Fortnite RAT: How to tell if an Application is Malware

Sdílet
Vložit
  • čas přidán 19. 11. 2023
  • I'm often asked how to tell if an application or exe is malware. Here is an example of a fortnite RAT analyzed in a sandbox to demonstrate as a tutorial the kind of indicators that can give away malicious behavior. Try Any.Run for free: any.run/?u... (sponsor)
    Get the pro version: any.run/demo/?...
    Buy the best antivirus: thepcsecuritychannel.com/best...
    Join the discussion on Discord: discord.tpsc.tech/
    Get your business endpoints tested by us: tpsc.tech/
    Contact us for business: thepcsecuritychannel.com/contact
  • Věda a technologie

Komentáře • 269

  • @Daxter250
    @Daxter250 Před 7 měsíci +84

    sadly this website only allows for 16 mb for free users and the rest are extremely expensive for normal private users (more than 100 bucks per month). 64 bit versions are only available for paying customers.
    nice idea but sry, its way too expensive for the typical app user.

  • @nemtudom5074
    @nemtudom5074 Před 7 měsíci +134

    4:50 1400 dollars a year is a bit far from 'pretty reasonable'

    • @VaultCord
      @VaultCord Před 6 měsíci +2

      hatching triage works well and it doesn't cost anything and they give you Win10

    • @planetfixer
      @planetfixer Před 6 měsíci +2

      oh shti dude youre right it is expensive. hey guy with no credentials, expertise, or intent to purchase the product at all, what do YOU think a reasonable price should be? i'll get in touch with my contacts and we can rectify the issue.

    • @SafetyKitten
      @SafetyKitten Před 6 měsíci

      @@planetfixer couldnt have said it better myself. hopefully one of the teams can get in contact with this new age genius

    • @masterTigress96
      @masterTigress96 Před 5 měsíci

      Not for professionals or enterprises. For your average joe running a homelab it is, but for bigger corporations this is a life saver and very reasonably priced.
      If you're into malware analysis on a professional level be reminded: as an example, just your average enterprise grade firewall will run you $30,000 just to buy it, and then thousands of dollars extra per year for a license to do traffic inspection and all that sort of jazz.
      Then take into consideration that you need a 3-2-1 setup for security and backup practices, so you need at least 2 of these expensive firewalls in 2 DC's, each with their own license that is thousands of dollars.
      On top of that the price for a 1U or 2U rack space these take up, electricity and maintenance and you get the picture.
      Now granted, the service provided by AnyRun will not replace an enterprise grade firewall, but it will allow you to save money elsewhere given that you now have a safer, remote, disposable way of running or analyzing malware.
      If you want to do this in your own DC, on your own VM's, you have to factor in extra costs for e.g. VMware/Hyper-V/Nutanix, switches, routers, and extra software such as antivirus, firewalling, data/malware analysis and more.
      All of that can be saved by just purchasing a simple, cheap license to rent some temporary compute on someone else's infrastructure.
      You can literally ditch your entire DC and equipment, buy a simple laptop, and analyze malware from a remote café drinking overpriced mocha frappochino's, if AnyRun provides everything you need to do your job that is.
      For most it will not be sufficient, but it will save you a lot of hassle and can save you a LOT of money!

    • @peacefusion
      @peacefusion Před 14 dny +1

      buying a cheap computer or laptop would be a lot easier than this service.

  • @PHaRTnONu
    @PHaRTnONu Před 7 měsíci +43

    Note: as of Nov 22nd 2023 not "anyone" can sign up they require a business email EVEN for the free account. Of course you can get around this by just having a parked domain, but yeah still mildly annoying for the avg person im sure.

  • @howa_tcp2501
    @howa_tcp2501 Před 7 měsíci +230

    4:41 "But they have pretty reasonable pricing" that _begins_ at *$1308 per year* or *$109 per month* and you're still limited to Windows 7 with that. But hey, at least you can now use the 64-bit edition.
    Not sure how detatched from reality you have to be to think that the cheapest premium plan being this expensive is "reasonably priced". Lmao

    • @magicaCZ
      @magicaCZ Před 7 měsíci +11

      subscribtion thats basically a second rent

    • @EagleGamerz
      @EagleGamerz Před 7 měsíci +39

      Not sure how detached from reality you have to be to think that security oriented solutions are supposed to be cheap lmao. I think that the clientele for this type of service may use it for their company or to supplement their job

    • @Pepo..
      @Pepo.. Před 7 měsíci +2

      now wait and whatch someone make their same version but open source

    • @tkynapsex
      @tkynapsex Před 7 měsíci +6

      @@turboxide It says "for individuals" and there's an enterprise version with even more features "for teams and organizations"

    • @katto1937
      @katto1937 Před 7 měsíci +5

      @@EagleGamerzNobody said they're meant to be cheap, but that's what the youtuber said it is even though it's not.
      Just because some products like IDA cost 5k per license doesn't make this any less expensive or "cheap".
      A Lamborghini doesn't make a BMW cheap.

