How Legitimate Software is hiding Malware

Поделиться
HTML-код
  • Опубликовано: 4 фев 2025

Комментарии • 157

  • @EricParker
    @EricParker  4 месяца назад +16

    Sponsored by PIA VPN.
    Go to piavpn.com/EricParker to get 83% off Private Internet Access with 4 months free!

    • @lussor1
      @lussor1 4 месяца назад +16

      Dude that vpn is bad for privacy

    • @AnonymousJack
      @AnonymousJack 4 месяца назад

      @@lussor1 i think its legit but not sure tho coz this is the first time i heard the name of this vpn

    • @curious_banda
      @curious_banda 4 месяца назад +10

      Eric aren't you the guy who made video on such VPNs?

    • @BlueIsLeet
      @BlueIsLeet 4 месяца назад +1

      @@lussor1 The quest for the bag makes people ignore these things

    • @lussor1
      @lussor1 4 месяца назад

      @@BlueIsLeet so true, like nord and operagx everywhere

  • @tearwastaken
    @tearwastaken 4 месяца назад +189

    Got me laughing after running the malware not once but twice

  • @SIMULATAN
    @SIMULATAN 4 месяца назад +314

    >Legitimate Software
    >NVIDIA GeForce Experience

    • @soundspark
      @soundspark 4 месяца назад +11

      There is a legitimate version of GFE; this is a fake malware version. Popular software is quite often impersonated.

    • @mare65
      @mare65 4 месяца назад +54

      @@soundspark I'm pretty sure what they mean is that GeForce Experience is bloatware that often gets mistakenly installed during driver installation.

    • @paranoiaproductions1221
      @paranoiaproductions1221 3 месяца назад +4

      ​@@mare65 Shadowplay and instant replay are both exceptionally good pieces of software. If you have no use for neither I guess you could call it bloatware.

    • @Thunderstyle7
      @Thunderstyle7 3 месяца назад

      @@paranoiaproductions1221 OBS can do both better with a bit of setup.

    • @81gamer81
      @81gamer81 3 месяца назад

      @@soundspark scare if/when they outcompete in SEO

  • @literallylegendary
    @literallylegendary 4 месяца назад +70

    I had a dream in which I clicked a RUclips ad and accidentally downloaded malware onto someone else's computer 😭😭

    • @zemzemuch
      @zemzemuch 4 месяца назад +6

      lmaooo i wish it was like that for real

    • @LuizDahoraavida
      @LuizDahoraavida 4 месяца назад +17

      Stop clicking stuff, my computer is going haywire

    • @ApolloRBLX
      @ApolloRBLX 4 месяца назад +8

      bros life cannot be this mundane

    • @IAmGodHimself777
      @IAmGodHimself777 2 месяца назад

      I have some malware nightmares as well

    • @thatonemelody
      @thatonemelody 9 дней назад

      @@IAmGodHimself777lucky. i dreamed of my pc exploding.

  • @feeber848
    @feeber848 4 месяца назад +80

    5:25 you can tell that someone in that group speaks polish

    • @fuwno
      @fuwno 4 месяца назад

      Kurwa!

    • @𤙵
      @𤙵 4 месяца назад

      kurwa

  • @isheamongus811
    @isheamongus811 4 месяца назад +32

    0:40 "This installer requires administrator permisson to run. Press OK to run the installer, or press Cancel to quit" - less sus.

    • @jeffzkiller3590
      @jeffzkiller3590 4 месяца назад +3

      @@isheamongus811 thank you for the ideas

    • @CommandoBlack123
      @CommandoBlack123 4 месяца назад +2

      OK runs it, Cancel runs it quietly

    • @isheamongus811
      @isheamongus811 3 месяца назад

      "RUNTMX2.DLL" is missing. "OK"

  • @russianspoon2367
    @russianspoon2367 4 месяца назад +94

    I would have thought DLL Hijacking would be more prevalent because it's not that hard to do and can give the impression that the app is legitmate. For example, some of those "cheats" videos could replace a DLL the game uses instead of straight away shipping an executable, which, to a non techy person, wouldn't be that suspicious in comparaison to running an .exe file. Not to mention the amount of sites that upload DLLs and how easy it would be for them to just embed malware in that, while still maintaining the illusion of safety to non techy people.

