This "Source Code" is malware

Поделиться
HTML-код
  • Опубликовано: 7 янв 2025

Комментарии •

  • @MashtyxAyyy
    @MashtyxAyyy 21 час назад +232

    Can't believe the threat actor tried to viciously paw at you in real time.

  • @LeaoMartelo
    @LeaoMartelo 22 часа назад +104

    About discord webhooks, they have a feature where you can delete them just by having its url, no need for having access to some control over it
    It's meant to help get rid of leaked links, so anyone can delete it if gets leaked, but also helpfull if you find malware with web hook link

    • @mu11668B
      @mu11668B 21 час назад

      Maybe not just delete them. Most of those trash tier malware comes from other open source skidware projects on GitHub. It's easy to generate fake messages in the exact format, and render the data useless on the receivers' end. :)

    • @speeder3235
      @speeder3235 16 часов назад +5

      Unfortunately since it's behind the website proxy, you cannot delete them in this manner. Still, it's nice to know in case you come across a malicious webhook.

  • @PASTRAMIKick
    @PASTRAMIKick 19 часов назад +87

    Holy shit the RAT guy connected!! That's crazy

    • @UrokLizard
      @UrokLizard 13 часов назад +2

      when? timestamp?

    • @Swaqq
      @Swaqq 13 часов назад +1

      @@UrokLizard 7:16

    • @FadkinsDiet
      @FadkinsDiet 12 часов назад +1

      They have a whole team of exploiters on call 24h. I'm surprised they didn't connect sooner.

    • @thatoneglitchpokemon
      @thatoneglitchpokemon 11 часов назад +1

      the trolling lol

  • @joseowl
    @joseowl 20 часов назад +14

    Thank you Eric for showcasing an example of this, since I've never seen it on action. IDEs (Visual Studio in this case) support running code for various reasons (mainly for automation of annoying tasks) at initializing a project, building it, exporting it, etc. This feature can be used for legit purposes, but also to run malware like this "cheat source code" does. Building from source code is not a completely safe process if you don't know *exactly* what you're dealing with.
    Additionally, not only the projects can be used to infect users, but also plugins, libraries and other components of the IDE that can be changed by the user.

  • @veritas7010
    @veritas7010 16 часов назад +7

    Thank you Eric that you channel exists, this is exactly the type of opsec that we need more of on youtube. Simple demos of behaviours in context. Keep it up thank you 👍

  • @MartinWoad
    @MartinWoad 22 часа назад +33

    I love "solution" files and other crap that executes arbitrary code for god knows what reason. The next on the list is npm and its pre and post scripts.

    • @username7763
      @username7763 52 минуты назад

      Sometimes they do important things that make setup easier. The problem is that we've gotten into the habit of trusting random source code from the Internet. In my day, if there was something wrong, you could blame your coworkers.

  • @Vynncent
    @Vynncent 21 час назад +44

    Neat, I didn't know a RAT could invert the mouse click... Now I wonder if my primary desktop got compromised a few years back

    • @Abcd123Alex
      @Abcd123Alex 16 часов назад +17

      U can basically do anything if u have a rat

    • @Joomluh12
      @Joomluh12 13 часов назад +6

      They usually come loaded with Visual Basic "prank" scripts (or code that does the same thing). They can also hide the taskbar, disable right-clicking, flip the desktop, make the CD tray open and close sporadically (if you have one), change the wallpaper, display a fake BSOD, etc. They pretty much give you access akin to being physically in front of the machine.

  • @trevorhart4120
    @trevorhart4120 16 часов назад +9

    .Net 4 is still supported. It literally says supported versions on the download page you clicked. My guess is they want 4.x since it’s the last version that includes the command line compiler (csc.exe) to build the malware on the target.

  • @M3KAI5ER44
    @M3KAI5ER44 17 часов назад +11

    I wonder what it would be like to watch the bad actor mess around with the vm, what key points they would target, things they'll generally do.

