GitHub ↗ ← 返回

How much malware can you get from fake CAPTCHAs?.ass

Enderman/How much malware can you get from fake CAPTCHAs?.assASS共 1148 条字幕
样式信息 (4)
Newman-CN-4K
名称Newman-CN-4K字体等距更纱黑体 SC字号125主色&H0055FFFF辅色&H000000FF描边色&H00FF43E4背景色&H00FF2FFF粗体0斜体0下划线0删除线0水平缩放100垂直缩放100间距0角度0边框样式1描边1.5阴影1.2对齐2左边距10右边距10垂直边距20编码1
Newman2-CN-4K
名称Newman2-CN-4K字体HarmonyOS Sans SC字号165主色&H00A0FFF5辅色&H00000000描边色&H96000000背景色&H00000000粗体0斜体0下划线0删除线0水平缩放100垂直缩放95间距0角度0边框样式3描边0.1阴影0对齐2左边距10右边距10垂直边距110编码1
Newman2-EN-4K
名称Newman2-EN-4K字体思源黑体 CN字号75主色&H00E0E0E0辅色&H000000FF描边色&H96000000背景色&HD2000000粗体0斜体0下划线0删除线0水平缩放100垂直缩放95间距0.6角度0边框样式3描边0.1阴影0对齐2左边距10右边距10垂直边距40编码1
Newman2-mod-4K
名称Newman2-mod-4K字体Unifont字号100主色&H00A0FFF5辅色&H00000000描边色&H96000000背景色&H00000000粗体0斜体0下划线0删除线0水平缩放100垂直缩放100间距0角度0边框样式1描边3阴影0.5对齐2左边距10右边距10垂直边距20编码1
#10:00:00.310:00:07.44Newman-CN-4K
{\blur10\fad(200,200)}翻译/压制/字幕制作:HAF半个水果
#20:00:08.640:00:18.64Newman-CN-4K
{\blur10\fad(200,200)\pos(1913.334,1908)}使用AI工具翻译,如有不准确的地方请在弹幕或评论区指正,谢谢!\N
!!真的有人看不到这行字!!
#30:00:19.140:00:24.14Newman-CN-4K
{\blur10\fad(200,200)\pos(1937.334,528)}翻译质量权威评价:原来25年就有小拉即用机翻糊弄人了
#40:00:24.640:00:29.64Newman-CN-4K
{\blur10\fad(200,200)\pos(1937.334,548)}♥本视频在Enderman频道会员有效期内翻译♥
#50:00:07.960:00:13.22Newman2-CN-4K
大家好 本期视频我们将上演一场假验证码大乱斗
#60:00:07.960:00:13.22Newman2-EN-4K
Hello everyone
#70:00:08.840:00:10.48Newman2-mod-4K
{\c&HE683E7&\move(4636,460,3204,448,27,544)}挑战完成!\N
{\c&HFFFFFF&}醒来吧,为观众们献上盛宴
#80:00:10.480:00:16.03Newman2-mod-4K
{\c&HE683E7&\move(3204,448,4472,456,5120,5404)}挑战完成!\N
{\c&HFFFFFF&}醒来吧,为观众们献上盛宴
#90:00:13.840:00:15.63Newman2-CN-4K
在之前的几期视频中
#100:00:13.840:00:15.63Newman2-EN-4K
So in the last couple videos
#110:00:15.640:00:23.23Newman2-CN-4K
我已多次证实 假验证码在当今非常普遍 而我实在不擅长发现它们
#120:00:15.640:00:23.23Newman2-EN-4K
I have been proven time and time again that fake Captcha are really common nowadays and I'm just really bad at finding them.
#130:00:23.410:00:25.88Newman2-CN-4K
以下是我一位订阅者提供的清单
#140:00:23.410:00:25.88Newman2-EN-4K
So here is a list
#150:00:26.140:00:27.96Newman2-CN-4K
MC Edge为我整理的一份清单
#160:00:26.140:00:27.96Newman2-EN-4K
MC Edge
#170:00:26.140:00:32.14Newman-CN-4K注释
{\blur10\pos(2880,1876)}*B站昵称:我的世界Edge UID:576823848*
#180:00:28.320:00:31.30Newman2-CN-4K
而每一个域名都是假的验证码
#190:00:28.320:00:31.30Newman2-EN-4K
and every domain is a fake Captcha.
#200:00:31.680:00:37.80Newman2-CN-4K
那么 我们将逐一访问清单上的每个网站 并执行它们要求的所有指令
#210:00:31.680:00:37.80Newman2-EN-4K
So we're gonna enter every site in this list and execute every command it asks us to execute.
#220:00:38.460:00:39.26Newman2-CN-4K
这就是挑战所在
#230:00:38.460:00:39.26Newman2-EN-4K
That's the challenge.
#240:00:39.440:00:42.84Newman2-CN-4K
目标就是... 我也不确定
#250:00:39.440:00:42.84Newman2-EN-4K
The objective is to
#260:00:43.020:00:44.20Newman2-CN-4K
让电脑感染恶意软件
#270:00:43.020:00:44.20Newman2-EN-4K
infect the computer with malware.
#280:00:44.820:00:45.48Newman2-CN-4K
开始行动吧
#290:00:44.820:00:45.48Newman2-EN-4K
So let's go.
#300:00:45.640:00:47.40Newman2-CN-4K
先运行第一个
#310:00:45.640:00:47.40Newman2-EN-4K
Let's go ahead and run the first one.
#320:00:48.140:00:49.70Newman2-CN-4K
看过前几期视频的观众
#330:00:48.140:00:49.70Newman2-EN-4K
If you watched the previous video
#340:00:49.800:00:51.40Newman2-CN-4K
可能记得这个域名
#350:00:49.800:00:51.40Newman2-EN-4K
you might remember this domain.
#360:00:52.140:00:53.84Newman2-CN-4K
这是个假冒的YouTube验证页面
#370:00:52.140:00:53.84Newman2-EN-4K
This is a fake YouTube Captcha.
#380:00:54.480:00:55.66Newman2-CN-4K
现在我们来运行它
#390:00:54.480:00:55.66Newman2-EN-4K
So let's go ahead and run that.
#400:00:56.260:00:58.88Newman2-CN-4K
首先会弹出真实的验证提示
#410:00:56.260:00:58.88Newman2-EN-4K
First we get a real Captcha at the beginning.
#420:00:58.880:01:06.32Newman2-CN-4K
等验证我们是真人后
#430:00:58.880:01:06.32Newman2-EN-4K
And then
#440:01:06.740:01:09.30Newman2-CN-4K
就会显示伪造的验证通知
#450:01:06.740:01:09.30Newman2-EN-4K
we get a fake Captcha.
#460:01:09.820:01:10.58Newman2-CN-4K
这操作妙不妙?
#470:01:09.820:01:10.58Newman2-EN-4K
Isn't that lovely?
#480:01:11.240:01:14.52Newman2-CN-4K
我挺意外这网站居然还没被标记为恶意站点
#490:01:11.240:01:14.52Newman2-EN-4K
I'm surprised it's still not been flagged as a malicious website.
#500:01:15.400:01:17.06Newman2-CN-4K
在继续访问YouTube前
#510:01:15.400:01:17.06Newman2-EN-4K
So before you continue to YouTube
#520:01:17.860:01:22.68Newman2-CN-4K
勾选这个复选框就会触发验证流程
#530:01:17.860:01:22.68Newman2-EN-4K
tick this checkbox and we get the verification steps.
#540:01:23.260:01:30.10Newman2-CN-4K
我准备新建个文档专门记录它要求执行的所有指令
#550:01:23.260:01:30.10Newman2-EN-4K
So I'm going to create another document where I'm going to save every command it asks us to execute.
#560:01:30.320:01:33.80Newman2-CN-4K
这绝对会很有意思
#570:01:30.320:01:33.80Newman2-EN-4K
I think this is going to be super nice.
#580:01:33.860:01:36.30Newman2-CN-4K
就像MapReduce那种分布式运算
#590:01:33.860:01:36.30Newman2-EN-4K
It's going to be like a MapReduce kind of thing.
#600:01:38.580:01:40.28Newman2-CN-4K
好 开始了
#610:01:38.580:01:40.28Newman2-EN-4K
Yeah
#620:01:41.600:01:42.04Newman2-CN-4K
漂亮
#630:01:41.600:01:42.04Newman2-EN-4K
Beautiful.
#640:01:42.220:01:43.00Newman2-CN-4K
瞧瞧这条指令
#650:01:42.220:01:43.00Newman2-EN-4K
Look at this command.
#660:01:43.640:01:44.94Newman2-CN-4K
这操作完全没毛病
#670:01:43.640:01:44.94Newman2-EN-4K
It's not suspicious at all.
#680:01:46.860:01:48.40Newman2-CN-4K
启动mshta进程
#690:01:46.860:01:48.40Newman2-EN-4K
Start process mshta.
#700:01:48.420:01:50.62Newman2-CN-4K
运行框里看着可太正常了
#710:01:48.420:01:50.62Newman2-EN-4K
It doesn't look suspicious in the run box at all.
#720:01:51.160:01:52.56Newman2-CN-4K
我可听不懂你在暗示什么
#730:01:51.160:01:52.56Newman2-EN-4K
I don't know what you're talking about.
#740:01:52.560:01:53.40Newman2-CN-4K
直接运行就完事了
#750:01:52.560:01:53.40Newman2-EN-4K
We're going to run this.
#760:01:54.120:01:54.42Newman2-CN-4K
哇哦
#770:01:54.120:01:54.42Newman2-EN-4K
Wow.
#780:01:54.640:01:58.38Newman2-CN-4K
这些域名八成是同一个人注册的
#790:01:54.640:01:58.38Newman2-EN-4K
I think these domains are owned by the same person.
#800:02:01.080:02:01.62Newman2-CN-4K
好家伙
#810:02:01.080:02:01.62Newman2-EN-4K
Damn.
#820:02:03.900:02:06.44Newman2-CN-4K
看吧 又弹出同样的验证窗口
#830:02:03.900:02:06.44Newman2-EN-4K
Oh
#840:02:07.440:02:13.04Newman2-CN-4K
差点忘了说 这些网站都是按它们仿冒的对象分类的
#850:02:07.440:02:13.04Newman2-EN-4K
And I almost forgot to mention that these websites are categorized by the website they're trying to mimic.
#860:02:13.620:02:16.70Newman2-CN-4K
所以第一类是YouTube诈骗网站
#870:02:13.620:02:16.70Newman2-EN-4K
So the first category is YouTube scams.
#880:02:16.700:02:22.90Newman2-CN-4K
所以你会先看到“继续前往YouTube前请验证”的界面
#890:02:16.700:02:22.90Newman2-EN-4K
So you get a before you continue to YouTube screen with a oh
#900:02:22.900:02:25.54Newman2-CN-4K
没错 弹出的还是同样的指令
#910:02:22.900:02:25.54Newman2-EN-4K
yeah
#920:02:26.000:02:32.74Newman2-CN-4K
所以这又是一个未被标记的域名 此刻正在实时传播恶意软件
#930:02:26.000:02:32.74Newman2-EN-4K
So that's another domain that's not been flagged and it's serving malware live right now.
#940:02:33.540:02:34.52Newman2-CN-4K
太棒了
#950:02:33.540:02:34.52Newman2-EN-4K
That's great.
#960:02:37.660:02:38.18Newman2-CN-4K
有意思
#970:02:37.660:02:38.18Newman2-EN-4K
Interesting.
#980:02:38.340:02:41.66Newman2-CN-4K
这是目前为止看起来最可信的域名了
#990:02:38.340:02:41.66Newman2-EN-4K
That's the most plausible looking domain so far.
#1000:02:42.420:02:44.46Newman2-CN-4K
你还会遇到Cloudflare验证码
#1010:02:42.420:02:44.46Newman2-EN-4K
You also get a Cloudflare captcha.
#1020:02:46.480:02:49.98Newman2-CN-4K
估计又是老一套的把戏 换汤不换药
#1030:02:46.480:02:49.98Newman2-EN-4K
Imagine it's just going to be the same thing over and over again.
#1040:02:52.080:02:55.08Newman2-CN-4K
是啊 看起来又是同样的套路 不断重复
#1050:02:52.080:02:55.08Newman2-EN-4K
Yeah
#1060:02:55.360:02:56.20Newman2-CN-4K
但这无关紧要
#1070:02:55.360:02:56.20Newman2-EN-4K
but it doesn't matter.
#1080:02:56.740:02:59.74Newman-CN-4K注释
{\blur10\pos(2172,1824)}*在 X 上关注!
#1090:02:57.020:02:58.04Newman2-CN-4K
{\pos(1920,1626)}是啊 老兄
#1100:02:57.020:02:58.04Newman2-EN-4K
{\pos(1920,1696)}Yeah
#1110:02:58.960:02:59.86Newman2-CN-4K
{\pos(1880,1626)}我的天哪
#1120:02:58.960:02:59.86Newman2-EN-4K
{\pos(1880,1696)}Holy moly.
#1130:03:03.940:03:06.92Newman2-CN-4K
果然 这五个网站弹出的都是同样的指令
#1140:03:03.940:03:06.92Newman2-EN-4K
And yep
#1150:03:07.920:03:17.40Newman2-CN-4K
这五个域名都指向同一个恶意网站\N
而且这些域名全都没有被安全平台标记
#1160:03:07.920:03:17.40Newman2-EN-4K
These five domains serve this exact same website and this website is malicious and none of these domains are flagged and
#1170:03:17.400:03:26.68Newman2-CN-4K
其中一个域名叫做YouTube-site.com 还有个叫YouTubeapprv 以及ReplyYouTube.com
#1180:03:17.400:03:26.68Newman2-EN-4K
one of the domains is called YouTubesite.com and one of them is YouTubeapprv and ReplyYouTube.com.
