Learning Malware Analysis with NoEscape Ransomware

Поделиться
HTML-код
  • Опубликовано: 5 ноя 2024

Комментарии • 83

  • @ThatLinuxDude
    @ThatLinuxDude Месяц назад +90

    Criminals really just ripped off Enderman's sample's name huh 💀

  • @austinclements8010
    @austinclements8010 Месяц назад +14

    Lot of good info for a burgeoning IT guy like me! only been in the field for 3 years and i always feel like im just at the doorway
    Ill need to look into Yara though, sounds pretty interesting to me 🤔

  • @Il_panda
    @Il_panda Месяц назад +14

    love your analysis videos

  • @timk8869
    @timk8869 Месяц назад +12

    any info on when the second part from AV testing comes out? would love to see eset and kaspersky which werent talked in the first vid

  • @Il_panda
    @Il_panda Месяц назад +16

    had some fun with some NoEscape but i was not able to find the website

    • @xpower7125
      @xpower7125 Месяц назад

      enderman's noescape or this?

  • @randomcommenterhaha7889
    @randomcommenterhaha7889 Месяц назад +3

    Can you do a video on how kaspersky turned into UltraAV selling all its users overnight

  • @chosenuwu
    @chosenuwu Месяц назад +8

    thank you for the educational videos :3

  • @sammyslepack
    @sammyslepack Месяц назад +2

    can you do a video on ultra av? kaspersky just transferred all of their customers to it and I'm not sure if it's even a fraction as good as Kaspersky. i cant find a single ounce of information about it.

  • @JustARandomGuy-9
    @JustARandomGuy-9 Месяц назад +1

    nice never knew you would test these types of malware

  • @xpower7125
    @xpower7125 Месяц назад +11

    enderman's noescape.exe >>>>>>>>>>>>

  • @WXYRGT
    @WXYRGT Месяц назад +9

    They ripped off the name from enderman

  • @getawaydriver101
    @getawaydriver101 Месяц назад +1

    Malwarebytes detect every time Call of Duty is launched a Sandbox Trojan
    Ip is listed with the domain on malwarebytes. ?

  • @Knards
    @Knards Месяц назад

    Could you run some tests on UltraAV, the app Kaspersky is migrating to?

  • @pierogi-n9u
    @pierogi-n9u Месяц назад +3

    pls do the new ultra av from pago its kacperskys replacment since it got banned

  • @DirtyHairy1
    @DirtyHairy1 Месяц назад +4

    Which Game Installer does NOT open a socket, load libraries, etc?
    so i cant play games any more?

    • @someoneunknown6894
      @someoneunknown6894 Месяц назад +9

      For example an installer that shouldn't connect to the internet
      You probably aren't talking about official games, but small/🏴‍☠️
      For both, why would it connect to the internet, right? Like if it's a small game, why the need for a server to install it?
      And I wouldn't expect 🏴‍☠️ to have online installers either, after all there's no internet at seas 😉
      Hope that helped

    • @klyoark
      @klyoark Месяц назад +2

      None of the things he said 100% indicate malware or malicious acts, but it SHOULD raise some flags especially on newer created files, installers and exes.

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун Месяц назад

      it's ridiculous to try estimate a program by using these flags.
      If you are going to estimate the program by yourself, so to say manually, first you should look into what exactly the program want to get access to. So you need utility like HIPS. Another way is to employ a disposable container or virtual machine, which you would be able to restore to the last saved state. You still should be aware that if you let data leak to the internet then it cannot be undone. And also some advance malware can recognize virtualization and "behave", so take this into account.
      That's why my suggestion is before you start learning programming skills (and which of, actually?) you need to become a capable sysadmin. You need to learn the tools that you can use )
      It's like learning auto engineering before you learn how to drive. Driver = capable user. Good driver = sysadmin. Racer = high tech sysadmin, capable of writing scripts, modifying software, may be even contributing to some open source projects. Step by step )

    • @ТоварищКамрадовСоциалистКоммун
  • @llama2113
    @llama2113 Месяц назад +1

    You should do UltraAV vs 2000 malware since Kaspersky is switching us users to it.

  • @LarksGaming
    @LarksGaming Месяц назад

    Whats the best antivirus to get?

