{\blur10\fad(200,200)}翻译/压制/字幕制作:HAF半个水果
{\blur10\fad(200,200)\pos(1997.334,728)}使用AI工具翻译,如有不准确的地方请在弹幕或评论区指正,谢谢!\N
!!真的有人看不到这行字!!
{\blur10\fad(200,200)\pos(1933.334,564)}翻译质量权威评价:原来25年就有小拉即用机翻糊弄人了
{\blur10\fad(200,200)\pos(1937.334,548)}♥本视频在Enderman频道会员有效期内翻译♥
I actually misspelled it.
This site has been reported as unsafe.
That's what we're looking for.
Continue to the unsafe site.
Give me the access to the Captcha.
I've been sent this four hours ago
and it seems like it's already dead
Or maybe it's detecting the proxy that I'm using.
{\blur10\pos(1920,2024)}*似了喵*
So it appears the malicious site is back up now.
我们要访问的是C-A-P-C-H-A-Bot.cc
So we're gonna visit it at C-A-P-C-H-A-Bot.cc.
老兄 我还得为这个假Cloudflare验证码干活
I was doing a Hail Mary curl request
Verify you're a human by completing the action below.
And here we got an iframe.
And the iframe is... oh my lord.
Can I just view the source?
The iframe is considered unsafe
I might not load this ever again.
We can run this separately.
So I think they basically ripped off the Cloudflare Captcha
and it contained an iframe
so they just used the Cloudflare template as a blueprint.
Is there any way I can somehow turn this off?
{\move(1920,2050,1916,1626,1420,1503)}然后刷新网站试试
{\move(1920,2120,1916,1700,1420,1503)}And let's update the website to get access to it.
{\blur10\pos(2172,1824)}*在 X 上关注!
I want to change the IP again.
I got another IP address.
By entering CaptchaBot.cc with Captcha being misspelled.
CaptchaBot.cc 请完成下方验证以确认你是人类
It doesn't look off at all.
You get the privacy button
Until you hit the checkbox.
Please wait while Cloudflare validates your connection.
Extra verification needed.
Press Windows plus R to open the run dialog
paste the verification text by pressing CTRL plus V
press OK to verify you're not a robot.
I was looking for a fake Cloudflare Captcha.
Because it looks the most genuine.
And I think there's supposed to be an image
but it didn't load for some reason.
I understand this is a malware and they're trying to infect me.
But as a tech illiterate person
I might as well just paste that.
They're using the property of a run box.
这个文本框长度有限 必须向左滚动才能看到真正的命令内容
The fact this text box has a limited length and you have to scroll to the left to get to the actual meat of the command.
And rem is pretty much a comment in batch.
So they just made a comment
which is at the beginning.
And the command is conhost.exe
进入用户配置文件 然后从这个IP和端口保存a.exe
And then run conhost.exe headless again
and then pretty much run the a.exe.
but it's another way of tricking the anti-malware into thinking you're actually running conhos
and conhost is running this code right here.
So let's see what it's all about.
but I think I'm gonna download this separately.
It's three megabytes long.
It doesn't let me download
I need to turn off Microsoft Defender first.
Microsoft Defender对恶意程序太敏感了
It's so annoying when it comes to malware.
I can't do anything with malware whenever Microsoft Defender is around.
Let's check out the properties of this file.
So that's what we're going to run.
It's gonna save it to my user profile.
It's gonna save it right here
I'm gonna run the Task Manager and show you exactly what happens.
Is this gonna detect the lobin?
So I'm assuming this executable has an anti-VM inside of it.
So it's not going to run...
It's not going to do anything.
Now we're in a hardened VM.
So let's go ahead and see what it does.
I'm gonna run the Installation Tracker and Process Hacker as usual.
I'm not gonna go super in-depth into the malware analysis.
You can do that with tools like any.run.
Because all this is pretty generic.
But let's go ahead and run that.
I think it impersonates microsoft.net framework.
So it's gonna run on every startup.
And then it started the app launch.
But I don't really quite get why.
Is there any command line?
I think that's a red herring.
I don't think it does anything.
它只是把自己保存到一个文件夹里 然后把自己添加到启动项
It just saves itself into a folder and then puts itself on startup.
So it's gonna start itself yet again.
I kind of want to see what's going on already.
I need Process Hacker for that.
a.exe just started with Explorer
I don't really know what's going on.
Could it be injecting something into that process?
If anyone in the comments down below want to explain why that happens
and what could be the potential reason why it creates applaunch
与此同时 我的订阅用户又发来个虚假Cloudflare验证码
It doesn't do dark mode at all.
which doesn't freaking load
but I'm gonna edit that in to compare.
And it looks kind of fake.
It's a little more cheaply made.
It reloads every single time.
I can't even do anything.
To better prove you're not a robot...
To better prove you're not a robot
Press and hold the Windows key plus R.
In the verification window
You will observe and agree.
Stop restarting every time.
You will observe and agree.
Recaptcha verification ID 645221.
Perform the steps above to finish verification.
I don't know what Recaptcha has to do with any of that
I didn't have enough time to press verify
because it updates every single time.
Did it copy anything into my clipboard?
Let me unload it into Notepad.
If the web search in Windows works...
So let's see what this guy does.
Then it obfuscates the string.
It concatenates the string.
It's to obfuscate and concatenate the strings.
And it just adds the link.
And then another bit of obfuscation here.
but let's do it via the run box.
I'm gonna... I'm gonna make it canonical.
I just don't know how to find them.
And then it's probably like replacing t's with e's.
Some kind of thing like that.
Let's deobfuscate that real quick.
which is the double slash plus $c
which is cvg plus all that.
i is already... it's a part of the executable script.
This is why it's failing.
This one is not plausible at all.
The capture bot one was pretty good
I'm gonna give them that.
Find out it's the same IP and the same port and the same file.
And we can be done with that.
Thanks for watching and take care.
{\blur90\fad(200,200)\fscx185\fscy188\pos(1885.333,840)}在 Youtube 上关注
{\blur10\fad(200,200)\pos(1953.333,496)}原标题:Can you spot this Fake CAPTCHA 原作者:Enderman\N
原视频上传日期:2025年8月7日
{\blur10\fad(200,200)\pos(1909.333,1220)}翻译/压制/字幕制作:HAF半个水果\N
翻译质量权威评价:原来25年就有小拉即用机翻糊弄人了
{\blur10\fad(200,200)\pos(1889.334,1336)}♥本视频在Enderman频道会员有效期内翻译♥\N
如果你喜欢这个视频,请多多支持和评论哒~ o((>ω< ))o\N
字幕制作不易,喜欢的话支持一下我吧!