How Legitimate Software is hiding Malware

Поділитися
Вставка
  • Опубліковано 16 січ 2025

КОМЕНТАРІ • 158

  • @EricParker
    @EricParker  3 місяці тому +16

    Sponsored by PIA VPN.
    Go to piavpn.com/EricParker to get 83% off Private Internet Access with 4 months free!

    • @lussor1
      @lussor1 3 місяці тому +14

      Dude that vpn is bad for privacy

    • @AnonymousJack
      @AnonymousJack 3 місяці тому

      @@lussor1 i think its legit but not sure tho coz this is the first time i heard the name of this vpn

    • @curious_banda
      @curious_banda 3 місяці тому +8

      Eric aren't you the guy who made video on such VPNs?

    • @BlueIsLeet
      @BlueIsLeet 3 місяці тому

      @@lussor1 The quest for the bag makes people ignore these things

    • @lussor1
      @lussor1 3 місяці тому

      @@BlueIsLeet so true, like nord and operagx everywhere

  • @tearwastaken
    @tearwastaken 3 місяці тому +189

    Got me laughing after running the malware not once but twice

  • @SIMULATAN
    @SIMULATAN 3 місяці тому +312

    >Legitimate Software
    >NVIDIA GeForce Experience

    • @soundspark
      @soundspark 3 місяці тому +11

      There is a legitimate version of GFE; this is a fake malware version. Popular software is quite often impersonated.

    • @mare65
      @mare65 3 місяці тому +54

      @@soundspark I'm pretty sure what they mean is that GeForce Experience is bloatware that often gets mistakenly installed during driver installation.

    • @paranoiaproductions1221
      @paranoiaproductions1221 3 місяці тому +4

      ​@@mare65 Shadowplay and instant replay are both exceptionally good pieces of software. If you have no use for neither I guess you could call it bloatware.

    • @Thunderstyle7
      @Thunderstyle7 3 місяці тому

      @@paranoiaproductions1221 OBS can do both better with a bit of setup.

    • @81gamer81
      @81gamer81 3 місяці тому

      @@soundspark scare if/when they outcompete in SEO

  • @literallylegendary
    @literallylegendary 3 місяці тому +69

    I had a dream in which I clicked a UA-cam ad and accidentally downloaded malware onto someone else's computer 😭😭

    • @zemzemuch
      @zemzemuch 3 місяці тому +6

      lmaooo i wish it was like that for real

    • @LuizDahoraavida
      @LuizDahoraavida 3 місяці тому +16

      Stop clicking stuff, my computer is going haywire

    • @ApolloRBLX
      @ApolloRBLX 3 місяці тому +7

      bros life cannot be this mundane

    • @IAmGodHimself777
      @IAmGodHimself777 Місяць тому

      I have some malware nightmares as well

  • @feeber848
    @feeber848 3 місяці тому +80

    5:25 you can tell that someone in that group speaks polish

    • @fuwno
      @fuwno 3 місяці тому

      Kurwa!

    • @𤙵
      @𤙵 3 місяці тому

      kurwa

  • @isheamongus811
    @isheamongus811 3 місяці тому +32

    0:40 "This installer requires administrator permisson to run. Press OK to run the installer, or press Cancel to quit" - less sus.

  • @russianspoon2367
    @russianspoon2367 3 місяці тому +94

    I would have thought DLL Hijacking would be more prevalent because it's not that hard to do and can give the impression that the app is legitmate. For example, some of those "cheats" videos could replace a DLL the game uses instead of straight away shipping an executable, which, to a non techy person, wouldn't be that suspicious in comparaison to running an .exe file. Not to mention the amount of sites that upload DLLs and how easy it would be for them to just embed malware in that, while still maintaining the illusion of safety to non techy people.

    • @optimumplatinum2640
      @optimumplatinum2640 3 місяці тому +24

      which is why you only use trusted mods from legitimate sources and reputable modders and not shady cheats

    • @mu11668B
      @mu11668B 3 місяці тому +2

      It IS prevalent. It's just not used to attack random kids cause doing so is unnecessary.

