GitHub ↗ ← 返回

Can you spot this Fake CAPTCHA.ass

Enderman/Can you spot this Fake CAPTCHA.assASS共 623 条字幕
样式信息 (3)
Newman-CN-4K
名称Newman-CN-4K字体等距更纱黑体 SC字号125主色&H0055FFFF辅色&H000000FF描边色&H00FF43E4背景色&H00FF2FFF粗体0斜体0下划线0删除线0水平缩放100垂直缩放100间距0角度0边框样式1描边1.5阴影1.2对齐2左边距10右边距10垂直边距20编码1
Newman2-CN-4K
名称Newman2-CN-4K字体HarmonyOS Sans SC字号165主色&H00A0FFF5辅色&H00000000描边色&H96000000背景色&H00000000粗体0斜体0下划线0删除线0水平缩放100垂直缩放95间距0角度0边框样式3描边0.1阴影0对齐2左边距10右边距10垂直边距110编码1
Newman2-EN-4K
名称Newman2-EN-4K字体思源黑体 CN字号75主色&H00E0E0E0辅色&H000000FF描边色&H96000000背景色&HD2000000粗体0斜体0下划线0删除线0水平缩放100垂直缩放95间距0.6角度0边框样式3描边0.1阴影0对齐2左边距10右边距10垂直边距40编码1
#10:00:00.360:00:07.49Newman-CN-4K
{\blur10\fad(200,200)}翻译/压制/字幕制作:HAF半个水果
#20:00:08.690:00:18.69Newman-CN-4K
{\blur10\fad(200,200)\pos(1997.334,728)}使用AI工具翻译,如有不准确的地方请在弹幕或评论区指正,谢谢!\N
!!真的有人看不到这行字!!
#30:00:18.840:00:23.84Newman-CN-4K
{\blur10\fad(200,200)\pos(1933.334,564)}翻译质量权威评价:原来25年就有小拉即用机翻糊弄人了
#40:00:23.930:00:28.93Newman-CN-4K
{\blur10\fad(200,200)\pos(1937.334,548)}♥本视频在Enderman频道会员有效期内翻译♥
#50:00:07.640:00:08.50Newman2-CN-4K
大家好
#60:00:07.640:00:08.50Newman2-EN-4K
Hello
#70:00:09.040:00:10.96Newman2-CN-4K
在这个视频里将要展示
#80:00:09.040:00:10.96Newman2-EN-4K
In this video
#90:00:18.280:00:20.76Newman2-CN-4K
(非静止画面)
#100:00:23.270:00:23.93Newman2-CN-4K
等等
#110:00:23.270:00:23.93Newman2-EN-4K
Oh
#120:00:24.370:00:24.83Newman2-CN-4K
稍等
#130:00:24.370:00:24.83Newman2-EN-4K
Hold on.
#140:00:25.110:00:26.73Newman2-CN-4K
我其实拼错了
#150:00:25.110:00:26.73Newman2-EN-4K
I actually misspelled it.
#160:00:26.910:00:28.37Newman2-CN-4K
不是CaptchaBot.cc
#170:00:26.910:00:28.37Newman2-EN-4K
It's not CaptchaBot.cc.
#180:00:28.630:00:32.47Newman2-CN-4K
是C-A-P-C-H-A-Bot.cc
#190:00:28.630:00:32.47Newman2-EN-4K
It's C-A-P-C-H-A-Bot.cc.
#200:00:37.580:00:38.84Newman2-CN-4K
它要加载了
#210:00:37.580:00:38.84Newman2-EN-4K
It's gonna load.
#220:00:40.480:00:43.10Newman2-CN-4K
该网站被报告为不安全
#230:00:40.480:00:43.10Newman2-EN-4K
This site has been reported as unsafe.
#240:00:44.180:00:44.82Newman2-CN-4K
太棒了
#250:00:44.180:00:44.82Newman2-EN-4K
Awesome.
#260:00:45.080:00:46.30Newman2-CN-4K
这正是我们要找的
#270:00:45.080:00:46.30Newman2-EN-4K
That's what we're looking for.
#280:00:46.760:00:48.02Newman2-CN-4K
继续访问不安全的网站
#290:00:46.760:00:48.02Newman2-EN-4K
Continue to the unsafe site.
#300:00:49.120:00:50.54Newman2-CN-4K
嘿 别这样啊
#310:00:49.120:00:50.54Newman2-EN-4K
Hey
#320:00:51.720:00:55.06Newman2-CN-4K
让我访问验证码
#330:00:51.720:00:55.06Newman2-EN-4K
Give me the access to the Captcha.
#340:00:56.260:00:58.60Newman2-CN-4K
我四小时前收到这个
#350:00:56.260:00:58.60Newman2-EN-4K
I've been sent this four hours ago
#360:00:58.960:01:01.40Newman2-CN-4K
看起来它已经失效了
#370:00:58.960:01:01.40Newman2-EN-4K
and it seems like it's already dead
#380:01:01.720:01:02.04Newman2-CN-4K
可能吧
#390:01:01.720:01:02.04Newman2-EN-4K
maybe.
#400:01:03.530:01:06.14Newman2-CN-4K
或者它在检测我用的代理
#410:01:03.530:01:06.14Newman2-EN-4K
Or maybe it's detecting the proxy that I'm using.
#420:01:09.770:01:10.43Newman2-CN-4K
哦 等等
#430:01:09.770:01:10.43Newman2-EN-4K
Oh
#440:01:10.570:01:11.85Newman2-CN-4K
DNS坏了吗?
#450:01:10.570:01:11.85Newman2-EN-4K
Did the DNS break?
#460:01:17.760:01:19.44Newman2-CN-4K
不 DNS没坏
#470:01:17.760:01:19.44Newman2-EN-4K
No
#480:01:28.050:01:29.11Newman2-CN-4K
它在工作
#490:01:28.050:01:29.11Newman2-EN-4K
It's working.
#500:01:34.910:01:36.73Newman-CN-4K
{\blur10\pos(1920,2024)}*似了喵*
#510:01:36.790:01:39.60Newman2-CN-4K
看来恶意网站现在又上线了
#520:01:36.790:01:39.60Newman2-EN-4K
So it appears the malicious site is back up now.
#530:01:40.240:01:45.60Newman2-CN-4K
我们要访问的是C-A-P-C-H-A-Bot.cc
#540:01:40.240:01:45.60Newman2-EN-4K
So we're gonna visit it at C-A-P-C-H-A-Bot.cc.
#550:01:46.260:01:49.16Newman2-CN-4K
CaptchaBot 但验证码拼错了
#560:01:46.260:01:49.16Newman2-EN-4K
CaptchaBot
#570:01:49.160:01:51.04Newman2-CN-4K
谁在乎呢?
#580:01:49.160:01:51.04Newman2-EN-4K
Who cares
#590:01:52.960:01:55.46Newman2-CN-4K
好了 网站被报告为不安全
#600:01:52.960:01:55.46Newman2-EN-4K
Alright
#610:01:55.520:01:56.52Newman2-CN-4K
我们已经看到了
#620:01:55.520:01:56.52Newman2-EN-4K
We've already seen that.
#630:01:57.120:01:58.22Newman2-CN-4K
这网站有点问题
#640:01:57.120:01:58.22Newman2-EN-4K
It has some issues.
