What THIS Fake Minecraft Mod is Really DOING

Поділитися
Вставка
  • Опубліковано 15 вер 2024
  • Recently an imposter mod was promoted in the Create Aeronautics mod server.
    Official Discord Server - / discord
    Reverse Engineering Skool - www.skool.com/...
    Follow me on X - / atericparker
    Real Create Aeronautics: • Create Aeronautics Mul...
    Disclaimer: The content in this video is for education and entertainment purposes to showcase the dangers of malware & malicious software. I do not encourage any form of illegal hacking, nor do I encourage the usage of game cheats, cracks or hacks.
    Cracks are sometimes shown to highlight the dangers of software piracy, my content is not intended to teach anybody how to pirate, or maliciously hack.
    More Malware Investigation Videos:
    → The latest "NORD" Malware - Nordsecured: • The latest 'NORD' Malw...
    →🧧VIRUS WARNING🧧 NEW Optifine for Minecraft 1.16 SCAM: • 🧧VIRUS WARNING🧧 NEW Op...
    → The wilkreate UA-cam stealer virus that started this whole trend: • Fake sponsor DESTROYS ...
    (C) Eric Parker 2024

КОМЕНТАРІ • 190

  • @Lachrymogenic
    @Lachrymogenic 9 днів тому +283

    malware devs cant be bothered to send an infected jar file these days
    like if i was gonna get an mc mod and you gave me an exe file i would look at you like you think im stupid or something

    • @thecakelover4578
      @thecakelover4578 9 днів тому +9

      true

    • @cirkulx
      @cirkulx 8 днів тому +20

      id honestly open it in resource hacker in case the idiot tried to add "haha you got hacked" as a dialog or string

    • @hcbs1986
      @hcbs1986 7 днів тому +1

      Deadass

    • @hcbs1986
      @hcbs1986 7 днів тому

      @@cirkulxtriage is a better way to do dat

  • @texturefounded
    @texturefounded 9 днів тому +324

    I was in the create aeronautic server when this happened
    The part that surprised me the most is that, because create aeronautic is a minecraft mod, it's supposed to be a .jar file, but instead it was a .exe, and the name was also not coherent with the mod, so it really surprised me that people still ran it (yes people did). But, because it's a dev (Reaper) who sent this file, people thought that it was a trustworthy file, which is understandable

    • @imjamf
      @imjamf 9 днів тому +62

      i'm not sure why they'd distribute it as an exe since you can hide malware in legitimate jar mods. but i guess that's too much work considering how lazy this malware seems

    • @min3craftpolska514
      @min3craftpolska514 9 днів тому +17

      My guess is that people ran an .exe because so many (most closed-source) mods/clients come in an .exe installer and people were just used to trusting things like this.

    • @undefinedCat
      @undefinedCat 9 днів тому

      ​@@min3craftpolska514yeah but there's like two mods that do it (optifine and essential). if you're playing 1.14+ you don't need optifine, use sodium. if you *really* need optifine, just download the forge mod version

    • @KSPAtlas
      @KSPAtlas 9 днів тому +7

      lol I remember when I installed the Oculus mod for use with some mod pack and it was broken, I checked curseforge and it appeared to have been hacked (random release name, bad English from a normally fluent writer, etc), seems I was one of the first to notice lmao

    • @commander3494
      @commander3494 9 днів тому

      @@KSPAtlas Oculus got hacked once?? Huh, how have I never heard of that

  • @alejandroalzatesanchez
    @alejandroalzatesanchez 9 днів тому +196

    The malware: "hiiii I wanna check in for a bit, byeeee"

    • @Tsunamicat108
      @Tsunamicat108 3 дні тому

      I’m in danger! *computer explodes*

  • @4crafters597
    @4crafters597 9 днів тому +140

    Trolli is a Brand of Candy and this looks like just the sort of game such a company would create as an ad campaign. Looks like the hackers also stole the game. Weird to go to such lengths, and then not distribute anything resembling a minecraft mod (should be a jar)

    • @Block_Piano
      @Block_Piano 9 днів тому +15

      The best they could have done is combine the malware with the actual jar

    • @commander3494
      @commander3494 9 днів тому +6

      Imagine how many people they could've gotten if they distributed a real mod malware....

