Malicious Office Files

Поділитися
Вставка
  • Опубліковано 13 січ 2025

КОМЕНТАРІ • 99

  • @Truttle1
    @Truttle1  8 місяців тому +14

    discord: discord.com/invite/EKPBjjUc65

    • @Cliffordlonghead
      @Cliffordlonghead 8 місяців тому

      First

    • @Cliffordlonghead
      @Cliffordlonghead 8 місяців тому

      Awesome video

    • @literallydoing4425
      @literallydoing4425 8 місяців тому

      Just wondering here, what animation software do you use?
      It seems like it'd be a good fit for me to start working with.

  • @void_vale
    @void_vale 8 місяців тому +135

    I always forget that Windows hides file extensions by default. That's such a terrible idea, I can't fathom how you would ever justify that, let alone come up with it...

    • @IceMetalPunk
      @IceMetalPunk 8 місяців тому +28

      They probably use the Apple excuse of "our customers aren't always technical, this might confuse them".

    • @eternia15
      @eternia15 8 місяців тому +9

      I agree, it has frustrated me for decades at this point. Who would consider this secure.

    • @matthewrease2376
      @matthewrease2376 8 місяців тому +4

      One of Windows' many, many issues.

    • @DigioBooks
      @DigioBooks 6 місяців тому +2

      I have come to spread the good news. Bowser’s Paper Mario mods are back.

  • @matthewrease2376
    @matthewrease2376 8 місяців тому +10

    2:30 this is the most praise Visual Basic has ever gotten or will get 😂😂

  • @cmyk8964
    @cmyk8964 8 місяців тому +40

    Fun fact: Etymologically, “ain’t” comes from “am not”!

    • @cassandradawn780
      @cassandradawn780 8 місяців тому +7

      that is indeed what it meant before the early 19th century, then it started being used as a contraction for "is not", "are not" and others. (just adding onto your comment; etymology is weird)

    • @carsoncoder
      @carsoncoder 8 місяців тому

      Then why don't we use amn't

    • @notwithouttext
      @notwithouttext 7 місяців тому +1

      and "aren't i" also comes from "am not"! "amn't" is hard to say, so it was simplified to "an't". and in the south of england, there was a sound change which lengthened a bunch of a's, like in bath, glass, example. it made "an't" and "aunt" no longer sound like "ant", and more like "ahnt". in that same part of england, r's had been dropped, so "an't" sounded exactly like "aren't", and it had a similar meaning. thus "an't i" became "aren't i", and it spread to american english as well.

    • @algotkristoffersson15
      @algotkristoffersson15 7 місяців тому

      Where does the I come from then?

    • @notwithouttext
      @notwithouttext 7 місяців тому +1

      @@algotkristoffersson15 the "a" sound changes in some accents in some positions before m, n, and g. so can't turns into cain't, but can isn't cain. similarly an't becomes ain't.

  •  8 місяців тому +59

    Obviously the best solution would be to ask for confirmation before changes to the file system, registry, mail sending etc. instead of the annoying and obstructive “You shall not open files from the internet. WE protected your device (because we, MS, control your PC, not you)”.

    • @ETXAlienRobot201
      @ETXAlienRobot201 8 місяців тому +13

      even better would've been not giving macros the level of access they have. if they're for automating certain tasks in documents, who do they need full filesystem access, access to the registry, ability to tweak the settings of word, etc... ?

    • @275hammy
      @275hammy 8 місяців тому

      ​@@ETXAlienRobot201 So people using it for legitimate purposes can do powerful things. Can't think of many good ones, but one could use macros to set up a word document with a letter format that is addressed to the person who sent the most recent email, look at a local database file to populate an Excel spreadsheet, etc.
      Not saying this as my position on the matter, just saying why it was likely made so powerful

    • @leonidas14775
      @leonidas14775 8 місяців тому +1

      They should make macros a feature that the user opts-in to installing. Most people will never use it anyway.

    • @BringMayFlowers
      @BringMayFlowers 8 місяців тому

      @@leonidas14775 As far as I remember (it's been years since I used Microsoft Office), it is, people just install it for either compatibility (unfortunately, in 80% of cases that compatibility is just with malware) or if they think they *might* need it one day just so they don't have to get the CD out again.

    • @u1f98a
      @u1f98a 8 місяців тому +4

      The problem is, users don't read message boxes. The text in a message box or a warning dialogue does not exist to a regular user. Even if you write "DO NOT THIS DO THIS IT IS VERY DESTRUCTIVE" in 72pt flashing text, users *will* ignore it. You cannot make dangerous operations a single dialog box click away because users just want to open this document, and don't care for anything getting in their way.
      If your response to that is "if they click the button to break their PC it's their fault", you don't understand the point. Microsoft does not make software for consumers. Microsoft makes software for businesses that consumers can buy. And, businesses will *never* buy software that lets a careless user send all their company secrets just by clicking a checkbox, no matter how much you hide it.