#650:02:02.810:02:05.73Newman2-CN-4K
老兄 我还得为这个假Cloudflare验证码干活
#660:02:02.810:02:05.73Newman2-EN-4K
Man
#670:02:05.830:02:06.59Newman2-CN-4K
拜托 兄弟
#680:02:05.830:02:06.59Newman2-EN-4K
Come on
#690:02:08.030:02:08.87Newman2-CN-4K
它刚才还能加载
#700:02:08.030:02:08.87Newman2-EN-4K
It just loaded.
#710:02:09.670:02:11.05Newman2-CN-4K
就在我开始录屏前
#720:02:09.670:02:11.05Newman2-EN-4K
Like
#730:02:11.190:02:13.33Newman2-CN-4K
我随手试了个curl请求
#740:02:11.190:02:13.33Newman2-EN-4K
I was doing a Hail Mary curl request
#750:02:13.390:02:14.65Newman2-CN-4K
居然成功了
#760:02:13.390:02:14.65Newman2-EN-4K
and it actually loaded.
#770:02:14.650:02:16.39Newman2-CN-4K
现在又不行了
#780:02:14.650:02:16.39Newman2-EN-4K
And it no longer loads.
#790:02:16.510:02:17.05Newman2-CN-4K
搞什么鬼?
#800:02:16.510:02:17.05Newman2-EN-4K
What the hell?
#810:02:18.050:02:19.69Newman2-CN-4K
好了 我要换IP了
#820:02:18.050:02:19.69Newman2-EN-4K
Alright
#830:02:20.490:02:22.73Newman2-CN-4K
OK 我又切了一次IP
#840:02:20.490:02:22.73Newman2-EN-4K
Alright
#850:02:23.150:02:24.13Newman2-CN-4K
再试一次
#860:02:23.150:02:24.13Newman2-EN-4K
Let's give this a whirl.
#870:02:24.910:02:26.05Newman2-CN-4K
哦 太棒了
#880:02:24.910:02:26.05Newman2-EN-4K
Oh
#890:02:26.790:02:28.01Newman2-CN-4K
终于出来了
#900:02:26.790:02:28.01Newman2-EN-4K
There we go
#910:02:32.690:02:35.55Newman2-CN-4K
“完成下方操作以验证您是人类”
#920:02:32.690:02:35.55Newman2-EN-4K
Verify you're a human by completing the action below.
#930:02:36.170:02:37.93Newman2-CN-4K
这里嵌了个iframe
#940:02:36.170:02:37.93Newman2-EN-4K
And here we got an iframe.
#950:02:38.690:02:43.57Newman2-CN-4K
这个iframe...我的天
#960:02:38.690:02:43.57Newman2-EN-4K
And the iframe is... oh my lord.
#970:02:44.090:02:45.47Newman2-CN-4K
能直接看源码吗?
#980:02:44.090:02:45.47Newman2-EN-4K
Can I just view the source?
#990:02:46.370:02:47.99Newman2-CN-4K
这个iframe被判定为不安全
#1000:02:46.370:02:47.99Newman2-EN-4K
The iframe is considered unsafe
#1010:02:48.110:02:49.45Newman2-CN-4K
所以不显示
#1020:02:48.110:02:49.45Newman2-EN-4K
so it doesn't render.
#1030:02:50.450:02:53.65Newman2-CN-4K
老天 让我看下源码吧
#1040:02:50.450:02:53.65Newman2-EN-4K
Oh lord
#1050:02:54.850:02:57.07Newman2-CN-4K
可能再也加载不出来了
#1060:02:54.850:02:57.07Newman2-EN-4K
I might not load this ever again.
#1070:02:58.230:02:59.87Newman2-CN-4K
iframe在哪?
#1080:02:58.230:02:59.87Newman2-EN-4K
Where's the iframe at?
#1090:03:00.750:03:03.31Newman2-CN-4K
源码里有个reference.html
#1100:03:00.750:03:03.31Newman2-EN-4K
So
#1110:03:03.650:03:05.03Newman2-CN-4K
我们可以单独运行这个
#1120:03:03.650:03:05.03Newman2-EN-4K
We can run this separately.
#1130:03:08.160:03:09.30Newman2-CN-4K
好 明白了
#1140:03:08.160:03:09.30Newman2-EN-4K
Okay
#1150:03:10.140:03:14.72Newman2-CN-4K
他们基本就是抄袭了Cloudflare验证码
#1160:03:10.140:03:14.72Newman2-EN-4K
So I think they basically ripped off the Cloudflare Captcha
#1170:03:14.960:03:17.10Newman2-CN-4K
里面嵌了个iframe
#1180:03:14.960:03:17.10Newman2-EN-4K
and it contained an iframe
#1190:03:17.280:03:21.52Newman2-CN-4K
直接拿Cloudflare模板当蓝本了
#1200:03:17.280:03:21.52Newman2-EN-4K
so they just used the Cloudflare template as a blueprint.
#1210:03:21.520:03:25.34Newman2-CN-4K
有没有办法能关掉这个?
#1220:03:21.520:03:25.34Newman2-EN-4K
Is there any way I can somehow turn this off?
#1230:03:25.620:03:26.82Newman2-CN-4K
烦死了
#1240:03:25.620:03:26.82Newman2-EN-4K
It's annoying me.
#1250:03:27.320:03:28.30Newman2-CN-4K
好了 开始操作
#1260:03:27.320:03:28.30Newman2-EN-4K
Alright
#1270:03:28.560:03:30.60Newman2-CN-4K
Edge设置 隐私
#1280:03:28.560:03:30.60Newman2-EN-4K
Edge settings
#1290:03:33.490:03:35.39Newman2-CN-4K
SmartScreen
#1300:03:33.490:03:35.39Newman2-EN-4K
smart screen.
#1310:03:36.490:03:38.55Newman2-CN-4K
把这破玩意儿关掉
#1320:03:36.490:03:38.55Newman2-EN-4K
Turn this crap off.
#1330:03:39.630:03:43.05Newman2-CN-4K
{\move(1920,2050,1916,1626,1420,1503)}然后刷新网站试试
#1340:03:39.630:03:43.05Newman2-EN-4K
{\move(1920,2120,1916,1700,1420,1503)}And let's update the website to get access to it.
#1350:03:41.390:03:44.39Newman-CN-4K
{\blur10\pos(2172,1824)}*在 X 上关注!
#1360:03:46.120:03:47.36Newman2-CN-4K
千万要成功啊
#1370:03:46.120:03:47.36Newman2-EN-4K
Please work.
#1380:03:48.240:03:50.46Newman2-CN-4K
我得再换个IP
#1390:03:48.240:03:50.46Newman2-EN-4K
I want to change the IP again.
#1400:03:51.520:03:53.06Newman2-CN-4K
好了 搞定了
#1410:03:51.520:03:53.06Newman2-EN-4K
Okay
#1420:03:53.400:03:53.72Newman2-CN-4K
搞定了
#1430:03:53.400:03:53.72Newman2-EN-4K
We're good.
#1440:03:53.820:03:55.22Newman2-CN-4K
又拿到个新IP地址
#1450:03:53.820:03:55.22Newman2-EN-4K
I got another IP address.
#1460:03:56.180:03:57.40Newman2-CN-4K
这次得谨慎使用
#1470:03:56.180:03:57.40Newman2-EN-4K
Let's use it wisely.