  • @KG4949-r9f
    @KG4949-r9f Před 7 měsíci +44

    it is malware if it has fortnite in the name

    • @wrathofainz
      @wrathofainz Před 7 měsíci +4

      As a prior fortnite hater, the game isn't that bad if you stick to Epic created game modes and keep them mics off.
      Never do anything more than solos because nobody seems to be able to use emotes and pings correctly :/

    • @Externalities
      @Externalities Před 7 měsíci

      @@dreaper5813 grrr popular bad!!1!!1! 👶

    • @Loujemouse
      @Loujemouse Před 7 měsíci

      @@dreaper5813 Your loss 🤷‍♂️ some people enjoy playing the game

    • @kaeji_namitsua
      @kaeji_namitsua Před 7 měsíci

      @@Loujemouse Really like who?

    • @Loujemouse
      @Loujemouse Před 7 měsíci

      @@kaeji_namitsua Me 🥰

  • @sudo720
    @sudo720 Před 7 měsíci +223

    How are you protecting your network? I know you’re in a VM but I know some malware (worms) can infect the network.

    • @Kaliyaz_GT
      @Kaliyaz_GT Před 7 měsíci +28

      no

    • @lukieswiss5555
      @lukieswiss5555 Před 7 měsíci +178

      Intrusion detection system, closing unnecessary ports, firewall configurations, vpn

    • @IDJENAwoqqqxdre
      @IDJENAwoqqqxdre Před 7 měsíci +2

      He could be ssh’d into a machine prob

    • @Catge
      @Catge Před 7 měsíci +18

      You can segment using vlans or firewall rules. It is best to airgap from the rest of your network

    • @ImSimpIicity
      @ImSimpIicity Před 7 měsíci +1

      @@corndoggoiscool8223VPN’s are not the solution to every problem.

  • @YourWealthCome
    @YourWealthCome Před 7 měsíci +24

    Not sure why people with regular email's can't sign up, even though there is a link for a Non-Commercial Trial and also a Community version for free link way down at the bottom of page; both asking for a business emails. (Not sure why a business would be downloading Video games cheats and hacks, I assume its for demo purposes). If we did have business email.. how long is the Trial?

  • @dylansmart1964
    @dylansmart1964 Před 5 měsíci +1

    I was needing this exact video, thank god im subcribed to you

  • @HutchyyHD
    @HutchyyHD Před 2 měsíci

    Absolute legend thank you for this brother keep up the good work and keeping us all safe

  • @ShrineFox
    @ShrineFox Před 7 měsíci +42

    Man I really wish there was an offline form of something like this that you could host on your own hardware for free. There's gotta be, right? Maybe not as robust as this, but some kind of VM that logs all the malicious connections and dropped EXEs and notifies you in real time. Closest thing I could find is something like CrowdSec that does this through a web portal

    • @Artiom97es
      @Artiom97es Před 7 měsíci

      im sure in vmware you can do it, but its not easy xd

    • @skylarkblue1
      @skylarkblue1 Před 7 měsíci +12

      You can do it with any VM software, but it won't be nearly as secure. Doing it over the web means it's fully sandboxed. Doing it on your PC means there is a realistic chance of it spreading to the host machine.

    • @knackrack615
      @knackrack615 Před 7 měsíci +1

      Cuckoo Sandbox, its FOSS and you can customize it to your heart's desire.

    • @Hrorrik
      @Hrorrik Před 7 měsíci

      Theres a lab by a youtuber named huskyhacks that shows how you can use VMs (windows + Remnux) to detonate malware fairly safely. The windows VM acts as detonation box and the Remnux box has inetsim or some other shit that basically tracks HTTP/DNS requests if you set it up properly. Might not be explaining things properly, I'm a noob lolol.

    • @dire284
      @dire284 Před 7 měsíci

      @@skylarkblue1 Aslong as its being hosted on a hardened VM with no known vulns then there isn't much downside to self hosting a solution for this other than complexity.