    • @optimumplatinum2640
      @optimumplatinum2640 4 месяца назад +24

      which is why you only use trusted mods from legitimate sources and reputable modders and not shady cheats

    • @mu11668B
      @mu11668B 4 месяца назад +2

      It IS prevalent. It's just not used to attack random kids cause doing so is unnecessary.

    • @leocarvalho8051
      @leocarvalho8051 3 месяца назад +1

      It is widelly used. Steam client dll is the biggest target

  • @KRT2132
    @KRT2132 4 месяца назад +60

    A video on how to properly use VirusTotal would be very beneficial. I'm new to the Security scene and I use it all the time, but I'm not sure how to 'properly' use it!

    • @User-kq3od
      @User-kq3od 4 месяца назад

      Its very simple, GPT could easily guide you through it, you could also very easily google this. You are actively delaying your learning by waiting for people to answer your questions when you could just go find the answers yourself. Eric is not some expert either.

    • @krispyford6558
      @krispyford6558 4 месяца назад +3

      I can answer this question. You need to set your antivirus whatever it may be to scan within files. Usually it's called a deep scan. Also scan for files bigger than 4mb. So for example I'm using Superantispywar. I would turn off ignore files bigger than 4mb. Your scan will take all day but it'll detect. Turn off Ignore non-executable files as you're looking for DLL based viruses. turn off scan only known file types. Turn off Ignore file system information. Hope this helps.

    • @IAmGodHimself777
      @IAmGodHimself777 2 месяца назад

      ⁠@@krispyford6558It only takes me a few hours.

  • @l8wt5
    @l8wt5 4 месяца назад +7

    I know I have commented this before, but it would be interesting to see how Smart App Control in Windows 11 does agains this type of attack. It's supposed to check signatures or reputation for executables and DLLs and in theory it sounds like it could protect against a lot of malware that signatures won't detect. Still haven't seen a single test of it sadly.

  • @Paleox
    @Paleox 4 месяца назад +9

    I can imagine eric accidentally running this on his native machine, and saying “alright, let me run this- FUCK! Oh my fucking god I ran it on my native machine-“

    • @alfonzo7822
      @alfonzo7822 25 дней назад

      Honestly, sounds like an average day for me 😅

  • @cr_cryptic
    @cr_cryptic Месяц назад +1

    10:31, why’s it look like it’s a binary text print but if you squint your eyes a little you can see like a guy sitting at a desk with someone over his shoulder? 🤨
    Not weird at all. 💀

  • @windgods1414
    @windgods1414 4 месяца назад +20

    Drivers from the "usual" sources" ? You mean those fake driver websites, not NVIDIA official website?

    • @gkbrickworks7924
      @gkbrickworks7924 4 месяца назад +4

      Tbh nvidia, whether hiding malware or not, has tons of bloat. I know this due to those stupid game ready drivers - there's no way to completely get rid of old ones once you update it. Unironically, it's easier to do a fresh download of windows than trying to deal with nvidia's shit.

  • @WisxpeeT
    @WisxpeeT 3 месяца назад +4

    The reason why people put passwords is because the antivirus can’t scan it usually this is used to send malware via email.

    • @WisxpeeT
      @WisxpeeT 3 месяца назад +4

      Don’t download free video editing programs if you don’t want 5 RATS on your device.

  • @Neuer_Alias_erstellen
    @Neuer_Alias_erstellen 4 месяца назад +18

    the nvidia installer should compair the sha256 and or size

    • @User-kq3od
      @User-kq3od 4 месяца назад +5

      That takes effort and care for security

    • @Neuer_Alias_erstellen
      @Neuer_Alias_erstellen 4 месяца назад +2

      @@User-kq3od i feel like Nvidia has enoght money lol

  • @bigland-id3sv
    @bigland-id3sv 4 месяца назад

    Thanks to this now I'm more paranoid to even install signed software

  • @lsl7080
    @lsl7080 4 месяца назад +33

    Don't activate windows!! stay strong brother

    • @awesomeguysuncle
      @awesomeguysuncle 4 месяца назад +15

      A certain github

    • @EricParker
      @EricParker  4 месяца назад +38

      these are throwaway vms, no point activating.

    • @soundspark
      @soundspark 4 месяца назад +4

      I actually pried my Windows 11 activation from a dying motherboard. Using a power supply hotwired with a UPS battery I coaxed the board to boot up long enough to make a Microsoft Account and register the license.