    • @Coppertine_
      @Coppertine_ 9 днів тому +5

      Had a play of it and i'm surprised by how good the graphics are for a simple platformer about gummy worms

    • @discussions.
      @discussions. 8 днів тому +2

      @@Coppertine_ yeah if ur bored and have like 20 minutes of free time its alright for free. though the jumping and collision detection kinda suck, wished they could've tweaked/fixed that. and the level design is suprisingly good

  • @maticz3923
    @maticz3923 9 днів тому +68

    Btw that hacker was an absolute idiot! Didnt even realise that it was a minecraft mod. The dude pinged everyone and said its an alpha of "the game" and that "we need testers"
    Also most of those downloads aren't infected people but people that wanted to have a look at the malware.

    • @Slash0mega
      @Slash0mega 8 днів тому +2

      Oh. I seen that before on a server for, i think, the long drive. It was probably a script kiddy attack. (Aka, a pre packaged attack) so it wasn't built for any one server specificly

    • @sixty5notch796
      @sixty5notch796 13 годин тому

      bro couldnt even get a jar malware or call it a mod😭

  • @tomtom987
    @tomtom987 8 днів тому +26

    1:43 trolli is a brand of candy, the game is indeed stolen from that brand.

  • @AyamineMISC
    @AyamineMISC 7 днів тому +10

    "ReLUNCH API" XD It was so hungry it caused an exception.

  • @daniel_8
    @daniel_8 9 днів тому +96

    I don't think many people fell for this, minecraft mods don't look like this. minecraft mods look like a jar file you put in the mods folder which minecraft runs. you can still make malware for a minecraft mod, but I don't think people expecting a jar file got tricked and ran an executable with a bunch of different files for electron.

    • @texturefounded
      @texturefounded 9 днів тому +22

      I agree. But there's people who just like dosen't know, and because create aeronautic is a really anticipated mod, some people possibly just run the file without thinking

    • @priestoffern1608
      @priestoffern1608 9 днів тому +11

      As in any minecraft related discord server, there's a ton of kids. That and having admin privileges on artists and other non savvy people is probably why it was targeted

    • @rubikquitous8482
      @rubikquitous8482 9 днів тому

      800 downloads says otherwise though right?

    • @daniel_8
      @daniel_8 9 днів тому +10

      @@rubikquitous8482 no, I'd guess most people downloaded it, saw the contents and deleted it

    • @jaythecoderx4623
      @jaythecoderx4623 9 днів тому +3

      @@rubikquitous8482 It was over 1200 before it was removed

  • @Master120
    @Master120 9 днів тому +52

    Eric's Parking Minecraft series when?

  • @YourLocalBaconDanceOnTop
    @YourLocalBaconDanceOnTop 9 днів тому +231

    Cat ears at 100k

  • @jaythecoderx4623
    @jaythecoderx4623 9 днів тому +12

    a few over 1000 people downloaded the the "leak"- kinda insane

  • @dvsur
    @dvsur 9 днів тому +12

    2:45 Trolli is a german Candy brand 👀

    • @AttacMage
      @AttacMage 8 днів тому +4

      it's distributed in the US as well

    • @dvsur
      @dvsur 8 днів тому

      @@AttacMage yes, but idk why they use the logo.

    • @AttacMage
      @AttacMage 8 днів тому +3

      @@dvsur someone else said it was an actual game made by Trolli

    • @dvsur
      @dvsur 7 днів тому

      @@AttacMage oh okey didn't know about that

  • @weshuiz1325
    @weshuiz1325 9 днів тому +8

    I love how this "mod" isn't even trying to pretend to be the alpha release of the mod or a mod file at all

  • @dadarkmatterdude
    @dadarkmatterdude 9 днів тому +15

    9.6k subs till Eric would have to put cat ears onto his head.

  • @SquaresToOvals
    @SquaresToOvals 18 годин тому +1

    Aeronautics is the only mod I've ever seen hyped up for an entire year without any release, and with videos showing builds but no actual demonstration of the mod's features; so I assumed the mod itself was some kind of scam. Wild to see this turn of events.

