How this RAT is hiding in "Free Software"

Поделиться
HTML-код
  • Опубликовано: 23 ноя 2024

Комментарии • 282

  • @starleaf-luna
    @starleaf-luna 25 дней назад +836

    god, I was so scared this was about the actual 7-Zip

    • @Chowder908
      @Chowder908 24 дня назад +114

      Same I like this guy's content but this felt click baity this is just your basic phishing/scam link

    • @djsweglord9909
      @djsweglord9909 24 дня назад

      @@Chowder908dude clickbaited us hard 😂 f this dude

    • @trenaxy9938
      @trenaxy9938 24 дня назад

      Literally says fake 7zip​@@Chowder908

    • @Rizouge
      @Rizouge 24 дня назад +48

      @@Chowder908 Since they removed the dislike counter to the public, I rely on good folks like you to help me not waste my time. Thanks.

    • @TheBryce98
      @TheBryce98 24 дня назад +43

      Yeah, clickbaiting on cybersec issues is kind of not okay. It creates alarm fatigue.

  • @pcmbreaks
    @pcmbreaks 25 дней назад +391

    God I almost had a heart attack looking at that thumbnail and first 10 seconds of video

    • @andreww8055
      @andreww8055 25 дней назад +23

      his thumbnails are all clickbait like that, the videos themselves are boring

    • @BlyssSarania
      @BlyssSarania 24 дня назад +15

      @@andreww8055 agree thumbnails are clickbait, disagree that videos are boring!

    • @darshan5726
      @darshan5726 24 дня назад

      @@andreww8055 instant downvote

    • @xeon39688
      @xeon39688 24 дня назад +2

      ​@@andreww8055 it's the meta to clickbait I suppose

    • @teamdoodz
      @teamdoodz 24 дня назад

      use dearrow

  • @LucyWoIf
    @LucyWoIf 25 дней назад +217

    Weird sketchy link, .exe download as .msix, windows defender flagging it? How do people fall for this actually... Even without the windows defender thing those are 2 obvious red flags

    • @EricParker
      @EricParker  25 дней назад +106

      msix is the "future" install format for windows.

    • @fizzsoduh
      @fizzsoduh 25 дней назад

      You can search 7-zip and sometimes these fake sites will show up first (as an advertisement). Some people disable defender for "fps gains" in games. Totally possible to fall for it.

    • @xenomorphisisdilage472
      @xenomorphisisdilage472 25 дней назад +8

      @@EricParker Any reason why?

    • @A_T_F_
      @A_T_F_ 25 дней назад

      @@xenomorphisisdilage472 My guess would be Microsoft wants people centralized to Windows Store for marketing and "research"

    • @MissxLariz
      @MissxLariz 25 дней назад

      Dumb people like my dad would fall for this because they literally dont know how to use their brains to think 🥲

  • @HuskyMoment
    @HuskyMoment 25 дней назад +48

    One thing is that for some reason, Igor "doesn't like" the security feature in Windows that marks files as "from the Internet" when you download them and has that feature off by default when you install 7zip. So basically, extracted files from zips are under less scrutiny when they're initially ran because that features off by default. May be worth a peek.

    • @gunt-her
      @gunt-her 7 дней назад +1

      It is unusual, but I also find many security "features" annoying, as in they only seem to get in the way, so I end up turning them off. Usually I don't advise others to turn them off, as I know why they exist for the average user, but there are valid reasons to not like them.

    • @gunt-her
      @gunt-her 7 дней назад +1

      As in it's very likely Igor simply finds this feature annoying to him personally.

  • @Adaminkton
    @Adaminkton 24 дня назад +23

    Congratulations on getting the VFIO gpu passthrough to work Eric!