#1190:03:26.840:03:36.21Newman2-CN-4K
这让我确信部分恶意软件正通过电子邮件传播他们才能疯狂钓鱼\N
利用这些域名 对用户进行钓鱼攻击
#1200:03:26.840:03:29.31Newman2-EN-4K
So this makes me believe part of this malware is
#1210:03:29.310:03:36.21Newman2-EN-4K
being distributed through email so that they can fish the hell out of people using that domain.
#1220:03:37.920:03:41.14Newman2-CN-4K
但无论如何 这是我们提取到的第一条指令
#1230:03:37.920:03:41.14Newman2-EN-4K
But anyways
#1240:03:42.300:03:51.46Newman2-CN-4K
这充分说明虚假验证码有多泛滥 它们正被大规模分发 而且这些域名
#1250:03:42.300:03:51.46Newman2-EN-4K
And this just goes out to show how common the fake captchas are and they're being distributed in masses and the domains
#1260:03:51.460:03:52.88Newman2-CN-4K
正在被批量购买
#1270:03:51.460:03:52.88Newman2-EN-4K
being bought in bulk
#1280:03:53.780:04:00.44Newman2-CN-4K
这也意味着不断有人上当受骗 大家真的该提高警惕了
#1290:03:53.780:04:00.44Newman2-EN-4K
which also in turn means that people fall for this and you guys should stop falling for that.
#1300:04:00.440:04:05.14Newman2-CN-4K
这是目前最新型的诈骗手法
#1310:04:00.440:04:05.14Newman2-EN-4K
That's kind of the newest trick in the book
#1320:04:05.300:04:07.66Newman2-CN-4K
但这招其实还是有点拙劣的
#1330:04:05.300:04:07.66Newman2-EN-4K
but it's still kind of
#1340:04:10.580:04:12.00Newman2-CN-4K
我认为这属于同一个幕后黑手
#1350:04:10.580:04:12.00Newman2-EN-4K
I think it's owned by the same person.
#1360:04:12.580:04:13.72Newman2-CN-4K
我无法否认
#1370:04:12.580:04:13.72Newman2-EN-4K
I can't even lie.
#1380:04:14.500:04:15.86Newman2-CN-4K
是的 这些手法如出一辙
#1390:04:14.500:04:15.86Newman2-EN-4K
Yeah
#1400:04:17.280:04:22.06Newman2-CN-4K
我准备把所有订房网站都测试一遍
#1410:04:17.280:04:22.06Newman2-EN-4K
I'm just going to insert every booking website.
#1420:04:24.100:04:27.70Newman2-CN-4K
是的 这些网站都暂时受到Cloudflare保护
#1430:04:24.100:04:27.70Newman2-EN-4K
Yeah
#1440:04:29.940:04:32.74Newman2-CN-4K
我只是说这些网站都受Cloudflare保护
#1450:04:29.940:04:32.74Newman2-EN-4K
I'm just saying it's all protected by Cloudflare.
#1460:04:34.680:04:38.26Newman2-CN-4K
所有这类域名都该被举报滥用
#1470:04:34.680:04:38.26Newman2-EN-4K
Every domain like this should get an abuse report.
#1480:04:43.700:04:43.90Newman2-CN-4K
#1490:04:43.700:04:43.90Newman2-EN-4K
Cool.
#1500:04:45.940:04:56.51Newman2-CN-4K
所以我们发现了一个仿冒的booking.com网站 有着同样风格的验证码 和同样逼真的滚动条
#1510:04:45.940:04:56.51Newman2-EN-4K
So we get a fake booking.com website with the same kind of looking captcha and the same genuine looking scroll on the back.
#1520:05:00.410:05:02.49Newman2-CN-4K
所以手法完全一致
#1530:05:00.410:05:02.49Newman2-EN-4K
So it's absolutely the same
#1540:05:02.750:05:09.03Newman2-CN-4K
不过我发现这次有个不同点 上次的域名是bookvrff.com
#1550:05:02.750:05:09.03Newman2-EN-4K
although there's one difference I'm noticing that last time it was bookvrff.com.
#1560:05:09.170:05:11.67Newman2-CN-4K
现在变成了dmnbkv.com
#1570:05:09.170:05:11.67Newman2-EN-4K
Now it's dmnbkv.com.
#1580:05:11.730:05:12.97Newman2-CN-4K
我们来看看bookvrff
#1590:05:11.730:05:12.97Newman2-EN-4K
Let's check out bookvrff
#1600:05:12.970:05:13.57Newman2-CN-4K
现在情况如何
#1610:05:12.970:05:13.57Newman2-EN-4K
how it's doing.
#1620:05:16.740:05:19.70Newman2-CN-4K
我觉得它被爆破了
#1630:05:16.740:05:19.70Newman2-EN-4K
I think it got blasted.
#1640:05:21.460:05:25.42Newman2-CN-4K
浏览器里依然显示“服务不可用”
#1650:05:21.460:05:25.42Newman2-EN-4K
It's still giving us the service unavailable treatment in the browser
#1660:05:25.580:05:31.32Newman2-CN-4K
但如果我们通过PowerShell运行 它就会下载某些东西
#1670:05:25.580:05:31.32Newman2-EN-4K
but it's going to download something if we run it through PowerShell.
#1680:05:31.560:05:35.90Newman2-CN-4K
这些钓鱼网站的域名正在
#1690:05:31.560:05:35.90Newman2-EN-4K
The domain names for phishing websites like that are being
#1700:05:36.100:05:46.70Newman2-CN-4K
我认为这些域名是人工挑选的 而投放器的域名则是随机生成的
#1710:05:36.100:05:46.70Newman2-EN-4K
I think they're being hand selected and the domains for the droppers are being randomly generated.
#1720:05:48.900:05:52.98Newman2-CN-4K
所以我们收到了三个伪造的booking.com验证码
#1730:05:48.900:05:52.98Newman2-EN-4K
So we get three booking.com fake captchas.
#1740:05:52.980:05:55.52Newman2-CN-4K
我们收到了五个伪造的YouTube验证码
#1750:05:52.980:05:55.52Newman2-EN-4K
We get five YouTube fake captchas.
#1760:05:57.220:06:02.60Newman2-CN-4K
还有一个booking.com的域名 什么内容都没提供给我们
#1770:05:57.220:06:02.60Newman2-EN-4K
And one of the booking.com domains doesn't serve us anything
#1780:06:02.800:06:05.02Newman2-CN-4K
返回了504错误
#1790:06:02.800:06:05.02Newman2-EN-4K
gives us an error 504.
#1800:06:06.260:06:11.16Newman2-CN-4K
我迅速转向Cloudflare验证码
#1810:06:06.260:06:11.16Newman2-EN-4K
I'm moving on swiftly to the Cloudflare captcha
#1820:06:11.280:06:12.64Newman2-CN-4K
伪造的Cloudflare验证码
#1830:06:11.280:06:12.64Newman2-EN-4K
the fake Cloudflare captcha.
#1840:06:13.280:06:15.38Newman2-CN-4K
这是我昨天分析的那个
#1850:06:13.280:06:15.38Newman2-EN-4K
This is the one I reviewed yesterday.
#1860:06:17.300:06:20.16Newman2-CN-4K
通过完成下方操作验证您是人类身份
#1870:06:17.300:06:20.16Newman2-EN-4K
And verify you're human by completing the action below.
#1880:06:21.940:06:22.98Newman2-CN-4K
绝-对-没-错
#1890:06:21.940:06:22.98Newman2-EN-4K
Abso-freaking-lutely.
#1900:06:28.300:06:29.66Newman2-CN-4K
这是命令
#1910:06:28.300:06:29.66Newman2-EN-4K
Here's the command.
#1920:06:29.880:06:34.46Newman2-CN-4K
这是我频道上期视频分析过的另一个命令
#1930:06:29.880:06:34.46Newman2-EN-4K
That's a different command I reviewed in the last video on my channel.
#1940:06:35.580:06:41.82Newman2-CN-4K
这是一个经过混淆的字符串 下载文件并执行
#1950:06:35.580:06:41.82Newman2-EN-4K
It's an obfuscated string that's downloading the file and then running it.
#1960:06:43.240:06:44.20Newman2-CN-4K
太好了
#1970:06:43.240:06:44.20Newman2-EN-4K
So that's great.
#1980:06:44.940:06:46.46Newman2-CN-4K
而我们又发现了一个新的字符串
#1990:06:44.940:06:46.46Newman2-EN-4K
And that's a new string we've got
#2000:06:46.580:06:47.04Newman2-CN-4K
终于
#2010:06:46.580:06:47.04Newman2-EN-4K
finally.
#2020:06:54.560:06:56.14Newman2-EN-4K
So this captcha is dead.
#2030:07:01.080:07:01.60Newman2-CN-4K
金融
#2040:07:01.080:07:01.60Newman2-EN-4K
Financial.
#2050:07:01.760:07:06.88Newman2-CN-4K
它应该是想拼写“金融”
#2060:07:01.760:07:06.88Newman2-EN-4K
I think it's trying to say financial.
#2070:07:07.400:07:08.38Newman2-CN-4K
能加载出来吗?
#2080:07:07.400:07:08.38Newman2-EN-4K
Will it load?
#2090:07:08.640:07:09.36Newman2-CN-4K
这才是关键问题
#2100:07:08.640:07:09.36Newman2-EN-4K
Is the question.
#2110:07:10.100:07:11.58Newman2-CN-4K
该网站已被标记为不安全
#2120:07:10.100:07:11.58Newman2-EN-4K
This site has been reported as unsafe.
#2130:07:11.740:07:11.88Newman2-CN-4K
真棒
#2140:07:11.740:07:11.88Newman2-EN-4K
Lovely.
#2150:07:12.160:07:13.44Newman2-CN-4K
这正是我们要找的
#2160:07:12.160:07:13.44Newman2-EN-4K
That's what we're looking for.
#2170:07:19.360:07:21.78Newman2-CN-4K
请完成下方操作以验证您是人类
#2180:07:19.360:07:21.78Newman2-EN-4K
Verify you're human by completing the action below.
#2190:07:22.880:07:26.16Newman2-CN-4K
这是我第一次见到Cloudflare验证码
#2200:07:22.880:07:26.16Newman2-EN-4K
So this is the first Cloudflare captcha I witnessed.
#2210:07:26.160:07:29.20Newman2-CN-4K
它竟然在伪造域名
#2220:07:26.160:07:29.20Newman2-EN-4K
That it's faking the domain name.
#2230:07:32.160:07:33.72Newman2-CN-4K
点击“我不是机器人”
#2240:07:32.160:07:33.72Newman2-EN-4K
Click I'm not a robot.
#2250:07:33.920:07:34.66Newman2-CN-4K
等等 它没反应
#2260:07:33.920:07:34.66Newman2-EN-4K
Wait
#2270:07:34.740:07:35.08Newman2-CN-4K
对吧?
#2280:07:34.740:07:35.08Newman2-EN-4K
does it?
#2290:07:36.820:07:38.54Newman2-CN-4K
它复制了什么内容吗?
#2300:07:36.820:07:38.54Newman2-EN-4K
Has it copied anything?
#2310:07:38.820:07:40.94Newman2-CN-4K
我的剪贴板里没有任何内容
#2320:07:38.820:07:40.94Newman2-EN-4K
It has not copied anything into my clipboard.
#2330:07:43.060:07:44.98Newman2-CN-4K
让我们手动触发
#2340:07:43.060:07:44.98Newman2-EN-4K
Let's make it happen.
#2350:07:47.300:07:48.34Newman2-CN-4K
脚本在哪里?
#2360:07:47.300:07:48.34Newman2-EN-4K
Where is the script?
#2370:07:48.580:07:49.30Newman2-CN-4K
脚本在这里
#2380:07:48.580:07:49.30Newman2-EN-4K
There is the script.
#2390:07:49.980:07:50.84Newman2-CN-4K
生成令牌
#2400:07:49.980:07:50.84Newman2-EN-4K
Generate token.
#2410:07:51.500:07:51.68Newman2-CN-4K
好的
#2420:07:51.500:07:51.68Newman2-EN-4K
Okay.
#2430:07:52.220:07:53.52Newman2-CN-4K
等等 这是俄语
#2440:07:52.220:07:53.52Newman2-EN-4K
Wait
#2450:07:54.280:07:55.42Newman2-CN-4K
快看
#2460:07:54.280:07:55.42Newman2-EN-4K
Yo
#2470:07:55.420:07:56.82Newman2-CN-4K
这是俄罗斯恶意软件
#2480:07:55.420:07:56.82Newman2-EN-4K
This is Russian malware.
#2490:07:57.560:08:03.64Newman2-CN-4K
这里的意思是删除问号后的所有内容
#2500:07:57.560:08:03.64Newman2-EN-4K
What this is saying here is remove everything after a question mark.
#2510:08:04.460:08:05.96Newman2-CN-4K
那是时间戳
#2520:08:04.460:08:05.96Newman2-EN-4K
That's a timestamp.
#2530:08:06.500:08:08.56Newman2-CN-4K
然后才是主令牌
#2540:08:06.500:08:08.56Newman2-EN-4K
Then it's the main token
#2550:08:08.940:08:10.44Newman2-CN-4K
60个字符长
#2560:08:08.940:08:10.44Newman2-EN-4K
60 characters.