#1480:03:59.460:04:05.24Newman2-CN-4K
访问故意拼错的CaptchaBot.cc
#1490:03:59.460:04:05.24Newman2-EN-4K
By entering CaptchaBot.cc with Captcha being misspelled.
#1500:04:06.740:04:07.42Newman2-CN-4K
妙啊!
#1510:04:06.740:04:07.42Newman2-EN-4K
Lovely!
#1520:04:07.700:04:10.20Newman2-CN-4K
终于没有微软SmartScreen了
#1530:04:07.700:04:10.20Newman2-EN-4K
Finally
#1540:04:11.360:04:13.88Newman2-CN-4K
好了 这就是网站的样子
#1550:04:11.360:04:13.88Newman2-EN-4K
Okay
#1560:04:14.940:04:18.54Newman2-CN-4K
CaptchaBot.cc 请完成下方验证以确认你是人类
#1570:04:14.940:04:18.54Newman2-EN-4K
CaptchaBot.cc
#1580:04:19.380:04:23.62Newman2-CN-4K
本质上就是个山寨版Cloudflare验证码
#1590:04:19.380:04:23.62Newman2-EN-4K
And essentially
#1600:04:24.160:04:26.52Newman2-CN-4K
看起来毫无违和感
#1610:04:24.160:04:26.52Newman2-EN-4K
It doesn't look off at all.
#1620:04:27.400:04:29.20Newman2-CN-4K
有隐私政策按钮
#1630:04:27.400:04:29.20Newman2-EN-4K
You get the privacy button
#1640:04:29.340:04:30.32Newman2-CN-4K
服务条款按钮
#1650:04:29.340:04:30.32Newman2-EN-4K
you get the terms button
#1660:04:30.420:04:34.32Newman2-CN-4K
还有RayID 装得跟真的一样
#1670:04:30.420:04:34.32Newman2-EN-4K
you get the RayID
#1680:04:35.480:04:37.90Newman2-CN-4K
直到你点击复选框
#1690:04:35.480:04:37.90Newman2-EN-4K
Until you hit the checkbox.
#1700:04:39.540:04:42.66Newman2-CN-4K
“正在等待Cloudflare验证您的连接”
#1710:04:39.540:04:42.66Newman2-EN-4K
Please wait while Cloudflare validates your connection.
#1720:04:43.680:04:45.10Newman2-CN-4K
“需要额外验证”
#1730:04:43.680:04:45.10Newman2-EN-4K
Extra verification needed.
#1740:04:45.840:04:48.38Newman2-CN-4K
“按Win+R打开运行对话框”
#1750:04:45.840:04:48.38Newman2-EN-4K
Press Windows plus R to open the run dialog
#1760:04:48.960:04:51.94Newman2-CN-4K
“按Ctrl+V粘贴验证文本”
#1770:04:48.960:04:51.94Newman2-EN-4K
paste the verification text by pressing CTRL plus V
#1780:04:52.560:04:55.04Newman2-CN-4K
“点击OK确认你不是机器人”
#1790:04:52.560:04:55.04Newman2-EN-4K
press OK to verify you're not a robot.
#1800:04:55.740:04:58.08Newman2-CN-4K
这就是为什么 折腾这么久
#1810:04:55.740:04:58.08Newman2-EN-4K
This is why
#1820:04:58.280:05:00.54Newman2-CN-4K
我在找假的Cloudflare验证码
#1830:04:58.280:05:00.54Newman2-EN-4K
I was looking for a fake Cloudflare Captcha.
#1840:05:00.960:05:03.06Newman2-CN-4K
因为它看起来最逼真
#1850:05:00.960:05:03.06Newman2-EN-4K
Because it looks the most genuine.
#1860:05:03.580:05:05.18Newman2-CN-4K
我觉得这里应该有一张图片
#1870:05:03.580:05:05.18Newman2-EN-4K
And I think there's supposed to be an image
#1880:05:05.280:05:06.86Newman2-CN-4K
但不知为何图片没有加载出来
#1890:05:05.280:05:06.86Newman2-EN-4K
but it didn't load for some reason.
#1900:05:07.060:05:08.16Newman2-CN-4K
等等 不对 它没加载出来
#1910:05:07.060:05:08.16Newman2-EN-4K
Oh wait
#1920:05:08.240:05:09.22Newman2-CN-4K
好吧 没有图片
#1930:05:08.240:05:09.22Newman2-EN-4K
Okay
#1940:05:09.740:05:11.62Newman2-CN-4K
不过看起来还是挺像真的
#1950:05:09.740:05:11.62Newman2-EN-4K
Well
#1960:05:11.940:05:12.30Newman2-CN-4K
对吧?
#1970:05:11.940:05:12.30Newman2-EN-4K
right?
#1980:05:13.060:05:14.24Newman2-CN-4K
作为一个技术宅
#1990:05:13.060:05:14.24Newman2-EN-4K
I mean
#2000:05:14.400:05:19.26Newman2-CN-4K
我明白这是恶意软件 他们想感染我的电脑
#2010:05:14.400:05:19.26Newman2-EN-4K
I understand this is a malware and they're trying to infect me.
#2020:05:19.260:05:21.72Newman2-CN-4K
但对于不懂技术的人来说
#2030:05:19.260:05:21.72Newman2-EN-4K
But as a tech illiterate person
#2040:05:22.060:05:24.82Newman2-CN-4K
我可能就直接粘贴了
#2050:05:22.060:05:24.82Newman2-EN-4K
I might as well just paste that.
#2060:05:25.400:05:27.22Newman2-CN-4K
这手法相当狡猾
#2070:05:25.400:05:27.22Newman2-EN-4K
So it's very crafty.
#2080:05:27.700:05:30.54Newman2-CN-4K
他们利用了运行框的特性
#2090:05:27.700:05:30.54Newman2-EN-4K
They're using the property of a run box.
#2100:05:31.120:05:42.18Newman2-CN-4K
这个文本框长度有限 必须向左滚动才能看到真正的命令内容
#2110:05:31.120:05:42.18Newman2-EN-4K
The fact this text box has a limited length and you have to scroll to the left to get to the actual meat of the command.
#2120:05:42.180:05:46.70Newman2-CN-4K
而rem在批处理中就是注释
#2130:05:42.180:05:46.70Newman2-EN-4K
And rem is pretty much a comment in batch.
#2140:05:47.220:05:49.06Newman2-CN-4K
所以他们只是写了段注释
#2150:05:47.220:05:49.06Newman2-EN-4K
So they just made a comment
#2160:05:49.260:05:55.32Newman2-CN-4K
除了让你忽略实际运行的命令外毫无作用
#2170:05:49.260:05:55.32Newman2-EN-4K
which does nothing
#2180:05:55.440:05:56.36Newman2-CN-4K
真正的命令藏在最开头
#2190:05:55.440:05:56.36Newman2-EN-4K
which is at the beginning.