  • @m4rt_
    @m4rt_ Před 7 měsíci +94

    Btw, just because you run it in a VM doesn't mean that you are safe from Malware.
    It is possible for it to escape VMs, and even though several layers of VMs.
    If you really want to avoid it, have a separate machine that isn't connected to anything.

    • @piratesephiroth
      @piratesephiroth Před 7 měsíci +35

      it's impossible for it to escape an online VM though

    • @neipas09
      @neipas09 Před 7 měsíci +10

      Then make a video showing how it can escape a VM if you think that's true.

    • @realdoinky
      @realdoinky Před 7 měsíci +4

      @@neipas09 it can escape the vm and infect the system at the kernel level

    • @shroomer3867
      @shroomer3867 Před 7 měsíci +1

      I wonder, if the virus does not specifically break any physical components, is it possible to dual-boot a machine and then just wipe the drive and reinstall the OS if your system got compromised?

    • @harshverma80
      @harshverma80 Před 7 měsíci

      ​@dreaper5813i want to ask that if i run or test malware on windows os created on usb or portable ssd then my system will remain safe or it will get infected?

  • @peterwassmuth4014
    @peterwassmuth4014 Před 7 měsíci

    Awesome thank you for sharing 🙏 💯‼

  • @AssassinJay
    @AssassinJay Před 7 měsíci

    Those 90s are sick!🔥🔥🔥

  • @DarkStormPhoenix
    @DarkStormPhoenix Před 7 měsíci

    Thank you leo amazing video and i wioo definitely try that site

  • @chambling8305
    @chambling8305 Před 6 měsíci +1

    rat is a genius name for malware like this

  • @cpuuk
    @cpuuk Před 7 měsíci +1

    Good to know.

  • @CODE_ROOM
    @CODE_ROOM Před 7 měsíci +68

    Best security channel on CZcams.

    • @Shocker99
      @Shocker99 Před 7 měsíci +11

      Best is a bit of a stretch.
      It's a reasonably good channel. The vast majority of the videos are advertisements for the software/services featured in the video. But it does help raise awareness of different types of bad software in the wild.

    • @mgjk
      @mgjk Před 7 měsíci +4

      ​@@Shocker99 I love this channel because they're to-the-point, technical and don't try to make you feel like you wouldn't understand what they're talking about. Any recommendations for better channels?

    • @500subswithoutvideos
      @500subswithoutvideos Před 7 měsíci

      NetworkChuck is way better.

  • @yoppindia
    @yoppindia Před 7 měsíci +1

    what is the tool you used to analyse process and traffic in vm, can it be installed locally?

  • @youdontneedmyrealname
    @youdontneedmyrealname Před 7 měsíci +6

    If only any.run wasn't so expensive for anyone to use. Professional use by a company that can pay for it is okay but it not remotely cheap enough for the average user wanting to see what a program does

  • @janmillerty4528
    @janmillerty4528 Před 7 měsíci

    Awesome ❤

  • @Kamikarus
    @Kamikarus Před 7 měsíci +5

    4:41 "But they have pretty reasonable pricing" No way, the cheapest offer costs $1308 per year and $109 per month. If that's reasonable, I don't know what wouldn't be but I guess something like $5000 a year (or month). What's the best, that with such cost it doesn't give you ability to use anything besides Windows 7 (but here's a "wow", it gives you ability to use *64 bit Windows 7* :00, just for half of your salary). I'm not even gonna start how much the second plan costs ☠☠
    I'm scared how much Enterprise costs but probably some magic price that I could buy a house with, probably that high that it wouldn't even fit in the column, that's why it isn't said

  • @billabrogar4628
    @billabrogar4628 Před 7 měsíci

    Wow,.the best cybersecurity channel,.worth it to subscribe ❤❤❤

  • @pyrotex8
    @pyrotex8 Před 7 měsíci +23

    I would love to see what you think about the state of malware and how it works on macOS. I found it very intriguing when you did some videos on linux. I know it may be tedious but it would be very neat.

    • @Xjag
      @Xjag Před 6 měsíci

      Aint no one making malware for macOS

    • @zaks7
      @zaks7 Před 6 měsíci

      @@Xjag That was a valid perspective, 15 years ago. Now there's enough and more malware for mac/ios.