  • @Mat-e6s
    @Mat-e6s 25 дней назад +101

    Wake up everyone eric uploaded

    • @AngusBro
      @AngusBro 25 дней назад +1

      @@Mat-e6s 🤣

    • @Mystixor
      @Mystixor 25 дней назад +1

      Thanks

    • @seanplaysgames2551
      @seanplaysgames2551 25 дней назад +5

      everyone single time he uploads i cheer in happiness

    • @BurnTheDemon1
      @BurnTheDemon1 25 дней назад +3

      seen this joke abt 50 times already

    • @xpower7125
      @xpower7125 25 дней назад +2

      me when it's 6PM

  • @hanswerner6882
    @hanswerner6882 25 дней назад +43

    imagine a guy opening his rat seeing your desktop LoL

  • @TrizziEhgan
    @TrizziEhgan 25 дней назад +27

    Aaand we keep telling computer newbies to watch out for fake websites...

    • @TheThouZands
      @TheThouZands 23 дня назад

      It is after all one of the main causes for cybercrimes, not having a little scrutiny with the links you go to

  • @unnam3d__
    @unnam3d__ 20 дней назад +3

    i thought you were talking about the ACTUAL 7-zip for a second
    nearly had 90 heart attacks

  • @MilahVR
    @MilahVR 25 дней назад +41

    i have a rat in my walls too

  • @scsa20
    @scsa20 21 день назад +1

    You say that there's no legitimately reason for a remote software should be installed discreetly but in the corporate world we deploy remote software via GPO all the time which uses the silent install options so the remote control software can be deployed without interrupting the end user. So yes there are legitimate reasons for a silent install option for installing remote software, it's just that a lot of malwares are abusing the free ones that's out there.

  • @mounirhafsa6193
    @mounirhafsa6193 25 дней назад +12

    Congrats for the new hardware

  • @Bellicosy
    @Bellicosy 25 дней назад +17

    It's great that you're trying to improve your video production quality, but I'm watching videos either on a tiny phone screen or a set-up that's at least 10 years old, so I will never be able to appreciate your efforts. I also don't know how much text on the screen really benefits from being in 4k. Maybe now you can have some lovely wallpapers! ^^

  • @sighted_
    @sighted_ 25 дней назад +18

    I work with Net Support at work, and it is real software, and I don't know how they managed to get a licence, as you pay per machine, and they also ask questions about your use case when you sign up

    • @Void4
      @Void4 25 дней назад +8

      Could just be a cracked version?

  • @theoshaviolation
    @theoshaviolation 24 дня назад +3

    POV: The Ratter is watching you mutulating his program:

  • @halfsine
    @halfsine 24 дня назад +8

    my jaw dropped and i thought "7ZIP DID WHAT???"

  • @yonice
    @yonice 24 дня назад +6

    That company name is Finnish, oddly enough. Properly formatted too with the Oy and all.

    • @uuberr
      @uuberr 24 дня назад

      Was thinking the same, looked up the company and it did look like a legit tech company.

  • @paws-at-you
    @paws-at-you 25 дней назад +101

    paws at eric

  • @unixtensor
    @unixtensor 25 дней назад +1

    Looking glass B7 is worth trying if you're using B6, B7 is an entirely different program but has its issues with Wayland explicit sync on the host

  • @joesmith1810
    @joesmith1810 19 дней назад

    Net support manager is a legitimate vendor, they support including their remote software as a part of other products, specifically a remote support component. So generally the main product is what is actively installed, and NetSupport is installed as a component of that program, rather than announcing itself.

  • @Babakinha
    @Babakinha 25 дней назад +4

    could you turn up the scale?
    it males wayyy easier to see on mobile or just small monitors ~w~

  • @zeeroeleven
    @zeeroeleven 25 дней назад +2

    interesting how this only got suggested to me after i was suspicious of old files.......

  • @GodDamnitTwitch
    @GodDamnitTwitch 25 дней назад +16

    Ah 7rat I saw this going around and God it makes installing from command line so much better every day

    • @theultimatetrashman887
      @theultimatetrashman887 25 дней назад +7

      Linux users trying to hack the matrix to install 7zip

    • @teethmrks6545
      @teethmrks6545 24 дня назад

      @@theultimatetrashman887sudo pacman -S p7zip unrar

    • @halfsine
      @halfsine 24 дня назад

      @@theultimatetrashman887 me when pacman -S 7-zip

    • @DJAutism1
      @DJAutism1 24 дня назад +2

      @@theultimatetrashman887can I stop seeing you everywhere please

    • @swagnemite-dl3sz
      @swagnemite-dl3sz 24 дня назад

      ​@@theultimatetrashman887Windows can use package managers as well. I use scoop to install 7-zip.