#2200:05:57.360:06:01.54Newman2-CN-4K
执行的是conhost.exe
#2210:05:57.360:06:01.54Newman2-EN-4K
And the command is conhost.exe
#2220:06:01.860:06:04.94Newman2-CN-4K
启动无头模式 运行cmd脚本
#2230:06:01.860:06:04.94Newman2-EN-4K
start headless
#2240:06:05.600:06:14.96Newman2-CN-4K
进入用户配置文件 然后从这个IP和端口保存a.exe
#2250:06:05.600:06:14.96Newman2-EN-4K
enter user profile
#2260:06:16.060:06:21.78Newman2-CN-4K
然后再次以无头模式运行conhost.exe
#2270:06:16.060:06:21.78Newman2-EN-4K
And then run conhost.exe headless again
#2280:06:21.920:06:25.28Newman2-CN-4K
然后基本上就是运行a.exe
#2290:06:21.920:06:25.28Newman2-EN-4K
and then pretty much run the a.exe.
#2300:06:25.720:06:26.24Newman2-CN-4K
就这样
#2310:06:25.720:06:26.24Newman2-EN-4K
That's it.
#2320:06:27.340:06:29.78Newman2-CN-4K
这不是MSHTA的方式
#2330:06:27.340:06:29.78Newman2-EN-4K
It's not the MSHTA way
#2340:06:29.980:06:35.44Newman2-CN-4K
但这又是另一种欺骗反恶意软件的手段
#2350:06:29.980:06:35.44Newman2-EN-4K
but it's another way of tricking the anti-malware into thinking you're actually running conhos
#2360:06:35.560:06:39.54Newman2-CN-4K
而conhost正在运行的代码就在这里
#2370:06:35.560:06:39.54Newman2-EN-4K
and conhost is running this code right here.
#2380:06:40.200:06:42.82Newman2-CN-4K
让我们看看这到底是怎么回事
#2390:06:40.200:06:42.82Newman2-EN-4K
So let's see what it's all about.
#2400:06:42.820:06:47.06Newman2-CN-4K
我完全可以剥离这个命令里的任何部分
#2410:06:42.820:06:47.06Newman2-EN-4K
I mean
#2420:06:47.340:06:52.38Newman2-CN-4K
但我打算单独下载这个
#2430:06:47.340:06:52.38Newman2-EN-4K
but I think I'm gonna download this separately.
#2440:06:54.680:06:55.68Newman2-CN-4K
漂亮 完美
#2450:06:54.680:06:55.68Newman2-EN-4K
Yeah
#2460:06:55.880:06:56.78Newman2-CN-4K
我们成功下载了
#2470:06:55.880:06:56.78Newman2-EN-4K
We get the download.
#2480:06:57.300:06:59.14Newman2-CN-4K
它有3MB大小
#2490:06:57.300:06:59.14Newman2-EN-4K
It's three megabytes long.
#2500:07:01.200:07:03.54Newman2-CN-4K
很明显 这是个病毒
#2510:07:01.200:07:03.54Newman2-EN-4K
It's a virus
#2520:07:08.040:07:09.52Newman2-CN-4K
它不让我下载
#2530:07:08.040:07:09.52Newman2-EN-4K
It doesn't let me download
#2540:07:10.440:07:11.40Newman2-CN-4K
我想下载它
#2550:07:10.440:07:11.40Newman2-EN-4K
I want to download it.
#2560:07:13.860:07:16.84Newman2-CN-4K
我得先把Microsoft Defender关掉
#2570:07:13.860:07:16.84Newman2-EN-4K
I need to turn off Microsoft Defender first.
#2580:07:19.840:07:21.62Newman2-CN-4K
Microsoft Defender对恶意程序太敏感了
#2590:07:19.840:07:21.62Newman2-EN-4K
It's so annoying when it comes to malware.
#2600:07:22.260:07:26.52Newman2-CN-4K
只要它在 我就没法处理任何恶意程序
#2610:07:22.260:07:26.52Newman2-EN-4K
I can't do anything with malware whenever Microsoft Defender is around.
#2620:07:27.640:07:29.60Newman2-CN-4K
不过它本来就应该这样
#2630:07:27.640:07:29.60Newman2-EN-4K
I mean
#2640:07:29.640:07:29.82Newman2-CN-4K
对吧?
#2650:07:29.640:07:29.82Newman2-EN-4K
right?
#2660:07:31.260:07:33.16Newman2-CN-4K
来看看这个文件的属性
#2670:07:31.260:07:33.16Newman2-EN-4K
Let's check out the properties of this file.
#2680:07:34.040:07:34.64Newman2-CN-4K
空的
#2690:07:34.040:07:34.64Newman2-EN-4K
Nothing.
#2700:07:34.920:07:35.74Newman2-CN-4K
什么都没有
#2710:07:34.920:07:35.74Newman2-EN-4K
Nothing here.
#2720:07:36.920:07:37.86Newman2-CN-4K
真有意思
#2730:07:36.920:07:37.86Newman2-EN-4K
Very interesting.
#2740:07:40.500:07:42.62Newman2-CN-4K
那我们就运行这个吧
#2750:07:40.500:07:42.62Newman2-EN-4K
So that's what we're going to run.
#2760:07:42.740:07:44.54Newman2-CN-4K
它会保存到我的用户配置文件里
#2770:07:42.740:07:44.54Newman2-EN-4K
It's gonna save it to my user profile.
#2780:07:45.220:07:46.62Newman2-CN-4K
就存在这个文件夹
#2790:07:45.220:07:46.62Newman2-EN-4K
It's gonna save it right here
#2800:07:46.700:07:48.16Newman2-CN-4K
然后运行它
#2810:07:46.700:07:48.16Newman2-EN-4K
in this folder
#2820:07:48.620:07:54.30Newman2-CN-4K
我打开任务管理器 让你看清发生了什么
#2830:07:48.620:07:54.30Newman2-EN-4K
I'm gonna run the Task Manager and show you exactly what happens.
#2840:07:55.580:07:56.46Newman2-CN-4K
点击确定
#2850:07:55.580:07:56.46Newman2-EN-4K
Press OK.
#2860:07:57.940:07:58.90Newman2-CN-4K
Conhost正在运行
#2870:07:57.940:07:58.90Newman2-EN-4K
Conhost is running.
#2880:07:59.980:08:00.64Newman2-CN-4K
检测到威胁
#2890:07:59.980:08:00.64Newman2-EN-4K
Threats found.
#2900:08:01.300:08:02.00Newman2-CN-4K
没关系
#2910:08:01.300:08:02.00Newman2-EN-4K
Doesn't matter.
#2920:08:02.180:08:03.32Newman2-CN-4K
出现a.exe
#2930:08:02.180:08:03.32Newman2-EN-4K
There's a.exe.
#2940:08:04.820:08:06.52Newman2-CN-4K
这能检测到lobin吗
#2950:08:04.820:08:06.52Newman2-EN-4K
Is this gonna detect the lobin?
#2960:08:06.720:08:07.84Newman2-CN-4K
不 它检测到的是...
#2970:08:06.720:08:07.84Newman2-EN-4K
No
#2980:08:09.000:08:10.42Newman2-CN-4K
恶意文件本身
#2990:08:09.000:08:10.42Newman2-EN-4K
malicious file itself
#3000:08:10.740:08:11.38Newman2-CN-4K
正在运行的恶意文件
#3010:08:10.740:08:11.38Newman2-EN-4K
which is running.
#3020:08:12.840:08:14.82Newman2-CN-4K
之后天知道会发生什么
#3030:08:12.840:08:14.82Newman2-EN-4K
And then
#3040:08:15.480:08:20.02Newman2-CN-4K
我猜这个可执行文件内置了反虚拟机机制
#3050:08:15.480:08:20.02Newman2-EN-4K
So I'm assuming this executable has an anti-VM inside of it.
