmare and I am glad I watched this as my lecture did mention about a nasty Trojan that hides itself and false-sense the antivirus-windows defender into thinking it removed, when it copies itself all over register, and other c\32 files to cause mayhem.
    Thanks for reminding me off the dangers.

  • @joytech23
    @joytech23 5 месяцев назад +36

    When playing with viruses in a virtual machine, it's better to do it from a machine you don't care about like a home lab. Some viruses can and do escape containers. Please turn off your network adapter on the VM and any sharing features between the VM/Host. Snapshots also work better than cloning and are way faster - just make sure you restore to the snapshot every time you boot the VM.
    A good test box would be a linux host virtualizing Windows, and if you can nest your machines that'll also work but just remember - work like each layer you try to contain can be breached.

    • @Follina.
      @Follina. 5 месяцев назад +5

      @@joytech23 Containers such as docker? Sure, VMs? Unless you're the target of a highly sophisticated government actor, not really.

    • @joytech23
      @joytech23 5 месяцев назад +3

      ​@@Follina. Escaping a container (VM or otherwise) in an environment that isn't well prepared is actually pretty easy.

    • @Follina.
      @Follina. 5 месяцев назад +1

      @@joytech23 Unless it's connected to your home network there is really not much you can do

    • @qingxinn_
      @qingxinn_ 5 месяцев назад

      I'm curious about this, but I can't find any reputable sources online. Do you mind sharing any sources/how you got this information? ^^

    • @genetalavera4256
      @genetalavera4256 4 месяца назад

      Yup I saw this happen once forgot what youtuber it was.

  • @solofdragons6446
    @solofdragons6446 5 месяцев назад +2

    I was not expecting the spy jumpscare lmao. Great video!

  • @yumeyamamoto
    @yumeyamamoto 5 месяцев назад +116

    5:37 "ladies and mental gen" ??

    • @AlexanderTzalumen
      @AlexanderTzalumen 5 месяцев назад +15

      _Mentalgen_

    • @Zakariaazzaim
      @Zakariaazzaim 5 месяцев назад +5

      😂😂😂😂😂😂😂thankfully im not the only one who heard that

    • @kedirabdu6913
      @kedirabdu6913 5 месяцев назад +13

      Probably a reference to an old TF2 meme. Where spy's famous catch-phrase is reversed.

    • @bekbekovv111
      @bekbekovv111 5 месяцев назад

      mentlegen.
      *proceeds to smoke guaranteed-lung-cancer-worth amount of cigarettes*

    • @EpicXcake
      @EpicXcake 5 месяцев назад +5

      Meet the mentlegen

  • @KareemWalid-l4d
    @KareemWalid-l4d 22 дня назад +3

    5:03 OK I WILL NOT READ YOUR FOLDER NAMES 😂😂😂😂😂

  • @RZ302
    @RZ302 5 месяцев назад +5

    You can also just use Windows Sandbox if you got Windows 11 Pro. Maybe set up a read-only shared folder and disable vgpu and networking before messing with malware.

    • @undefinedCat
      @undefinedCat 5 месяцев назад

      it exists on windows 10 too

  • @TheStevenWhiting
    @TheStevenWhiting 5 месяцев назад +2

    4:05 Not always. There are some out there that can jump to the host machine. There are also plenty out there that will detect if they are in a VM and not actually do anything to hide what they really are.

  • @Activation123
    @Activation123 5 месяцев назад +50

    vegas is NOT an editing software.
    it's a bad attempt at one. it was good before magix bought it 💀💀💀. Also yeah, you would have gotten an email from Magix, not ... Sony Vegas PR or whatever.

    • @SenseiYasir
      @SenseiYasir 5 месяцев назад +2

      You're right... It's the best one.

    • @Activation123
      @Activation123 5 месяцев назад +3

      @@SenseiYasir uhhh no

    • @FlushDesert22
      @FlushDesert22 5 месяцев назад +10

      At least Vegas doesn't require a subscription to use, and a fee to unsubscribe.