    • @seedney
      @seedney 4 месяца назад +2

      @@soundspark You change the motherboard and license is still valid?

    • @CommandoBlack123
      @CommandoBlack123 4 месяца назад +1

      @@seedneyas long as the old motherboard never boots again Microsoft assumes its fine…

  • @KohtaHirano
    @KohtaHirano 4 месяца назад +13

    Just curious, I notice the video is in 1440p and 4K but doesn't look much different than 1080p. Are you upscaling to get YT to apply the VP9 codec by any chance?

    • @morgotts
      @morgotts 4 месяца назад +3

      unrelated I love the dokuro pfp :)

    • @iladshyanchess
      @iladshyanchess 2 месяца назад

      I’ve never seen that being done! Learning stuff everyday

  • @joa-p2m
    @joa-p2m 4 месяца назад +5

    You have a collection of very useful tools.

  • @jeffzkiller3590
    @jeffzkiller3590 4 месяца назад +2

    are you doing these videos with windows defender on or off? thats a pretty big thing to be an oversight for it

  • @no-one3795
    @no-one3795 4 месяца назад +14

    Can't trust anything these days 😓

  • @JJFX-
    @JJFX- 4 месяца назад +1

    I wouldn't call this new but certainly not as common. Nvidia could verify the expected libraries prior to loading them and I'm surprised if they aren't for some of them but at a certain point it just isn't practical. Many don't need updates very often but those that do would need to be accounted for whenever Nvidia updates their software. I do this for some 3rd party libraries packaged with my programs for various reasons.
    That said, in cases like this the installer is already a red flag but that wouldn't always be necessary to use this same technique.

  • @cinderwolf32
    @cinderwolf32 4 месяца назад +9

    I'm gonna guess DLLs!

  • @vladislavkaras491
    @vladislavkaras491 4 месяца назад

    Huh... I did not expect that it could be possible to do so!
    Thanks for the video!

  • @gooniesfan7911
    @gooniesfan7911 4 месяца назад +1

    I could listen to this man speak 24 7 ❤😊

  • @abhaydxgaming
    @abhaydxgaming 4 месяца назад +2

    Nice video dude..
    Btw what would u recommend as the best antivirus for the best overall protection? Is Norton 360 a good option?

    • @jeffzkiller3590
      @jeffzkiller3590 4 месяца назад +3

      lol

    • @peacesyn
      @peacesyn 3 месяца назад

      Common sense and VirtualBox if your skeptical

    • @abdou.the.heretic
      @abdou.the.heretic 3 месяца назад

      Borderline schizo levels of paranoia, and a keen eye.

  • @cup-noodle-love
    @cup-noodle-love 3 месяца назад +1

    A tale old as time.

  • @dariusscovill7970
    @dariusscovill7970 4 месяца назад

    i have a feeling i have a ton of these sitting in my pc to cleanse

  • @DeepfriedChips
    @DeepfriedChips 4 месяца назад +3

    Electron is not CEF
    They are separate projects and Electron does not depend on libcef

    • @gabrielesilinic
      @gabrielesilinic 3 месяца назад

      No it does. Otherwise how the hell would it load a chromium WebView in the first place?
      Search and Read: "Electron Internals: Building Chromium as a Library"

  • @NightfallGemini
    @NightfallGemini 3 месяца назад +2

    5:09 "nonce_proof" ... huh? are they using the term, or is that just a weirdly (hilariously) unfortunate shortening of something?

    • @EricParker
      @EricParker  3 месяца назад +1

      it has a different meaning in cryptography.

  • @JustARandomGuy-9
    @JustARandomGuy-9 4 месяца назад +1

    Can You make a tutorial for the wireguard thing and how to setup a config for it

  • @mateuszabramek7015
    @mateuszabramek7015 4 месяца назад

    "new way"? Nah, it's an old way commonly named ratting software where rat is the malware.

  • @Icythot-m6i
    @Icythot-m6i 4 месяца назад +2

    theres a website i like using for software, and its a community who back engineer paid software and when they upload it they leave in the description what it is and how it works

  • @Omer_Faruk053
    @Omer_Faruk053 Месяц назад

    I probably dont have any malware since I dont download things often but I hope if I did get one from that one time I downloaded a few mods for Minecraft I hope mcafee can find it worst case scenario a hard drive reset

  • @TheDeadman1810
    @TheDeadman1810 4 месяца назад +9

    Which software did he use to capture network traffic?