    • @Xjag
      @Xjag Před 6 měsíci +1

      @@zaks7 yeah but realistically noones using them on people, most people are on windows, iPhone would be next to impossible because apple is so quick at patching vulnerabilities

    • @timnonik2736
      @timnonik2736 Před 6 měsíci

      Might have legal reasons, since macOS is only allowed on apple hardware

  • @suululu
    @suululu Před 7 měsíci +1

    i love you because you keep us infomed. i hate you because u give me the feeling i do everything wrong and although Avast and Malwarebytes say there is nothing, i feel like there is something. So yeah, thanks

  • @juniorsancanari
    @juniorsancanari Před 7 měsíci +2

    Hi, I'm a follower of your channel and would like to make a suggestion. Carry out the Blackberry Cylancer test, given that the last test was four years ago

  • @erwynnipegerwynnipeg8455
    @erwynnipegerwynnipeg8455 Před 7 měsíci +5

    well it's nice if YOU can try it for free but telling your average viewer to use it... that's not fair, because they don't have the money. That's the problem I've run into.

  • @punch3n3ergy37
    @punch3n3ergy37 Před 5 měsíci

    I'd love to see a tutorial to make a self-hosted sandbox. Filtering all requests etc. can be tricky because windows does shady stuff as well.

  • @DENTIC
    @DENTIC Před 7 měsíci +2

    A whole business account just to do this

  • @M2356U
    @M2356U Před 7 měsíci +4

    4:34 no, not anyone can sign up. You have to have a business mail and normal providers like proton or gmail do not work.

    • @cardaib9022
      @cardaib9022 Před 6 měsíci

      just make on then its so easy

  • @juanm3058
    @juanm3058 Před 5 měsíci +1

    hiiii great video btw two questions
    1. what if its a false positive
    2. what if the rat is a bios virus that stays on your motherboard

  • @ejonesss
    @ejonesss Před 7 měsíci +2

    a rat is also a larger more aggressive form of a mouse

  • @NotAcid.
    @NotAcid. Před 6 měsíci

    Nice video

  • @epici.
    @epici. Před 7 měsíci +1

    thx :D

  • @useracazzo
    @useracazzo Před 7 měsíci +3

    What would be an alternative way of checking a application without using a website like this? Is virtual Box safe to do this? What tools would I use to analyse this traffic in the VM?
    I understand this is a product placement, for a good product I am sure, but would appreciate an answer.

    • @tacayey4080
      @tacayey4080 Před 7 měsíci +1

      analyzing the file with virus total or submitting it and wait for someone to run it in an environment. Also, in the beginning he showed process explorer which is free. What you dont understand google or take a class in malware analysis(most are free in youtube). Furthermore, you can set up a vm of your liking and run it there to see if anything breaks, however a lot of malware has the ability to not activate when it detects a vm. Other AV software has the ability to run it but its almost never free. Remember that most things that are good are not going to be free because time, effort and resources are constantly being put into it. If u dont have the knowledge or cant be bothered, google it or pay for a service.

    • @LeZClan
      @LeZClan Před 7 měsíci +1

      virus total does the same job, but you will have to read to understand what it did to your pc so you can fix it maybe. i ran a fake directx installer and virus total showed me everything that any run would show, just not as simple.

    • @skylarkblue1
      @skylarkblue1 Před 7 měsíci

      Triage is a fantastic site that you can use a lot more of for free than this. Virus total isn't always the best as it can only take small files, and often spits out false positives - you need to know how to read the files to understand their reports. Doing it on your PC isn't overly safe as malware can, and have in the past, be known for breaking out of VMs and infecting the host computer (your actual computer).

  • @user-mn8lz7gf6d
    @user-mn8lz7gf6d Před 6 měsíci +1

    I've installed all kinds of questionable software, but so far I haven't had any issues.
    Also that site is for businesses only.
    A video on how to do all that yourself would be a lot more helpful.

  • @rygull
    @rygull Před 7 měsíci +7

    I wonder if you can use blue stacks to run infected apks and keep your PC safe.

    • @Kaliyaz_GT
      @Kaliyaz_GT Před 7 měsíci +2

      bluestacks cant run exe , also you can't run cheats on bluestacks they have soomekind antivirus ldplayer doesnt really have it

    • @abitterberry2149
      @abitterberry2149 Před 7 měsíci +7

      I wouldn't do that. If I remember correctly, you can copy/paste and drag&drop from your host to bluestacks, and you don't want shared resources to analyze malware.
      I would suggest installing genymotion inside a virtual machine. You could then install burpsuite in your VM and proxy all your android web requests to burpsuite and analyze its network activity.