  • @toineenzo
    @toineenzo 20 часов назад +13

    “Hello everybody” not fast enough

  • @threeMetreJim
    @threeMetreJim 15 часов назад +4

    If you ever come across their upload area, best to just keep sending random junk to it (made to look like what they are looking for) until it either exceeds their service limit (some free services, which you can also report for abuse) or they get fed up with fake stuff. For tgram bot uploads, it is also possible to delete all of their stolen stuff if you want to (or steal it yourself, to maybe identify and warn the owners of the data).

  • @unitazer
    @unitazer 16 часов назад +1

    Eric is probably one of the best channels to watch when you have to wake up in 4 hours. cool stuff analysis, good software/general advice.

  • @JACKTHEMANTV
    @JACKTHEMANTV 20 часов назад +4

    hey eric! just wanted to let you know that i really value your videos and that i have learnt a lot.

  • @centdemeern1
    @centdemeern1 11 часов назад +2

    I’d love to see what the threat actor does once they connect to the machine, out of morbid curiosity

  • @kidpresident_1475
    @kidpresident_1475 7 часов назад +1

    Crazy how I'm earning a bachelor's in cybersecurity but my University might as well just be a certification Farm atp because I learn everything awesome in the evening from channels like yours.

  • @centdemeern1
    @centdemeern1 11 часов назад +6

    13:04 an “x client” could also refer to a client for the x windowing system, which may be more common

  • @GravityExploitz
    @GravityExploitz 21 час назад +7

    You can delete a discord webhook via api stuff. you dont have to work at discord to do it.

    • @EricParker
      @EricParker  19 часов назад +3

      if we don't know the actual webhook.

    • @GravityExploitz
      @GravityExploitz 5 часов назад

      @ oh fair point. there is always ways to reverse engineer. i dont know how the webhook gets stored for the website baaed stuff through.

  • @markusTegelane
    @markusTegelane 22 часа назад +21

    0:35 the correct option is actually to open with "Visual Studio Version Selector", because if you have multiple versions of Visual Studio, it'll automatically open the it with the version that matches the solution

    • @Lorh_o
      @Lorh_o 19 часов назад +4

      Doesn't really matter considering this is a VM & not some kind of tutorial on using visual studio.

    • @markusTegelane
      @markusTegelane 18 часов назад +3

      @Lorh_o yeah, doesn't really matter in this case, I just wanted to point it out

  • @ParksandRecs-x2w
    @ParksandRecs-x2w 18 часов назад +3

    I find it at least a novel way to get around Data Execution Prevention. I suppose this explains why VSCode implemented trusted workspaces and such.

  • @jtw-r
    @jtw-r 14 часов назад +2

    5:06: wtf was that RAR file …

  • @aligutmann392
    @aligutmann392 17 часов назад +2

    Just want to add the non destructive removal isnt really something anyone should rely on. If you are hit this ahrs there is only one solution. Reinstall. And even then that moght not be enough if it has embedded itself in other places than your OS.

    • @FadkinsDiet
      @FadkinsDiet 12 часов назад

      Not really done other than by state actors.

    • @y_strikes2770
      @y_strikes2770 4 часа назад

      You are misinformed ​@@FadkinsDiet

  • @vodkacsaa
    @vodkacsaa 19 часов назад +3

    5:20 what the hell, i just saw when the video was posted, but i knew about this type of code execution for like half a year, damn Microsoft

  • @scbtripwire
    @scbtripwire 14 часов назад

    Is this about FodyWeaver specifically? I've encountered that before because of another developer but I had removed it at the time, seeing it as unnecessary.