    • @SmilerRyanYT
      @SmilerRyanYT 4 месяца назад +9

      The proxy he uses is mitmproxy with wireguard on the vm.

    • @BelkinJr
      @BelkinJr 4 месяца назад +1

      @@SmilerRyanYT thank youuuu

  • @the-answer-is-42
    @the-answer-is-42 4 месяца назад +2

    Question: Is this technique as viable on Linux (i.e. use a legit executable but a compromised library) as on Windows?
    Asking because I'm a Linux user and I just realized I don't know how easy it is to use a compromised library on my OS of choice. Guessing it's roughly the same, just don't know.

    • @seedney
      @seedney 4 месяца назад +2

      yes...

    • @RmFrZQ
      @RmFrZQ 3 месяца назад

      Of course. It is even easier on Linux, because ".so" files don't have Digital Signatures.
      Anything accessible to user is available for the attacker.
      But in order to compromise system library (i.e. installed to /lib/ ) and establish persistence at system level, attacker have to get root access first.
      This is why you should never execute some software, you just downloaded from external source, as root.
      This is why you should never blindly trust binary files from external sources. Always analyze build scripts and at least skim through source code, before compiling it and execute it.

    • @the-answer-is-42
      @the-answer-is-42 3 месяца назад

      @@RmFrZQ Ok, thanks. I think us Linux folks should see if we can improve things a bit, then.
      Generally, I'm very careful from where I install things and how. If I see any software installation involving sudo, curl and piping curl into a shell, I just refuse to install it because it just feels like a red flag.

    • @RmFrZQ
      @RmFrZQ 3 месяца назад

      @@the-answer-is-42 Oh, don't get me wrong, there are many solutions and techniques exist already. SELinux and AppArmor help with restricting access to areas where some app should never have. Also there are various isolation techniques ranging from simple, like chroot, to more complex, like containers and VMs.

    • @burgedham
      @burgedham Месяц назад

      ​@@the-answer-is-42 yeah, shady install scripts are a serious threat to the 7 people in the world that use Linux desktop

  • @S1nistre
    @S1nistre 4 месяца назад +3

    What is the of the tool like wirshark 0:58 here

    • @user-uq6eu5rs3o
      @user-uq6eu5rs3o 3 месяца назад +2

      mitmproxy running through wireguard

  • @bartoszkowalski6986
    @bartoszkowalski6986 4 месяца назад

    Nahh I'm so cooked 💀.
    I could easily and maybe already have downloaded legitimate looking software without having any idea it was malicious.
    I would really appreciate inquiring on methods to determine whether the file(s) I'm downloading are malicious.

  • @R4as0n
    @R4as0n 4 месяца назад +2

    Compromised package is not legitimate software

  • @barny541
    @barny541 3 месяца назад

    I don't understand anything that's being said in the video or in the comments. It feels like watching aliens interact, the aliens in question being reddit tech nerds

  • @jc008titan
    @jc008titan 4 месяца назад

    wait, you guys didn't check every single file from an archieve of a pirated game before running it?!?

  • @mohammadiaa
    @mohammadiaa 4 месяца назад +4

    How

  • @coolcatgame
    @coolcatgame 4 месяца назад +1

    shouldn't Electron get a hash of all it's dlls?

    • @LuizDahoraavida
      @LuizDahoraavida 4 месяца назад

      If you're internal you can just hook everything if you care

    • @SaviorTheBurn
      @SaviorTheBurn 4 месяца назад

      Companies don't sign dlls most of the time. It's a huge attack surface.

  • @kodak1587
    @kodak1587 4 месяца назад +6

    Pretty ironic that you use Opera while talking about malware

  • @omarafnan4372
    @omarafnan4372 4 месяца назад

    Can someone ans my question so some times when I am using my pc my cmd would randomly pop up on my screen and them go away I did the scan and there wasn't any malware or anything like that and I did the full scan FYI so anyone can help me out 😊

  • @NNorthern-j7y
    @NNorthern-j7y 4 месяца назад +1

    where is the cat girl costume..?