    • @Activation123
      @Activation123 5 месяцев назад

      @@FlushDesert22 yeah fair, I use resolve lmao. But in all seriousness, at least other softwares are stable most of the time... And dont require you pay an obscene amount every time you upgrade. Also Vegas just... Doesn't have much support anymore

    • @justinhamilton8647
      @justinhamilton8647 5 месяцев назад +2

      It used to be great until whatever they screwed up. Anything I render on vegas either is littered with black frames or extremely pixely. Sticking with pirated premiere that runs on any machine post 2013 lol

  • @Vaibryn
    @Vaibryn 28 дней назад

    Additional advice:
    When using VMs to open shady files, absolutely cut off the network adapter in the VMs settings. A lot of advanced trojans are able to replicate themselves over your local network (basically all devices that are accessible throughout your home network, including your router) and aren't just limited to the machine they are executed on.

  • @jobo_o
    @jobo_o 5 месяцев назад +4

    W video, really smart to open the file in a virtual box :)

  • @Dusty_Monkey
    @Dusty_Monkey 16 дней назад +1

    I just had the weirdest ad play before this video, basically it's a guy that's gonna jump off a really small hill and someone was trying to stop him by saying "You can still learn how to code while making money" or something along the lines of that then this guy just walks up to the camera person and says "BUT I'M STILL A JANITO-" and that's when I skipped the ad, that was a truly deep story and a weird ad 😭😭

  • @Einzigartigitsme
    @Einzigartigitsme 5 месяцев назад +4

    there is inbuild windows virtual machine, which cleans everything as soon as you shut it down
    it is in "turn windows features on or off" and virtual machines
    hope it helps!!

    • @teggolT
      @teggolT 5 месяцев назад +1

      isn't that a pro feature or sth

    • @sunsetsonwheels
      @sunsetsonwheels 5 месяцев назад +1

      Isn't it called Windows Sandbox?

    • @somedude8728
      @somedude8728 5 месяцев назад +1

      @@sunsetsonwheels I think sandbox is for Windows 11 only

  • @Clash_Royale_King21
    @Clash_Royale_King21 9 дней назад

    4:08 “STOP READING MY FOLDER NAMES” is a cool detail😂

  • @Trisks
    @Trisks 5 месяцев назад +190

    Bog when he discovers some viruses are capable of escaping Virtual Machines

    • @AndRei-yc3ti
      @AndRei-yc3ti 5 месяцев назад +2

      How?

    • @pastaya
      @pastaya 5 месяцев назад +50

      @@AndRei-yc3ti exploiting the networking

    • @WindowsDestroyer
      @WindowsDestroyer 5 месяцев назад +9

      Or some one could do just exploits with the hypervisor

    • @Follina.
      @Follina. 5 месяцев назад +50

      ​@@WindowsDestroyerIf you're thinking of exploits capable of escaping a network isolated VM, yea, no, those exploits go for millions, they ARE NOT going to be used on a YTber

    • @polarrbtw
      @polarrbtw 5 месяцев назад +28

      no one is risking a 0day for a 110k youtuber

  • @KaiCross-l5i
    @KaiCross-l5i 5 месяцев назад +2

    OH MY GOSH. THE TWO ERRORS HE JUST GOT WHEN HE MADE THE VM WERE THE EXACT 2 THAT I GOT AND SPENT OVER A MONTH TROUBLESHOOTING AND RESEARCHING THINGS. THEN THIS ISN'T EVEN RELATED TO IT AND FIXES BOTH ERRORS IN THE SIMPLEST WAY POSSIBLE!

  • @GTAG_Blurry
    @GTAG_Blurry 5 месяцев назад +3

    Once someone dmed me on Discord, tried to get me to go on a SCAM Roblox website and join their group for “free robux” (they didn’t have any group funds.) And I knew it was a scam, because 1. I was logged out. 2. The Roblox logo was swapped with the charts button.