  • @Vallee152
    @Vallee152 8 місяців тому +21

    I had a job specifically for writing macros in Excel documents
    They used the excel documents as databases

    • @rigen97
      @rigen97 8 місяців тому +2

      happens much too often
      I think it's because excel is easier to learn and easier to print from for "office" people
      honestly it probably beats Access in small business

    • @IceMetalPunk
      @IceMetalPunk 8 місяців тому +3

      At my company, we're currently in the process of setting up our internal databases for the second time (long story). But this time, we're doing it right; because currently, half our information is stored in various and sundry Google Sheets, often populated from Google Forms, and nowhere else 😑 I'm the one who advocated hard to fix that...

    • @Vallee152
      @Vallee152 8 місяців тому +2

      @@rigen97 they do have a proper database that they pay an enterprise subscription to, forget what it's called, but it's missing some features they would like, so they export any active work orders, claims, etc. as CSV's and put them into XLM's

  • @henke37
    @henke37 8 місяців тому +4

    You know the fun part of macros? You can load arbitrary dlls and call functions in them. So even if they didn't include all the destructive features by default, you could just add them to VBA yourself.

  • @thiesenf
    @thiesenf 8 місяців тому +6

    The famous "I Love You" malware was written in WBA...

    • @MrLetsGamePlayHD
      @MrLetsGamePlayHD 8 місяців тому

      It was written in vbs (VBScript) which already comes with windows.

    • @EdKolis
      @EdKolis 7 місяців тому

      Even VBscript is going to be deprecated soon. Wonder what will happen to all the classic ASP web apps?

  • @FinnPlanetballs
    @FinnPlanetballs 8 місяців тому +49

    oh boy! it's august 4th, and i hope my word document hasn't been infected!

    • @Truttle1
      @Truttle1  8 місяців тому +19

      uhm ackshually it’s April 24

  • @womagrid
    @womagrid 8 місяців тому +13

    The animation style seems to imply an inaudible reggae soundtrack.

  • @lonec1777
    @lonec1777 8 місяців тому +2

    The reason variable names in a lot of malware is confusing is because they want it to be difficult to decipher what the malicious code is doing. This is especially true whenever the symbols or code is in someway viewable.

  • @Alex1891
    @Alex1891 8 місяців тому +1

    As one of the comments ever written, I would like to say that I found it cool and cohesive when you made the point of showing file extensions by showing us the project folder for this video!

  • @JimWolfie
    @JimWolfie 8 місяців тому +7

    Bowser has big obfuscation energy. I approve

  • @matthewrease2376
    @matthewrease2376 8 місяців тому +1

    9:28 office also exists online is and free. It's also more accessible for those with disabilities. And it's not Google so there's that.

  • @Bautista_Fam._y_Co.
    @Bautista_Fam._y_Co. 7 місяців тому +1

    6:06 That ain't a virus, i'ts a worm!

  • @u1f98a
    @u1f98a 8 місяців тому +1

    also, microsoft ported the vba editor to macOS because of course they did.
    it looks as out of place as you'd expect

  • @official-obama
    @official-obama 8 місяців тому +9

    as foretold in the prophecy

    • @Truttle1
      @Truttle1  8 місяців тому +4

      zomg official obama???

    • @official-obama
      @official-obama 8 місяців тому +1

      @@Truttle1 yeah
      i need to become president again can you give me your credit card information

    • @Truttle1
      @Truttle1  8 місяців тому +3

      @@official-obama my old number ended in 666 so if you find my lost card in houston that i cancelled three months ago and it ends in 666 it's probably mine.

  • @i_teleported_bread7404
    @i_teleported_bread7404 8 місяців тому +1

    0:06 Is this the first time we actually learn Eidex's full name? I don't recall it being mentioned in any previous videos.

    • @Truttle1
      @Truttle1  8 місяців тому +1

      It was in earlier videos such as the Whenever one (I think) but this was the first time I gave him a middle name.
      Eidex Firben Lagarto is actually a joke name, see if you can find what the joke is :P

  • @the-pink-hacker
    @the-pink-hacker 8 місяців тому +1

    I love the framing device you chose for this video. Great hidden gem!

  • @garbageyoutubechannel310
    @garbageyoutubechannel310 8 місяців тому +5

    why r they moving around so much

  • @kornsuwin
    @kornsuwin 8 місяців тому +2

    adobe ads try not to have the worst compressed music ever challenge

  • @ghasttastic1912
    @ghasttastic1912 8 місяців тому +5

    9:05 hypnospace fan detected.

  • @1leon000
    @1leon000 8 місяців тому +5

    kilroy was here

  • @ArthurKhazbs
    @ArthurKhazbs 6 місяців тому +1

    So it's gonna be August 4th, 2024. Got it.