#2570:08:11.440:08:16.20Newman2-CN-4K
其余部分都是随机数
#2580:08:11.440:08:16.20Newman2-EN-4K
And the rest is random nonce.
#2590:08:20.140:08:21.88Newman2-CN-4K
还有更多俄语注释吗?
#2600:08:20.140:08:21.88Newman2-EN-4K
Are there any more Russian comments?
#2610:08:24.380:08:26.46Newman2-CN-4K
所以这段代码源自俄罗斯
#2620:08:24.380:08:26.46Newman2-EN-4K
So this code is of Russian origin
#2630:08:26.600:08:27.72Newman2-CN-4K
知道这点很有用
#2640:08:26.600:08:27.72Newman2-EN-4K
which is nice to know.
#2650:08:29.380:08:33.38Newman2-CN-4K
好的 这就是它试图复制的命令
#2660:08:29.380:08:33.38Newman2-EN-4K
Okay
#2670:08:37.270:08:38.29Newman2-CN-4K
看到了吗?
#2680:08:37.270:08:38.29Newman2-EN-4K
See this?
#2690:08:38.430:08:47.25Newman2-CN-4K
这是另一种混淆方式 他们直接用base64编码命令 然后通过PowerShell运行
#2700:08:38.430:08:47.25Newman2-EN-4K
So this is another type of obfuscation where they just use base64 to encode the command and run it through PowerShell
#2710:08:47.250:08:50.87Newman2-CN-4K
因为PowerShell支持执行base64编码命令
#2720:08:47.250:08:50.87Newman2-EN-4K
because PowerShell supports running base64 encoded commands.
#2730:08:52.510:08:55.07Newman2-CN-4K
所以这里又多了层间接调用
#2740:08:52.510:08:55.07Newman2-EN-4K
So there is another layer of indirection
#2750:08:55.290:08:56.47Newman2-CN-4K
也就是cmd斜杠c
#2760:08:55.290:08:56.47Newman2-EN-4K
which is cmd slash c
#2770:08:56.610:08:58.97Newman2-CN-4K
也就是通过cmd斜杠c来运行脚本
#2780:08:56.610:08:58.97Newman2-EN-4K
which means to run the script.
#2790:08:59.430:09:02.23Newman2-CN-4K
我们马上来解码这段base64
#2800:08:59.430:09:02.23Newman2-EN-4K
Let's go ahead and decode this base64 real quick.
#2810:09:05.110:09:09.75Newman2-CN-4K
这不是utf-8编码 可能是utf-16之类的
#2820:09:05.110:09:09.75Newman2-EN-4K
It's not utf-8
#2830:09:12.740:09:14.04Newman2-CN-4K
抱歉 正在自动检测编码
#2840:09:12.740:09:14.04Newman2-EN-4K
Sorry
#2850:09:15.120:09:16.38Newman2-CN-4K
哦对 太棒了
#2860:09:15.120:09:16.38Newman2-EN-4K
Oh yeah
#2870:09:17.280:09:18.16Newman2-CN-4K
看这个
#2880:09:17.280:09:18.16Newman2-EN-4K
Look at that.
#2890:09:18.640:09:22.22Newman2-CN-4K
所以我们得到了另一种字符串
#2900:09:18.640:09:22.22Newman2-EN-4K
So we get a different kind of a string.
#2910:09:22.820:09:26.52Newman2-CN-4K
基本上 我也不太明白这是什么意思
#2920:09:22.820:09:26.52Newman2-EN-4K
And basically
#2930:09:27.540:09:28.04Newman2-CN-4K
老实说
#2940:09:27.540:09:28.04Newman2-EN-4K
Honestly.
#2950:09:29.260:09:31.78Newman2-CN-4K
HTTPS开头的PowerShell命令
#2960:09:29.260:09:31.78Newman2-EN-4K
HTTPS something PowerShell.
#2970:09:33.100:09:36.32Newman2-CN-4K
看来开头的令牌生成函数
#2980:09:33.100:09:36.32Newman2-EN-4K
So it seems like the token generation function at the beginning
#2990:09:36.700:09:38.50Newman2-CN-4K
当然还带着俄语注释
#3000:09:36.700:09:38.50Newman2-EN-4K
with Russian comments of course
#3010:09:39.140:09:43.34Newman2-CN-4K
和末尾这个随机数有关
#3020:09:39.140:09:43.34Newman2-EN-4K
is related to this nonce at the end.
#3030:09:43.460:09:46.00Newman2-CN-4K
它试图模仿CloudFlare的行为
#3040:09:43.460:09:46.00Newman2-EN-4K
It's trying to mimic the CloudFlare behavior.
#3050:09:46.980:09:51.80Newman2-CN-4K
这和PowerShell命令毫无关系
#3060:09:46.980:09:51.80Newman2-EN-4K
It doesn't have anything to do with the PowerShell command.
#3070:09:52.400:09:58.64Newman2-CN-4K
这可能是另一种混淆手段 他们从这个网站发起网络请求
#3080:09:52.400:09:58.64Newman2-EN-4K
It might be another type of obfuscation where they invoke the web request from this website.
#3090:09:58.880:10:00.12Newman2-CN-4K
而且这里应该有个网站
#3100:09:58.880:10:00.12Newman2-EN-4K
And there's supposed to be a website
#3110:10:00.320:10:05.26Newman2-CN-4K
他们很可能有个中央控制面板 专门为投放器提供虚假域名
#3120:10:00.320:10:05.26Newman2-EN-4K
and they probably have a centralized dashboard where they supply the fake domain names for droppers
#3130:10:05.440:10:11.64Newman2-CN-4K
这些虚假域名会流向下游网站 然后被复制到你的剪贴板里
#3140:10:05.440:10:11.64Newman2-EN-4K
which are streamed down to those websites and then copied into your clipboard.
#3150:10:13.280:10:14.40Newman2-CN-4K
复选框的addEventListener事件
#3160:10:13.280:10:14.40Newman2-EN-4K
Checkbox addEventListener.
#3170:10:16.260:10:19.28Newman2-CN-4K
哦 原来问题出在这里
#3180:10:16.260:10:19.28Newman2-EN-4K
Oh
#3190:10:19.880:10:21.28Newman2-CN-4K
读取writeText方法
#3200:10:19.880:10:21.28Newman2-EN-4K
Reading writeText.
#3210:10:21.440:10:22.34Newman2-CN-4K
writeText在哪?
#3220:10:21.440:10:22.34Newman2-EN-4K
Where is writeText?
#3230:10:25.840:10:27.12Newman2-CN-4K
剪贴板的writeText
#3240:10:25.840:10:27.12Newman2-EN-4K
Clipboard writeText.
#3250:10:28.100:10:30.36Newman2-CN-4K
等等 先别急
#3260:10:28.100:10:30.36Newman2-EN-4K
Oh
#3270:10:30.620:10:31.84Newman2-CN-4K
这难道全是垃圾代码?
#3280:10:30.620:10:31.84Newman2-EN-4K
Is this just garbage?
#3290:10:32.480:10:37.16Newman2-CN-4K
看起来他们直接从其他网站复制粘贴了内容
#3300:10:32.480:10:37.16Newman2-EN-4K
It seems like they just copy-pasted stuff from the other site
#3310:10:37.380:10:40.50Newman2-CN-4K
然后随便塞了点东西进去
#3320:10:37.380:10:40.50Newman2-EN-4K
and then just put another thing in here.
#3330:10:41.100:10:43.96Newman2-CN-4K
所以这才是他们真正执行的命令
#3340:10:41.100:10:43.96Newman2-EN-4K
So this is the real command they're executing.
#3350:10:45.100:10:47.92Newman2-CN-4K
点击与否其实无关紧要
#3360:10:45.100:10:47.92Newman2-EN-4K
It doesn't really matter if we click or not.
#3370:10:47.920:10:50.76Newman2-CN-4K
所有代码都能在控制台看到
#3380:10:47.920:10:50.76Newman2-EN-4K
All the code is available in the console.
#3390:10:51.460:10:53.54Newman2-CN-4K
我觉得他们只是搞砸了JavaScript
#3400:10:51.460:10:53.54Newman2-EN-4K
I think they just actually messed up the JS
#3410:10:54.280:10:55.16Newman2-CN-4K
不过没关系
#3420:10:54.280:10:55.16Newman2-EN-4K
but it's okay.
#3430:10:55.340:10:55.94Newman2-CN-4K
这样反而更好
#3440:10:55.340:10:55.94Newman2-EN-4K
It's for the better.
#3450:10:57.620:11:01.56Newman2-CN-4K
他们从某个假Cloudflare网站
#3460:10:57.620:11:01.56Newman2-EN-4K
So they just ripped off this command from some other website
#3470:11:01.840:11:02.90Newman2-CN-4K
直接照搬了这个命令
#3480:11:01.840:11:02.90Newman2-EN-4K
fake Cloudflare website
#3490:11:03.080:11:07.04Newman2-CN-4K
然后插入了这段代码
#3500:11:03.080:11:07.04Newman2-EN-4K
and then they inserted this.
#3510:11:09.220:11:11.08Newman2-CN-4K
现在这样看起来好多了
#3520:11:09.220:11:11.08Newman2-EN-4K
And this looks much better.
#3530:11:11.080:11:17.38Newman2-CN-4K
这里执行的是PowerShell发起网络请求
#3540:11:11.080:11:17.38Newman2-EN-4K
What it does here
#3550:11:17.520:11:18.02Newman2-CN-4K
发起一个fetch请求
#3560:11:17.520:11:18.02Newman2-EN-4K
a fetch.
#3570:11:18.280:11:21.72Newman2-CN-4K
它通过XMLHttp发起请求
#3580:11:18.280:11:21.72Newman2-EN-4K
It fetches using XMLHttp
#3590:11:21.840:11:22.72Newman2-CN-4K
就像JS那样
#3600:11:21.840:11:22.72Newman2-EN-4K
just like JS.
#3610:11:23.380:11:27.76Newman2-CN-4K
然后它对$h执行getHttpRequest
#3620:11:23.380:11:27.76Newman2-EN-4K
Then it does a getHttpRequest to $h
#3630:11:27.840:11:29.62Newman2-CN-4K
这里$h就是变量
#3640:11:27.840:11:29.62Newman2-EN-4K
which is the variable here.
#3650:11:30.440:11:32.90Newman2-CN-4K
它本质上是在下载这个文件
#3660:11:30.440:11:32.90Newman2-EN-4K
It basically downloads this file.
#3670:11:33.800:11:35.12Newman2-CN-4K
这是一样的操作
#3680:11:33.800:11:35.12Newman2-EN-4K
That's the same thing.
#3690:11:35.900:11:37.32Newman2-CN-4K
每当你获取一个文件时
#3700:11:35.900:11:37.32Newman2-EN-4K
Whenever you get a file
#3710:11:37.420:11:38.40Newman2-CN-4K
它就会下载该文件
#3720:11:37.420:11:38.40Newman2-EN-4K
it downloads the file.
#3730:11:40.400:11:41.36Newman2-CN-4K
然后...
#3740:11:40.400:11:41.36Newman2-EN-4K
And then...
#3750:11:42.380:11:42.86Newman2-CN-4K
IEX(交互式执行环境)
#3760:11:42.380:11:42.86Newman2-EN-4K
IEX.
#3770:11:43.060:11:45.50Newman2-CN-4K
它只是打开文件并执行脚本
#3780:11:43.060:11:45.50Newman2-EN-4K
It just opens it
#3790:11:46.240:11:48.64Newman2-CN-4K
我们继续看看这到底是怎么回事
#3800:11:46.240:11:48.64Newman2-EN-4K
Let's go ahead and check what's this all about.
#3810:11:52.340:11:53.66Newman2-CN-4K
而且它是经过混淆处理的
#3820:11:52.340:11:53.66Newman2-EN-4K
And it's obfuscated.
#3830:11:53.800:11:55.46Newman2-CN-4K
看起来又是Base64编码
#3840:11:53.800:11:55.46Newman2-EN-4K
It looks like Base64 again
#3850:11:55.540:11:55.94Newman2-CN-4K
不是吗?
#3860:11:55.540:11:55.94Newman2-EN-4K
doesn't it?
#3870:11:56.800:11:58.80Newman2-CN-4K
哦对 确实是Base64编码
#3880:11:56.800:11:58.80Newman2-EN-4K
Oh yeah
#3890:11:59.060:11:59.32Newman2-CN-4K
等等
#3900:11:59.060:11:59.32Newman2-EN-4K
Wait.
#3910:12:00.000:12:01.14Newman2-CN-4K
等等 等一下 等一下
#3920:12:00.000:12:01.14Newman2-EN-4K
Wait
#3930:12:01.180:12:01.86Newman2-CN-4K
稍等一下
#3940:12:01.180:12:01.86Newman2-EN-4K
hold up a second.
#3950:12:02.680:12:04.54Newman2-CN-4K
还是说这只是混淆手段?
#3960:12:02.680:12:04.54Newman2-EN-4K
Or is this just obfuscation?
#3970:12:05.300:12:07.98Newman2-CN-4K
因为我看到末尾有些内容
#3980:12:05.300:12:07.98Newman2-EN-4K
Because I see something at the end.
#3990:12:08.540:12:12.60Newman2-CN-4K
看起来关键部分在文件底部
#4000:12:08.540:12:12.60Newman2-EN-4K
So it looks like the meat is at the bottom of the file.
#4010:12:13.840:12:18.24Newman2-CN-4K
好的 我认为开头是个Base64编码的可执行文件
#4020:12:13.840:12:18.24Newman2-EN-4K
Okay
#4030:12:18.380:12:19.62Newman2-CN-4K
并被赋值给了一个变量
#4040:12:18.380:12:19.62Newman2-EN-4K
and it's assigned to a variable.