    • @leocarvalho8051
      @leocarvalho8051 3 місяці тому +1

      It is widelly used. Steam client dll is the biggest target

  • @Paleox
    @Paleox 3 місяці тому +9

    I can imagine eric accidentally running this on his native machine, and saying “alright, let me run this- FUCK! Oh my fucking god I ran it on my native machine-“

    • @alfonzo7822
      @alfonzo7822 6 днів тому

      Honestly, sounds like an average day for me 😅

  • @KRT2132
    @KRT2132 3 місяці тому +58

    A video on how to properly use VirusTotal would be very beneficial. I'm new to the Security scene and I use it all the time, but I'm not sure how to 'properly' use it!

    • @User-kq3od
      @User-kq3od 3 місяці тому

      Its very simple, GPT could easily guide you through it, you could also very easily google this. You are actively delaying your learning by waiting for people to answer your questions when you could just go find the answers yourself. Eric is not some expert either.

    • @krispyford6558
      @krispyford6558 3 місяці тому +3

      I can answer this question. You need to set your antivirus whatever it may be to scan within files. Usually it's called a deep scan. Also scan for files bigger than 4mb. So for example I'm using Superantispywar. I would turn off ignore files bigger than 4mb. Your scan will take all day but it'll detect. Turn off Ignore non-executable files as you're looking for DLL based viruses. turn off scan only known file types. Turn off Ignore file system information. Hope this helps.

    • @IAmGodHimself777
      @IAmGodHimself777 Місяць тому

      ⁠@@krispyford6558It only takes me a few hours.

  • @l8wt5
    @l8wt5 3 місяці тому +7

    I know I have commented this before, but it would be interesting to see how Smart App Control in Windows 11 does agains this type of attack. It's supposed to check signatures or reputation for executables and DLLs and in theory it sounds like it could protect against a lot of malware that signatures won't detect. Still haven't seen a single test of it sadly.

  • @windgods1414
    @windgods1414 3 місяці тому +20

    Drivers from the "usual" sources" ? You mean those fake driver websites, not NVIDIA official website?

    • @gkbrickworks7924
      @gkbrickworks7924 3 місяці тому +4

      Tbh nvidia, whether hiding malware or not, has tons of bloat. I know this due to those stupid game ready drivers - there's no way to completely get rid of old ones once you update it. Unironically, it's easier to do a fresh download of windows than trying to deal with nvidia's shit.

  • @WisxpeeT
    @WisxpeeT 3 місяці тому +4

    The reason why people put passwords is because the antivirus can’t scan it usually this is used to send malware via email.

    • @WisxpeeT
      @WisxpeeT 3 місяці тому +4

      Don’t download free video editing programs if you don’t want 5 RATS on your device.

  • @lsl7080
    @lsl7080 3 місяці тому +33

    Don't activate windows!! stay strong brother

    • @awesomeguysuncle
      @awesomeguysuncle 3 місяці тому +15

      A certain github

    • @EricParker
      @EricParker  3 місяці тому +38

      these are throwaway vms, no point activating.

    • @soundspark
      @soundspark 3 місяці тому +4

      I actually pried my Windows 11 activation from a dying motherboard. Using a power supply hotwired with a UPS battery I coaxed the board to boot up long enough to make a Microsoft Account and register the license.

    • @seedney
      @seedney 3 місяці тому +2

      @@soundspark You change the motherboard and license is still valid?

    • @CommandoBlack123
      @CommandoBlack123 3 місяці тому +1

      @@seedneyas long as the old motherboard never boots again Microsoft assumes its fine…

  • @no-one3795
    @no-one3795 3 місяці тому +14

    Can't trust anything these days 😓

  • @KohtaHirano
    @KohtaHirano 3 місяці тому +13

    Just curious, I notice the video is in 1440p and 4K but doesn't look much different than 1080p. Are you upscaling to get YT to apply the VP9 codec by any chance?

    • @morgotts
      @morgotts 3 місяці тому +3

      unrelated I love the dokuro pfp :)

    • @iladshyanchess
      @iladshyanchess 2 місяці тому

      I’ve never seen that being done! Learning stuff everyday

  • @Neuer_Alias_erstellen
    @Neuer_Alias_erstellen 3 місяці тому +18

    the nvidia installer should compair the sha256 and or size

    • @User-kq3od
      @User-kq3od 3 місяці тому +5

      That takes effort and care for security

    • @Neuer_Alias_erstellen
      @Neuer_Alias_erstellen 3 місяці тому +2

      @@User-kq3od i feel like Nvidia has enoght money lol

  • @cinderwolf32
    @cinderwolf32 3 місяці тому +9

    I'm gonna guess DLLs!