    • @unnamed_fruit8
      @unnamed_fruit8 4 месяца назад +1

      Free robux in general is already a huge red flag

    • @GTAG_Blurry
      @GTAG_Blurry 4 месяца назад

      @@unnamed_fruit8 nah group funds is real

    • @GTAG_Blurry
      @GTAG_Blurry Месяц назад

      @@unnamed_fruit8but still I agree

  • @guxalu
    @guxalu 3 месяца назад +1

    "Que gameplay incrível do novo EA FC 25, mano! 👏🔥 A forma como você controla o time é impressionante, parece até que o jogo fica mais fácil nas suas mãos! Adorei as jogadas e as finalizações, tá jogando como um profissional! Bora ver mais dessas partidas insanas! 🚀⚽

  • @Volstx
    @Volstx 4 месяца назад +2

    "Kindly" is scammer's favourite word

  • @kopes28
    @kopes28 5 месяцев назад +1

    This is actually something ive thought about over the last like 4 years, when I was getting into streaming and doing YT on another channel I started to wonder how RUclipsrs/streamers/people on social media keep their accounts safe when companies or people email them for promo or to collab, or even just send a link to a YT video that might redirect them if they dont know better to check the link. Some of the people I follow on IG have posted "Email this email videos or a written statement to why you should" and so on, and I thought what if someone just hates that person and sends a fake word document and they just open it on their PC or phone and they just start stealing their shit?

  • @Neitheradentist
    @Neitheradentist 5 месяцев назад +6

    2:50 and also if someone somehow finds the link(VERY SITUACIONAL!!!)

  • @blahblahgdp
    @blahblahgdp 4 месяца назад +1

    the immediate redflag is the sender not having zomato in the email

  • @Ryusakiiii
    @Ryusakiiii 5 месяцев назад +17

    Just realised Zomato doesn't exist in other countries. Basically it's like doordash

  • @joao9042
    @joao9042 5 месяцев назад

    for virtual machines, you should use snapshots instead of clones, it uses way less storage, and you can return to a specific backup when needed.

  • @Violetstarclouds
    @Violetstarclouds 5 месяцев назад +5

    5:04 "STOP READING MY FOLDER NAMES" is literally the funniest thing ive seen-

  • @JesseyEHH
    @JesseyEHH 5 месяцев назад +1

    Last year, i was on my 10 year old laptop, and i was playing minecraft. I was always so into minecraft, however, i was watching a youtuber by the name of ecosoldier and he told me if i went to a site then i could get a specific minecraft mod. When i went to the website, it asked if i was a bot. I said no, and then it installed a virus. But now the conputer has been wiped and i use it to play steam games to this day

  • @m241m
    @m241m 5 месяцев назад +5

    This video basically shows that Windows Defender works great and why it should be on at least sometimes 😁😁

  • @charuseTV
    @charuseTV 3 месяца назад +1

    Google also doesn't scan Zip files if they are too large like 300 MB, they don't need a password

  • @Zeben84
    @Zeben84 5 месяцев назад +14

    Reading the domain of the emails should have been where this video ended !

    • @n0rbert79
      @n0rbert79 5 месяцев назад +2

      Thank you, was on my mind since seeing the first email.

  • @downinohioswaglikeohio123
    @downinohioswaglikeohio123 4 месяца назад +1

    "stop reading my folder names" bro was determined💀

  • @rfr3fr3fr3fr3f
    @rfr3fr3fr3fr3f 5 месяцев назад +9

    7:30 POLAAAANDDDDDD RAAAAAAAAAAAAHHHHHHHHH!!!!

  • @TensaZanota
    @TensaZanota 5 месяцев назад

    even if it was an ad it is the best ad , i already use this application from time to time , but instead of some simulating montage you gived us a big lesson

  • @Nick12_45
    @Nick12_45 5 месяцев назад +17

    14:00 AHH I ALWAYS FALL FOR IT

  • @TylerTheDevourer
    @TylerTheDevourer 5 месяцев назад

    Well done, sir. I would have also had some suspicion regarding this “company” (3.18 USD is hopefully _not_ a stock price you’d want to have) but the way you also handled the rest was truly remarkable. Wishing you luck in your other financial ventures

  • @RealCenti
    @RealCenti 5 месяцев назад +5

    How bro gets sponsored 😭 I never get

    • @SusAmongud
      @SusAmongud 5 месяцев назад +1

      Verified jump scare💀

  • @syntaxzero1677
    @syntaxzero1677 2 месяца назад +1

    Just a note; running viruses on a virtual machine is not always safe. There are viruses designed to detect virtual machines, and break out of them, infecting the actual host machine.