#4050:12:19.920:12:23.26Newman2-CN-4K
这里有个变量名经过混淆
#4060:12:19.920:12:23.26Newman2-EN-4K
Here is a variable
#4070:12:24.120:12:26.72Newman2-CN-4K
以Base64字符串形式存储
#4080:12:24.120:12:26.72Newman2-EN-4K
which is stored as a Base64 string
#4090:12:26.720:12:29.48Newman2-CN-4K
随后会从Base64转换回来
#4100:12:26.720:12:29.48Newman2-EN-4K
which is then converted from Base64.
#4110:12:32.320:12:33.68Newman2-CN-4K
然后...
#4120:12:32.320:12:33.68Newman2-EN-4K
And then...
#4130:12:33.680:12:36.12Newman2-CN-4K
将扩展名改为CMD
#4140:12:33.680:12:36.12Newman2-EN-4K
Change extension to CMD.
#4150:12:36.800:12:39.00Newman2-CN-4K
其实它依然是可执行文件
#4160:12:36.800:12:39.00Newman2-EN-4K
Well
#4170:12:39.300:12:42.44Newman2-CN-4K
CMD扩展名并未改变本质
#4180:12:39.300:12:42.44Newman2-EN-4K
The CMD extension does nothing to change it.
#4190:12:42.720:12:46.72Newman2-CN-4K
EXE格式的CMD文件仍可执行
#4200:12:42.720:12:46.72Newman2-EN-4K
You can still execute a CMD file if it's in EXE.
#4210:12:47.440:12:51.78Newman2-CN-4K
接着它向另一个文件写入文本
#4220:12:47.440:12:51.78Newman2-EN-4K
And then it writes text to another file
#4230:12:52.080:12:53.78Newman2-CN-4K
可能存放到CameraRoll目录
#4240:12:52.080:12:53.78Newman2-EN-4K
which is probably in CameraRoll.
#4250:12:54.140:12:54.68Newman2-CN-4K
具体路径是哪里?
#4260:12:54.140:12:54.68Newman2-EN-4K
Where was it?
#4270:12:56.460:12:57.80Newman2-CN-4K
我忘了存储位置
#4280:12:56.460:12:57.80Newman2-EN-4K
I forgot where it was.
#4290:12:57.980:13:00.02Newman2-CN-4K
找到了 UserProfile\Pictures\CameraRoll
#4300:12:57.980:13:00.02Newman2-EN-4K
Okay
#4310:13:00.140:13:02.14Newman2-CN-4K
它把自己存入CameraRoll目录
#4320:13:00.140:13:02.14Newman2-EN-4K
It saves itself to a CameraRoll.
#4330:13:03.940:13:06.18Newman2-CN-4K
然后写入以下字节数据
#4340:13:03.940:13:06.18Newman2-EN-4K
So it writes the following bytes.
#4350:13:06.540:13:09.26Newman2-CN-4K
Start.EncryptedGenerator64.exe
#4360:13:06.540:13:09.26Newman2-EN-4K
Start.EncryptedGenerator64.exe
#4370:13:09.280:13:13.82Newman2-CN-4K
应该就是这个文件的Base64编码
#4380:13:09.280:13:13.82Newman2-EN-4K
which is probably the Base64 representation of that file right here.
#4390:13:15.080:13:18.62Newman2-CN-4K
随后添加自启动项
#4400:13:15.080:13:18.62Newman2-EN-4K
And then it adds itself to the Startup.
#4410:13:19.900:13:22.00Newman2-CN-4K
这里写着UserStartup.HKCU
#4420:13:19.900:13:22.00Newman2-EN-4K
UserStartup.HKCU right here.
#4430:13:24.100:13:29.70Newman2-CN-4K
这个启动项名称...非常可疑
#4440:13:24.100:13:29.70Newman2-EN-4K
Name... yeah
#4450:13:32.640:13:34.08Newman2-CN-4K
接着...
#4460:13:32.640:13:34.08Newman2-EN-4K
And then...
#4470:13:34.080:13:36.60Newman2-CN-4K
它会删除释放器之类的
#4480:13:34.080:13:36.60Newman2-EN-4K
Well
#4490:13:36.840:13:39.48Newman2-CN-4K
基本流程就是这样
#4500:13:36.840:13:39.48Newman2-EN-4K
So that's the basic idea.
#4510:13:40.220:13:43.38Newman2-CN-4K
这是另一种投放恶意软件的方式
#4520:13:40.220:13:43.38Newman2-EN-4K
So that's another way to drop malware onto your computer.
#4530:13:43.380:13:46.18Newman2-CN-4K
用Base64编码全部内容
#4540:13:43.380:13:46.18Newman2-EN-4K
It's to encode everything in Base64
#4550:13:46.600:13:49.78Newman2-CN-4K
再通过PowerShell执行
#4560:13:46.600:13:49.78Newman2-EN-4K
and then execute it via PowerShell.
#4570:13:49.900:13:52.56Newman2-CN-4K
因为PowerShell支持运行Base64编码
#4580:13:49.900:13:52.56Newman2-EN-4K
Because PowerShell supports executing Base64.
#4590:13:54.600:13:56.80Newman2-CN-4K
好了 看下一个案例
#4600:13:54.600:13:56.80Newman2-EN-4K
Alright
#4610:13:59.180:14:03.91Newman2-CN-4K
IrinaParashev.com 顺便一提Irina是典型的俄罗斯名字
#4620:13:59.180:14:03.91Newman2-EN-4K
IrinaParashev.com Irina is a Russian name
#4630:14:07.680:14:09.92Newman2-EN-4K
Oh my god
#4640:14:10.060:14:11.82Newman2-CN-4K
居然有个完整伪造网站
#4650:14:10.060:14:11.82Newman2-EN-4K
There's an entire fake website.
#4660:14:13.100:14:16.06Newman2-CN-4K
后面还跟着虚假验证码
#4670:14:13.100:14:16.06Newman2-EN-4K
Which is then followed by a fake CAPTCHA.
#4680:14:16.400:14:17.68Newman2-CN-4K
这种手法我还是第一次见
#4690:14:16.400:14:17.68Newman2-EN-4K
I've never seen that before
#4700:14:17.800:14:18.92Newman2-CN-4K
这手法相当高明
#4710:14:17.800:14:18.92Newman2-EN-4K
that's very impressive.
#4720:14:20.300:14:22.00Newman2-CN-4K
让我们验证一下你是人类
#4730:14:20.300:14:22.00Newman2-EN-4K
Let's verify we're human
#4740:14:22.300:14:23.74Newman2-CN-4K
这明显是伪造的验证
#4750:14:22.300:14:23.74Newman2-EN-4K
which is obviously fake.
#4760:14:27.400:14:29.10Newman2-CN-4K
这种手法我还是第一次见
#4770:14:27.400:14:29.10Newman2-EN-4K
I've never seen that before.
#4780:14:31.020:14:33.54Newman2-CN-4K
这些键 我的天哪
#4790:14:31.020:14:33.54Newman2-EN-4K
These keys
#4800:14:33.640:14:34.28Newman2-CN-4K
看看这个
#4810:14:33.640:14:34.28Newman2-EN-4K
look at that.
#4820:14:34.280:14:35.96Newman2-CN-4K
真漂亮
#4830:14:34.280:14:35.96Newman2-EN-4K
They're beautiful.
#4840:14:36.740:14:39.28Newman2-CN-4K
让我们复制它要求我们执行的命令
#4850:14:36.740:14:39.28Newman2-EN-4K
Let's copy the command it asked us to execute.
#4860:14:41.100:14:43.26Newman2-CN-4K
天啊 mshta
#4870:14:41.100:14:43.26Newman2-EN-4K
Oh my lord
#4880:14:43.520:14:45.84Newman2-CN-4K
我们直接进入实战环节
#4890:14:43.520:14:45.84Newman2-EN-4K
So we're going directly to the action.
#4900:14:46.220:14:52.02Newman2-CN-4K
使用mshta从IP地址下载某些东西
#4910:14:46.220:14:52.02Newman2-EN-4K
We're using mshta to drop something from an IP address.
#4920:14:52.980:14:54.82Newman2-CN-4K
然后执行代码
#4930:14:52.980:14:54.82Newman2-EN-4K
And code something.
#4940:14:55.540:14:58.68Newman2-CN-4K
这些应该是传给mshta的参数
#4950:14:55.540:14:58.68Newman2-EN-4K
I think these are arguments that are passed to mshta.
#4960:14:59.040:15:00.44Newman2-CN-4K
我们保留这部分
#4970:14:59.040:15:00.44Newman2-EN-4K
We're gonna keep that.
#4980:15:01.060:15:05.18Newman2-CN-4K
我要把开头的重复项删掉
#4990:15:01.060:15:05.18Newman2-EN-4K
I'm gonna remove the duplicates at the beginning.
#5000:15:06.780:15:08.16Newman2-CN-4K
因为它们都来自同一个控制者
#5010:15:06.780:15:08.16Newman2-EN-4K
Because they're owned by the same person.
#5020:15:11.180:15:12.96Newman2-CN-4K
好 继续下一个
#5030:15:11.180:15:12.96Newman2-EN-4K
Okay
#5040:15:14.020:15:17.20Newman2-CN-4K
我其实很想知道网站后台有什么
#5050:15:14.020:15:17.20Newman2-EN-4K
I'm actually quite interested to see what's on the back of the site.
#5060:15:20.460:15:21.70Newman2-CN-4K
调试器暂停?什么情况?
#5070:15:20.460:15:21.70Newman2-EN-4K
Pause in debugger
#5080:15:22.780:15:23.80Newman2-CN-4K
我不是故意的
#5090:15:22.780:15:23.80Newman2-EN-4K
I didn't mean to.
#5100:15:25.620:15:29.28Newman2-CN-4K
天啊 下载React开发者工具获得更好开发体验
#5110:15:25.620:15:29.28Newman2-EN-4K
Oh my god
#5120:15:29.380:15:30.42Newman2-CN-4K
这是个React应用
#5130:15:29.380:15:30.42Newman2-EN-4K
That's a React app.
#5140:15:31.240:15:33.78Newman2-CN-4K
等等 这是反调试器吗?
#5150:15:31.240:15:33.78Newman2-EN-4K
Wait
#5160:15:35.020:15:38.10Newman2-CN-4K
稍等 这是为了防止你调试网站?
#5170:15:35.020:15:38.10Newman2-EN-4K
Wait
#5180:15:39.080:15:41.64Newman2-CN-4K
他们想阻止我调试网站?
#5190:15:39.080:15:41.64Newman2-EN-4K
Are they trying to prevent me from debugging the site?
#5200:15:42.360:15:42.92Newman2-CN-4K
什么?
#5210:15:42.360:15:42.92Newman2-EN-4K
What?
#5220:15:43.680:15:44.00Newman2-CN-4K
真的假的?
#5230:15:43.680:15:44.00Newman2-EN-4K
Really?
#5240:15:47.000:15:49.08Newman2-CN-4K
哇靠 搞什么鬼?
#5250:15:47.000:15:49.08Newman2-EN-4K
Whoa
#5260:15:50.140:15:54.06Newman2-CN-4K
没错 这绝对是为了让你无法调试
#5270:15:50.140:15:54.06Newman2-EN-4K
Yeah
#5280:15:54.280:15:57.48Newman2-CN-4K
你根本找不到它从哪复制的链接
#5290:15:54.280:15:57.48Newman2-EN-4K
And you can't find where it copies the link from.
#5300:15:57.480:16:00.48Newman2-CN-4K
太阴险了兄弟
#5310:15:57.480:16:00.48Newman2-EN-4K
That's so dodgy
#5320:16:02.280:16:03.42Newman2-CN-4K
真恶心
#5330:16:02.280:16:03.42Newman2-EN-4K
So disgusting.
#5340:16:05.220:16:08.98Newman2-CN-4K
而且网页语言设置是ro-ro罗马尼亚语
#5350:16:05.220:16:08.98Newman2-EN-4K
Also
#5360:16:09.260:16:11.36Newman2-CN-4K
难怪他们想偷我们钱包
#5370:16:09.260:16:11.36Newman2-EN-4K
No wonder they're trying to steal our wallets here.
#5380:16:13.700:16:17.92Newman2-CN-4K
不过只要拿到可执行文件就无所谓
#5390:16:13.700:16:17.92Newman2-EN-4K
Anyways
#5400:16:23.080:16:24.80Newman2-CN-4K
这又是假网站吧?
#5410:16:23.080:16:24.80Newman2-EN-4K
This be another fake website?
#5420:16:26.560:16:28.26Newman2-CN-4K
哦 不安全
#5430:16:26.560:16:28.26Newman2-EN-4K
Oh
#5440:16:28.600:16:29.44Newman2-CN-4K
谁能想到呢
#5450:16:28.600:16:29.44Newman2-EN-4K
Who would have known?
#5460:16:31.260:16:33.24Newman2-CN-4K
看起来和第一个网站一样
#5470:16:31.260:16:33.24Newman2-EN-4K
Oh
#5480:16:34.280:16:36.54Newman2-CN-4K
而且 看起来和第一个网站一样
#5490:16:34.280:16:36.54Newman2-EN-4K
Also
#5500:16:37.220:16:39.20Newman2-CN-4K
而且 看起来和第一个...
#5510:16:37.220:16:39.20Newman2-EN-4K
Also
#5520:16:39.200:16:41.04Newman2-CN-4K
哦 微软防护报告
#5530:16:39.200:16:41.04Newman2-EN-4K
Oh
#5540:16:41.360:16:45.08Newman2-CN-4K
微软防护未发现威胁自上次报告
#5550:16:41.360:16:45.08Newman2-EN-4K
Microsoft Defender Antivirus did not find any threats since your last summary.