  • @brandonroeder2461
    @brandonroeder2461 24 дня назад +1

    I had a neighbor that couldn't help but to click on just about anything that popped up on his laptop while surfing. Needless to say his setup was constantly infected with something to the point of having to reinstall windows. I did this for him a handful of times. 😂 He never learned. The goofiest infection was a fake blue screen that was instructing him to call or goto some site for assistance. He didn't know he could just alt-tab out of it.

  • @AndrewGaming587YT
    @AndrewGaming587YT 19 дней назад

    Talk about bad notifications, this has been uploaded for about a week and I just got the upload notification literally an hour ago for this

  • @AngusBro
    @AngusBro 25 дней назад +7

    I got no sound, can someone tell me is 7zip a virus cos I'm scared now!

    • @Insomiotic
      @Insomiotic 25 дней назад +7

      From the real site it totally safe

    • @EricParker
      @EricParker  25 дней назад +21

      It's not a virus unless you downloaded from the fake site.

    • @awesomeguysuncle
      @awesomeguysuncle 25 дней назад +28

      @@EricParkerThe downside of clickbait

    • @brandonroeder2461
      @brandonroeder2461 25 дней назад

      ​​​@@awesomeguysuncle I had a neighbor that couldn't help but to click on just about anything that popped up on his laptop while surfing. Needless to say his setup was constantly infected with something to the point of having to reinstall windows. I did this for him a handful of times. 😂 He never learned. The goofiest infection was a fake blue screen that was instructing him to call or goto some site for assistance. He didn't know he could just alt-tab out of it.

    • @YumiizArts
      @YumiizArts 25 дней назад +2

      @@InsomioticI’ve tried and got malicious warnings from the official distribution places. So not sure.. I don’t trust it myself. The 2010 one comes up clean, but the rest aren’t. One of the recent releases was so bad it caused the VM to shut off. So idk

  • @OwO2L
    @OwO2L 24 дня назад

    I would definitely wanna see how you made your setup, it'd be big help to have natively running vm that I can use for old games without using a vm app or such

  • @danielhn93
    @danielhn93 24 дня назад

    Is there any way to set up a live "command and control center" to control a dummy computer and show an example of what the attackers could do? Sort of like Danooct1 with his Blaster worm video involving separate PCs. I'm really curious.

  • @mludiq
    @mludiq 25 дней назад +1

    Why did i thought it was about a guitar pedal 😭😭

  • @Grif_on96
    @Grif_on96 25 дней назад +1

    Yeah , would be cool to see video about how you set up such powerful VM .
    I'm previously tried to set up VirtualBox and VMware , but i always got lost in guides at some point .

  • @bankmanager
    @bankmanager 22 дня назад

    The resolution is beautiful.

  • @em.4800
    @em.4800 24 дня назад +1

    If you had worked in IT you'd understand why we need to install RMM tools discreetely as it needs to be easy to push out with a script for remote support (when migrating from one vendor to another, or if you are pushing out tools through Intune environments, etc,etc...). If it can be done easily with a script it means less disruption as businesses with hundreds to thousands of users and PCs will make it impossible for IT firms to actually push out software in a timely manner.
    You can't trust users to press 3 buttons and they will complain and bitch if it's not an easy or unattended install.
    Yes this tool is being used maliciously, and a lot of legitimate RMM tools are being used maliciously (screenconnect, atera recently). But unfortunately, that is how it is. Criminals will do whatever they can do steal data and make money.

  • @knightmare7975
    @knightmare7975 24 дня назад

    Same thing happened with ghost spectre window iso. 7zip was having unusual background activity. Also there was powershell running all the time. Ghost spectre's windows isos are not safe.

    • @Sypaka
      @Sypaka 24 дня назад +3

      That's the thing. Ghost Spectre (or rather: any other "optimized" windows distro for gamers) disable a TON of security features, including UAC. An admin account permanently runs with admin-privs and access to every (former) protected filepath, file, network, etc. Ofc they can run malicious stuff in the back - aside from the bloat they added, which ruins the whole point of a debloated Windows.

