Learning Malware Analysis with NoEscape Ransomware

Поділитися
Вставка
  • Опубліковано 25 лис 2024

КОМЕНТАРІ • 83

  • @ThatLinuxDude
    @ThatLinuxDude 2 місяці тому +91

    Criminals really just ripped off Enderman's sample's name huh 💀

  • @austinclements8010
    @austinclements8010 2 місяці тому +14

    Lot of good info for a burgeoning IT guy like me! only been in the field for 3 years and i always feel like im just at the doorway
    Ill need to look into Yara though, sounds pretty interesting to me 🤔

  • @Il_panda
    @Il_panda 2 місяці тому +14

    love your analysis videos

  • @timk8869
    @timk8869 2 місяці тому +12

    any info on when the second part from AV testing comes out? would love to see eset and kaspersky which werent talked in the first vid

  • @Il_panda
    @Il_panda 2 місяці тому +16

    had some fun with some NoEscape but i was not able to find the website

    • @xpower7125
      @xpower7125 Місяць тому

      enderman's noescape or this?

  • @randomcommenterhaha7889
    @randomcommenterhaha7889 2 місяці тому +3

    Can you do a video on how kaspersky turned into UltraAV selling all its users overnight

  • @chosenuwu
    @chosenuwu 2 місяці тому +8

    thank you for the educational videos :3

  • @JustARandomGuy-9
    @JustARandomGuy-9 2 місяці тому +1

    nice never knew you would test these types of malware

  • @WXYRGT
    @WXYRGT 2 місяці тому +9

    They ripped off the name from enderman

  • @xpower7125
    @xpower7125 2 місяці тому +11

    enderman's noescape.exe >>>>>>>>>>>>

  • @FarmYardGaming
    @FarmYardGaming 2 місяці тому

    Kaspersky has been doing interesting things recently

  • @llama2113
    @llama2113 2 місяці тому +1

    You should do UltraAV vs 2000 malware since Kaspersky is switching us users to it.

  • @megis127
    @megis127 2 місяці тому +5

    Please do scare us with technical details

  • @GamMngitSssEmoTionaL5953
    @GamMngitSssEmoTionaL5953 2 місяці тому

    Great video once again 👏 i would be interesting to see you could implemented this new software Dolus for security and or game developer to catch cheaters
    Dolus is an advanced threat deception platform that simulates an extendable virtual sandbox environment on your PC, tricking sophisticated malware into revealing itself to your antivirus or shutting down.

  • @JorgeLopez-qj8pu
    @JorgeLopez-qj8pu 2 місяці тому +2

    Your Network Infected
    Your Files Encrypted
    Long Have We Waited
    For A Blunder You Committed

  • @pierogi-n9u
    @pierogi-n9u 2 місяці тому +3

    pls do the new ultra av from pago its kacperskys replacment since it got banned

  • @sammyslepack
    @sammyslepack 2 місяці тому +2

    can you do a video on ultra av? kaspersky just transferred all of their customers to it and I'm not sure if it's even a fraction as good as Kaspersky. i cant find a single ounce of information about it.

  • @getawaydriver101
    @getawaydriver101 2 місяці тому +1

    Malwarebytes detect every time Call of Duty is launched a Sandbox Trojan
    Ip is listed with the domain on malwarebytes. ?

  • @Knards
    @Knards 2 місяці тому

    Could you run some tests on UltraAV, the app Kaspersky is migrating to?

  • @peterwassmuth4014
    @peterwassmuth4014 2 місяці тому

    Awesome Thank you for Sharing 💯✴

  • @DirtyHairy1
    @DirtyHairy1 2 місяці тому +4

    Which Game Installer does NOT open a socket, load libraries, etc?
    so i cant play games any more?

    • @someoneunknown6894
      @someoneunknown6894 2 місяці тому +9

      For example an installer that shouldn't connect to the internet
      You probably aren't talking about official games, but small/🏴‍☠️
      For both, why would it connect to the internet, right? Like if it's a small game, why the need for a server to install it?
      And I wouldn't expect 🏴‍☠️ to have online installers either, after all there's no internet at seas 😉
      Hope that helped

    • @klyoark
      @klyoark 2 місяці тому +2

      None of the things he said 100% indicate malware or malicious acts, but it SHOULD raise some flags especially on newer created files, installers and exes.