#5560:16:45.600:16:47.06Newman2-CN-4K
马上就不一样了
#5570:16:45.600:16:47.06Newman2-EN-4K
Well
#5580:16:47.720:16:50.98Newman2-CN-4K
这让我想起第一个假Cloudflare网站
#5590:16:47.720:16:50.98Newman2-EN-4K
This reminds me of the first fake Cloudflare website
#5600:16:51.100:16:53.16Newman2-CN-4K
它也会后台更新
#5610:16:51.100:16:53.16Newman2-EN-4K
and it also updates in the background.
#5620:16:53.160:16:58.38Newman2-CN-4K
估计会复制同样的剪贴板链接
#5630:16:53.160:16:58.38Newman2-EN-4K
This is probably gonna have the same exact clipboard link.
#5640:16:59.600:17:01.44Newman2-CN-4K
马上就能验证
#5650:16:59.600:17:01.44Newman2-EN-4K
Let's confirm that is
#5660:17:01.720:17:02.72Newman2-CN-4K
是不是这样
#5670:17:01.720:17:02.72Newman2-EN-4K
in fact
#5680:17:03.740:17:05.34Newman2-CN-4K
继续吧
#5690:17:03.740:17:05.34Newman2-EN-4K
And move on.
#5700:17:12.550:17:15.35Newman2-CN-4K
哦 这是暗黑模式那个
#5710:17:12.550:17:15.35Newman2-EN-4K
Oh
#5720:17:16.250:17:19.03Newman2-CN-4K
但验证码本身没变暗黑
#5730:17:16.250:17:19.03Newman2-EN-4K
But the Captcha itself isn't really in the dark mode
#5740:17:19.210:17:20.79Newman2-CN-4K
搞什么鬼?
#5750:17:19.210:17:20.79Newman2-EN-4K
so what the hell
#5760:17:22.310:17:23.27Newman2-CN-4K
验证人类身份
#5770:17:22.310:17:23.27Newman2-EN-4K
Verify you're human.
#5780:17:23.410:17:23.87Newman2-CN-4K
没问题
#5790:17:23.410:17:23.87Newman2-EN-4K
Sure.
#5800:17:26.070:17:27.43Newman2-CN-4K
哇 新花样
#5810:17:26.070:17:27.43Newman2-EN-4K
Oh
#5820:17:27.810:17:29.15Newman2-CN-4K
从没见过这种
#5830:17:27.810:17:29.15Newman2-EN-4K
I've never seen this one before.
#5840:17:29.750:17:31.09Newman2-CN-4K
“更有效证明非机器人”
#5850:17:29.750:17:31.09Newman2-EN-4K
To better prove you're not a robot.
#5860:17:31.450:17:33.15Newman2-CN-4K
呵 还是老一套
#5870:17:31.450:17:33.15Newman2-EN-4K
Oh
#5880:17:33.290:17:36.39Newman2-CN-4K
老一套 但我得把所有东西复制粘贴到运行框里
#5890:17:33.290:17:36.39Newman2-EN-4K
same old
#5900:17:36.790:17:37.31Newman2-CN-4K
可惜啊
#5910:17:36.790:17:37.31Newman2-EN-4K
unfortunately.
#5920:17:38.050:17:42.51Newman2-CN-4K
哦 它用的招数和我见过最逼真的假Cloudflare验证码如出一辙
#5930:17:38.050:17:42.51Newman2-EN-4K
Oh
#5940:17:43.130:17:44.37Newman2-CN-4K
看看这个
#5950:17:43.130:17:44.37Newman2-EN-4K
Check this out.
#5960:17:44.510:17:47.01Newman2-CN-4K
如果我们把这个输入运行框里
#5970:17:44.510:17:47.01Newman2-EN-4K
If we input that into the run box
#5980:17:47.590:17:50.15Newman2-CN-4K
字符串最末尾有个注释
#5990:17:47.590:17:50.15Newman2-EN-4K
there is a comment at the very end of the string
#6000:17:50.310:17:51.95Newman2-CN-4K
所以看起来还挺像那么回事
#6010:17:50.310:17:51.95Newman2-EN-4K
so it looks plausible.
#6020:17:54.970:17:58.61Newman2-CN-4K
我其实不明白reCaptcha和Cloudflare有什么关系
#6030:17:54.970:17:58.61Newman2-EN-4K
I actually don't know what reCaptcha has to do with Cloudflare
#6040:17:58.670:18:00.01Newman2-CN-4K
但谁在乎呢?
#6050:17:58.670:18:00.01Newman2-EN-4K
but who cares?
#6060:18:00.770:18:02.53Newman2-CN-4K
总之 这里的思路是
#6070:18:00.770:18:02.53Newman2-EN-4K
Anyways
#6080:18:02.930:18:10.55Newman2-CN-4K
它会从cf-unstable.media下载Captcha.txt文件
#6090:18:02.930:18:10.55Newman2-EN-4K
it downloads Captcha.txt from cfunstable.media
#6100:18:10.830:18:13.69Newman2-CN-4K
CF大概代表Cloudflare
#6110:18:10.830:18:13.69Newman2-EN-4K
CF probably standing for Cloudflare.
#6120:18:13.910:18:17.03Newman2-CN-4K
然后将其重命名为Captcha.vbs
#6130:18:13.910:18:17.03Newman2-EN-4K
Then it calls it Captcha.vbs
#6140:18:17.190:18:21.03Newman2-CN-4K
接着启动这个vbs文件
#6150:18:17.190:18:21.03Newman2-EN-4K
it renames the file
#6160:18:21.550:18:21.97Newman2-CN-4K
妙啊
#6170:18:21.550:18:21.97Newman2-EN-4K
Awesome.
#6180:18:23.110:18:24.73Newman2-CN-4K
来看看里面有什么花样
#6190:18:23.110:18:24.73Newman2-EN-4K
Let's check out what it has to offer.
#6200:18:25.730:18:27.79Newman2-CN-4K
糟糕 失效了
#6210:18:25.730:18:27.79Newman2-EN-4K
Oh no
#6220:18:27.990:18:28.87Newman2-CN-4K
NxDomain错误
#6230:18:27.990:18:28.87Newman2-EN-4K
NxDomain.
#6240:18:29.670:18:31.73Newman2-CN-4K
域名被查封了还是怎么
#6250:18:29.670:18:31.73Newman2-EN-4K
The domain was seized or something.
#6260:18:33.310:18:34.87Newman2-CN-4K
CaptchaBot.cc网站
#6270:18:33.310:18:34.87Newman2-EN-4K
CaptchaBot.cc.
#6280:18:35.830:18:37.69Newman2-CN-4K
传说中的CaptchaBot验证码
#6290:18:35.830:18:37.69Newman2-EN-4K
The legendary CaptchaBot.
#6300:18:41.610:18:43.17Newman2-CN-4K
为什么会有药丸图标?
#6310:18:41.610:18:43.17Newman2-EN-4K
Why is there a pill?
#6320:18:47.490:18:48.37Newman2-CN-4K
让我看看有什么猫腻
#6330:18:47.490:18:48.37Newman2-EN-4K
Show me the money.
#6340:18:50.790:18:52.25Newman2-CN-4K
CaptchaBot已经挂了!
#6350:18:50.790:18:52.25Newman2-EN-4K
CaptchaBot is dead!
#6360:18:52.590:18:53.35Newman2-CN-4K
NxDomain错误
#6370:18:52.590:18:53.35Newman2-EN-4K
NxDomain.
#6380:18:53.510:18:53.77Newman2-CN-4K
什么?
#6390:18:53.510:18:53.77Newman2-EN-4K
What?
#6400:18:54.110:18:54.35Newman2-CN-4K
真的假的?
#6410:18:54.110:18:54.35Newman2-EN-4K
Really?
#6420:18:55.090:18:57.11Newman2-CN-4K
我昨天还在分析它呢
#6430:18:55.090:18:57.11Newman2-EN-4K
I was just reviewing it yesterday
#6440:18:57.490:18:58.67Newman2-CN-4K
现在居然就失效了
#6450:18:57.490:18:58.67Newman2-EN-4K
and now it's dead.
#6460:18:59.350:19:00.77Newman2-CN-4K
CaptchaBot已经离我们而去
#6470:18:59.350:19:00.77Newman2-EN-4K
CaptchaBot is no longer with us.
#6480:19:01.430:19:02.85Newman2-CN-4K
这些网站寿命都很短暂
#6490:19:01.430:19:02.85Newman2-EN-4K
They are very short-lived.
#6500:19:03.030:19:04.73Newman2-CN-4K
虚假验证码网站转瞬即逝
#6510:19:03.030:19:04.73Newman2-EN-4K
The fake Captchas are super short-lived
#6520:19:04.870:19:06.69Newman2-CN-4K
但它们被批量制造
#6530:19:04.870:19:06.69Newman2-EN-4K
but they are produced in masses
#6540:19:06.870:19:08.31Newman2-CN-4K
所以仍然大量存在
#6550:19:06.870:19:08.31Newman2-EN-4K
so there are still many of them.
#6560:19:09.170:19:13.67Newman2-CN-4K
这是最后一个假冒Cloudflare验证码类网站
#6570:19:09.170:19:13.67Newman2-EN-4K
This was the last website from the fake Cloudflare Captcha category.
#6580:19:14.710:19:18.91Newman2-CN-4K
现在我们要转向杂项分类
#6590:19:14.710:19:18.91Newman2-EN-4K
We're moving on to the miscellaneous category.
#6600:19:19.250:19:20.60Newman2-CN-4K
直接运行这个网站看看
#6610:19:19.250:19:20.60Newman2-EN-4K
Let's go ahead and run that website.
#6620:19:20.600:19:24.60Newman2-CN-4K
这个看起来没什么可疑的
#6630:19:20.600:19:24.60Newman2-EN-4K
Nothing suspicious about that one.
#6640:19:25.940:19:26.90Newman2-CN-4K
虚假模糊效果
#6650:19:25.940:19:26.90Newman2-EN-4K
Fake blur.
#6660:19:27.680:19:29.06Newman2-CN-4K
上面用俄语写着
#6670:19:27.680:19:29.06Newman2-EN-4K
And it says in Russian
#6680:19:29.200:19:30.12Newman2-CN-4K
“我不是机器人”
#6690:19:29.200:19:30.12Newman2-EN-4K
I'm not a robot.
#6700:19:30.700:19:32.96Newman2-CN-4K
实在不明白为什么对我显示俄语
#6710:19:30.700:19:32.96Newman2-EN-4K
I really don't understand why it speaks Russian to me
#6720:19:33.080:19:35.24Newman2-CN-4K
我的IP明明是瑞典的
#6730:19:33.080:19:35.24Newman2-EN-4K
because my IP is Swedish.
#6740:19:36.100:19:39.78Newman2-CN-4K
不管了 先点击看看
#6750:19:36.100:19:39.78Newman2-EN-4K
But anyway
#6760:19:39.780:19:41.54Newman2-CN-4K
哦 现在变成乌克兰语了
#6770:19:39.780:19:41.54Newman2-EN-4K
Oh
#6780:19:42.180:19:44.02Newman2-CN-4K
乌克兰语写着:
#6790:19:42.180:19:44.02Newman2-EN-4K
In Ukrainian
#6800:19:44.300:19:48.94Newman2-CN-4K
“完成以下步骤以通过验证”
#6810:19:44.300:19:48.94Newman2-EN-4K
complete these steps to complete the check.
#6820:19:49.300:19:51.56Newman2-CN-4K
“为了更好确认您不是机器人”
#6830:19:49.300:19:51.56Newman2-EN-4K
To better verify that you're not a robot
#6840:19:52.720:19:53.74Newman2-CN-4K
“请执行以下操作”
#6850:19:52.720:19:53.74Newman2-EN-4K
do the following.
#6860:19:55.740:19:58.84Newman2-CN-4K
“按下Win+R键 再按Ctrl+V键”
#6870:19:55.740:19:58.84Newman2-EN-4K
Press Win plus R
#6880:19:59.320:20:00.06Newman2-CN-4K
“然后按回车键”
#6890:19:59.320:20:00.06Newman2-EN-4K
and then Enter.
#6900:20:00.520:20:02.22Newman2-CN-4K
完成以上步骤后
#6910:20:00.520:20:02.22Newman2-EN-4K
After these steps are completed
#6920:20:02.600:20:06.18Newman2-CN-4K
您将被重定向至内容页面
#6930:20:02.600:20:06.18Newman2-EN-4K
you will be redirected to the page with the content.
#6940:20:06.180:20:10.96Newman2-CN-4K
好吧 来看看剪贴板里复制了什么
#6950:20:06.180:20:10.96Newman2-EN-4K
All right
#6960:20:16.560:20:20.58Newman2-CN-4K
哦 看来这种情况比我想象的更常见
#6970:20:16.560:20:20.58Newman2-EN-4K
Oh yeah
#6980:20:21.520:20:23.78Newman2-CN-4K
他们只是在这里添加评论
#6990:20:21.520:20:23.78Newman2-EN-4K
They're just adding the comment here
#7000:20:24.280:20:28.54Newman2-CN-4K
所以你无法看到实际粘贴到运行框里的内容
#7010:20:24.280:20:28.54Newman2-EN-4K
so you don't see what you're actually pasting in the run box.
#7020:20:29.020:20:29.34Newman2-CN-4K
太棒了
#7030:20:29.020:20:29.34Newman2-EN-4K
Awesome.