  • @realpain84
    @realpain84 24 дня назад

    Ha! Got samr graphic card... good video. Shows vividly how crucial is proper &running patch management in your enterprise...cheers

  • @Drywest
    @Drywest 24 дня назад

    Could we get a tutorial on that Single PC (Dual Recording Setup) Hardware

  • @Kamerzystanasyt
    @Kamerzystanasyt 25 дней назад +3

    perfect thumbnail

  • @artabon6540
    @artabon6540 16 дней назад

    Thanks man for your efforts, keep up.

  • @savagetheunicorn4555
    @savagetheunicorn4555 24 дня назад

    I was going to ask for a setup video haha

  • @swify08
    @swify08 25 дней назад +1

    This only applies to new installs of 7zip right? Not some type of exploit, I'm safe if I already downloaded it right?

    • @luma6052
      @luma6052 25 дней назад

      it’s not the real 7zip application, it’s fake. if you download the real 7zip (either later or now) you’ll be fine.

    • @zssr
      @zssr 25 дней назад

      This is a fake site dupe made to rat people, it has nothing to do with the official 7zip website.

    • @Bearsgr
      @Bearsgr 25 дней назад +3

      its a fake site, its safe if its from the real one

  • @JPs-q1o
    @JPs-q1o 25 дней назад +2

    Hownis this fake installer getting past SHA256 checks and manifest signature checks?

  • @ZaiTheDragon
    @ZaiTheDragon 19 дней назад

    hey eric, quick question, i'm thinking about becoming a cybersecurity agen/hacker as my profession. how should i go about this?

  • @LibanQi
    @LibanQi 25 дней назад +2

    Keylogger i think

  • @cybernit3
    @cybernit3 24 дня назад

    Thanks for showing that tool Binary Ninja.

  • @chunkychuck
    @chunkychuck 25 дней назад

    Oh "Download 7-Zip for another Windows platforms" is a typo on the real page. (Should be "other" instead of "another", or "platform" instead of "platforms"). I thought the grammar error was a sign of the page being fake 😅

  • @Bzra17
    @Bzra17 25 дней назад +1

    How do i know if i have a banking trojan i downloaded something and someone told me its a banking trojan could you tell me how to know?

    • @zyxwv
      @zyxwv 25 дней назад

      virus scan, what did you download

    • @Bzra17
      @Bzra17 25 дней назад

      @@zyxwv i downloaded a launcher msi and then in that launcher i downloaded a game so you could say msi

    • @Bzra17
      @Bzra17 25 дней назад

      @@zyxwv btw i did a full scan it scanned 3million files it said it had 1 threat which are unwanted apps and onedrive file recovery thats all it had in protection history

    • @Bzra17
      @Bzra17 25 дней назад

      @@zyxwv and also if i reset my whole pc so like everything is gone will the trojan go away?

  • @hksininen
    @hksininen 25 дней назад +1

    What happened to the astoflo client video?

  • @alacai
    @alacai 25 дней назад +2

    Not related but is Resource Hacker also malware?

    • @EricParker
      @EricParker  25 дней назад +7

      Not if you download it from the official site.

  • @_gherry
    @_gherry 24 дня назад

    why does your vm have more storage than my laptop

  • @HazelHerger
    @HazelHerger 24 дня назад

    if you had a pascal main before im sorry to inform you but you could use looking glass vm with single gpu

    • @HazelHerger
      @HazelHerger 24 дня назад

      its called nvidia VGPU you could have heard of vgpu unlocking

    • @Adaminkton
      @Adaminkton 24 дня назад

      @@HazelHerger yes, you can but you will need a special script that will disable your gpu's drivers on the host os. And to return to using it, you will likely need to reboot.

  • @EinGamer22
    @EinGamer22 23 дня назад

    Yikes! This scared me.
    It's scary that this is a thing. Anyone could fall for that. The link of the download website is the only giveaway for an unsuspecting user.