  • @carl.7879
    @carl.7879 13 часов назад

    What distro did you use to film this? (I saw you using KDE Plamsa when configuring the VM)

  • @DoXHoster
    @DoXHoster 20 часов назад +4

    As someone who has coded mod menus and programs programs for cod games i had false positives hits running virustotal on them but this definitely has a virus in it lol

  • @mobilephones-si6mr
    @mobilephones-si6mr 22 часа назад +1

    will you make a video about nl hybired my anti viras say it a virous but they say it is a false posotive

  • @SindromeGames1
    @SindromeGames1 22 часа назад +1

    hey Eric what is the oficial download for process explorer?

    • @jakem5039
      @jakem5039 20 часов назад +2

      microsoft store sysinternals suite

    • @SindromeGames1
      @SindromeGames1 19 часов назад

      @@jakem5039 Thanks!

  • @beyonddark4229
    @beyonddark4229 18 часов назад +2

    can you make video about NL Hybrid please!?

  • @Bahzur
    @Bahzur 15 часов назад

    Wait, am i correct to assume this malware doesnt check anything Firefox related since it only looked at Chrome and Edge?

    • @FadkinsDiet
      @FadkinsDiet 12 часов назад +1

      Not worth it, Firefox has such small market share

    • @Bahzur
      @Bahzur 10 часов назад

      @@FadkinsDiet Meaning im immune to this malware! (not really lol but atleast the session grabber)

    • @prohax3475
      @prohax3475 8 часов назад

      it steals firefox too

  • @balintee
    @balintee 16 часов назад

    Can you see if roblox executor: Solara is a malicious program?

  • @TrizziEhgan
    @TrizziEhgan 23 часа назад +76

    Lesson: Never get cheats for video games

    • @chief-u3f
      @chief-u3f 23 часа назад +31

      Lesson: Download from trusted sources, and check whatever you're installing

    • @TrizziEhgan
      @TrizziEhgan 23 часа назад

      @@chief-u3f That one too

    • @theairaccumulator7144
      @theairaccumulator7144 23 часа назад +2

      Or if you do at least don't be a fool about it

    • @jaskejaske
      @jaskejaske 23 часа назад +19

      Just create them yourself

    • @TrizziEhgan
      @TrizziEhgan 23 часа назад +1

      @@chief-u3f That one too (RUclips deleted my reply :()

  • @kunoxy
    @kunoxy 12 часов назад

    hi eric, could you try to look at some JAR files for minecraft, there is a huge community for skyblock (a game on hypixel) and there is a LOT of ratting happening, like every second mod is a rat. could you maybe try to make a video on how to see if code is malicious or not

    • @kunoxy
      @kunoxy 12 часов назад

      ps i could show some examples which are well known

  • @Theman23135
    @Theman23135 19 часов назад

    Can you check if project nocturno is legit?

  • @les_railgun
    @les_railgun 18 часов назад

    hey, where did you download FRST64, whats the source?

    • @JuiceyDev
      @JuiceyDev 16 часов назад

      can't tell you
      1. that's dangerous, it can infect your pc involuntarily by accidental clicks
      2. bad actors can spread it to cause chaos
      3. thats illegal
      4. google's TOS says otherwise.

  • @pogggs
    @pogggs 20 часов назад +1

    that's crazy someone tried to crash the party lol

  • @tweakingondatza
    @tweakingondatza 13 часов назад +2

    Is this a new exploit?

  • @literally_Orso
    @literally_Orso 17 часов назад

    Why you did this on Windows 10?

  • @em0rdul
    @em0rdul 22 часа назад +4

    Can you make a video about NLHybrid i don’t know if it’s a virus or not

    • @prohax1
      @prohax1 20 часов назад +1

      It's safe i used it and so does my friend who was a old mod

  • @wrathofainz
    @wrathofainz 19 часов назад +2

    MS-HTA vs MS-Heych-TA
    FIGHT!

  • @pueraeternus.
    @pueraeternus. 22 часа назад +3

    lets all love lain

  • @skantekyt
    @skantekyt 20 часов назад +6

    for me xclient sounds like something for X11

  • @jenniferr2033
    @jenniferr2033 17 часов назад +1

    I am not gonna download anything no more

  • @IceburgSlim8481
    @IceburgSlim8481 21 час назад

    Yo E can you do one on pulover's macro creator they say it has malware.