  • @bahaatuffaha6607
    @bahaatuffaha6607 Před 7 měsíci +2

    Can I upload a whole application to the sandbox or this just works for single executable file?

    • @ANYRUN
      @ANYRUN Před 7 měsíci +1

      Hello,Yes, sure. You can upload even many application files at once in an archive, the only limitations are file sizes.

    • @chrisdawson1776
      @chrisdawson1776 Před 7 měsíci

      @@ANYRUN🤡🤡

  • @MegaNatebreezy
    @MegaNatebreezy Před 7 měsíci

    Can someone tell me how to setup a good sandbox? I know vlans can still identify your router and vms arent completely fool proof. What does everyone do for max separation?

  • @doronefraim7240
    @doronefraim7240 Před 7 měsíci +2

    thank for the video , why do you use internet while running a RAT ?
    isn't it dangerous ?
    it could infect your computer as well when the sandbox uses the your main PC for internet connection

    • @MrSnipmania
      @MrSnipmania Před 7 měsíci +1

      I guess he is using a specific vlan on the VM with only internet access through his router and blocked all kind of other traffic through strict policies, maybe with a specific network card to be extra sure (at least I hope, if not it would be ironic for a channel about security)

    • @tomtravis858
      @tomtravis858 Před 6 měsíci

      The only way that would happen is through a no-click exploit in windows/whatever software he has facing the internet. These exploits sell for literal millions of dollars, you have nothing to worry about.

  • @danialde
    @danialde Před 7 měsíci

    what about Windows Sandbox?

  • @seedney
    @seedney Před 7 měsíci

    What about OS X, linux, BSD? How to tell if web apps are malicious etc?

  • @jll9764
    @jll9764 Před 6 měsíci +1

    Bro really made a Ad for Any run..

  • @Hestyrial
    @Hestyrial Před 7 měsíci

    Can you do a video about peerblock ?

  • @LeZClan
    @LeZClan Před 7 měsíci

    wanted to try any run but cant sign up at all, not even for the free task host. had a fake file running on my pc and wanted to check it, well virustotal does the same job, but you have to dig abit deeper and reed its behavior tab, figured it out, ran sfc scannow and that fixed most of the corrupted files, everything else was done from myself by hand deleting temp files.... nice programm that i would use, but not like that sry.

  • @anakyn222
    @anakyn222 Před 7 měsíci +8

    How can anyone use it if you need an buisness E-Mail?

    • @57tlm78
      @57tlm78 Před 7 měsíci

      Same issue. We are normal people trying to be safe

    • @marcfabricatore1506
      @marcfabricatore1506 Před 7 měsíci

      @@57tlm78get a college email, it is considered to be a business email.

    • @Kamikarus
      @Kamikarus Před 7 měsíci

      I have the same question and same issue

  • @dONALDBLOOD
    @dONALDBLOOD Před 7 měsíci

    My security application makes me impossible to run random executables I downloaded.

  • @creepybeat
    @creepybeat Před 7 měsíci +1

    me as a fortnite player, i really think people should never use hacks or any cheat for playing, it will make you suck at the game and youll never learn any skill at all.
    fortnite is a great game for sure, many updates makes the game looks fresh and cool. have a great game! gg

    • @xxxod
      @xxxod Před 7 měsíci +1

      my aim is already good enough that i get accused of aimbot
      I just need a cheat that can crank for me and do edits 😭😭

  • @Alchemetica
    @Alchemetica Před 7 měsíci

    How does Windows 11 Pro sandbox rate?

  • @tercmd
    @tercmd Před 7 měsíci +4

    1:18 by the way, maybe you shouldn't have signed in to a paid AnyRun account on a VM running a RAT/infostealer
    Ok, I guess AnyRun gave you an enterprise account, but that's still value given to the attacker.

    • @WockOps
      @WockOps Před 7 měsíci

      Aren't they islolated?

    • @marcfabricatore1506
      @marcfabricatore1506 Před 7 měsíci +2

      @@WockOpsthey are, the guy has no idea what he’s talking about lol. The AnyRun credentials aren’t stored on the AnyRun VM LOL!

    • @tercmd
      @tercmd Před 7 měsíci

      @@marcfabricatore1506 but he's signed in to Anyrun on the VM he ran the malware on (look at the taskbar with MS Edge, which had AnyRun signed in, and the malware)

    • @WockOps
      @WockOps Před 7 měsíci

      thats what I figured...@@marcfabricatore1506

  • @HDrive-In
    @HDrive-In Před 7 měsíci

    I use vm in a winPE base, running vm in 7 is easy, try getting everything to work but have it work in PE

  • @alifnaufal
    @alifnaufal Před 7 měsíci

    Hey, my name is Fortnite Big Chungus and I like this video.