  • @FarmYardGaming
    @FarmYardGaming Месяц назад

    Kaspersky has been doing interesting things recently

  • @CarNage2x
    @CarNage2x Месяц назад +2

    Can you test Kaspersky new US av? UltraAV

    • @juanfigueroa4989
      @juanfigueroa4989 Месяц назад

      I was going to ask the same. It was installed automatically after i tried to update Kaspersky. I want to be sure is good as Kaspersky was. If it scores bad then i will try ESET.

    • @juanfigueroa4989
      @juanfigueroa4989 Месяц назад

      I'm testing in and from the get go is consuming more RAM than what Kaspersky did, in my system at least.

    • @hydradragonantivirus
      @hydradragonantivirus Месяц назад

      it's just proofs ultraAV is shit look eclypsee tech video

  • @megis127
    @megis127 Месяц назад +5

    Please do scare us with technical details

  • @robbob1866
    @robbob1866 Месяц назад

    Hi Leo. I'm getting phishing emails that have my name, address and phone number. Is there any way I can scrub my info from being used? I know there are ways to remove info from legitimate sites but what about illegitimate ones? Thanks for your work!

  • @multiplayforall5591
    @multiplayforall5591 Месяц назад +1

    avast one vs malware pls

  • @GamMngitSssEmoTionaL5953
    @GamMngitSssEmoTionaL5953 Месяц назад

    Great video once again 👏 i would be interesting to see you could implemented this new software Dolus for security and or game developer to catch cheaters
    Dolus is an advanced threat deception platform that simulates an extendable virtual sandbox environment on your PC, tricking sophisticated malware into revealing itself to your antivirus or shutting down.

  • @whygeo
    @whygeo Месяц назад

    Test the kaspersky replacement

  • @salteveline
    @salteveline Месяц назад +2

    how are the data recovery steps ?

  • @barrywang2402
    @barrywang2402 Месяц назад

    pls do compare eset,kaspersky,norton360

  • @ТоварищКамрадовСоциалистКоммун

    in the mean time when windows users learn how to protect against unauthorized encrypts,
    which AV to install and how much it will cost,
    is it worth to update to win11 or stay with win10.
    Linux users updated recently to 24.04.1
    and so far so good

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун Месяц назад

      The suggestion to learn programming is good, but...
      my suggestion is before you start learning programming skills (and which of, actually?) you need to become a capable sysadmin. You need to learn the tools that you are gonna use )
      You learn how to drive before learning auto engineering, right?
      Driver = capable user. Good driver = sysadmin. Racer = high tech sysadmin, capable of writing scripts, modifying software, may be even contributing to some open source projects.
      Step by step )

  • @MattBeckman-lk8jf
    @MattBeckman-lk8jf Месяц назад

    brother I was wondering mac is prone to virus ? you show windows all the time ? what if we have virus in macos how would we remove it ?

  • @peterwassmuth4014
    @peterwassmuth4014 Месяц назад

    Awesome Thank you for Sharing 💯✴

  • @JorgeLopez-qj8pu
    @JorgeLopez-qj8pu Месяц назад +2

    Your Network Infected
    Your Files Encrypted
    Long Have We Waited
    For A Blunder You Committed

  • @JayJay-jy8kz
    @JayJay-jy8kz Месяц назад

    How do I learn malware analysis and cyber security? Anyone of experience has a roadmap for self study?

  • @gabrielandy9272
    @gabrielandy9272 Месяц назад

    windows kernel or OS kernels in general should have way more restrictive permission to file alterations, really all software should run in their own little box and wanting to acess each specific folder would need password/permission

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун Месяц назад

      a good things of windows (no joke) is a free ride style. You want to install some crp on your PC, you can do it. If you want to improve your security, improve it by using it the way how any linux system is meant to be used. Use non admin account for nonadmin tasks, increase UAC protection level, improve your Defender protection settings by adjusting security in programs like DefenderUI.
      IF you still not happy, install some HIPS utility, which is included in many security suits like Kaspersky, Sophos, ESET, Comodo/Xcitium and some other

    • @gabrielandy9272
      @gabrielandy9272 Месяц назад

      @@ТоварищКамрадовСоциалистКоммун but having a basic permission system already included would improve it so much