  • @bigland-id3sv
    @bigland-id3sv 3 місяці тому

    Thanks to this now I'm more paranoid to even install signed software

  • @DeepfriedChips
    @DeepfriedChips 3 місяці тому +3

    Electron is not CEF
    They are separate projects and Electron does not depend on libcef

    • @gabrielesilinic
      @gabrielesilinic 3 місяці тому

      No it does. Otherwise how the hell would it load a chromium WebView in the first place?
      Search and Read: "Electron Internals: Building Chromium as a Library"

  • @cr_cryptic
    @cr_cryptic 27 днів тому +1

    10:31, why’s it look like it’s a binary text print but if you squint your eyes a little you can see like a guy sitting at a desk with someone over his shoulder? 🤨
    Not weird at all. 💀

  • @Icythot-m6i
    @Icythot-m6i 3 місяці тому +2

    theres a website i like using for software, and its a community who back engineer paid software and when they upload it they leave in the description what it is and how it works

  • @jeffzkiller3590
    @jeffzkiller3590 3 місяці тому +2

    are you doing these videos with windows defender on or off? thats a pretty big thing to be an oversight for it

  • @dariusscovill7970
    @dariusscovill7970 3 місяці тому

    i have a feeling i have a ton of these sitting in my pc to cleanse

  • @joa-p2m
    @joa-p2m 3 місяці тому +5

    You have a collection of very useful tools.

  • @TheDeadman1810
    @TheDeadman1810 3 місяці тому +9

    Which software did he use to capture network traffic?

    • @SmilerRyanYT
      @SmilerRyanYT 3 місяці тому +9

      The proxy he uses is mitmproxy with wireguard on the vm.

    • @BelkinJr
      @BelkinJr 3 місяці тому +1

      @@SmilerRyanYT thank youuuu

  • @NightfallGemini
    @NightfallGemini 3 місяці тому +2

    5:09 "nonce_proof" ... huh? are they using the term, or is that just a weirdly (hilariously) unfortunate shortening of something?

    • @EricParker
      @EricParker  3 місяці тому +1

      it has a different meaning in cryptography.

  • @R4as0n
    @R4as0n 3 місяці тому +2

    Compromised package is not legitimate software

  • @JJFX-
    @JJFX- 3 місяці тому +1

    I wouldn't call this new but certainly not as common. Nvidia could verify the expected libraries prior to loading them and I'm surprised if they aren't for some of them but at a certain point it just isn't practical. Many don't need updates very often but those that do would need to be accounted for whenever Nvidia updates their software. I do this for some 3rd party libraries packaged with my programs for various reasons.
    That said, in cases like this the installer is already a red flag but that wouldn't always be necessary to use this same technique.

  • @S1nistre
    @S1nistre 3 місяці тому +3

    What is the of the tool like wirshark 0:58 here

  • @mateuszabramek7015
    @mateuszabramek7015 3 місяці тому

    "new way"? Nah, it's an old way commonly named ratting software where rat is the malware.

  • @cup-noodle-love
    @cup-noodle-love 3 місяці тому +1

    A tale old as time.

  • @gooniesfan7911
    @gooniesfan7911 3 місяці тому +1

    I could listen to this man speak 24 7 ❤😊

  • @abhaydxgaming
    @abhaydxgaming 3 місяці тому +2

    Nice video dude..
    Btw what would u recommend as the best antivirus for the best overall protection? Is Norton 360 a good option?

    • @jeffzkiller3590
      @jeffzkiller3590 3 місяці тому +3

      lol

    • @peacesyn
      @peacesyn 2 місяці тому

      Common sense and VirtualBox if your skeptical

    • @abdou.the.heretic
      @abdou.the.heretic 2 місяці тому

      Borderline schizo levels of paranoia, and a keen eye.

  • @vladislavkaras491
    @vladislavkaras491 3 місяці тому

    Huh... I did not expect that it could be possible to do so!
    Thanks for the video!