  • @Redstoneprojrjr
    @Redstoneprojrjr Před 7 měsíci +1

    Please do not login to any run on the infected vm.

  • @Beni-11324
    @Beni-11324 Před 3 dny

    how do i get a business email to sign up in any.run?

  • @code-teamX
    @code-teamX Před 7 měsíci

    What about windows sandbox?

  • @TunaTheScripter
    @TunaTheScripter Před 7 měsíci

    What VM do u use?

  • @leto1449
    @leto1449 Před 7 měsíci +1

    what if I made a simple app that has RAT that only stars working after couples days so it will start ? no all ip wonts be detected right away and a user will keep the software there

    • @leexgx
      @leexgx Před 7 měsíci +5

      Still likely sets a schedule task to run at a later date

    • @leto1449
      @leto1449 Před 7 měsíci

      but it doesn't use the windows task schedule just checks after 3 days and then init
      @@leexgx

    • @MTGeomancer
      @MTGeomancer Před 7 měsíci +2

      Yes that would work and is very common. It would only schedule a task if the creator wanted it to run at a later time on its own.
      The malware would have to actually do what it was that made the person download it though. In this case, cheat in Fortnite. If the cheat didn't work, they'd just delete it.
      This video was just a means of showing off that web based virtualization service as an advertisement.

    • @leto1449
      @leto1449 Před 7 měsíci

      @@MTGeomancer ohh I see thanks I meant not for fortnite but something else like

    • @dire284
      @dire284 Před 7 měsíci

      Its somewhat common to see this method being used, most AV sandboxes will automatically skip long sleep functions and other suspicious looking things.

  • @alexandertikanis5236
    @alexandertikanis5236 Před 7 měsíci

    Completely out of topic, where can i get that wallpaper

  • @jonnygiantrobot
    @jonnygiantrobot Před 7 měsíci

    Is any. Run related to any. do?

  • @LemmingPaul2
    @LemmingPaul2 Před 7 měsíci +2

    what a joke this video... the license that he was using here is round about 3500$ :'D

  • @Fhrgwrrr
    @Fhrgwrrr Před 7 měsíci +2

    How to register on any.app if i don’t have bussiness?

    • @Kamikarus
      @Kamikarus Před 7 měsíci

      I have the same question

  • @grichard1585
    @grichard1585 Před 7 měsíci +1

    How about running exe's in Sandboxie?

    • @medivyanshsingh
      @medivyanshsingh Před 7 měsíci

      That won't help much. plus some applications will not work at all

  • @justthomas3832
    @justthomas3832 Před 6 měsíci

    i had the same and i am alr busy 2 months stopping the hacker from loggin in to my accounts and stealing money but he went live on tiktok and i have photos and vids of him

  • @trentdavies4976
    @trentdavies4976 Před 7 měsíci

    A RATTE got me two days ago. It was annoying.

  • @Scubad1975
    @Scubad1975 Před 7 měsíci +1

    whats the best free sandbox to use

    • @Shocker99
      @Shocker99 Před 7 měsíci +3

      Virtual box is free.
      Windows Sandbox if you have Win10/11 Pro

  • @l7xcast966
    @l7xcast966 Před 7 měsíci +5

    It would be nice if a normal person can sign up for app any run , it asks me for a business email and i dont want to pay for one

    • @YourWealthCome
      @YourWealthCome Před 7 měsíci +3

      Yup, Same here and its odd since it says Non-Commercial Trial; If we did have business email.. how long is the Trial?

  • @NyanCoder
    @NyanCoder Před 7 měsíci +38

    "Russian IP... Russian IP..."
    I'd say other connections with named URLs are also could be suspicious activities with injected IP and/or faked DNS requests (and page names) regardless in which country they hold their virtual servers

    • @numbersandreality
      @numbersandreality Před 7 měsíci +8

      But the IP was Russian

    • @SFBenjaminK
      @SFBenjaminK Před 7 měsíci

      same thing in China & Russia or around the world they call it U.S IP

    • @pcsecuritychannel
      @pcsecuritychannel  Před 7 měsíci +31

      That's not necessarily true, a disproportionate number of russian ips are associated with suspicious activity, often because the authorities there are less adept (willfully or otherwise) of shutting down access to such infrastructure and a lot of cybercriminal gangs are from eastern EU/Russia. Of course it isn't always the case, but this video is trying to show the viewers examples of different things (like the country the connection is made to, if it is a known hostname etc) that they can use to narrow down suspicious behavior.

