{\blur10\fad(200,200)}翻译/压制/字幕制作:HAF半个水果
{\blur10\fad(200,200)\pos(1913.334,1908)}使用AI工具翻译,如有不准确的地方请在弹幕或评论区指正,谢谢!\N
!!真的有人看不到这行字!!
{\blur10\fad(200,200)\pos(1937.334,528)}翻译质量权威评价:原来25年就有小拉即用机翻糊弄人了
{\blur10\fad(200,200)\pos(1937.334,548)}♥本视频在Enderman频道会员有效期内翻译♥
{\c&HE683E7&\move(4636,460,3204,448,27,544)}挑战完成!\N
{\c&HFFFFFF&}醒来吧,为观众们献上盛宴
{\c&HE683E7&\move(3204,448,4472,456,5120,5404)}挑战完成!\N
{\c&HFFFFFF&}醒来吧,为观众们献上盛宴
So in the last couple videos
我已多次证实 假验证码在当今非常普遍 而我实在不擅长发现它们
I have been proven time and time again that fake Captcha are really common nowadays and I'm just really bad at finding them.
{\blur10\pos(2880,1876)}*B站昵称:我的世界Edge UID:576823848*
and every domain is a fake Captcha.
那么 我们将逐一访问清单上的每个网站 并执行它们要求的所有指令
So we're gonna enter every site in this list and execute every command it asks us to execute.
infect the computer with malware.
Let's go ahead and run the first one.
If you watched the previous video
you might remember this domain.
This is a fake YouTube Captcha.
So let's go ahead and run that.
First we get a real Captcha at the beginning.
I'm surprised it's still not been flagged as a malicious website.
So before you continue to YouTube
tick this checkbox and we get the verification steps.
So I'm going to create another document where I'm going to save every command it asks us to execute.
I think this is going to be super nice.
It's going to be like a MapReduce kind of thing.
It's not suspicious at all.
It doesn't look suspicious in the run box at all.
I don't know what you're talking about.
I think these domains are owned by the same person.
And I almost forgot to mention that these websites are categorized by the website they're trying to mimic.
So the first category is YouTube scams.
所以你会先看到“继续前往YouTube前请验证”的界面
So you get a before you continue to YouTube screen with a oh
所以这又是一个未被标记的域名 此刻正在实时传播恶意软件
So that's another domain that's not been flagged and it's serving malware live right now.
That's the most plausible looking domain so far.
You also get a Cloudflare captcha.
Imagine it's just going to be the same thing over and over again.
{\blur10\pos(2172,1824)}*在 X 上关注!
{\pos(1880,1696)}Holy moly.
这五个域名都指向同一个恶意网站\N
而且这些域名全都没有被安全平台标记
These five domains serve this exact same website and this website is malicious and none of these domains are flagged and
其中一个域名叫做YouTube-site.com 还有个叫YouTubeapprv 以及ReplyYouTube.com
one of the domains is called YouTubesite.com and one of them is YouTubeapprv and ReplyYouTube.com.
这让我确信部分恶意软件正通过电子邮件传播他们才能疯狂钓鱼\N
利用这些域名 对用户进行钓鱼攻击
So this makes me believe part of this malware is
being distributed through email so that they can fish the hell out of people using that domain.
这充分说明虚假验证码有多泛滥 它们正被大规模分发 而且这些域名
And this just goes out to show how common the fake captchas are and they're being distributed in masses and the domains
which also in turn means that people fall for this and you guys should stop falling for that.
That's kind of the newest trick in the book
I think it's owned by the same person.
I'm just going to insert every booking website.
I'm just saying it's all protected by Cloudflare.
Every domain like this should get an abuse report.
所以我们发现了一个仿冒的booking.com网站 有着同样风格的验证码 和同样逼真的滚动条
So we get a fake booking.com website with the same kind of looking captcha and the same genuine looking scroll on the back.
So it's absolutely the same
不过我发现这次有个不同点 上次的域名是bookvrff.com
although there's one difference I'm noticing that last time it was bookvrff.com.
It's still giving us the service unavailable treatment in the browser
但如果我们通过PowerShell运行 它就会下载某些东西
but it's going to download something if we run it through PowerShell.
The domain names for phishing websites like that are being
我认为这些域名是人工挑选的 而投放器的域名则是随机生成的
I think they're being hand selected and the domains for the droppers are being randomly generated.
所以我们收到了三个伪造的booking.com验证码
So we get three booking.com fake captchas.
We get five YouTube fake captchas.
还有一个booking.com的域名 什么内容都没提供给我们
And one of the booking.com domains doesn't serve us anything
I'm moving on swiftly to the Cloudflare captcha
the fake Cloudflare captcha.
This is the one I reviewed yesterday.
And verify you're human by completing the action below.
That's a different command I reviewed in the last video on my channel.
It's an obfuscated string that's downloading the file and then running it.
And that's a new string we've got
I think it's trying to say financial.
This site has been reported as unsafe.
That's what we're looking for.
Verify you're human by completing the action below.