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 2 місяці тому

      it's ridiculous to try estimate a program by using these flags.
      If you are going to estimate the program by yourself, so to say manually, first you should look into what exactly the program want to get access to. So you need utility like HIPS. Another way is to employ a disposable container or virtual machine, which you would be able to restore to the last saved state. You still should be aware that if you let data leak to the internet then it cannot be undone. And also some advance malware can recognize virtualization and "behave", so take this into account.
      That's why my suggestion is before you start learning programming skills (and which of, actually?) you need to become a capable sysadmin. You need to learn the tools that you can use )
      It's like learning auto engineering before you learn how to drive. Driver = capable user. Good driver = sysadmin. Racer = high tech sysadmin, capable of writing scripts, modifying software, may be even contributing to some open source projects. Step by step )

    • @ТоварищКамрадовСоциалистКоммун
  • @whygeo
    @whygeo 2 місяці тому

    Test the kaspersky replacement

  • @multiplayforall5591
    @multiplayforall5591 2 місяці тому +1

    avast one vs malware pls

  • @barrywang2402
    @barrywang2402 2 місяці тому

    pls do compare eset,kaspersky,norton360

  • @gabrielandy9272
    @gabrielandy9272 2 місяці тому

    windows kernel or OS kernels in general should have way more restrictive permission to file alterations, really all software should run in their own little box and wanting to acess each specific folder would need password/permission

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 2 місяці тому

      a good things of windows (no joke) is a free ride style. You want to install some crp on your PC, you can do it. If you want to improve your security, improve it by using it the way how any linux system is meant to be used. Use non admin account for nonadmin tasks, increase UAC protection level, improve your Defender protection settings by adjusting security in programs like DefenderUI.
      IF you still not happy, install some HIPS utility, which is included in many security suits like Kaspersky, Sophos, ESET, Comodo/Xcitium and some other

    • @gabrielandy9272
      @gabrielandy9272 2 місяці тому

      @@ТоварищКамрадовСоциалистКоммун but having a basic permission system already included would improve it so much

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 2 місяці тому

      @@gabrielandy9272 Basic permission is already included or requires minor tweaks best done with utilities like DefenderUI.
      Advanced control unfortunately not available directly from Windows, and requires some additional software

  • @CarNage2x
    @CarNage2x 2 місяці тому +2

    Can you test Kaspersky new US av? UltraAV

    • @juanfigueroa4989
      @juanfigueroa4989 2 місяці тому

      I was going to ask the same. It was installed automatically after i tried to update Kaspersky. I want to be sure is good as Kaspersky was. If it scores bad then i will try ESET.

    • @juanfigueroa4989
      @juanfigueroa4989 2 місяці тому

      I'm testing in and from the get go is consuming more RAM than what Kaspersky did, in my system at least.

    • @hydradragonantivirus
      @hydradragonantivirus 2 місяці тому

      it's just proofs ultraAV is shit look eclypsee tech video

  • @salteveline
    @salteveline 2 місяці тому +2

    how are the data recovery steps ?

  • @guilherme5094
    @guilherme5094 2 місяці тому

    Thanks!

  • @robbob1866
    @robbob1866 Місяць тому

    Hi Leo. I'm getting phishing emails that have my name, address and phone number. Is there any way I can scrub my info from being used? I know there are ways to remove info from legitimate sites but what about illegitimate ones? Thanks for your work!

  • @LarksGaming
    @LarksGaming Місяць тому

    Whats the best antivirus to get?

  • @deansynan7424
    @deansynan7424 2 місяці тому

    Well Done

  • @ТоварищКамрадовСоциалистКоммун

    in the mean time when windows users learn how to protect against unauthorized encrypts,
    which AV to install and how much it will cost,
    is it worth to update to win11 or stay with win10.
    Linux users updated recently to 24.04.1
    and so far so good

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 2 місяці тому

      The suggestion to learn programming is good, but...
      my suggestion is before you start learning programming skills (and which of, actually?) you need to become a capable sysadmin. You need to learn the tools that you are gonna use )
      You learn how to drive before learning auto engineering, right?
      Driver = capable user. Good driver = sysadmin. Racer = high tech sysadmin, capable of writing scripts, modifying software, may be even contributing to some open source projects.
      Step by step )

  • @MattBeckman-lk8jf
    @MattBeckman-lk8jf 2 місяці тому

    brother I was wondering mac is prone to virus ? you show windows all the time ? what if we have virus in macos how would we remove it ?