    • @YatagarasuTomiyasu
      @YatagarasuTomiyasu Před 7 měsíci +7

      Based on statistics, there is a good reason to see a Russian IP more carefully.

    • @NyanCoder
      @NyanCoder Před 7 měsíci

      @@pcsecuritychannel It's not the point which I'm talking about. Yes, in terms of numbers of attacks and botnets amount its definitely true. But in this case I can just rent a vps and host on it simple DNS server, that would serve my own proxie's IPs on any request and make a DNS request to fake service then send to my proxy (in any country where I can rent a vps/vds) some data through TCP with fake HTTP(S) header and proxy whould do the rest. If anywhere the proxy is downed, just remove the IP from the list, up a new extra proxy and sit'n'watch, it's that simple

  • @Anonymous30304
    @Anonymous30304 Před 7 měsíci

    do a Norton vs bit Defender

  • @Fox_
    @Fox_ Před 7 měsíci +1

    welp, registration is for business emails only...

  • @666222333111
    @666222333111 Před 7 měsíci

    what if you dont create a seperate exe but embed everything to run as one and use a good crypter? hmm

    • @dire284
      @dire284 Před 7 měsíci +1

      RunPE is mostly useless nowadays, you'll get clapped the second you decrypt your load method.

  • @ObscenePizza
    @ObscenePizza Před 7 měsíci

    Requires a "Business Email" to register.

  • @maurixasgd
    @maurixasgd Před 7 měsíci

    I downloaded a suspicious file and my facbook account is stolen i deleted file malware bytes didint detect anything

  • @nonjucto
    @nonjucto Před 7 měsíci +3

    Is the sandbox feature on Windows robust enough to be used like this?

    • @claytonwells8425
      @claytonwells8425 Před 7 měsíci +1

      That was my question / assumption. All though, I don't know that I would consider it sandboxed enough on the windows machine for my own comfort level. If I were to do it locally I would maybe consider VirtualBox by Oracle depending on how concerning the file is. I do like the web solution presented in his sponsor though, I also may consider that if I find myself wanting to test a particular file

    • @UrbexAlliance-SG
      @UrbexAlliance-SG Před 7 měsíci +1

      No matter which sandbox you use for malware testing (VirtualBox, VMWare, Windows Sandbox etc.) you will have to use a VPN on your host machine and need to set up a guest network to be really on the safe side. Otherwise, Windows Sandbox definitely is strong enough.

    • @claytonwells8425
      @claytonwells8425 Před 7 měsíci

      @@UrbexAlliance-SG Thanks for your information, I appreciate your comment 🙏🏻

    • @jeffnorsegod8080
      @jeffnorsegod8080 Před 7 měsíci

      @@UrbexAlliance-SGWould you mind elaborating further? I think I understand what you said, but I’m new to this cybersecurity stuff. As far as I understand it, VMs are not totally airtight and safe to run suspicious files and applications in because they still connect to your router and network, which a smart virus or something could use to breakout and end up on your host machine. So using a guest network for your VM would… somehow? (not sure on the specifics) help prevent your network from being compromised, while a VPN on your host machine would act as a second layer between your network and your machine in case your network was infected. Did I understand that all correctly? I am very interested in this subject!

  • @Gringle_
    @Gringle_ Před 6 měsíci

    wait did I just get advertised to

  • @SebastianRoczz
    @SebastianRoczz Před 7 měsíci

    you shoudl really mention that you need a business email for anyrun because I cant use it

  • @skystoyhunts7225
    @skystoyhunts7225 Před 7 měsíci +2

    Is virtual box free?