#3060:08:20.120:08:21.54Newman2-CN-4K
含有反虚拟机代码
#3070:08:20.120:08:21.54Newman2-EN-4K
It has anti-VM code.
#3080:08:21.680:08:22.66Newman2-CN-4K
具备虚拟机检测功能
#3090:08:21.680:08:22.66Newman2-EN-4K
It has VM detection.
#3100:08:24.020:08:26.08Newman2-CN-4K
所以它不会真正运行...
#3110:08:24.020:08:26.08Newman2-EN-4K
So it's not going to run...
#3120:08:27.780:08:29.66Newman2-CN-4K
不会执行任何操作
#3130:08:27.780:08:29.66Newman2-EN-4K
It's not going to do anything.
#3140:08:29.760:08:30.96Newman2-CN-4K
任何实质性操作
#3150:08:29.760:08:30.96Newman2-EN-4K
Anything of importance.
#3160:08:32.240:08:35.90Newman2-CN-4K
好的 这就是我从虚拟机里提取的a.exe文件
#3170:08:32.240:08:35.90Newman2-EN-4K
Okay
#3180:08:36.220:08:37.58Newman2-CN-4K
现在我们处于加固的虚拟机环境中
#3190:08:36.220:08:37.58Newman2-EN-4K
Now we're in a hardened VM.
#3200:08:37.840:08:39.50Newman2-CN-4K
那我们来看看它会有什么行为
#3210:08:37.840:08:39.50Newman2-EN-4K
So let's go ahead and see what it does.
#3220:08:41.500:08:45.34Newman2-CN-4K
我照例运行安装追踪器和进程黑客工具
#3230:08:41.500:08:45.34Newman2-EN-4K
I'm gonna run the Installation Tracker and Process Hacker as usual.
#3240:08:45.520:08:48.78Newman2-CN-4K
我就不深入分析这个恶意软件了
#3250:08:45.520:08:48.78Newman2-EN-4K
I'm not gonna go super in-depth into the malware analysis.
#3260:08:48.980:08:51.42Newman2-CN-4K
你可以用any.run这类工具来实现
#3270:08:48.980:08:51.42Newman2-EN-4K
You can do that with tools like any.run.
#3280:08:51.680:08:52.62Newman2-CN-4K
但我只是想
#3290:08:51.680:08:52.62Newman2-EN-4K
But I just
#3300:08:52.940:08:54.40Newman2-CN-4K
我懒得折腾了 老兄
#3310:08:52.940:08:54.40Newman2-EN-4K
I can't be bothered
#3320:08:55.620:08:57.30Newman2-CN-4K
因为这些都是很常见的套路
#3330:08:55.620:08:57.30Newman2-EN-4K
Because all this is pretty generic.
#3340:08:58.480:08:59.74Newman2-CN-4K
那就直接运行它吧
#3350:08:58.480:08:59.74Newman2-EN-4K
But let's go ahead and run that.
#3360:09:03.780:09:05.44Newman2-CN-4K
正在安装a.exe
#3370:09:03.780:09:05.44Newman2-EN-4K
Installing a.exe.
#3380:09:07.240:09:08.18Newman2-CN-4K
出现了
#3390:09:07.240:09:08.18Newman2-EN-4K
There it is.
#3400:09:08.180:09:09.82Newman2-CN-4K
出现了
#3410:09:08.180:09:09.82Newman2-EN-4K
There it is.
#3420:09:10.100:09:11.18Newman2-CN-4K
应用程序启动
#3430:09:10.100:09:11.18Newman2-EN-4K
App launch.
#3440:09:12.020:09:14.93Newman2-CN-4K
applaunch.exe
#3450:09:12.020:09:14.93Newman2-EN-4K
applaunch.exe
#3460:09:18.810:09:19.73Newman2-CN-4K
等等
#3470:09:18.810:09:19.73Newman2-EN-4K
Hold up.
#3480:09:21.010:09:24.95Newman2-CN-4K
它似乎在伪装成微软.NET框架
#3490:09:21.010:09:24.95Newman2-EN-4K
I think it impersonates microsoft.net framework.
#3500:09:26.450:09:28.91Newman2-CN-4K
哦 它被添加到了启动项
#3510:09:26.450:09:28.91Newman2-EN-4K
Oh
#3520:09:30.570:09:33.41Newman2-CN-4K
这样每次开机都会自动运行
#3530:09:30.570:09:33.41Newman2-EN-4K
So it's gonna run on every startup.
#3540:09:35.450:09:37.67Newman2-CN-4K
然后它启动了applaunch程序
#3550:09:35.450:09:37.67Newman2-EN-4K
And then it started the app launch.
#3560:09:38.150:09:40.09Newman2-CN-4K
但我实在不太明白为什么
#3570:09:38.150:09:40.09Newman2-EN-4K
But I don't really quite get why.
#3580:09:41.330:09:43.03Newman2-CN-4K
有命令行参数吗
#3590:09:41.330:09:43.03Newman2-EN-4K
Is there any command line?
#3600:09:44.170:09:45.07Newman2-CN-4K
嗯 其实没有
#3610:09:44.170:09:45.07Newman2-EN-4K
Well
#3620:09:47.790:09:49.39Newman2-CN-4K
applaunch.exe 是干什么用的
#3630:09:47.790:09:49.39Newman2-EN-4K
What is applaunch for
#3640:09:50.610:09:52.53Newman2-CN-4K
我觉得这是个误导线索
#3650:09:50.610:09:52.53Newman2-EN-4K
I think that's a red herring.
#3660:09:53.390:09:55.63Newman2-CN-4K
我不认为它有什么实际功能
#3670:09:53.390:09:55.63Newman2-EN-4K
I don't think it does anything.
#3680:09:56.450:10:00.25Newman2-CN-4K
它只是把自己保存到一个文件夹里 然后把自己添加到启动项
#3690:09:56.450:10:00.25Newman2-EN-4K
It just saves itself into a folder and then puts itself on startup.
#3700:10:00.850:10:01.79Newman2-CN-4K
会不会是窃密程序?
#3710:10:00.850:10:01.79Newman2-EN-4K
Could it be a stealer?
#3720:10:01.790:10:03.09Newman2-CN-4K
好的
#3730:10:01.790:10:03.09Newman2-EN-4K
Okay.
#3740:10:03.810:10:05.99Newman2-CN-4K
所以它又会再次自启动
#3750:10:03.810:10:05.99Newman2-EN-4K
So it's gonna start itself yet again.
#3760:10:07.090:10:08.97Newman2-CN-4K
我有点想看看现在到底什么情况了
#3770:10:07.090:10:08.97Newman2-EN-4K
I kind of want to see what's going on already.
#3780:10:11.210:10:12.95Newman2-CN-4K
我需要用Process Hacker来查看
#3790:10:11.210:10:12.95Newman2-EN-4K
I need Process Hacker for that.
#3800:10:16.170:10:18.83Newman2-CN-4K
a.exe 刚刚随资源管理器启动了
#3810:10:16.170:10:18.83Newman2-EN-4K
a.exe just started with Explorer
#3820:10:19.190:10:20.29Newman2-CN-4K
显然如此
#3830:10:19.190:10:20.29Newman2-EN-4K
obviously.