#7040:20:30.300:20:31.44Newman2-CN-4K
继续下一个
#7050:20:30.300:20:31.44Newman2-EN-4K
On to the next one.
#7060:20:31.780:20:33.46Newman2-CN-4K
这只是一个直接的IP地址
#7070:20:31.780:20:33.46Newman2-EN-4K
That's just a direct IP address.
#7080:20:36.980:20:39.16Newman2-CN-4K
我要继续访问那个未保存的网站
#7090:20:36.980:20:39.16Newman2-EN-4K
I'm going to continue to that unsaved website.
#7100:20:39.300:20:40.32Newman2-CN-4K
看起来像是钓鱼网站
#7110:20:39.300:20:40.32Newman2-EN-4K
And it looks like phishing.
#7120:20:41.580:20:43.04Newman2-CN-4K
像是个假验证码
#7130:20:41.580:20:43.04Newman2-EN-4K
It looks like a fake CAPTCHA
#7140:20:43.540:20:45.94Newman2-CN-4K
但步骤更多
#7150:20:43.540:20:45.94Newman2-EN-4K
but with extra steps.
#7160:20:51.560:20:52.64Newman2-CN-4K
让我登录
#7170:20:51.560:20:52.64Newman2-EN-4K
Get me signed in.
#7180:20:53.780:20:55.78Newman2-CN-4K
不知为何显示由微软制作
#7190:20:53.780:20:55.78Newman2-EN-4K
It's made by Microsoft for some reason.
#7200:20:56.600:20:57.78Newman2-CN-4K
验证码没有加载出来
#7210:20:56.600:20:57.78Newman2-EN-4K
The reCAPTCHA didn't load.
#7220:20:58.680:21:02.58Newman2-CN-4K
哦 然后你会遇到一个假验证码
#7230:20:58.680:21:02.58Newman2-EN-4K
Oh
#7240:21:03.700:21:08.14Newman2-CN-4K
为什么要有这么多额外步骤 明明可以直接加载网站?
#7250:21:03.700:21:08.14Newman2-EN-4K
Why are there all these extra steps and you could just load the site?
#7260:21:11.680:21:14.64Newman2-CN-4K
我觉得这是西班牙语
#7270:21:11.680:21:14.64Newman2-EN-4K
I think that's Spanish.
#7280:21:16.800:21:18.74Newman2-CN-4K
要么是西班牙语 要么是葡萄牙语
#7290:21:16.800:21:18.74Newman2-EN-4K
Either Spanish or Portuguese.
#7300:21:19.360:21:25.22Newman2-CN-4K
这个直接发起网络请求 并用IEX命令执行
#7310:21:19.360:21:25.22Newman2-EN-4K
So this one invokes the web request and directly runs it using IEX command.
#7320:21:25.740:21:26.96Newman2-CN-4K
毫无隐藏
#7330:21:25.740:21:26.96Newman2-EN-4K
And there is nothing to hide.
#7340:21:27.060:21:28.04Newman2-CN-4K
完全没有混淆
#7350:21:27.060:21:28.04Newman2-EN-4K
It's not obfuscated.
#7360:21:28.380:21:32.94Newman2-CN-4K
当然 除了最后那个小彩蛋
#7370:21:28.380:21:32.94Newman2-EN-4K
Except
#7380:21:33.500:21:35.14Newman2-CN-4K
来看下一个
#7390:21:33.500:21:35.14Newman2-EN-4K
Moving on to the next one.
#7400:21:37.480:21:40.10Newman2-CN-4K
这个假验证码托管在GitHub上
#7410:21:37.480:21:40.10Newman2-EN-4K
So this fake CAPTCHA is hosted on GitHub.
#7420:21:42.900:21:45.00Newman2-CN-4K
名叫reCAPTCHA-phish
#7430:21:42.900:21:45.00Newman2-EN-4K
It's called reCAPTCHA-phish.
#7440:21:45.320:21:45.98Newman2-CN-4K
等等 稍等
#7450:21:45.320:21:45.98Newman2-EN-4K
Wait
#7460:21:46.100:21:50.40Newman2-CN-4K
可能只是个演示
#7470:21:46.100:21:50.40Newman2-EN-4K
Maybe it's actually a little demonstration.
#7480:21:55.100:21:57.92Newman2-CN-4K
我觉得这其实不是假验证码
#7490:21:55.100:21:57.92Newman2-EN-4K
Yeah
#7500:22:00.240:22:04.26Newman2-CN-4K
应该是个恶意软件数据库 有人只是上传了个验证码
#7510:22:00.240:22:04.26Newman2-EN-4K
I think it's a malware database and someone just posted a CAPTCHA there.
#7520:22:04.260:22:08.86Newman2-CN-4K
用于演示目的
#7530:22:04.260:22:08.86Newman2-EN-4K
For demonstration purposes.
#7540:22:09.640:22:10.46Newman2-CN-4K
没错 就是这样
#7550:22:09.640:22:10.46Newman2-EN-4K
Yeah
#7560:22:14.240:22:18.80Newman2-CN-4K
原来还有另一个Drew也在像我这样保存恶意软件
#7570:22:14.240:22:18.80Newman2-EN-4K
Oh
#7580:22:19.740:22:20.02Newman2-CN-4K
真不错
#7590:22:19.740:22:20.02Newman2-EN-4K
Lovely.
#7600:22:20.860:22:22.32Newman2-CN-4K
去关注这家伙吧
#7610:22:20.860:22:22.32Newman2-EN-4K
Go follow this guy or something.
#7620:22:23.340:22:26.46Newman2-CN-4K
来看今天的最后一个验证码
#7630:22:23.340:22:26.46Newman2-EN-4K
Moving on to the last CAPTCHA of the day
#7640:22:34.200:22:35.22Newman2-CN-4K
B2B旅游网站
#7650:22:34.200:22:35.22Newman2-EN-4K
B2B travel.
#7660:22:35.660:22:39.18Newman2-CN-4K
这是个为某网站定制的Cloudflare验证码
#7670:22:35.660:22:39.18Newman2-EN-4K
Oh
#7680:22:39.800:22:41.24Newman2-CN-4K
域名明显是假的
#7690:22:39.800:22:41.24Newman2-EN-4K
The domain is obviously fake.
#7700:22:41.300:22:43.04Newman2-CN-4K
它试图伪造这个B字母
#7710:22:41.300:22:43.04Newman2-EN-4K
It's trying to fake the B here.
#7720:22:44.520:22:47.36Newman2-CN-4K
行吧 点这个按钮
#7730:22:44.520:22:47.36Newman2-EN-4K
Sure
#7740:22:48.300:22:50.62Newman2-CN-4K
可能还是同样的套路
#7750:22:48.300:22:50.62Newman2-EN-4K
And it might be just the same thing.
#7760:22:51.560:22:52.54Newman2-CN-4K
等等 先别急
#7770:22:51.560:22:52.54Newman2-EN-4K
Oh
#7780:22:52.700:22:55.10Newman2-CN-4K
我刚看到验证通过了
#7790:22:52.700:22:55.10Newman2-EN-4K
I just saw it verified me.
#7800:22:55.780:22:57.20Newman2-CN-4K
明明显示验证成功
#7810:22:55.780:22:57.20Newman2-EN-4K
It verified me successfully.
#7820:22:57.360:22:59.10Newman2-CN-4K
那为什么不跳转到网站呢
#7830:22:57.360:22:59.10Newman2-EN-4K
Why aren't you moving on to the website then
#7840:22:59.200:22:59.34Newman2-CN-4K
嗯?
#7850:22:59.200:22:59.34Newman2-EN-4K
huh?
#7860:23:03.240:23:08.70Newman2-CN-4K
它从网站下载了另一个文件然后运行HTA文件
#7870:23:03.240:23:08.70Newman2-EN-4K
It downloads another file from the website and then runs the HTA file.
#7880:23:09.280:23:10.18Newman2-CN-4K
就这样
#7890:23:09.280:23:10.18Newman2-EN-4K
That's it.
#7900:23:11.240:23:17.56Newman2-CN-4K
这些虚假验证码目前都在活跃中 问题很严重
#7910:23:11.240:23:17.56Newman2-EN-4K
So all these fake CAPTCHAs are live right now and it's a huge problem.
#7920:23:17.780:23:22.40Newman2-CN-4K
总有一天 这些网站会让我们的网络环境更加恶化
#7930:23:17.780:23:22.40Newman2-EN-4K
And one day
#7940:23:22.500:23:31.88Newman2-CN-4K
因为浏览器政策会越来越严格 未经授权的剪贴板访问默认都会被网站禁止
#7950:23:22.500:23:29.88Newman2-EN-4K
Simply because the browser policies are going to become tighter and unauthorized clipboard access is going to be
#7960:23:29.880:23:31.88Newman2-EN-4K
restricted for websites by default.
#7970:23:31.960:23:34.36Newman2-CN-4K
毕竟现在这功能被用来诈骗了
#7980:23:31.960:23:34.36Newman2-EN-4K
Because it's now utilized for scams.
#7990:23:36.240:23:37.60Newman2-CN-4K
确实挺遗憾的
#8000:23:36.240:23:37.60Newman2-EN-4K
Yeah
#8010:23:37.760:23:42.02Newman2-CN-4K
我的网站就用剪贴板功能来复制代码
#8020:23:37.760:23:42.02Newman2-EN-4K
My website uses clipboard access to copy the code into your clipboard.
#8030:23:42.560:23:48.06Newman2-CN-4K
所以我觉得 navigator剪贴板API可能很快会被弃用
#8040:23:42.560:23:48.06Newman2-EN-4K
So yeah
#8050:23:48.780:23:50.14Newman2-CN-4K
虽然很可惜
#8060:23:48.780:23:50.14Newman2-EN-4K
It's going to be really sad
#8070:23:50.320:23:53.42Newman2-CN-4K
但谁让诈骗分子都在利用这个功能来伪装呢
#8080:23:50.320:23:53.42Newman2-EN-4K
but that's what these scams are utilizing to look more genuine.
#8090:23:54.040:23:57.86Newman2-CN-4K
看来这个功能快要保不住了
#8100:23:54.040:23:57.86Newman2-EN-4K
So yeah
#8110:23:57.860:24:00.66Newman2-CN-4K
总之 这就是我们今天的
#8120:23:57.860:24:00.66Newman2-EN-4K
Anyways
#8130:24:00.860:24:02.98Newman2-CN-4K
“丰收成果”
#8140:24:00.860:24:02.98Newman2-EN-4K
bountiful harvest we have reaped.
#8150:24:03.520:24:08.72Newman2-CN-4K
现在该在这台电脑上运行这些命令了
#8160:24:03.520:24:08.72Newman2-EN-4K
And I think it's time to start all these commands on this computer.
#8170:24:09.940:24:17.42Newman2-CN-4K
好 打开运行窗口
#8180:24:09.940:24:17.42Newman2-EN-4K
Alright
#8190:24:18.660:24:21.04Newman2-CN-4K
挨个执行这些命令
#8200:24:18.660:24:21.04Newman2-EN-4K
And run one after another.
#8210:24:24.080:24:24.72Newman2-CN-4K
检测到威胁
#8220:24:24.080:24:24.72Newman2-EN-4K
Threats found.
#8230:24:24.900:24:25.96Newman2-CN-4K
糟糕 等等
#8240:24:24.900:24:25.96Newman2-EN-4K
Oh no
#8250:24:26.040:24:27.70Newman2-CN-4K
得先关闭微软 Defender
#8260:24:26.040:24:27.70Newman2-EN-4K
I need to turn off the Microsoft Defender.
#8270:24:27.900:24:28.40Newman2-CN-4K
点击修复
#8280:24:27.900:24:28.40Newman2-EN-4K
Click fix.
#8290:24:28.980:24:30.04Newman2-CN-4K
不不不不不
#8300:24:28.980:24:30.04Newman2-EN-4K
No
#8310:24:30.040:24:31.12Newman2-CN-4K
等等 等一下
#8320:24:30.040:24:31.12Newman2-EN-4K
no
#8330:24:31.500:24:32.16Newman2-CN-4K
实时保护?
#8340:24:31.500:24:32.16Newman2-EN-4K
Real-time protection?
#8350:24:32.460:24:33.10Newman2-CN-4K
关掉它
#8360:24:32.460:24:33.10Newman2-EN-4K
Get rid of that.
#8370:24:36.020:24:36.94Newman2-CN-4K
重新运行
#8380:24:36.020:24:36.94Newman2-EN-4K
Running this again.
#8390:24:40.640:24:41.66Newman2-CN-4K
它在下载东西
#8400:24:40.640:24:41.66Newman2-EN-4K
It's downloading stuff.
#8410:24:41.820:24:42.58Newman2-CN-4K
应用程序工具?
#8420:24:41.820:24:42.58Newman2-EN-4K
Application tool?
#8430:24:42.980:24:43.34Newman2-CN-4K
允许
#8440:24:42.980:24:43.34Newman2-EN-4K
Yes.
#8450:24:44.360:24:46.92Newman2-CN-4K
快点让我...
#8460:24:44.360:24:46.92Newman2-EN-4K
Come on
#8470:24:48.660:24:50.12Newman2-CN-4K
任务管理器PS1
#8480:24:48.660:24:50.12Newman2-EN-4K
Task Manager PS1.
#8490:24:50.740:24:52.66Newman2-CN-4K
天啊 怎么回事
#8500:24:50.740:24:52.66Newman2-EN-4K
Oh my god
#8510:24:55.020:24:56.52Newman2-CN-4K
它在伪装成任务管理器
#8520:24:55.020:24:56.52Newman2-EN-4K
It's trying to fake a task manager
#8530:24:56.660:24:58.82Newman2-CN-4K
但我很清楚这不是
#8540:24:56.660:24:58.82Newman2-EN-4K
but I know for sure it's not a task manager.