  • @magnusprime3269
    @magnusprime3269 Před 7 měsíci

    Hello can you do a video on trojan rat at minecraft

  • @ForikiTheRat
    @ForikiTheRat Před 7 měsíci

    can you do a video about hardened windows vs normal windows

  • @therealperco
    @therealperco Před 7 měsíci

    this is why u get notifications saying chang ur password on ur iphone in settings they get ur passwords trust i just did a major password wipe i had this exact exe im just trynna find a vid to watch while i eat lmao idk how i find this

  • @2turntjosh
    @2turntjosh Před 6 měsíci

    Ikn some devs that make a working cheat it’s normally shitty but it works but it’s a. Rat lots of paid ones are crypto miners to I just recommend make your own or download ones from trusted communities

  • @SantoSVD98
    @SantoSVD98 Před 7 měsíci +1

    Lol 109/mo (minimum) is a resonable price? 😅 It's -in a single month- more than what is necessary to spend to have the full unlocked version of the best antiviruses in the commerce rn for an entire year. Not so acceptable

  • @ovum
    @ovum Před 7 měsíci

    Is using Windows Sandbox safe?

  • @steelkatana
    @steelkatana Před 7 měsíci

    Seen the pricing??? Good Luck if you want to test Windows 11

  • @ntrq
    @ntrq Před 7 měsíci

    I'll post this on TikTok because some scammers use TikTok for promotion

    • @Gringle_
      @Gringle_ Před 6 měsíci

      You're promoting this guys advertisement on Tiktok? You shouldn't do that unless you get $$$$$$$$ for it like this guy did.

    • @ntrq
      @ntrq Před 6 měsíci

      You misunderstood me. I posted this man's clip on Tik Tok because I see a lot of script kids promoting such programs on Tik Tok.@@Gringle_

  • @BabaNamKevalamGames
    @BabaNamKevalamGames Před 7 měsíci

    109/mo or 299/mo is not a reasonable price... with that money i can save to build my own computer and test it installing those programs and then reinstalling the OSor using a virtual machine, o a personal server just that purpose.

  • @iUseVegas
    @iUseVegas Před 7 měsíci +1

    While I am against malware, I don't mind the cheaters getting fookd

  • @RandomUsername2004
    @RandomUsername2004 Před 7 měsíci

    Viruses re getting common unfortunately

  • @mnageh-bo1mm
    @mnageh-bo1mm Před 7 měsíci +1

    the answer ? ... u simply don't... ever heard of time bombs ?

  • @neuroplush7657
    @neuroplush7657 Před 7 měsíci

    Good video, but any.run is not reasonably priced.

  • @iTakeCash
    @iTakeCash Před 7 měsíci

    What if i have a firewall? Will it alert me that the exe is trying to make a connection?

  • @robloxfan4271
    @robloxfan4271 Před 7 měsíci +2

    wont let me sign up for any.run it keeps telling me i need a business email

    • @YourWealthCome
      @YourWealthCome Před 7 měsíci

      Yup, Same here and its odd since it says Non-Commercial Trial; If we did have business email.. how long is the Trial?

    • @thel3218
      @thel3218 Před 7 měsíci +1

      I am pretty sure I used a personal Gmail when I signed up a few years ago

    • @Kamikarus
      @Kamikarus Před 7 měsíci

      same issue

  • @m2ngur
    @m2ngur Před 6 měsíci +1

    so this wasnt really a video on "how to tell if an application is malware" now is it. i think the title "sponsored video of a ridiculously fucking expensive application that im trying to shill to you" would fit the content of this video better

  • @wintrywind
    @wintrywind Před 7 měsíci

    Naw why do i need to text them to get a personal account, no thanks I'll just stick to the usual malwarebytes.

  • @harisjafri9459
    @harisjafri9459 Před 7 měsíci

    Can the malware detect that it's currently detonating in sandbox?

    • @TheGlendriv
      @TheGlendriv Před 7 měsíci

      Can? yes. All malwares? not really.

  • @trevordoeseverything219
    @trevordoeseverything219 Před 7 měsíci

    I will rest some adobe torrents on this 😅

  • @abrokenpal
    @abrokenpal Před 7 měsíci

    Did you really log in to a online service website on an infected system environment, especially by a RAT? Nice cyber security stuff

  • @goten1343
    @goten1343 Před 7 měsíci

    can you send me the link to those cheats, i want to be bugha

  • @BurnOrphans
    @BurnOrphans Před měsícem

    I don't actually mind cheaters all tht much, I mean they're legit installing malware onto their pc to cheat in a game only to be banned half an hour later.

  • @Tesko249clips
    @Tesko249clips Před 7 měsíci +5

    Honestly I have nothing against malware inside applications that are obviously designed for cheating in competitive Multiplayer games. Kudos to the maker! :)

  • @cattameme
    @cattameme Před 7 měsíci

    Where can i find a safe process explorer?

  • @joepjoep9531
    @joepjoep9531 Před 7 měsíci

    30 seconds late wow