  • @nikvett
    @nikvett 20 часов назад

    This was a very neat video, today I learned.

  • @paws-at-you
    @paws-at-you 23 часа назад +25

    paws at eric

  • @miku10v3
    @miku10v3 23 часа назад +4

    yo i'm on time

    • @KayleighOwO
      @KayleighOwO 21 час назад

      omg miku hi big fan

    • @miku10v3
      @miku10v3 21 час назад +1

      @KayleighOwO your name seems familiar

    • @KayleighOwO
      @KayleighOwO 20 часов назад

      @miku10v3 meow :3

    • @miku10v3
      @miku10v3 20 часов назад

      @@KayleighOwO meow~ :3

  • @kidpresident_1475
    @kidpresident_1475 7 часов назад

    Comment to boost the algorithm, incredible work

  • @hsbbeicysbve
    @hsbbeicysbve 17 часов назад

    yea if that happens to me im just installing windows again

  • @EricParker
    @EricParker  23 часа назад +31

    In semi related news, I just got an email about the GTA:SA leak people are talking about. Apparently it is fake and contains a malicious exe, source: www.heise.de/en/news/Leaked-source-code-of-GTA-San-Andreas-allegedly-contains-ransomware-10228731.html

    • @user-lx2ep9hd4k
      @user-lx2ep9hd4k 20 часов назад +2

      It's fake news. The real one is called gtasasc.7z while this guy shows gtasa.7z
      As for the real zip, nobody knows the password

    • @brendethedev2858
      @brendethedev2858 17 часов назад

      ​@user-lx2ep9hd4k might be crackable by guessing keywords. Tominecon was a old encrypted mineraft related zip file that got cracked last year. Not by breaking the encryption but by automatically trying passwords from leaks and databreaches

  • @AROAH
    @AROAH 16 часов назад +2

    The irony of using Opera while analyzing malware
    Also, inverting the mouse buttons may indicate the RATer being left-handed.

    • @sas408
      @sas408 15 часов назад +1

      no he just spammed every "fun" feature existing in their malware

    • @AROAH
      @AROAH 13 часов назад

      @ Yeah, probably.

  • @giridharpavan1592
    @giridharpavan1592 22 часа назад

    so the antivirus are scam..

  • @ELiasmannen1
    @ELiasmannen1 17 часов назад

    he used xworm on the vm

    • @JuiceyDev
      @JuiceyDev 16 часов назад

      NOO WAYY THATS CRAZY!!!

  • @luckybutunlucky8937
    @luckybutunlucky8937 16 часов назад

    Just don't use cheats off the internet. Make your own.

    • @hereniho
      @hereniho 16 часов назад +1

      Just don't play games that you need cheats to play. Make your own games.

    • @luckybutunlucky8937
      @luckybutunlucky8937 16 часов назад +1

      @@hereniho Don't play on the operating system just make your own.

    • @selectionn
      @selectionn 15 часов назад +3

      just dont use cheats? its really not that hard to NOT ruin the experience for everyone else, yourself included.
      Im glad there is malware in this, cheaters deserve to have to re-install windows and lose all their files.

    • @luckybutunlucky8937
      @luckybutunlucky8937 15 часов назад

      @@selectionn Who ruined your Fortnite experience? People are gonna cheat, might as well be smart enough to make your own.

  • @apathetic_graffiti
    @apathetic_graffiti 18 часов назад +1

    Shit's scary

  • @tatsuyamashita
    @tatsuyamashita 22 часа назад

    hi eric parker

  • @TheOneAndOnlyOuuo
    @TheOneAndOnlyOuuo 16 часов назад +2

    So this is a Microsoft specific exploit? One more reason to not use VS Code.