#8550:24:58.940:25:00.86Newman2-CN-4K
我们都知道这根本不是任务管理器
#8560:24:58.940:25:00.86Newman2-EN-4K
We all know full well it's not a task manager.
#8570:25:02.680:25:03.56Newman2-CN-4K
又来一个
#8580:25:02.680:25:03.56Newman2-EN-4K
Another one.
#8590:25:05.360:25:06.28Newman2-CN-4K
又一个
#8600:25:05.360:25:06.28Newman2-EN-4K
And another one.
#8610:25:08.780:25:09.94Newman2-CN-4K
再来一个
#8620:25:08.780:25:09.94Newman2-EN-4K
And another one.
#8630:25:11.840:25:12.88Newman2-CN-4K
还有
#8640:25:11.840:25:12.88Newman2-EN-4K
And another one.
#8650:25:13.020:25:13.14Newman2-CN-4K
等等
#8660:25:13.020:25:13.14Newman2-EN-4K
Wait.
#8670:25:14.720:25:18.42Newman2-CN-4K
天呐 现在运行着这么多垃圾程序
#8680:25:14.720:25:18.42Newman2-EN-4K
Oh lord
#8690:25:22.010:25:22.53Newman2-CN-4K
MSHTA?
#8700:25:22.010:25:22.53Newman2-EN-4K
MSHTA?
#8710:25:23.410:25:25.33Newman2-CN-4K
我需要更多网页框架
#8720:25:23.410:25:25.33Newman2-EN-4K
I need more web frames.
#8730:25:25.550:25:26.63Newman2-CN-4K
给我更多网页框架
#8740:25:25.550:25:26.63Newman2-EN-4K
Give me more web frames.
#8750:25:26.830:25:27.35Newman2-CN-4K
检测到威胁
#8760:25:26.830:25:27.35Newman2-EN-4K
Threats found.
#8770:25:27.710:25:28.35Newman2-CN-4K
关掉
#8780:25:27.710:25:28.35Newman2-EN-4K
Turn it off.
#8790:25:28.770:25:29.41Newman2-CN-4K
快关掉
#8800:25:28.770:25:29.41Newman2-EN-4K
Turn it off.
#8810:25:30.210:25:32.07Newman2-CN-4K
别开实时保护
#8820:25:30.210:25:32.07Newman2-EN-4K
Don't run the real-time protection.
#8830:25:32.750:25:33.81Newman2-CN-4K
滚开
#8840:25:32.750:25:33.81Newman2-EN-4K
Get out of here.
#8850:25:36.030:25:37.43Newman2-CN-4K
我要全部允许
#8860:25:36.030:25:37.43Newman2-EN-4K
I'm gonna allow everything.
#8870:25:37.590:25:38.97Newman2-CN-4K
我不管了 微软防护
#8880:25:37.590:25:38.97Newman2-EN-4K
I don't care
#8890:25:41.430:25:42.93Newman2-CN-4K
我要关闭所有防护
#8900:25:41.430:25:42.93Newman2-EN-4K
I'm gonna turn off everything.
#8910:25:43.150:25:46.15Newman2-CN-4K
为什么它... 连篡改防护也关掉
#8920:25:43.150:25:46.15Newman2-EN-4K
Why is it... I'm gonna turn off tamper protection as well.
#8930:25:47.530:25:48.89Newman2-CN-4K
为什么总打扰我?
#8940:25:47.530:25:48.89Newman2-EN-4K
Why is it bothering me?
#8950:25:50.690:25:53.17Newman2-CN-4K
为什么对我这么苛刻?
#8960:25:50.690:25:53.17Newman2-EN-4K
Why is it so mean to me?
#8970:26:02.220:26:02.46Newman2-CN-4K
好的
#8980:26:02.220:26:02.46Newman2-EN-4K
Okay.
#8990:26:05.830:26:07.31Newman2-CN-4K
最后一个
#9000:26:05.830:26:07.31Newman2-EN-4K
And the last one.
#9010:26:12.340:26:13.56Newman2-CN-4K
服务控制
#9020:26:12.340:26:13.56Newman2-EN-4K
Service control.
#9030:26:13.740:26:15.94Newman2-CN-4K
原来它们名称都不一样
#9040:26:13.740:26:15.94Newman2-EN-4K
Okay
#9050:26:17.560:26:18.90Newman2-CN-4K
配置运行PS1
#9060:26:17.560:26:18.90Newman2-EN-4K
Config run PS1.
#9070:26:19.180:26:20.70Newman2-CN-4K
对 我们要运行所有程序
#9080:26:19.180:26:20.70Newman2-EN-4K
Yes
#9090:26:23.480:26:25.82Newman2-CN-4K
这个就留在里面
#9100:26:23.480:26:25.82Newman2-EN-4K
I'm gonna keep that in here.
#9110:26:30.780:26:36.08Newman2-CN-4K
得到四个HTA框架 还有一堆PowerShell窗口
#9120:26:30.780:26:36.08Newman2-EN-4K
We get four HTA frames and we get a bunch of PowerShell windows.
#9130:26:36.740:26:42.18Newman2-CN-4K
PhaseCond32.exe 是个伪造程序
#9140:26:36.740:26:42.18Newman2-EN-4K
PhaseCond32.exe
#9150:26:42.920:26:46.58Newman2-CN-4K
用了Visual Studio图标
#9160:26:42.920:26:46.58Newman2-EN-4K
Yeah
#9170:26:47.820:26:48.98Newman2-CN-4K
微软Visual Studio
#9180:26:47.820:26:48.98Newman2-EN-4K
Microsoft Visual Studio.
#9190:26:49.280:26:49.68Newman2-CN-4K
有意思
#9200:26:49.280:26:49.68Newman2-EN-4K
Interesting.
#9210:26:49.900:26:51.58Newman2-CN-4K
代码覆盖率检测工具
#9220:26:49.900:26:51.58Newman2-EN-4K
Code coverage instrumentation tool.
#9230:26:52.420:26:54.20Newman2-CN-4K
专门针对开发者的
#9240:26:52.420:26:54.20Newman2-EN-4K
So it's tailored to developers.
#9250:26:54.620:26:58.00Newman2-CN-4K
可能是新手程序员 容易中招
#9260:26:54.620:26:58.00Newman2-EN-4K
Probably to juniors
#9270:26:59.640:27:04.50Newman2-CN-4K
让它们运行一会儿 五分钟后回来查看
#9280:26:59.640:27:04.50Newman2-EN-4K
We're gonna let them stew for a bit and then come back to it in like five minutes.
#9290:27:06.420:27:08.72Newman2-CN-4K
这两个卡住了
#9300:27:06.420:27:08.72Newman2-EN-4K
Okay
#9310:27:08.900:27:10.68Newman2-CN-4K
不知道什么原因
#9320:27:08.900:27:10.68Newman2-EN-4K
I am not really sure why.
#9330:27:10.960:27:11.98Newman2-CN-4K
直接关掉吧
#9340:27:10.960:27:11.98Newman2-EN-4K
I'm gonna close them off.
#9350:27:14.140:27:15.24Newman2-CN-4K
等等 什么?
#9360:27:14.140:27:15.24Newman2-EN-4K
Oh
#9370:27:17.940:27:20.14Newman2-CN-4K
要求重新运行
#9380:27:17.940:27:20.14Newman2-EN-4K
It's asking to run it again.
#9390:27:22.600:27:23.74Newman2-CN-4K
正在下载东西
#9400:27:22.600:27:23.74Newman2-EN-4K
It's downloading something.
#9410:27:23.860:27:24.82Newman2-CN-4K
开启病毒防护
#9420:27:23.860:27:24.82Newman2-EN-4K
Turn on virus protection.
#9430:27:25.000:27:25.78Newman2-CN-4K
不了 谢谢
#9440:27:25.000:27:25.78Newman2-EN-4K
No
#9450:27:28.650:27:33.69Newman2-CN-4K
无法访问文件“core data”该文件正被另一进程使用
#9460:27:28.650:27:33.69Newman2-EN-4K
The process cannot access the file core data because it's being used by another process.
#9470:27:34.170:27:35.47Newman2-CN-4K
看来是同一个投放器
#9480:27:34.170:27:35.47Newman2-EN-4K
Oh
#9490:27:35.610:27:39.87Newman2-CN-4K
它试图用相同名称调用自身 结果失败了
#9500:27:35.610:27:39.87Newman2-EN-4K
It's trying to call itself the same name and then just fails.
#9510:27:41.130:27:42.25Newman2-CN-4K
真顽固
#9520:27:41.130:27:42.25Newman2-EN-4K
Oh
#9530:27:42.410:27:43.15Newman2-CN-4K
太顽固了
#9540:27:42.410:27:43.15Newman2-EN-4K
It's very persistent.
#9550:27:43.390:27:45.43Newman2-CN-4K
就像你关掉一个窗口
#9560:27:43.390:27:45.43Newman2-EN-4K
It's like if you close that window
#9570:27:45.890:27:47.19Newman2-CN-4K
它会再弹出两个
#9580:27:45.890:27:47.19Newman2-EN-4K
it creates two more.
#9590:27:47.830:27:48.67Newman2-CN-4K
类似这样
#9600:27:47.830:27:48.67Newman2-EN-4K
Something like that.
#9610:27:49.030:27:49.91Newman2-CN-4K
快看
#9620:27:49.030:27:49.91Newman2-EN-4K
Look at that.
#9630:27:50.030:27:50.59Newman2-CN-4K
什么?
#9640:27:50.030:27:50.59Newman2-EN-4K
What?
#9650:27:50.710:27:51.71Newman2-CN-4K
太恶心了
#9660:27:50.710:27:51.71Newman2-EN-4K
That's so disgusting.
#9670:27:51.710:27:54.49Newman2-CN-4K
这让我想起勒索软件
#9680:27:51.710:27:54.49Newman2-EN-4K
And this kind of reminds me of ransomware.
#9690:27:55.030:27:57.39Newman2-CN-4K
老观众可能记得
#9700:27:55.030:27:57.39Newman2-EN-4K
I think if you guys watched me long enough
#9710:27:57.570:27:59.71Newman2-CN-4K
NoMoreRansom那个案例
#9720:27:57.570:27:59.71Newman2-EN-4K
you might remember NoMoreRansom.
#9730:28:00.510:28:03.19Newman2-CN-4K
每次启动样本时
#9740:28:00.510:28:03.19Newman2-EN-4K
And whenever you started the sample
#9750:28:03.590:28:07.05Newman2-CN-4K
它都死缠烂打要管理员权限
#9760:28:03.590:28:07.05Newman2-EN-4K
it was pesting you to run it with administrator privileges.
#9770:28:07.250:28:10.75Newman2-CN-4K
如果拒绝 就会反复触发UAC弹窗
#9780:28:07.250:28:10.75Newman2-EN-4K
And if you said no
#9790:28:11.650:28:13.13Newman2-CN-4K
现在这个很像那种情况
#9800:28:11.650:28:13.13Newman2-EN-4K
This kind of reminds me of that.
#9810:28:16.030:28:22.31Newman2-CN-4K
HTA剩余部分显示...Windows无法访问指定设备路径或文件
#9820:28:16.030:28:22.31Newman2-EN-4K
So the rest of HTA can be... Windows cannot access the specified device path or file.
#9830:28:22.410:28:24.79Newman2-CN-4K
您可能没有权限访问该项目
#9840:28:22.410:28:24.79Newman2-EN-4K
You may not have the appropriate permissions to access the item.
#9850:28:25.450:28:29.87Newman2-CN-4K
你以为运行这么多恶意软件后我们赢了
#9860:28:25.450:28:29.87Newman2-EN-4K
And you would think we have come out victorious after we have run so much malware on our computer.
#9870:28:30.110:28:35.75Newman2-CN-4K
但别急 任务管理器里还有残留进程
#9880:28:30.110:28:35.75Newman2-EN-4K
But not so fast
#9890:28:36.310:28:38.21Newman2-CN-4K
比如有两个core data进程
#9900:28:36.310:28:38.21Newman2-EN-4K
For example
#9910:28:38.410:28:40.79Newman2-CN-4K
这个正在大量占用CPU
#9920:28:38.410:28:40.79Newman2-EN-4K
which is consuming a bunch of CPU right here.
#9930:28:41.750:28:45.89Newman2-CN-4K
而且据我所知 它被设置成了开机启动
#9940:28:41.750:28:44.87Newman2-EN-4K
And it's being put on startup
#9950:28:45.070:28:45.89Newman2-EN-4K
as far as I know.
#9960:28:46.630:28:49.47Newman2-CN-4K
在Roaming文件夹还有个z.hta
#9970:28:46.630:28:49.47Newman2-EN-4K
There is z.hta in roaming
#9980:28:49.850:28:54.03Newman2-CN-4K
真是“棒极了”
#9990:28:49.850:28:54.03Newman2-EN-4K
which is I guess super cool.
#10000:28:54.570:28:56.01Newman2-CN-4K
它运行着PowerShell
#10010:28:54.570:28:56.01Newman2-EN-4K
Which runs PowerShell
#10020:28:56.630:28:58.97Newman2-CN-4K
它运行着任务管理器并执行某些操作
#10030:28:56.630:28:58.97Newman2-EN-4K
which runs task manager and does something.
#10040:29:01.870:29:03.33Newman2-CN-4K
然后又重复执行一遍
#10050:29:01.870:29:03.33Newman2-EN-4K
And then does it again.