  • @Garlakel
    @Garlakel 9 днів тому +15

    I remember I downloaded this in a rush, but the .zip file was corrupted (?) and I could not unpackage it nor open it.
    Guess I got lucky.

    • @nooo0bb3namewastaken91
      @nooo0bb3namewastaken91 4 дні тому

      If you were gonna run it, that would be insane, also, hi.

    • @KiraSlith
      @KiraSlith День тому

      Windows Defender is getting better at flagging these kinds of things at download. Your AV probably caught it and you didn't notice.

  • @thatgotofinal
    @thatgotofinal 8 днів тому +4

    I would argue that the only good advice to give to someone who got any kind of malware is to make a fresh install of windows. Confirming it didn't touch anything else to to stay for longer is just not possible for vast majority of people and might gave them some false sense of security. So many things it can do... from changing other .exes to even editing your minecraft modpack .jar and good luck noticing that.

    • @undefinedchannel9916
      @undefinedchannel9916 8 днів тому

      Unless you manually check every single exe and dll on your device then you can never be completely sure.

  • @System_._.064
    @System_._.064 8 днів тому +5

    This is the most stupidest fake malware. In minecraft, mods arent installed using .exe's or executables asides from .jar files, and you dont have to open the .jar file to get the mod, you have to place it to %appdata%/minecraft/mods and get an modloader that the mod uses. The only people i see getting affected by this is minecrafts main demographic audience a.k.a kids

  • @taxevader86
    @taxevader86 9 днів тому +11

    i was in this situation and it was crazy my slow internet saved my pc

  • @volcanic_sloth
    @volcanic_sloth 9 днів тому +50

    i love how only 1 out of 5 comments is not about cat ears

  • @Awesomium3
    @Awesomium3 9 днів тому +47

    why the fuck is everybody yapping about cat ears and tails???????

    • @cinderwolf32
      @cinderwolf32 9 днів тому +16

      "regedit for Minecraft" video pinned comment

    • @MikeyTheA
      @MikeyTheA 9 днів тому +3

      100k catears

    • @Iroquois_Pliskin
      @Iroquois_Pliskin 9 днів тому +2

      🐈😺

    • @KSPAtlas
      @KSPAtlas 9 днів тому +5

      Because cat ears at 100k

    • @Plasticshavings
      @Plasticshavings 9 днів тому +3

      A stupid unfunny joke that eric's community came up with because hahhahahaha furry or something

  • @Trimint123
    @Trimint123 6 днів тому +1

    Any logical person would know that you didn't need an .exe file on your mod to work on your Minecraft. It needs an external modloader to load a .jar files like Forge and Fabric to make the mod works.
    The mod itself you showcased on the video are meant to be an addon expansion mod called Create (hence *Create* Aeronautics), so it wouldn't be logical either way if it can load it standalone through an .exe file as the original mod itself need at least Create mod in the modloader.

  • @just-nickel
    @just-nickel 8 днів тому +2

    hacker is freaking out after this guy shows the alt of task manager 💀

  • @Lordseriouspig
    @Lordseriouspig 9 днів тому +2

    3:07 it just wants more lunch

  • @GeraldTM
    @GeraldTM 9 днів тому +1

    Thanks for looking at my suggestion!

  • @xenopanther
    @xenopanther 9 днів тому +2

    I'm wondering how these malware will handle Windows 11 machines where WMIC has been uninstalled

  • @eradication.
    @eradication. 6 днів тому

    It sounds like a kinda similiar scam where you're DMed a "game" someone has been working on except it's stealer malware

  • @victorien3704
    @victorien3704 9 днів тому +1

    Thank god I left that server before. I got warned for posting a cartoon stick spider

  • @Typocat
    @Typocat 8 днів тому +2

    Did you hear about people getting timed out in the discord for pirati- watching WALL-E on the VC using Watch Together? Very silly.

    • @andrupka8749
      @andrupka8749 8 днів тому

      Sounds very much like an aeronautics moderation moment.

    • @Typocat
      @Typocat 6 днів тому

      @@andrupka8749 Yeah, they couldnt even stop the watch together, so people in it was just getting timed out

    • @judaspriestforever153
      @judaspriestforever153 3 дні тому

      Who cares it’s just a movie

  • @navnotav
    @navnotav 9 днів тому +3

    What's up with cat ears?
    I don't know what's it about feels like I'm missing out 😁

    • @_catzee
      @_catzee 9 днів тому +4

      Eric Parker will wear cat ears (I guess) at 100k subscribers.