  • @Golem642
    @Golem642 8 місяців тому +7

    I remember when i was younger i used to make very simple batch viruses that spams terminal consoles
    Nostalgia kicking hard

    • @Truttle1
      @Truttle1  8 місяців тому +9

      When I was in AP CS in high school, I made a Java program that moved the mouse to the Start Menu and shut your PC down. It was really fun sending that to students in the class and not telling them what it did. It was even more fun synchronizing all the PCs in the classroom to shut down by having it start at a specific time and play music as it did so :P

    • @Cliffordlonghead
      @Cliffordlonghead 8 місяців тому

      ​@Thiruttle1

    • @IceMetalPunk
      @IceMetalPunk 8 місяців тому

      In college, I first learned about fork bombs and was like, "that doesn't seem so hard". So I hid a sort of fork bomb in a "game" that added itself to Startup with a flag that would cause the "game" to just keep forking itself exponentially. I released it onto a game dev forum as "a WIP game that I'd like feedback on", from a burner account, and then was amused at my own smugness.
      A few months later, I forgot what it was and opened it on my machine...
      ...fun times when you're a cocky little piece of shit who thinks breaking things is fun, and then karma bites you 😂

    • @rockpie.iso.tar.bz2
      @rockpie.iso.tar.bz2 8 місяців тому

      10 cmd
      20 goto 10

  • @Maker0824
    @Maker0824 8 місяців тому +1

    That’s some idle animations

  • @rigen97
    @rigen97 8 місяців тому

    kinda surprised this didn't touch on popular ransomware

  • @jacobusburger
    @jacobusburger 8 місяців тому

    “Bro wake up, new Truttle1 video dropped!”

  • @angelcaru
    @angelcaru 8 місяців тому +2

    I would know, I started programming on VBA :)

  • @mrdoognoog
    @mrdoognoog 8 місяців тому

    squisherz theme for the outro, that's really cool™️

  • @Areds1X
    @Areds1X 7 місяців тому +1

    i found a programming language ya didnt make a video on it: among us

  • @gydo1942
    @gydo1942 8 місяців тому

    ah yes, office macros. I once used it to gain access to my teacher's computer using a metasploit reverse payload. (with permission!) Good times.

  • @lessefrost
    @lessefrost 6 місяців тому

    I wouldn't say its obsolete to be honest, though VBA has gotten less relevant in the STEM field as Python and other things have taken over it is still around. I still make a living half doing laboratory testing and half writing data analysis programs and I create/distribute VBA for a lot of less heavy data crunching tasks. It's definitely got it's "dinosaur" feel to it though. A lot of stuff that can be better handled in other languages can be absolutely hair pulling to do with VBA but theres still nice wizards out there willing to pass down the skills of the ancients.

  • @enthusiasticgeek7237
    @enthusiasticgeek7237 8 місяців тому +1

    hypnospace music???

  • @matthewrease2376
    @matthewrease2376 8 місяців тому

    Writes simpson joke
    Gets 20 months in prison
    Bruh.

    • @Truttle1
      @Truttle1  8 місяців тому +1

      I think it was the crashing email servers via exponential spam part that got him in prison though

    • @matthewrease2376
      @matthewrease2376 8 місяців тому

      @@Truttle1 just a skill issue, it got them to upgrade their servers 😂😂

  • @Nbrother1234
    @Nbrother1234 8 місяців тому +1

    This is your 2^7th video

  • @nnnArchive
    @nnnArchive 8 місяців тому

    ay how ya doin’? you been feelin’ any different since the redesign? also do you have any plans to bring back cosmos quest?

  • @bahmoudd
    @bahmoudd 8 місяців тому

    You sound alot like Jan Misali

  • @unchaynd7266
    @unchaynd7266 7 місяців тому

    Have you tried using Linux

    • @Truttle1
      @Truttle1  7 місяців тому +1

      I use Linux quite often actually.

  • @Cliffordlonghead
    @Cliffordlonghead 8 місяців тому +1

    Hi

  • @TopchetoEU
    @TopchetoEU 8 місяців тому

    500 vieews in 2 hours??? criminal

  • @randomazzy11
    @randomazzy11 8 місяців тому

    OMG HI TRUTTLE1

    • @Truttle1
      @Truttle1  8 місяців тому +1

      OMG HI RANDOMAZZY11

  • @Stiky_Piston
    @Stiky_Piston 8 місяців тому +1

    YAY! ANOTHER 1eltturT vid!

  • @JoaoCarlos-df1zw
    @JoaoCarlos-df1zw 8 місяців тому +2

    First!

  • @YEWCHENGYINMoe
    @YEWCHENGYINMoe 8 місяців тому +1

    17h ago

  • @moth.monster
    @moth.monster 6 місяців тому +1

    libreoffice tho :) it's free and open source and Google can't delete your documents

  • @cyberpunkspike
    @cyberpunkspike 3 години тому

    google docs sucks, word is far better.