  • @pueraeternus.
    @pueraeternus. 22 часа назад +7

    I hate microsoft

    • @какойтошизик
      @какойтошизик 21 час назад +7

      We all do, mate. We all do.

    • @kirill9064
      @kirill9064 17 часов назад

      @@какойтошизик What would happen if microsoft suddenly lost all windows source code after Windows 7?

  • @halifoxies2911
    @halifoxies2911 19 часов назад

    thanks eric

  • @GriffinForte
    @GriffinForte 16 часов назад

    ok

  • @alvenzz7609
    @alvenzz7609 23 часа назад

    hii

  • @jamesp1389
    @jamesp1389 4 часа назад

    Why are there so many children here asking you to look at roblox malware 😂

  • @Ha1oMiner
    @Ha1oMiner 17 часов назад

    eric i love you

  • @prohax3475
    @prohax3475 22 часа назад

    wtf

  • @י̈ד
    @י̈ד 23 часа назад

    hi

  • @Nikolas_GQ
    @Nikolas_GQ 23 часа назад

    Hi

  • @notomg9452
    @notomg9452 23 часа назад

    damn

  • @塞kyoto-live塞
    @塞kyoto-live塞 22 часа назад +4

    i know the owner of this

    • @Luna5829
      @Luna5829 22 часа назад +20

      skid alert 🚨

    • @notbillymays
      @notbillymays 22 часа назад +8

      how to get caught making malware: befriend someone like this

  • @TheKodeToad
    @TheKodeToad 23 часа назад

    ericsniped

  • @-kekmacska-48
    @-kekmacska-48 23 часа назад +1

    conclusion: only aquire open-source software from trusted code hosting websites, like github, gitlab, gitea, sourcehut, etc

    • @theairaccumulator7144
      @theairaccumulator7144 23 часа назад +54

      Lol there is so much malware on github he's even made a video about it

    • @xFR34KEEx
      @xFR34KEEx 22 часа назад

      @@mrtz187 I used gitea for our team. highly recommend

    • @Eyevou
      @Eyevou 22 часа назад +2

      git will let anyone post anything.

    • @monkaSisLife
      @monkaSisLife 21 час назад +2

      no, conclusion: don't download project files, build it yourself instead & check the source code before.

    • @-kekmacska-48
      @-kekmacska-48 18 часов назад

      @@monkaSisLife are makefiles safer?

  • @lostsightt
    @lostsightt 23 часа назад

    WAKE UP F1LTHY

  • @phonkeyu4107
    @phonkeyu4107 22 часа назад

    crazy how im friends with the guy who made this xd

    • @therealyojames
      @therealyojames 20 часов назад +2

      💀

    • @selectionn
      @selectionn 15 часов назад +3

      wow thats so cool bro, what a freaking bad ass(sorry for swearing), can i be your friend?
      NO ONE CARES LMAO. You're literally like 10 years old. Be a good little Timmy and dont go around downloading cheats for online games, it ruins the fun for us adults who just want to relax and enjoy an online video game.

    • @pure_leaf7331
      @pure_leaf7331 13 часов назад

      blud youre a snitch

  • @Dacodes
    @Dacodes 5 часов назад

    yo eric, you should chekc out exit lag, ive seen rumours about it being a RAT and i have it and am a little worried

  • @actuallyjest
    @actuallyjest 23 часа назад

    hi

  • @塞kyoto塞
    @塞kyoto塞 22 часа назад

    i know the owner of this

    • @塞kyoto塞
      @塞kyoto塞 22 часа назад

      if u want more info, reponde to this message

    • @塞kyoto塞
      @塞kyoto塞 22 часа назад

      and if u wanna know where its hidden just repond

    • @YaySyu
      @YaySyu 22 часа назад +27

      @@塞kyoto塞 12 year olds thinking they are cool lmao so cringe

    • @pure_leaf7331
      @pure_leaf7331 13 часов назад +1

      sugma