#3840:10:20.810:10:21.97Newman2-CN-4K
来看看它要做什么
#3850:10:20.810:10:21.97Newman2-EN-4K
Let's see what it does.
#3860:10:22.730:10:26.91Newman2-CN-4K
applaunch.exe 老实说
#3870:10:22.730:10:26.91Newman2-EN-4K
applaunch.exe Honestly
#3880:10:27.070:10:29.23Newman2-CN-4K
我完全搞不清楚状况
#3890:10:27.070:10:29.23Newman2-EN-4K
I don't really know what's going on.
#3900:10:29.230:10:32.43Newman2-CN-4K
它会不会在往那个进程里注入东西?
#3910:10:29.230:10:32.43Newman2-EN-4K
Could it be injecting something into that process?
#3920:10:36.040:10:37.14Newman2-CN-4K
我有点懵
#3930:10:36.040:10:37.14Newman2-EN-4K
I'm puzzled.
#3940:10:38.320:10:42.42Newman2-CN-4K
如果评论区有哪位大神想解释这种现象
#3950:10:38.320:10:42.42Newman2-EN-4K
If anyone in the comments down below want to explain why that happens
#3960:10:42.960:10:46.04Newman2-CN-4K
以及它创建applaunch.exe的潜在原因
#3970:10:42.960:10:46.04Newman2-EN-4K
and what could be the potential reason why it creates applaunch
#3980:10:46.660:10:47.52Newman2-CN-4K
欢迎畅所欲言
#3990:10:46.660:10:47.52Newman2-EN-4K
be my guest.
#4000:10:48.000:10:48.86Newman2-CN-4K
请在下方留言
#4010:10:48.000:10:48.86Newman2-EN-4K
Comment down below.
#4020:10:50.140:10:55.00Newman2-CN-4K
与此同时 我的订阅用户又发来个虚假Cloudflare验证码
#4030:10:50.140:10:55.00Newman2-EN-4K
And in the meantime
#4040:10:55.220:10:59.08Newman2-CN-4K
这域名...我连念都懒得念
#4050:10:55.220:10:59.08Newman2-EN-4K
which is... I mean
#4060:11:00.220:11:01.90Newman2-CN-4K
界面长这样
#4070:11:00.220:11:01.90Newman2-EN-4K
So here's how it looks.
#4080:11:02.000:11:02.94Newman2-CN-4K
有点不同
#4090:11:02.000:11:02.94Newman2-EN-4K
It's a little different.
#4100:11:03.420:11:06.00Newman2-CN-4K
它压根不支持暗黑模式
#4110:11:03.420:11:06.00Newman2-EN-4K
It doesn't do dark mode at all.
#4120:11:06.180:11:07.22Newman2-CN-4K
连装都不装一下
#4130:11:06.180:11:07.22Newman2-EN-4K
It doesn't even try.
#4140:11:08.700:11:11.10Newman2-CN-4K
但你看 这里根本没有链接
#4150:11:08.700:11:11.10Newman2-EN-4K
But yeah
#4160:11:11.220:11:12.52Newman2-CN-4K
不像CaptchaBot那样
#4170:11:11.220:11:12.52Newman2-EN-4K
as opposed to CaptchaBot
#4180:11:12.540:11:14.12Newman2-CN-4K
这破玩意儿根本加载不出来
#4190:11:12.540:11:14.12Newman2-EN-4K
which doesn't freaking load
#4200:11:14.400:11:16.32Newman2-CN-4K
但我会剪辑进去做个对比
#4210:11:14.400:11:16.32Newman2-EN-4K
but I'm gonna edit that in to compare.
#4220:11:18.020:11:19.62Newman2-CN-4K
而且看起来就很假
#4230:11:18.020:11:19.62Newman2-EN-4K
And it looks kind of fake.
#4240:11:19.800:11:21.44Newman2-CN-4K
稍微山寨点
#4250:11:19.800:11:21.44Newman2-EN-4K
It's a little cheaper.
#4260:11:21.820:11:23.34Newman2-CN-4K
做工明显更廉价
#4270:11:21.820:11:23.34Newman2-EN-4K
It's a little more cheaply made.
#4280:11:24.200:11:25.80Newman2-CN-4K
它每次都会重新加载
#4290:11:24.200:11:25.80Newman2-EN-4K
It reloads every single time.
#4300:11:26.000:11:27.26Newman2-CN-4K
我什么都做不了
#4310:11:26.000:11:27.26Newman2-EN-4K
I can't even do anything.
#4320:11:27.260:11:30.22Newman2-CN-4K
但一旦我们点击“我不是机器人”
#4330:11:27.260:11:30.22Newman2-EN-4K
But once we click
#4340:11:30.480:11:31.30Newman2-CN-4K
来看看会发生什么
#4350:11:30.480:11:31.30Newman2-EN-4K
Let's see what happens.
#4360:11:32.340:11:33.54Newman2-CN-4K
这就是它的操作
#4370:11:32.340:11:33.54Newman2-EN-4K
That's what it does.
#4380:11:34.020:11:36.22Newman2-CN-4K
为了更好地证明你不是机器人...
#4390:11:34.020:11:36.22Newman2-EN-4K
To better prove you're not a robot...
#4400:11:36.220:11:38.76Newman2-CN-4K
为了更好地证明你不是机器人
#4410:11:36.220:11:38.76Newman2-EN-4K
To better prove you're not a robot
#4420:11:38.900:11:39.78Newman2-CN-4K
行吧 请便
#4430:11:38.900:11:39.78Newman2-EN-4K
sure
#4440:11:40.740:11:43.18Newman2-CN-4K
按住Windows键加R键
#4450:11:40.740:11:43.18Newman2-EN-4K
Press and hold the Windows key plus R.
#4460:11:43.460:11:44.54Newman2-CN-4K
在验证窗口中
#4470:11:43.460:11:44.54Newman2-EN-4K
In the verification window
#4480:11:44.640:11:47.22Newman2-CN-4K
按Ctrl V 再按键盘回车键完成
#4490:11:44.640:11:47.22Newman2-EN-4K
press Ctrl V
#4500:11:47.680:11:49.76Newman2-CN-4K
你将看到并同意
#4510:11:47.680:11:49.76Newman2-EN-4K
You will observe and agree.
#4520:11:49.980:11:50.80Newman2-CN-4K
天啊 老兄
#4530:11:49.980:11:50.80Newman2-EN-4K
Oh my god
#4540:11:50.860:11:51.36Newman2-CN-4K
快点
#4550:11:50.860:11:51.36Newman2-EN-4K
Come on.
#4560:11:51.740:11:52.42Newman2-CN-4K
快点 现在
#4570:11:51.740:11:52.42Newman2-EN-4K
Come on now.
#4580:11:52.540:11:54.50Newman2-CN-4K
别每次都重启
#4590:11:52.540:11:54.50Newman2-EN-4K
Stop restarting every time.
#4600:11:54.500:11:57.40Newman2-CN-4K
你将看到并同意
#4610:11:54.500:11:57.40Newman2-EN-4K
You will observe and agree.
#4620:11:57.980:11:59.14Newman2-CN-4K
我不是机器人
#4630:11:57.980:11:59.14Newman2-EN-4K
I am not a robot.
#4640:11:59.500:12:03.06Newman2-CN-4K
验证码ID 645221
#4650:11:59.500:12:03.06Newman2-EN-4K
Recaptcha verification ID 645221.