  • @schrimblo
    @schrimblo 8 днів тому +1

    oh my god create aeronautics mentioned

  • @justcama
    @justcama 9 днів тому +1

    I saw the create aeronautics announcement on their server. Luckily, I didn't download it as I was skeptical 😂

  • @kramsdell_
    @kramsdell_ 8 днів тому +2

    if he gets hacked then i will assume that he forgot to use a vm

  • @Iroquois_Pliskin
    @Iroquois_Pliskin 9 днів тому +4

    the cat ears

  • @user-random-1
    @user-random-1 9 днів тому +5

    There are a lot of comments saying that mods are supposed to be a .jar file. Just wanted to remind, that there are mods that have installer such as essential, optifine, impact and other. So I don’t see nothing wrong with it (but it is still pretty stupid tho 😅)

    • @OtherFarLands
      @OtherFarLands 9 днів тому +7

      All those are mods that I dont trust in the first place, there is really no reason for any of those other then Optifine to have an installer since that can also run standalone without Forge mod loader installed. Optifine is considered legacy/unsupported if you are using it with any other mods. Also Impact is a Hack client with a mod version, which I wouldnt trust either way.

    • @sneak3009
      @sneak3009 9 днів тому +1

      Forge as well. Much like Optifine though the installer is part of the samw jar as the mod(loader). Many probably dont realise they even have installers unless they ran the jar alone accidentally.

    • @Eavontide
      @Eavontide День тому

      essential is selling the data of children, optifine is deprecated at this point, and impact is a cheat client.

    • @SquaresToOvals
      @SquaresToOvals 18 годин тому

      Those mods are scams though.

  • @einze2085
    @einze2085 7 днів тому

    Hey Eric,
    If possible, could you please make a video about basic checkpoints to ensure computer safety on windows 10/11 and Linux? A simple list of things that people can go through and verify whether their PCs or laptops have been infected or not.
    Love your videos, would love to see you talk about network threats too!

  • @Voxelstice
    @Voxelstice 9 днів тому +7

    I honestly actually fell for this, and I only realized something was up when it killed Firefox and discord, I immediately taskkilled it and changed all of my passwords afterwards. it didn't even seem like it sent them to anywhere considering I haven't been hacked nor received anything in my email
    Why did I download this and not realize beforehand? Simply from being excited and slightly careless
    The funny thing is that the uninstaller actually did its job. Couldn't really find these registry keys and the auto run thing anymore

    • @undefinedchannel9916
      @undefinedchannel9916 8 днів тому +1

      Please tell me you reinstalled windows.

    • @Voxelstice
      @Voxelstice 8 днів тому

      @@undefinedchannel9916 too much stuff im not bothered

    • @NaraSherko
      @NaraSherko 8 днів тому +1

      Lil bro needs some ict lessons

    • @Voxelstice
      @Voxelstice 7 днів тому

      @@undefinedchannel9916 no i didn't reinstall it
      there was just too many files on the system i couldn't be bothered

    • @Voxelstice
      @Voxelstice 7 днів тому

      @@NaraSherko what

  • @ApoLk_
    @ApoLk_ 9 днів тому +2

    I dont understanding what youre saying sometimes, i be watching and then you say "This may be the mainframe hyper code web firewall attempt at nuking the server" and then ill be like "yeah i agree that must be it too"

  • @moneyman6227
    @moneyman6227 7 днів тому +1

    Can you explain why the hackers are doing some of the stuff on the computer like checking if it’s a hosted server or what is the electron app and how they are running a website on it

    • @judaspriestforever153
      @judaspriestforever153 3 дні тому

      Electron is a web tool kit for embedded web applications like discord or telegram and it’s basically just chromium embedded framework but even worse performance

    • @judaspriestforever153
      @judaspriestforever153 3 дні тому

      They check for money and cam detection

  • @dttrsp
    @dttrsp 13 годин тому

    man i was loving playing this Trolli game

  • @RegonGaming
    @RegonGaming 9 днів тому +1

    never expected to see that on your channel...
    when i downloaded it the zip file just had an exe and some yml file inside.
    i still have the zip file btw