  • @JustARandomGuy-9
    @JustARandomGuy-9 3 місяці тому +1

    Can You make a tutorial for the wireguard thing and how to setup a config for it

  • @bartoszkowalski6986
    @bartoszkowalski6986 3 місяці тому

    Nahh I'm so cooked 💀.
    I could easily and maybe already have downloaded legitimate looking software without having any idea it was malicious.
    I would really appreciate inquiring on methods to determine whether the file(s) I'm downloading are malicious.

  • @jc008titan
    @jc008titan 3 місяці тому

    wait, you guys didn't check every single file from an archieve of a pirated game before running it?!?

  • @mohammadiaa
    @mohammadiaa 3 місяці тому +4

    How

  • @barny541
    @barny541 2 місяці тому

    I don't understand anything that's being said in the video or in the comments. It feels like watching aliens interact, the aliens in question being reddit tech nerds

  • @agusz..
    @agusz.. 3 місяці тому +7

    the nvidia software you downloaded was a fake one, right?

    • @esco8778
      @esco8778 3 місяці тому +7

      The installer was legit. The DLL the installer was looking for was not.

    • @EricParker
      @EricParker  3 місяці тому +6

      nvidia exe is real, libcef is fake.

  • @kodak1587
    @kodak1587 3 місяці тому +6

    Pretty ironic that you use Opera while talking about malware

  • @NNorthern-j7y
    @NNorthern-j7y 3 місяці тому +1

    where is the cat girl costume..?

  • @the-answer-is-42
    @the-answer-is-42 3 місяці тому +2

    Question: Is this technique as viable on Linux (i.e. use a legit executable but a compromised library) as on Windows?
    Asking because I'm a Linux user and I just realized I don't know how easy it is to use a compromised library on my OS of choice. Guessing it's roughly the same, just don't know.

    • @seedney
      @seedney 3 місяці тому +2

      yes...

    • @RmFrZQ
      @RmFrZQ 2 місяці тому

      Of course. It is even easier on Linux, because ".so" files don't have Digital Signatures.
      Anything accessible to user is available for the attacker.
      But in order to compromise system library (i.e. installed to /lib/ ) and establish persistence at system level, attacker have to get root access first.
      This is why you should never execute some software, you just downloaded from external source, as root.
      This is why you should never blindly trust binary files from external sources. Always analyze build scripts and at least skim through source code, before compiling it and execute it.

    • @the-answer-is-42
      @the-answer-is-42 2 місяці тому

      @@RmFrZQ Ok, thanks. I think us Linux folks should see if we can improve things a bit, then.
      Generally, I'm very careful from where I install things and how. If I see any software installation involving sudo, curl and piping curl into a shell, I just refuse to install it because it just feels like a red flag.

    • @RmFrZQ
      @RmFrZQ 2 місяці тому

      @@the-answer-is-42 Oh, don't get me wrong, there are many solutions and techniques exist already. SELinux and AppArmor help with restricting access to areas where some app should never have. Also there are various isolation techniques ranging from simple, like chroot, to more complex, like containers and VMs.

    • @burgedham
      @burgedham Місяць тому

      ​@@the-answer-is-42 yeah, shady install scripts are a serious threat to the 7 people in the world that use Linux desktop

  • @coolcatgame
    @coolcatgame 3 місяці тому +1

    shouldn't Electron get a hash of all it's dlls?

    • @LuizDahoraavida
      @LuizDahoraavida 3 місяці тому

      If you're internal you can just hook everything if you care

    • @SaviorTheBurn
      @SaviorTheBurn 3 місяці тому

      Companies don't sign dlls most of the time. It's a huge attack surface.

  • @Gwiddyy
    @Gwiddyy 3 місяці тому +1

    hey man can we get a virustotal tutorial

  • @Den_Ukrainian001
    @Den_Ukrainian001 3 місяці тому +2

    Why😔😔😔

  • @HuzaBird0.2
    @HuzaBird0.2 3 місяці тому

    How they hook dll on legimated software

  • @Omer_Faruk053
    @Omer_Faruk053 Місяць тому

    I probably dont have any malware since I dont download things often but I hope if I did get one from that one time I downloaded a few mods for Minecraft I hope mcafee can find it worst case scenario a hard drive reset

  • @BobSockTwo
    @BobSockTwo 3 місяці тому +14

    Pls, use dark mode in your videos!!