  • @wrathofainz
    @wrathofainz 24 дня назад

    Ok, so Fitgirl is safe until he says something.
    I personally haven't had any issues (I watched my traffic with proxifier when I used windows)

  • @alexsworld7970
    @alexsworld7970 24 дня назад

    LETS GO! We get to watch another masterpiece of art! I am happy :)

  • @BurnTheDemon1
    @BurnTheDemon1 25 дней назад +1

    Bro I love the way you say bye, also I am watching ur subscriber count skyrocket holly..

  • @ggorg0
    @ggorg0 25 дней назад +1

    Please make a video on how to debloat windows 11 and set it up for a VM, removing all the crap that is, of course, not useful at all on a VM! Because the system you have here looks *very* clean!

    • @EricParker
      @EricParker  25 дней назад +3

      I will talk about it in the hone video (I also made one on gaming isos), but my general view is debloating is a waste of time that can introduce security & reliability issues. My VMs use LTSC releases, which contain less bloat than retail ones.

    • @ggorg0
      @ggorg0 25 дней назад +2

      ​@@EricParkerok, cool! thanks

  • @HazelHerger
    @HazelHerger 24 дня назад

    when windows happily eats more memory on the same scale no matter how much memory you have 8gig

    • @ManuFortis
      @ManuFortis 24 дня назад

      I've found through using Windows without Explorer exe running, that alot of that bloat goes away. Makes it kind of easier to find the other offenders at that point in the ram usage department, force them to stop, and then if you really need explorer for any reason, restart it through run command.
      I'll turn it off for some older games, that just seem to not like having it running. If you have any games that don't seem to want to run reliably and crash to desktop often or even blue screen for no apparent reason, give it a try. Just pre-open any applications you want open before ending the process for explorer exe. Then alt tab to cycle through them when needed. Fair heads up though, your volume control goes bye bye with it. So set that stuff in advance too. A bit of a proces I admit, but some of those games I play go from being a 30-60 minute mess of trying to get them to not crash, to running basically flawlessly for hours on end. Some crashes still, but far less by comparison. Dungeon Siege is a good example for this, as is Dragon Age Origins.

  • @yay-r6j
    @yay-r6j 24 дня назад +1

    PCI pass through, just don't run any malware that flashes your video cards firmware with some dodgy code xD

  • @JustARandomGuy-9
    @JustARandomGuy-9 25 дней назад

    nice quality my guy eric finnaly got the stuff

  • @alone-vf4vy
    @alone-vf4vy 19 дней назад

    VFIO GPU Passthrough = Safe to run Malware?

  • @YourBoyCocofelon
    @YourBoyCocofelon 24 дня назад

    1:13 MI6??? Was that a Freudian slip?

  • @leminegaming
    @leminegaming 23 дня назад

    That rat is real software... our school uses it and it has terrible security...

  • @riufq
    @riufq 24 дня назад

    Which vm did you used?
    Virtualbox or WindowsVM?

    • @Adaminkton
      @Adaminkton 24 дня назад +1

      @@riufq he uses KVM with GPU passthrough and looking glass for view.

  • @BeethovenHD
    @BeethovenHD 24 дня назад

    Looking-Glass -|- I see you're a man of culture as well.

  • @Buddy_Pall
    @Buddy_Pall 19 дней назад

    that thumbnail is stupid, thanks for scaring me while i was not home at my pc making me think i use malware almost daily.

  • @Physics-vb6nz
    @Physics-vb6nz 24 дня назад

    jesus i thought you're talking about the real 7zip

  • @oAteur
    @oAteur 24 дня назад

    wait i downloaded this what do i do

  • @Hour_daze
    @Hour_daze 24 дня назад

    thank you Eric Parker we love you ^_^

  • @rakuran
    @rakuran 24 дня назад

    is downloading software from F95zone or Skidrow safe?

  • @no-one3795
    @no-one3795 25 дней назад +3

    Let's all love eric!

  • @goosetip
    @goosetip 25 дней назад

    I wonder if there is a fake winRAR out there

  • @Jeroen-IT
    @Jeroen-IT 24 дня назад

    Great quality!