  • @HuzaBird0.2
    @HuzaBird0.2 4 месяца назад

    How they hook dll on legimated software

  • @CapaciousCore
    @CapaciousCore 2 месяца назад

    One of the domain names sounds very Polish :)

  • @MrKata55
    @MrKata55 3 месяца назад

    5:30 I couldn't help but laugh at the CnC server URL. Are the hackers polish or something?? Well that be concerning but there are bad actors in every nation and ours sure has some technical talents that may go astray...

  • @Den_Ukrainian001
    @Den_Ukrainian001 4 месяца назад +2

    Why😔😔😔

  • @teriotheh
    @teriotheh 4 месяца назад +30

    I remember trolling PIA customer service. Good VPN though, i bought it afterwards.

    • @SparklesFall
      @SparklesFall 4 месяца назад +4

      Why💀💀

    • @teriotheh
      @teriotheh 4 месяца назад

      @@SparklesFall its funnye

    • @slayyyter4686
      @slayyyter4686 4 месяца назад

      Have fun getting all your data logged while using PIA!

    • @teriotheh
      @teriotheh 4 месяца назад

      @@slayyyter4686 it works fine so far, no red flags

  • @Gwiddyy
    @Gwiddyy 4 месяца назад +1

    hey man can we get a virustotal tutorial

  • @PalestineHomunculi
    @PalestineHomunculi 4 месяца назад

    Running untested, viewer submitted code at 150k

  • @unrealircdtutorials
    @unrealircdtutorials 4 месяца назад

    Bro's accent switching between American and English and a tiny bit of posh scots, please help me understand what's going on

  • @BobSockTwo
    @BobSockTwo 4 месяца назад +14

    Pls, use dark mode in your videos!!

  • @hahayes1122
    @hahayes1122 4 месяца назад +9

    hehehe

    • @vas45gdvvas6
      @vas45gdvvas6 4 месяца назад +3

      You look related to this lol

  • @epicstar86
    @epicstar86 4 месяца назад

    peak content

  • @Subtleminecraftplayer
    @Subtleminecraftplayer 4 месяца назад +4

    Opinion on verizon rn?

    • @EricParker
      @EricParker  4 месяца назад +4

      the telco?

    • @undefinedCat
      @undefinedCat 4 месяца назад

      @@EricParker ig yeah

    • @Subtleminecraftplayer
      @Subtleminecraftplayer 4 месяца назад +5

      @@EricParker Yes its down atm

    • @SkylerAk
      @SkylerAk 4 месяца назад

      @@Subtleminecraftplayerhuge outage in Alaska, the whole state was out

  • @twister8946
    @twister8946 4 месяца назад +2

    hi

  • @Tir5d.Turtle
    @Tir5d.Turtle 4 месяца назад +6

    I have GeForce Experience from the Nvidia website am i safe?

    • @mjaypierce9549
      @mjaypierce9549 4 месяца назад +9

      of course

    • @JonnyAppleWeed
      @JonnyAppleWeed 4 месяца назад

      If you have to ask a question like that, you're probably not at all safe, and it's not because of a program.

    • @LuizDahoraavida
      @LuizDahoraavida 4 месяца назад

      Safe and bloated

  • @HafizurRahman-vh7hw
    @HafizurRahman-vh7hw 4 месяца назад +7

    Where is the cat pfp Eric

  • @Umb19
    @Umb19 4 месяца назад

    If anything is free. Genuineley why shouldnt it be malicious

  • @vvorldnewsmedia
    @vvorldnewsmedia 4 месяца назад

    this is so easy and has been seen alog time ago its cute you think this hahaha

  • @hamburger_eatspie
    @hamburger_eatspie 3 месяца назад +1

    dude, activate your windows like bruh🙄

  • @kevinwong_2016
    @kevinwong_2016 4 месяца назад +3

    1st🗿

  • @cool-username-u9r
    @cool-username-u9r 4 месяца назад +4

    maid suit at 200k

    • @JonnyAppleWeed
      @JonnyAppleWeed 4 месяца назад +1

      We don't need to know about your fantasies, thanks.

  • @jiggilowjow
    @jiggilowjow 3 месяца назад

    hold on... you have opera?now i know for sure you dont know what your doing.... wait right next toit is firefox? with the lovely mozilla malware... get better at computing before you make vids... i still cant get rid of the empty mozilla maintenance empty registry from the one time i down loaded firefox....