  • @naufalnasrullah6965
    @naufalnasrullah6965 2 місяці тому

    your discord link is invalid :(

  • @getawaydriver101
    @getawaydriver101 2 місяці тому

    Do 1 on cod

  • @JayJay-jy8kz
    @JayJay-jy8kz 2 місяці тому

    How do I learn malware analysis and cyber security? Anyone of experience has a roadmap for self study?

  • @getawaydriver101
    @getawaydriver101 2 місяці тому

    Can you make a video on Windows Defender blank I've gone through registry and it's Microsoft reinstallation Windows reinstallation computer everything runs fine I turned on smartwatch on Windows Defender so now I've been experiencing window UI being blank so I have Malwarebytes on there premium VPN to kind of help the system run it seems to be running fine gets 300 frames in my games 200 what not it's got a 4070 super 14 107 under voltage 300 MHz offset it runs very well it has no issues as far as Hardware I'm just having software problems with Windows Defender

    • @getawaydriver101
      @getawaydriver101 2 місяці тому

      I have fixed it by the way 2 days later there was a bios update related to security bug which apparently from what I was doing some research on is one very rare issue but it's fixed now. 👌 😅😅😮😂😂 🎉

  • @MrMarbles
    @MrMarbles 2 місяці тому

    I stay secure bro

  • @earnwithaix
    @earnwithaix 2 місяці тому +1

    Hey my laptop keeps opening 8 tabs of whatever browser i use a default this started happening randomly after last night i tried it all to fix it i removed all my extensions reseted crome logged out my email also cleared browsing history for all time this kept happening so i format my pc reinstalled crome it worked fine for 20 mins then it stated happening again i ran a full system scan it said there are no virus i use quick heal antivirus even when i close all the tabs form task manager they open again as soon as i close them and crome tabs keep refreshing and coming back to home screen please help me I can’t find a solution online i tried to use edge but the same thing started happening there pls help or reply to this at this point im desperate for a solution this started happening few days after I installed a crack for IDM and last night i visited few Chinese e-commerce website plz help me

  • @wh17efox
    @wh17efox 2 місяці тому

    i see i new video posted - instant click on it 🙂

  • @iam_best
    @iam_best 2 місяці тому +1

    NoEscape but boring...

  • @punowtoplaygame1945
    @punowtoplaygame1945 2 місяці тому

    Hey PC Security. Can you boot Safe Boot Normal/Classic Base Model/Original on of Windows if you want need something Internet of Safe Boot version of Windows's OS boot. If you are looking for some Anti-Virus (OS Device Of Boot Safe" be fine. Can get Anti-Ransome Computer Free or Paid. On the website forms check stats review of Anti-virus Strong Age Web. By, good or deactivating Ransome Computer

  • @Skul1ybe
    @Skul1ybe 2 місяці тому

    .

  • @buzzsah
    @buzzsah 2 місяці тому +1

    I am done with this channel. A lot of BS, no answers. Get to the point. Which is the best all around program? What do you use?

  • @franciscohorna5542
    @franciscohorna5542 2 місяці тому

    and norton 360 blockes this also norton 360 delix blockes all ramsomware threats automatically never had ransomware since using since 2010

    • @𤙵
      @𤙵 2 місяці тому +6

      norton isnt even good

    • @franciscohorna5542
      @franciscohorna5542 2 місяці тому

      @@𤙵 its been good for me been using since 2010 norton 360 delux for up to 5 devices btw it way better than windows defener what are you using there bitdefener thats good also

    • @usertempeuqwer7576
      @usertempeuqwer7576 2 місяці тому

      Good job installing spyware on your system !!! Still using Windows ? you suck hard :D

    • @zhonow
      @zhonow 2 місяці тому +2

      @@franciscohorna5542 norton is not sufficient, thats what he meant by not good i think

    • @franciscohorna5542
      @franciscohorna5542 2 місяці тому

      @@zhonow i know well have not had issues with my norton 360 delux here so far no issues only issue is its high on cpu usage when doing full scans thats it nother than that its my seciroty solution im using here and of course i update everything on here thats my number 1 security here not norton 360 delux thats only added protection