  • @HyperMango_
    @HyperMango_ 23 дня назад

    That fake site looks legit all but the link address and download file type, if I'm looking at it right. Also Windows 11 can handle 7zip, zip, rar, tar and such by default now, so 7zip is really only useful for passcoded archives unless windows can open those as well. Do like your vids showing how to see what malware does! I think you should do a video maybe on finding malware already on a machine like you did with this but as a tutorial for general use.

  • @quewexold
    @quewexold 25 дней назад

    now i know how rat can work, thank you very much!

  • @xpower7125
    @xpower7125 25 дней назад

    is the VM Windows 11 LTSC?

  • @Dhkan
    @Dhkan 24 дня назад

    Yes yes yes malware analysis ! Thanks !

  • @PalestineHomunculi
    @PalestineHomunculi 24 дня назад

    What do you use for your vms

  • @BobSockTwo
    @BobSockTwo 25 дней назад

    Hello, please upload a video if you launch a virus through PortProton (steam proton outside steam) what can it do to Linux?

  • @definitelyaraven
    @definitelyaraven 25 дней назад

    I'm hoping they were watching what you were doing on that VM because it'd be really funny..

  • @pande9661
    @pande9661 14 дней назад

    can u make a video for the vm setup with gpu integration?

  • @_GhostMiner
    @_GhostMiner 24 дня назад

    1:35 i think you could do that with the sethc exploit

  • @blatantguide
    @blatantguide 24 дня назад

    4:25 Do you really need 64Gb of ram to run a small rat on a VM? My PC has half of it
    Wait it's not even a VM!? 😮

  • @rogercruz1547
    @rogercruz1547 23 дня назад

    Yeah, when you use windows and you use search engines to find a website from which to download your software and you disable protection and you accept everything without reading, there really is a chance you get the wrong software installed. Who knew?!
    If it was a well poisoning attack on the open-source repository by adding a dependency to the software which contains a RAT then the thumbnail would make sense.

  • @mioszjastrzebski8326
    @mioszjastrzebski8326 25 дней назад

    Does Watacac = RAT?

  • @JustARandomGuy-9
    @JustARandomGuy-9 25 дней назад

    also i downloaded kaspersky then downloaded process hacker and it gets detected alot

  • @moeabdo3114
    @moeabdo3114 24 дня назад

    Please Show us how to play games from fit girl and dodi using windows vm , no vids about it

  • @Youriinho
    @Youriinho 24 дня назад +2

    Fit-girl repack 😂

  • @mohamedajkour5510
    @mohamedajkour5510 15 дней назад

    Thank you sir for your videos

  • @doshamiheh9800
    @doshamiheh9800 24 дня назад

    can you please do a VPN called HMA , I think there is a rat on it .

  • @JoiLobo-y3b
    @JoiLobo-y3b 24 дня назад

    Please eric upload a setup video i really need it😊 thanks

  • @4rumani
    @4rumani 24 дня назад +3

    Shame on you for the misleading thumbnail

  • @EastRev
    @EastRev 23 дня назад +1

    Clickbait Thumbnail make me Peed my pant

  • @WolfyRed
    @WolfyRed 24 дня назад +1

    Psudo-Cluckbait

  • @youseffahim4008
    @youseffahim4008 25 дней назад

    can you use windows 10 in the next video?

  • @lelkasa361
    @lelkasa361 24 дня назад +1

    clock bait!

  • @HuzaBird0.2
    @HuzaBird0.2 25 дней назад

    Rat are this capain on fake website?

  • @shiroyasha0024
    @shiroyasha0024 25 дней назад

    i fking love your videos, keep it up

  • @Slav_0282
    @Slav_0282 24 дня назад

    Wtf i was about to uninstall 7-zip

  • @action4free369
    @action4free369 24 дня назад

    It is need for future. Only things from the big brother is ok. Orwell84

  • @furycorp
    @furycorp 24 дня назад +1

    clickbait security scare thumbnail = immediate downvote

  • @arix_zenx
    @arix_zenx 24 дня назад

    can u make video about gameloop

  • @gabriledyt
    @gabriledyt 25 дней назад

    Just use winget