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун Месяц назад

      @@gabrielandy9272 Basic permission is already included or requires minor tweaks best done with utilities like DefenderUI.
      Advanced control unfortunately not available directly from Windows, and requires some additional software

  • @getawaydriver101
    @getawaydriver101 Месяц назад

    Can you make a video on Windows Defender blank I've gone through registry and it's Microsoft reinstallation Windows reinstallation computer everything runs fine I turned on smartwatch on Windows Defender so now I've been experiencing window UI being blank so I have Malwarebytes on there premium VPN to kind of help the system run it seems to be running fine gets 300 frames in my games 200 what not it's got a 4070 super 14 107 under voltage 300 MHz offset it runs very well it has no issues as far as Hardware I'm just having software problems with Windows Defender

    • @getawaydriver101
      @getawaydriver101 Месяц назад

      I have fixed it by the way 2 days later there was a bios update related to security bug which apparently from what I was doing some research on is one very rare issue but it's fixed now. 👌 😅😅😮😂😂 🎉

  • @getawaydriver101
    @getawaydriver101 Месяц назад

    Do 1 on cod

  • @deansynan7424
    @deansynan7424 Месяц назад

    Well Done

  • @naufalnasrullah6965
    @naufalnasrullah6965 Месяц назад

    your discord link is invalid :(

  • @guilherme5094
    @guilherme5094 Месяц назад

    Thanks!

  • @MrMarbles
    @MrMarbles Месяц назад

    I stay secure bro

  • @wh17efox
    @wh17efox Месяц назад

    i see i new video posted - instant click on it 🙂

  • @iam_best
    @iam_best Месяц назад +1

    NoEscape but boring...

  • @earnwithaix
    @earnwithaix Месяц назад +1

    Hey my laptop keeps opening 8 tabs of whatever browser i use a default this started happening randomly after last night i tried it all to fix it i removed all my extensions reseted crome logged out my email also cleared browsing history for all time this kept happening so i format my pc reinstalled crome it worked fine for 20 mins then it stated happening again i ran a full system scan it said there are no virus i use quick heal antivirus even when i close all the tabs form task manager they open again as soon as i close them and crome tabs keep refreshing and coming back to home screen please help me I can’t find a solution online i tried to use edge but the same thing started happening there pls help or reply to this at this point im desperate for a solution this started happening few days after I installed a crack for IDM and last night i visited few Chinese e-commerce website plz help me

  • @punowtoplaygame1945
    @punowtoplaygame1945 Месяц назад

    Hey PC Security. Can you boot Safe Boot Normal/Classic Base Model/Original on of Windows if you want need something Internet of Safe Boot version of Windows's OS boot. If you are looking for some Anti-Virus (OS Device Of Boot Safe" be fine. Can get Anti-Ransome Computer Free or Paid. On the website forms check stats review of Anti-virus Strong Age Web. By, good or deactivating Ransome Computer

  • @Skul1ybe
    @Skul1ybe Месяц назад

    .

  • @buzzsah
    @buzzsah Месяц назад +1

    I am done with this channel. A lot of BS, no answers. Get to the point. Which is the best all around program? What do you use?

  • @franciscohorna5542
    @franciscohorna5542 Месяц назад

    and norton 360 blockes this also norton 360 delix blockes all ramsomware threats automatically never had ransomware since using since 2010

    • @𤙵
      @𤙵 Месяц назад +6

      norton isnt even good

    • @franciscohorna5542
      @franciscohorna5542 Месяц назад

      @@𤙵 its been good for me been using since 2010 norton 360 delux for up to 5 devices btw it way better than windows defener what are you using there bitdefener thats good also

    • @usertempeuqwer7576
      @usertempeuqwer7576 Месяц назад

      Good job installing spyware on your system !!! Still using Windows ? you suck hard :D

    • @zhonow
      @zhonow Месяц назад +2

      @@franciscohorna5542 norton is not sufficient, thats what he meant by not good i think

    • @franciscohorna5542
      @franciscohorna5542 Месяц назад

      @@zhonow i know well have not had issues with my norton 360 delux here so far no issues only issue is its high on cpu usage when doing full scans thats it nother than that its my seciroty solution im using here and of course i update everything on here thats my number 1 security here not norton 360 delux thats only added protection