  • @hboyd2003
    @hboyd2003 5 месяцев назад +9

    This looks to be the same thing that got Linus Tech Tips' channel hacked a while back. I can definitely see this working on those less tech savvy (and a virus windows defender has not seen before)

  • @dragonmusic_editedtoperfection
    @dragonmusic_editedtoperfection 3 месяца назад +1

    4:10 there should be a disclaimer that virtual box can protect ur actual pc BUT there are malware that can bypass and get to ur actual pc (not even that hard)
    if somebody just trusted your statment here they would think they are safe and could get theyr pc destoryed

  • @Kitsune_Dev
    @Kitsune_Dev 5 месяцев назад +4

    i would love it for you to review a Framework 16 laptop!

  • @shitpostinggang
    @shitpostinggang 2 месяца назад

    Bro gave us a VM tutorial for a video about addressing a scam, props to you man 🗣

  • @kapecadam280
    @kapecadam280 3 месяца назад +3

    7:38 yooo poland

  • @CLOYO
    @CLOYO 5 месяцев назад +1

    I will never stop reading your folders BOGGGGG

  • @Holloww12
    @Holloww12 5 месяцев назад +13

    7:41 poland mentioned!!!!!!!!

    • @forcemanis
      @forcemanis 4 месяца назад +1

      NETHERLANDS MENTIONED ASWELL!!! :D

    • @forcemanis
      @forcemanis 4 месяца назад

      I just realized it wasn't exactly a good thing... :(

  • @majoramarix
    @majoramarix 5 месяцев назад +1

    You can use sandbox instead of VM its easier to spen and you don't need to delete them, they will be erased after you close it

  • @HaryanviKashmiri
    @HaryanviKashmiri 5 месяцев назад +10

    I am an Indian who has been to your country of Switzerland, Zomato doesn’t even work outside of India, checked while I was in Switzerland and it didn’t work. It’s undoubtedly fake.

  • @sabdullahz
    @sabdullahz 5 месяцев назад +1

    Alternatively, you can also use windows sandbox option for running untrusted files.

  • @PCsAddictionZ
    @PCsAddictionZ 5 месяцев назад +8

    Nice informative video. I didn't know influencers get this much malicious activity in their mailbox. Interesting to see. Just a few notes regarding the video:
    1) As others said, simply running a malware on a VM (although typically safe) it can bypass it or tamper with ur network. Best practice is to do it on a complete "dirty" machine and in isolated VLAN (although there is also vlan hopping as an issue but hard to do)
    2) Checking the URL when clicking a link is also a good practice but not 100% safe as they can use cyrillic or greek alphabet letters which are similar to latin alphabet.
    3) Mail address domains can be spoofed so even if you receive an email from a legit looking domain it probably has a different "Reply To" address (something that cannot be seen with the average email client

    • @itsTyrion
      @itsTyrion 5 месяцев назад

      3) I'd say Thunderbird is pretty average and it shows it

    • @PCsAddictionZ
      @PCsAddictionZ 5 месяцев назад

      @@itsTyrion I mean depends on the type of organisation u are. Most of the ones I know use outlook which it doesn't show without modifications. And outside of professional environments Gmail, yahoo etc are the average clients which also don't show it

  • @mohammedbakr6251
    @mohammedbakr6251 4 месяца назад

    6:06 you can use the snapshots feature, it's a better way to achieve the same result, you can also have many snapshots for different states of your system and switch between them anytime.

  • @Rustydakitty
    @Rustydakitty 5 месяцев назад +4

    "STOP READING MY FOLDER NAMES" lmao

  • @johnanthony6612
    @johnanthony6612 5 месяцев назад +1

    tip incase you didnt know - can use windows sandbox instead of a VM - then just close & restart windows sandbox - would do the same as removing the vm and resetting it up

  • @Artificerhatescavs
    @Artificerhatescavs 3 месяца назад +3

    3:42 fine i guess I'll stop😞