#4660:12:03.480:12:05.46Newman2-CN-4K
按照上述步骤完成验证
#4670:12:03.480:12:05.46Newman2-EN-4K
Perform the steps above to finish verification.
#4680:12:06.020:12:09.42Newman2-CN-4K
我不明白验证码跟这些有什么关系
#4690:12:06.020:12:09.42Newman2-EN-4K
I don't know what Recaptcha has to do with any of that
#4700:12:09.540:12:10.12Newman2-CN-4K
但好吧
#4710:12:09.540:12:10.12Newman2-EN-4K
but sure.
#4720:12:11.800:12:14.34Newman2-CN-4K
我根本没时间点击验证按钮
#4730:12:11.800:12:14.34Newman2-EN-4K
I didn't have enough time to press verify
#4740:12:14.440:12:16.94Newman2-CN-4K
因为每次都会刷新
#4750:12:14.440:12:16.94Newman2-EN-4K
because it updates every single time.
#4760:12:16.940:12:18.08Newman2-CN-4K
等等
#4770:12:16.940:12:18.08Newman2-EN-4K
Oh
#4780:12:18.200:12:18.74Newman2-CN-4K
稍等
#4790:12:18.200:12:18.74Newman2-EN-4K
Hold up.
#4800:12:20.720:12:23.02Newman2-CN-4K
它有没有复制东西到剪贴板?
#4810:12:20.720:12:23.02Newman2-EN-4K
Did it copy anything into my clipboard?
#4820:12:23.660:12:25.90Newman2-CN-4K
让我粘贴到记事本里
#4830:12:23.660:12:25.90Newman2-EN-4K
Let me unload it into Notepad.
#4840:12:26.860:12:29.15Newman2-CN-4K
如果Windows的网页搜索能用的话...
#4850:12:26.860:12:29.15Newman2-EN-4K
If the web search in Windows works...
#4860:12:30.000:12:30.78Newman2-CN-4K
等等
#4870:12:30.000:12:30.78Newman2-EN-4K
Oh
#4880:12:31.320:12:31.94Newman2-CN-4K
真的
#4890:12:31.320:12:31.94Newman2-EN-4K
Really.
#4900:12:32.160:12:32.70Newman2-CN-4K
成功了
#4910:12:32.160:12:32.70Newman2-EN-4K
It worked.
#4920:12:33.240:12:34.82Newman2-CN-4K
来看看这家伙到底在干嘛
#4930:12:33.240:12:34.82Newman2-EN-4K
So let's see what this guy does.
#4940:12:37.320:12:38.00Newman2-CN-4K
PowerShell
#4950:12:37.320:12:38.00Newman2-EN-4K
PowerShell.
#4960:12:38.060:12:39.02Newman2-CN-4K
搜索PowerShell
#4970:12:38.060:12:39.02Newman2-EN-4K
Search PowerShell.
#4980:12:39.360:12:41.78Newman2-CN-4K
然后它混淆了字符串
#4990:12:39.360:12:41.78Newman2-EN-4K
Then it obfuscates the string.
#5000:12:42.680:12:45.12Newman2-CN-4K
HTTP加S加那部分
#5010:12:42.680:12:45.12Newman2-EN-4K
HTTP plus S plus that.
#5020:12:45.220:12:46.60Newman2-CN-4K
它拼接了字符串
#5030:12:45.220:12:46.60Newman2-EN-4K
It concatenates the string.
#5040:12:47.880:12:54.36Newman2-CN-4K
没错 这就是绕过反恶意软件检测恶意链接的方法之一
#5050:12:47.880:12:54.36Newman2-EN-4K
But yeah
#5060:12:54.540:12:56.82Newman2-CN-4K
通过混淆和拼接字符串
#5070:12:54.540:12:56.82Newman2-EN-4K
It's to obfuscate and concatenate the strings.
#5080:12:57.160:12:58.88Newman2-CN-4K
这是其中一种手段
#5090:12:57.160:12:58.88Newman2-EN-4K
That's one of the ways.
#5100:12:58.880:13:00.82Newman2-CN-4K
然后它添加了链接
#5110:12:58.880:13:00.82Newman2-EN-4K
And it just adds the link.
#5120:13:04.640:13:08.66Newman2-CN-4K
这里又有一段混淆代码
#5130:13:04.640:13:08.66Newman2-EN-4K
And then another bit of obfuscation here.
#5140:13:13.420:13:15.54Newman2-CN-4K
它创建了一个对象
#5150:13:13.420:13:15.54Newman2-EN-4K
It creates an object.
#5160:13:15.900:13:18.58Newman2-CN-4K
对 我猜就是下载可执行文件然后运行
#5170:13:15.900:13:18.58Newman2-EN-4K
Yeah
#5180:13:18.820:13:20.24Newman2-CN-4K
至少原理是这样
#5190:13:18.820:13:20.24Newman2-EN-4K
Well
#5200:13:21.520:13:23.20Newman2-CN-4K
我有点不敢运行
#5210:13:21.520:13:23.20Newman2-EN-4K
I am afraid to run it
#5220:13:23.320:13:24.26Newman2-CN-4K
但还是试试吧
#5230:13:23.320:13:24.26Newman2-EN-4K
but let's do it.
#5240:13:26.080:13:28.46Newman2-CN-4K
天啊 这看起来太可怕了
#5250:13:26.080:13:28.46Newman2-EN-4K
Oh God
#5260:13:28.560:13:30.54Newman2-CN-4K
不过还是通过运行窗口执行吧
#5270:13:28.560:13:30.54Newman2-EN-4K
but let's do it via the run box.
#5280:13:31.080:13:31.38Newman2-CN-4K
确定
#5290:13:31.080:13:31.38Newman2-EN-4K
Sure.
#5300:13:31.820:13:33.80Newman2-CN-4K
我要...我要规范化操作
#5310:13:31.820:13:33.80Newman2-EN-4K
I'm gonna... I'm gonna make it canonical.
#5320:13:35.240:13:36.26Newman2-CN-4K
看看会发生什么
#5330:13:35.240:13:36.26Newman2-EN-4K
See what it does.
#5340:13:43.230:13:47.63Newman2-CN-4K
事实证明现在网上充斥着这类虚假的程序
#5350:13:43.230:13:47.63Newman2-EN-4K
Apparently
#5360:13:48.350:13:50.29Newman2-CN-4K
只是我不知道怎么找到它们
#5370:13:48.350:13:50.29Newman2-EN-4K
I just don't know how to find them.
#5380:13:52.530:13:53.99Newman2-CN-4K
真的什么都没发生?
#5390:13:52.530:13:53.99Newman2-EN-4K
It really does nothing?
#5400:13:54.150:13:54.59Newman2-CN-4K
什么?
#5410:13:54.150:13:54.59Newman2-EN-4K
What?
#5420:13:54.710:13:55.19Newman2-CN-4K
不可能
#5430:13:54.710:13:55.19Newman2-EN-4K
No way.
#5440:13:55.590:13:56.23Newman2-CN-4K
肯定...
#5450:13:55.590:13:56.23Newman2-EN-4K
It must be...
#5460:13:59.030:14:00.55Newman2-CN-4K
为什么它会自动关闭?
#5470:13:59.030:14:00.55Newman2-EN-4K
Why does it self-close?