  • @unblockabl
    @unblockabl 9 днів тому +2

    Very nice analysis! Thank you

  • @Craft2guardian
    @Craft2guardian 7 днів тому

    That’s why I do not trust discord downpoads

  • @Olflix
    @Olflix 9 днів тому +5

    i will be anticipating the cat ears with great interest

  • @juniorwmg
    @juniorwmg 3 дні тому

    Trolli is a sweets brand, popular in Germany. The game is definitely stolen.

  • @manaholic1680
    @manaholic1680 9 днів тому +22

    Can we get cat tail at 500k

  • @darksoocool
    @darksoocool 9 днів тому +2

    only 10 k subs more , eric parker....

  • @2.Plus.2.Equals.5
    @2.Plus.2.Equals.5 7 днів тому

    This is why we can't have nice things.

  • @Gl1tch_Alpha
    @Gl1tch_Alpha 5 днів тому

    I dont even know why and how the people in the discord downloaded an exe file (note: 500+ USERS DOWNLOADED IT)

  • @NoahtheEpicGuy
    @NoahtheEpicGuy 4 дні тому

    I would complain that this is the laziest shit of malware ever, but that's a good thing. I'm still gonna complain though (and then get hacked or whatever in two decades. mark my words).
    No but like, this is so painfully obvious. Ah yes, a textbook case of a Minecraft mod distribution. Classic folder with its own DLLs and exe. I used to use Skydaz to install all my mods, where you would download an EXE file to install the mod... except, y'know, the exe's were standalone and didn't come with any supplementary files. Also, they worked really well. This is just such a lazy attempt at malware that it should be called malwhere? I can't see it! (First of all, horrible pun that doesn't really make sense unless you interpret it sarcastically, but also I hate Chromium-based shit with a passion because, to me (and I know this is a somewhat crazy opinion, don't @ me), it's so overkill and lazy for like 90% of cases. Also when people make software using Chromium and then charge money for changing the _theme_ and all the themes are essentially built-in HTML gradients... that's when you know you're working with the absolute _best_ developers. Sorry, had to rant about that for a second lol.)
    TL;DR malware author dumb dumb. I'm loving all of the comments roasting and shaming on the malware author for being less sharp than a lobotomy patient.

  • @DaylightDev
    @DaylightDev 2 дні тому

    This is so common and usual

  • @notreallyokay9355
    @notreallyokay9355 9 днів тому

    Was wondering about the username, but the SSD confirmed it :)

  • @Boxersteavee
    @Boxersteavee 7 днів тому

    Oh hey you did make a video on it!!!

  • @Soccera0
    @Soccera0 9 днів тому +1

    cat ears for engagement

  • @aether64bit
    @aether64bit 9 днів тому +1

    Cat ears are waiting

  • @Nex_il
    @Nex_il 7 днів тому

    I seen ur new video but it got tooken down for violating yt community guidelines that's so dumb I'm sorry man but I did see the entire video before it got tooken down good video

  • @YuraSuper2048
    @YuraSuper2048 9 днів тому +1

    WE ARE GETTING TO THE CAT EARS 🎉🎉🎉🎉

  • @exzzorpe
    @exzzorpe 9 днів тому +25

    cat ears at 100k

  • @GeneralPurposeVehicl
    @GeneralPurposeVehicl 6 днів тому

    Stealing the product Key? Why? All that does is earn you the ire of everyone else on the planet.

  • @eladelikraybill7904
    @eladelikraybill7904 9 днів тому +1

    great editing super underrated video

  • @anonuser260
    @anonuser260 8 днів тому

    Please do a minecraft lets play

  • @nb94840
    @nb94840 9 днів тому +2

    Who can explain, why is everyone in the comments are talking about cat ears?