  • @omarafnan4372
    @omarafnan4372 3 місяці тому

    Can someone ans my question so some times when I am using my pc my cmd would randomly pop up on my screen and them go away I did the scan and there wasn't any malware or anything like that and I did the full scan FYI so anyone can help me out 😊

  • @PalestineHomunculi
    @PalestineHomunculi 3 місяці тому

    Running untested, viewer submitted code at 150k

  • @CapaciousCore
    @CapaciousCore 2 місяці тому

    One of the domain names sounds very Polish :)

  • @Subtleminecraftplayer
    @Subtleminecraftplayer 3 місяці тому +4

    Opinion on verizon rn?

    • @EricParker
      @EricParker  3 місяці тому +4

      the telco?

    • @undefinedCat
      @undefinedCat 3 місяці тому

      @@EricParker ig yeah

    • @Subtleminecraftplayer
      @Subtleminecraftplayer 3 місяці тому +5

      @@EricParker Yes its down atm

    • @SkylerAk
      @SkylerAk 3 місяці тому

      @@Subtleminecraftplayerhuge outage in Alaska, the whole state was out

  • @teriotheh
    @teriotheh 3 місяці тому +30

    I remember trolling PIA customer service. Good VPN though, i bought it afterwards.

    • @SparklesFall
      @SparklesFall 3 місяці тому +4

      Why💀💀

    • @teriotheh
      @teriotheh 3 місяці тому

      @@SparklesFall its funnye

    • @slayyyter4686
      @slayyyter4686 3 місяці тому

      Have fun getting all your data logged while using PIA!

    • @teriotheh
      @teriotheh 3 місяці тому

      @@slayyyter4686 it works fine so far, no red flags

  • @MrKata55
    @MrKata55 3 місяці тому

    5:30 I couldn't help but laugh at the CnC server URL. Are the hackers polish or something?? Well that be concerning but there are bad actors in every nation and ours sure has some technical talents that may go astray...

  • @unrealircdtutorials
    @unrealircdtutorials 3 місяці тому

    Bro's accent switching between American and English and a tiny bit of posh scots, please help me understand what's going on

  • @Tir5d.Turtle
    @Tir5d.Turtle 3 місяці тому +6

    I have GeForce Experience from the Nvidia website am i safe?

    • @mjaypierce9549
      @mjaypierce9549 3 місяці тому +9

      of course

    • @JonnyAppleWeed
      @JonnyAppleWeed 3 місяці тому

      If you have to ask a question like that, you're probably not at all safe, and it's not because of a program.

    • @LuizDahoraavida
      @LuizDahoraavida 3 місяці тому

      Safe and bloated

  • @HafizurRahman-vh7hw
    @HafizurRahman-vh7hw 3 місяці тому +7

    Where is the cat pfp Eric

  • @twister8946
    @twister8946 3 місяці тому +2

    hi

  • @epicstar86
    @epicstar86 3 місяці тому

    peak content

  • @hahayes1122
    @hahayes1122 3 місяці тому +9

    hehehe

    • @vas45gdvvas6
      @vas45gdvvas6 3 місяці тому +3

      You look related to this lol

  • @Umb19
    @Umb19 3 місяці тому

    If anything is free. Genuineley why shouldnt it be malicious

  • @hamburger_eatspie
    @hamburger_eatspie 3 місяці тому +1

    dude, activate your windows like bruh🙄

  • @vvorldnewsmedia
    @vvorldnewsmedia 3 місяці тому

    this is so easy and has been seen alog time ago its cute you think this hahaha

  • @kevinwong_2016
    @kevinwong_2016 3 місяці тому +3

    1st🗿

  • @cool-username-u9r
    @cool-username-u9r 3 місяці тому +4

    maid suit at 200k

    • @JonnyAppleWeed
      @JonnyAppleWeed 3 місяці тому +1

      We don't need to know about your fantasies, thanks.

  • @jiggilowjow
    @jiggilowjow 3 місяці тому

    hold on... you have opera?now i know for sure you dont know what your doing.... wait right next toit is firefox? with the lovely mozilla malware... get better at computing before you make vids... i still cant get rid of the empty mozilla maintenance empty registry from the one time i down loaded firefox....