#5480:14:01.750:14:03.41Newman2-CN-4K
启动PowerShell
#5490:14:01.750:14:03.41Newman2-EN-4K
Let's start PowerShell.
#5500:14:08.620:14:10.44Newman2-CN-4K
天啊 别这样
#5510:14:08.620:14:10.44Newman2-EN-4K
Oh my god
#5520:14:11.300:14:12.84Newman2-CN-4K
哦 它在下载一个txt文件
#5530:14:11.300:14:12.84Newman2-EN-4K
Oh
#5540:14:12.960:14:13.44Newman2-CN-4K
是啊 当然
#5550:14:12.960:14:13.44Newman2-EN-4K
Yeah
#5560:14:13.760:14:13.98Newman2-CN-4K
当然
#5570:14:13.760:14:13.98Newman2-EN-4K
Sure.
#5580:14:14.260:14:17.34Newman2-CN-4K
然后大概会把t替换成e之类的
#5590:14:14.260:14:17.34Newman2-EN-4K
And then it's probably like replacing t's with e's.
#5600:14:18.340:14:20.18Newman2-CN-4K
某种类似的替换操作
#5610:14:18.340:14:20.18Newman2-EN-4K
Some kind of thing like that.
#5620:14:22.080:14:24.10Newman2-CN-4K
$c是个变量
#5630:14:22.080:14:24.10Newman2-EN-4K
$c
#5640:14:24.320:14:27.46Newman2-CN-4K
我们...来还原混淆字符串
#5650:14:24.320:14:27.46Newman2-EN-4K
Well
#5660:14:28.040:14:28.74Newman2-CN-4K
这还挺有意思
#5670:14:28.040:14:28.74Newman2-EN-4K
That's kind of fun.
#5680:14:29.900:14:30.92Newman2-CN-4K
等等 什么?
#5690:14:29.900:14:30.92Newman2-EN-4K
Wait
#5700:14:31.700:14:33.28Newman2-CN-4K
哦 刚才卡了一下
#5710:14:31.700:14:33.28Newman2-EN-4K
Oh
#5720:14:34.940:14:36.70Newman2-CN-4K
我们快速反混淆一下
#5730:14:34.940:14:36.70Newman2-EN-4K
Let's deobfuscate that real quick.
#5740:14:38.990:14:41.58Newman2-CN-4K
阿里巴巴巴巴
#5750:14:38.990:14:41.58Newman2-EN-4K
Alibabababa.
#5760:14:42.960:14:44.44Newman2-CN-4K
等等 阿拉巴巴
#5770:14:42.960:14:44.44Newman2-EN-4K
Wait
#5780:14:44.660:14:45.02Newman2-CN-4K
抱歉
#5790:14:44.660:14:45.02Newman2-EN-4K
I'm sorry.
#5800:14:53.520:14:54.34Newman2-CN-4K
kh在哪?
#5810:14:53.520:14:54.34Newman2-EN-4K
Where's kh?
#5820:14:58.480:15:00.24Newman2-CN-4K
哦 kh等于那个加b
#5830:14:58.480:15:00.24Newman2-EN-4K
Oh
#5840:15:00.560:15:04.56Newman2-CN-4K
也就是双斜杠加$c
#5850:15:00.560:15:04.56Newman2-EN-4K
which is the double slash plus $c
#5860:15:04.920:15:07.70Newman2-CN-4K
也就是cvg加后面那些
#5870:15:04.920:15:07.70Newman2-EN-4K
which is cvg plus all that.
#5880:15:18.680:15:19.52Newman2-CN-4K
i是什么?
#5890:15:18.680:15:19.52Newman2-EN-4K
What is i?
#5900:15:19.660:15:22.92Newman2-CN-4K
i已经是...可执行脚本的一部分
#5910:15:19.660:15:22.92Newman2-EN-4K
i is already... it's a part of the executable script.
#5920:15:26.260:15:27.92Newman2-CN-4K
哦 没了
#5930:15:26.260:15:27.92Newman2-EN-4K
Oh
#5940:15:28.320:15:29.50Newman2-CN-4K
是吗?
#5950:15:28.320:15:29.50Newman2-EN-4K
Is it?
#5960:15:29.560:15:31.79Newman2-CN-4K
阿拉巴巴巴巴
#5970:15:29.560:15:31.79Newman2-EN-4K
Alababababa.
#5980:15:32.340:15:33.62Newman2-CN-4K
所以才会失败
#5990:15:32.340:15:33.62Newman2-EN-4K
This is why it's failing.
#6000:15:33.940:15:34.40Newman2-CN-4K
好吧
#6010:15:33.940:15:34.40Newman2-EN-4K
Okay
#6020:15:35.300:15:44.02Newman2-CN-4K
这些虚假验证页面正是通过这类花招来绕过反病毒检测
#6030:15:35.300:15:44.02Newman2-EN-4K
But yes
#6040:15:46.970:15:49.45Newman2-CN-4K
这是个假冒的Cloudflare验证
#6050:15:46.970:15:49.45Newman2-EN-4K
Yeah
#6060:15:49.570:15:51.17Newman2-CN-4K
这个假得太明显了
#6070:15:49.570:15:51.17Newman2-EN-4K
This one is not plausible at all.
#6080:15:51.170:15:53.64Newman2-CN-4K
不过之前那个验证机器人页面做得还挺像样的
#6090:15:51.170:15:53.64Newman2-EN-4K
The capture bot one was pretty good
#6100:15:53.790:15:55.03Newman2-CN-4K
这点得承认
#6110:15:53.790:15:55.03Newman2-EN-4K
I'm gonna give them that.
#6120:15:58.030:15:59.71Newman2-CN-4K
放进运行框里
#6130:15:58.030:15:59.71Newman2-EN-4K
Put that in the run box.
#6140:16:01.550:16:05.05Newman2-CN-4K
发现是相同IP相同端口相同文件
#6150:16:01.550:16:05.05Newman2-EN-4K
Find out it's the same IP and the same port and the same file.
#6160:16:05.870:16:07.77Newman2-CN-4K
这下可以结案了
#6170:16:05.870:16:07.77Newman2-EN-4K
And we can be done with that.
#6180:16:08.290:16:10.21Newman2-CN-4K
感谢观看 保重
#6190:16:08.290:16:10.21Newman2-EN-4K
Thanks for watching and take care.
#6200:16:11.580:16:31.49Newman-CN-4K
{\blur90\fad(200,200)\fscx185\fscy188\pos(1885.333,840)}在 Youtube 上关注
#6210:16:03.090:16:08.09Newman-CN-4K
{\blur10\fad(200,200)\pos(1953.333,496)}原标题:Can you spot this Fake CAPTCHA 原作者:Enderman\N
原视频上传日期:2025年8月7日
#6220:16:12.160:16:17.16Newman-CN-4K
{\blur10\fad(200,200)\pos(1909.333,1220)}翻译/压制/字幕制作:HAF半个水果\N
翻译质量权威评价:原来25年就有小拉即用机翻糊弄人了
#6230:16:17.440:16:22.44Newman-CN-4K
{\blur10\fad(200,200)\pos(1889.334,1336)}♥本视频在Enderman频道会员有效期内翻译♥\N
如果你喜欢这个视频,请多多支持和评论哒~ o((>ω< ))o\N
字幕制作不易,喜欢的话支持一下我吧!