    • @texturefounded
      @texturefounded 9 днів тому +1

      In a video (I don't remember which one), erik said that at 100k sub he will put on cat ears (I don't remember if it was a cat hear headphone)

  • @UCRLz82Y52S6eVw
    @UCRLz82Y52S6eVw 9 днів тому +1

    REAL IWAKURA SSD📢📢📢

  • @goongleton
    @goongleton 9 днів тому

    this fake minecraft mod gave me autism. eric to the rescue LFG

  • @cool-username-u9r
    @cool-username-u9r 9 днів тому +6

    stopping the cat ears at 100k haters

  • @cbxgang
    @cbxgang 9 днів тому +5

    dont forget…the cat ears

  • @centdemeern1
    @centdemeern1 5 днів тому

    Isn’t trolli a candy brand?

  • @Gibby27
    @Gibby27 9 днів тому +6

    Hey there, im a anarchy minecraft player. Ratted hacked clients, minecraft exploits and general malicious activity is often a part of the fun of playing on a anarchy server. I was wondering if you would be interested on making a video looking into some common minecraft hacked clients and exploits used in the servers history? if so id like to help!

    • @HuskyMoment
      @HuskyMoment 9 днів тому +4

      felonies are part of the fun of minecraft apparently

    • @Gibby27
      @Gibby27 7 днів тому

      @@HuskyMoment Read more carefully. Its sarcasm, and clearly I mentioned anarchy minecraft. Go learn about 2b2t!

  • @zkh9118
    @zkh9118 8 днів тому

    10:10 What is the name of this software ?

  • @user-nq6wn4hm7s
    @user-nq6wn4hm7s 8 днів тому

    i... am Steve.

  • @axelpixel1
    @axelpixel1 7 днів тому

    Hey, the new video that you just uploaded got taken down, but I have a copy of it.
    Would it be alright if I reupload it? And please tell me what the reason is, so the video also dosen't get taken down.
    Cheers!

    • @prohax1
      @prohax1 7 днів тому

      yo bro can u send me it pls

    • @axelpixel1
      @axelpixel1 7 днів тому

      @@prohax1 on what?

  • @danvasicek4122
    @danvasicek4122 2 дні тому

    cat ears, remember?

  • @MisterBiist6000
    @MisterBiist6000 9 днів тому

    teach us how to find a rat 🔥

  • @piegripalternativeaccount8022
    @piegripalternativeaccount8022 9 днів тому +2

    cat ears, fuck yeah!

  • @TannerGN
    @TannerGN 9 днів тому

    What do you run files like this on?

  • @mehmettaha35
    @mehmettaha35 7 днів тому

    Rip discord grabber

  • @traincrisisthetrain
    @traincrisisthetrain 8 днів тому

    I have a Linux computer.

  • @Mind_BENDERfacts
    @Mind_BENDERfacts 9 днів тому +1

    What’s the real mod download

    • @cathode_mothray
      @cathode_mothray 9 днів тому +4

      Don't think it's out yet

    • @andrupka8749
      @andrupka8749 8 днів тому +1

      It’s not out yet. Valkyrien Skies 2 and Clockwork (an expansion for VS2) do the exact same thing as aeronautics but even better.

  • @Plasticshavings
    @Plasticshavings 9 днів тому

    If I see, one more comment. ONE MORE GODDAMN COMMENT ABOUT THE CAT EARS

  • @user-qbxjwxumr
    @user-qbxjwxumr 9 днів тому +10

    car ears 😼

  • @Xq43
    @Xq43 9 днів тому +4

    10k off cat ears

  • @aq_921
    @aq_921 9 днів тому +6

  • @Nikolas_GQ
    @Nikolas_GQ 9 днів тому

    Interesting…

  • @eaeaeaeaeaeaeaeaeaeae
    @eaeaeaeaeaeaeaeaeaeae 9 днів тому

    ok

  • @Catlover我爱猫
    @Catlover我爱猫 9 днів тому

    cooked

  • @Polokalap
    @Polokalap 12 годин тому

    meow

  • @salazirko
    @salazirko 9 днів тому

    I failed my task, almost every comment is infected with a pure rot

    • @superJK92
      @superJK92 8 днів тому

      You mean Purr rot (🥁 tshh (baa dum tshh)

  • @evangamingrealofficial
    @evangamingrealofficial 9 днів тому

    678th like!!!!!!

  • @applicationrevoked998
    @applicationrevoked998 9 днів тому

    Andrew tate accent, nice video