#10060:29:03.990:29:06.99Newman2-CN-4K
让我们检查一下启动项的注册表键值
#10070:29:03.990:29:06.99Newman2-EN-4K
Let's check out the startup registry key.
#10080:29:07.810:29:09.95Newman2-CN-4K
通常它会写入HKCU(当前用户注册表)
#10090:29:07.810:29:09.95Newman2-EN-4K
Usually writes itself into HKCU
#10100:29:10.590:29:12.89Newman2-CN-4K
因为它只能访问当前用户
#10110:29:10.590:29:12.89Newman2-EN-4K
because it only has access to the current user.
#10120:29:13.750:29:17.73Newman2-CN-4K
如你所见 这里有个小条目
#10130:29:13.750:29:17.73Newman2-EN-4K
As you can see
#10140:29:18.650:29:21.91Newman2-CN-4K
这个条目名为encryptedgenerator64.exe
#10150:29:18.650:29:21.91Newman2-EN-4K
which is called encryptedgenerator64.exe
#10160:29:22.110:29:24.05Newman2-CN-4K
它被储存在我们的相机相册里
#10170:29:22.110:29:24.05Newman2-EN-4K
that is stored in our camera roll.
#10180:29:24.910:29:26.23Newman2-CN-4K
图片文件夹 相机相册
#10190:29:24.910:29:26.23Newman2-EN-4K
Pictures
#10200:29:27.210:29:28.35Newman2-CN-4K
看 就在这儿
#10210:29:27.210:29:28.35Newman2-EN-4K
And there it is.
#10220:29:29.970:29:32.13Newman2-CN-4K
我也不太确定这个文件是什么
#10230:29:29.970:29:32.13Newman2-EN-4K
I'm not really sure what that file is.
#10240:29:32.130:29:33.31Newman2-CN-4K
弹出通知
#10250:29:32.130:29:33.31Newman2-EN-4K
Popup notify.
#10260:29:34.310:29:35.99Newman2-CN-4K
AOMEI分区助手
#10270:29:34.310:29:35.99Newman2-EN-4K
AOMEI partition assistant.
#10280:29:36.350:29:36.65Newman2-CN-4K
当然
#10290:29:36.350:29:36.65Newman2-EN-4K
Sure.
#10300:29:37.390:29:38.73Newman2-CN-4K
这个我是信任的
#10310:29:37.390:29:38.73Newman2-EN-4K
I do trust that.
#10320:29:39.710:29:41.65Newman2-CN-4K
还有mshta程序
#10330:29:39.710:29:41.65Newman2-EN-4K
There is mshta as well
#10340:29:41.810:29:42.79Newman2-CN-4K
正在后台运行
#10350:29:41.810:29:42.79Newman2-EN-4K
running in the background.
#10360:29:44.310:29:46.77Newman2-CN-4K
就算我查看命令行参数
#10370:29:44.310:29:46.77Newman2-EN-4K
If I viewed the command line
#10380:29:46.830:29:49.53Newman2-CN-4K
也不是什么好东西
#10390:29:46.830:29:49.53Newman2-EN-4K
it wouldn't be any good.
#10400:29:50.530:29:53.23Newman2-CN-4K
对 就是那个z.hta文件
#10410:29:50.530:29:53.23Newman2-EN-4K
Yeah
#10420:29:54.330:29:57.51Newman2-CN-4K
我们来看看启动文件夹
#10430:29:54.330:29:57.51Newman2-EN-4K
Let's check out the startup folder.
#10440:29:59.370:30:01.09Newman2-CN-4K
好 这就是启动程序
#10450:29:59.370:30:01.09Newman2-EN-4K
Okay
#10460:30:03.610:30:06.87Newman2-CN-4K
存放在Roaming目录下的
#10470:30:03.610:30:06.87Newman2-EN-4K
Which is stored in data box under roaming
#10480:30:07.310:30:09.24Newman2-CN-4K
AppData文件夹里
#10490:30:07.310:30:09.24Newman2-EN-4K
under app data.
#10500:30:09.550:30:11.13Newman2-CN-4K
Launcher.exe启动器
#10510:30:09.550:30:11.13Newman2-EN-4K
Launcher.exe.
#10520:30:11.830:30:13.47Newman2-CN-4K
然后是boot.svc启动服务
#10530:30:11.830:30:13.47Newman2-EN-4K
Then we got boot.svc.
#10540:30:13.770:30:14.93Newman2-CN-4K
哦对 就是那个引导服务
#10550:30:13.770:30:14.93Newman2-EN-4K
Oh yes
#10560:30:16.130:30:20.21Newman2-CN-4K
实际是AppData/StoreBin目录下的coredata.exe程序
#10570:30:16.130:30:18.91Newman2-EN-4K
Which is coredata.exe under store bin
#10580:30:19.110:30:20.21Newman2-EN-4K
under app data.
#10590:30:20.730:30:22.11Newman2-CN-4K
还有删除应用的功能
#10600:30:20.730:30:22.11Newman2-EN-4K
And we have delete app
#10610:30:23.310:30:25.67Newman2-CN-4K
这是一个URL链接
#10620:30:23.310:30:25.67Newman2-EN-4K
which is a URL.
#10630:30:26.210:30:26.57Newman2-CN-4K
有意思
#10640:30:26.210:30:26.57Newman2-EN-4K
Interesting.
#10650:30:27.570:30:30.79Newman2-CN-4K
所以是C盘Windows目录下的 tybd7.exe文件
#10660:30:27.570:30:30.79Newman2-EN-4K
So it's tybd7.exe under C Windows.
#10670:30:30.790:30:32.05Newman2-CN-4K
在上一个视频中
#10680:30:30.790:30:32.05Newman2-EN-4K
In the previous video
#10690:30:32.390:30:36.27Newman2-CN-4K
我当时太累了 没注意到其实是在 C盘Windows临时文件夹里
#10700:30:32.390:30:36.27Newman2-EN-4K
I was too tired to see that it was actually in C Windows temp.
#10710:30:36.490:30:39.83Newman2-CN-4K
所以我之前一直在查常规的临时文件夹
#10720:30:36.490:30:39.83Newman2-EN-4K
So I was looking into the regular temp folder.
#10730:30:40.130:30:42.93Newman2-CN-4K
来看看Windows临时文件夹里有什么
#10740:30:40.130:30:42.93Newman2-EN-4K
Let's check out the Windows temp folder.
#10750:30:47.310:30:48.25Newman2-CN-4K
运行配置
#10760:30:47.310:30:48.25Newman2-EN-4K
Config run.
#10770:30:48.630:30:51.43Newman2-CN-4K
所以这里有个 config_run.ps1文件
#10780:30:48.630:30:51.43Newman2-EN-4K
So there is the config run ps1 file.
#10790:30:51.730:30:52.47Newman2-CN-4K
脚本就在这里
#10800:30:51.730:30:52.47Newman2-EN-4K
There is the script.
#10810:30:52.770:30:54.45Newman2-CN-4K
来看看这个脚本是做什么的
#10820:30:52.770:30:54.45Newman2-EN-4K
Let's see what it does.
#10830:30:54.830:30:57.01Newman2-CN-4K
它禁用了Windows Defender防御程序
#10840:30:54.830:30:57.01Newman2-EN-4K
It disables Windows Defender
#10850:30:57.230:30:57.71Newman2-CN-4K
当然
#10860:30:57.230:30:57.71Newman2-EN-4K
of course.
#10870:30:58.390:31:01.07Newman2-CN-4K
没错 这确实与coredata.exe有关
#10880:30:58.390:31:01.07Newman2-EN-4K
And yeah
#10890:31:01.070:31:04.73Newman2-CN-4K
想看代码的话 你可以自己读
#10900:31:01.070:31:04.73Newman2-EN-4K
You can read the code if you want.
#10910:31:04.930:31:06.15Newman2-CN-4K
我懒得看
#10920:31:04.930:31:06.15Newman2-EN-4K
I can't really be bothered.
#10930:31:06.790:31:10.43Newman2-CN-4K
看来我们的电脑确实感染了一堆窃密木马
#10940:31:06.790:31:10.43Newman2-EN-4K
So yeah
#10950:31:10.630:31:12.33Newman2-CN-4K
而这些窃密程序 隐蔽性极强
#10960:31:10.630:31:12.33Newman2-EN-4K
And these stealers are stealthy.
#10970:31:12.610:31:14.39Newman2-CN-4K
所以这台电脑 你已经不能再用了
#10980:31:12.610:31:14.39Newman2-EN-4K
So you can't use this computer anymore
#10990:31:14.510:31:14.99Newman2-CN-4K
基本可以确定
#11000:31:14.510:31:14.99Newman2-EN-4K
pretty much.
#11010:31:15.230:31:16.51Newman2-CN-4K
这些木马根本不会显露痕迹
#11020:31:15.230:31:16.51Newman2-EN-4K
They don't really show themselves.
#11030:31:17.390:31:19.87Newman2-CN-4K
我们直接重启电脑 看看会发生什么
#11040:31:17.390:31:19.87Newman2-EN-4K
Let's go ahead and restart the computer and see what happens.
#11050:31:25.690:31:26.21Newman2-CN-4K
好了
#11060:31:25.690:31:26.21Newman2-EN-4K
Alrighty.
#11070:31:27.090:31:28.79Newman2-CN-4K
电脑已经重启完毕
#11080:31:27.090:31:28.79Newman2-EN-4K
We have restarted the computer.
#11090:31:29.830:31:32.07Newman2-CN-4K
我第一时间想查看任务管理器
#11100:31:29.830:31:32.07Newman2-EN-4K
I immediately want to check the task manager.
#11110:31:32.070:31:36.37Newman2-CN-4K
Encrypted generator 64.exe已经在运行了
#11120:31:32.070:31:36.37Newman2-EN-4K
Encrypted generator 64.exe is already running.
#11130:31:37.170:31:39.77Newman2-CN-4K
不知为何 微软Teams自动启动了
#11140:31:37.170:31:39.77Newman2-EN-4K
For some reason
#11150:31:41.870:31:46.21Newman2-CN-4K
之前电脑没中毒时 它可不在启动项里
#11160:31:41.870:31:46.21Newman2-EN-4K
They weren't on startup back when the machine was not infected.
#11170:31:47.750:31:48.41Newman2-CN-4K
这是什么?
#11180:31:47.750:31:48.41Newman2-EN-4K
What's that?
#11190:31:48.590:31:49.37Newman2-CN-4K
等等 打开文件
#11200:31:48.590:31:49.37Newman2-EN-4K
Wait
#11210:31:49.570:31:52.39Newman2-CN-4K
哦 突然弹出一堆命令提示符
#11220:31:49.570:31:52.39Newman2-EN-4K
Oh
#11230:31:53.310:31:54.37Newman2-CN-4K
真有趣
#11240:31:53.310:31:54.37Newman2-EN-4K
That's lovely.
#11250:31:55.070:31:57.35Newman2-CN-4K
看来它把自己替换到程序数据目录了
#11260:31:55.070:31:57.35Newman2-EN-4K
Oh
#11270:31:57.750:31:58.05Newman2-CN-4K
好的
#11280:31:57.750:31:58.05Newman2-EN-4K
Okay.
#11290:31:59.390:32:01.01Newman2-CN-4K
果然 coredata也出现了
#11300:31:59.390:32:01.01Newman2-EN-4K
Yeah
#11310:32:02.110:32:02.87Newman2-CN-4K
就是这样
#11320:32:02.110:32:02.87Newman2-EN-4K
That's it.
#11330:32:06.230:32:10.47Newman2-CN-4K
没错 这就是运行假验证码木马的下场
#11340:32:06.230:32:10.47Newman2-EN-4K
So yes
#11350:32:11.430:32:12.89Newman2-CN-4K
这台电脑已经废了
#11360:32:11.430:32:12.89Newman2-EN-4K
You cannot use this computer anymore.
#11370:32:13.590:32:15.29Newman2-CN-4K
要是我直接就重装系统了
#11380:32:13.590:32:15.29Newman2-EN-4K
I would just reinstall personally.
#11390:32:16.190:32:19.69Newman2-CN-4K
所以千万别中这种骗局
#11400:32:16.190:32:19.69Newman2-EN-4K
So yeah
#11410:32:20.410:32:21.47Newman2-CN-4K
感谢观看
#11420:32:20.410:32:21.47Newman2-EN-4K
And thank you for watching.
#11430:32:22.150:32:22.93Newman2-CN-4K
保重
#11440:32:22.150:32:22.93Newman2-EN-4K
Take care.
#11450:32:24.340:32:44.23Newman-CN-4K
{\blur90\fad(200,200)\fscx185\fscy188\pos(1885.333,840)}在 Youtube 上关注
#11460:32:17.260:32:22.26Newman-CN-4K
{\blur10\fad(200,200)\pos(1953.333,496)}原标题:How much malware can you get from fake CAPTCHAs? 原作者:Enderman\N
原视频上传日期:2025年8月8日
#11470:32:25.180:32:30.18Newman-CN-4K
{\blur10\fad(200,200)\pos(1909.333,1220)}翻译/压制/字幕制作:HAF半个水果\N
翻译质量权威评价:原来25年就有小拉即用机翻糊弄人了
#11480:32:30.490:32:35.49Newman-CN-4K
{\blur10\fad(200,200)\pos(1889.334,1336)}♥本视频在Enderman频道会员有效期内翻译♥\N
如果你喜欢这个视频,请多多支持和评论哒~ o((>ω< ))o\N
字幕制作不易,喜欢的话支持一下我吧!