So this is the first Cloudflare captcha I witnessed.
That it's faking the domain name.
It has not copied anything into my clipboard.
What this is saying here is remove everything after a question mark.
And the rest is random nonce.
Are there any more Russian comments?
So this code is of Russian origin
这是另一种混淆方式 他们直接用base64编码命令 然后通过PowerShell运行
So this is another type of obfuscation where they just use base64 to encode the command and run it through PowerShell
因为PowerShell支持执行base64编码命令
because PowerShell supports running base64 encoded commands.
So there is another layer of indirection
which means to run the script.
Let's go ahead and decode this base64 real quick.
So we get a different kind of a string.
HTTPS something PowerShell.
So it seems like the token generation function at the beginning
with Russian comments of course
is related to this nonce at the end.
It's trying to mimic the CloudFlare behavior.
It doesn't have anything to do with the PowerShell command.
这可能是另一种混淆手段 他们从这个网站发起网络请求
It might be another type of obfuscation where they invoke the web request from this website.
And there's supposed to be a website
他们很可能有个中央控制面板 专门为投放器提供虚假域名
and they probably have a centralized dashboard where they supply the fake domain names for droppers
这些虚假域名会流向下游网站 然后被复制到你的剪贴板里
which are streamed down to those websites and then copied into your clipboard.
Checkbox addEventListener.
It seems like they just copy-pasted stuff from the other site
and then just put another thing in here.
So this is the real command they're executing.
It doesn't really matter if we click or not.
All the code is available in the console.
I think they just actually messed up the JS
So they just ripped off this command from some other website
and then they inserted this.
And this looks much better.
Then it does a getHttpRequest to $h
which is the variable here.
It basically downloads this file.
Let's go ahead and check what's this all about.
It looks like Base64 again
Or is this just obfuscation?
Because I see something at the end.
So it looks like the meat is at the bottom of the file.
and it's assigned to a variable.
which is stored as a Base64 string
which is then converted from Base64.
The CMD extension does nothing to change it.
You can still execute a CMD file if it's in EXE.
And then it writes text to another file
which is probably in CameraRoll.
找到了 UserProfile\Pictures\CameraRoll
It saves itself to a CameraRoll.
So it writes the following bytes.
Start.EncryptedGenerator64.exe
Start.EncryptedGenerator64.exe
which is probably the Base64 representation of that file right here.
And then it adds itself to the Startup.
UserStartup.HKCU right here.
So that's the basic idea.
So that's another way to drop malware onto your computer.
It's to encode everything in Base64
and then execute it via PowerShell.
Because PowerShell supports executing Base64.
IrinaParashev.com 顺便一提Irina是典型的俄罗斯名字
IrinaParashev.com Irina is a Russian name
There's an entire fake website.
Which is then followed by a fake CAPTCHA.
I've never seen that before
I've never seen that before.
Let's copy the command it asked us to execute.
So we're going directly to the action.
We're using mshta to drop something from an IP address.
I think these are arguments that are passed to mshta.
I'm gonna remove the duplicates at the beginning.
Because they're owned by the same person.
I'm actually quite interested to see what's on the back of the site.
Are they trying to prevent me from debugging the site?
And you can't find where it copies the link from.
No wonder they're trying to steal our wallets here.
This be another fake website?
Microsoft Defender Antivirus did not find any threats since your last summary.
This reminds me of the first fake Cloudflare website
and it also updates in the background.
This is probably gonna have the same exact clipboard link.
But the Captcha itself isn't really in the dark mode
I've never seen this one before.
To better prove you're not a robot.
哦 它用的招数和我见过最逼真的假Cloudflare验证码如出一辙
If we input that into the run box
there is a comment at the very end of the string
我其实不明白reCaptcha和Cloudflare有什么关系
I actually don't know what reCaptcha has to do with Cloudflare
它会从cf-unstable.media下载Captcha.txt文件
it downloads Captcha.txt from cfunstable.media
CF probably standing for Cloudflare.
Then it calls it Captcha.vbs
Let's check out what it has to offer.
The domain was seized or something.
The legendary CaptchaBot.
I was just reviewing it yesterday
CaptchaBot is no longer with us.
They are very short-lived.
The fake Captchas are super short-lived
but they are produced in masses
so there are still many of them.
This was the last website from the fake Cloudflare Captcha category.
We're moving on to the miscellaneous category.
Let's go ahead and run that website.
Nothing suspicious about that one.
I really don't understand why it speaks Russian to me
because my IP is Swedish.
complete these steps to complete the check.
To better verify that you're not a robot
After these steps are completed
you will be redirected to the page with the content.
They're just adding the comment here
so you don't see what you're actually pasting in the run box.
That's just a direct IP address.
I'm going to continue to that unsaved website.
And it looks like phishing.
It looks like a fake CAPTCHA
It's made by Microsoft for some reason.
The reCAPTCHA didn't load.
Why are there all these extra steps and you could just load the site?
Either Spanish or Portuguese.
So this one invokes the web request and directly runs it using IEX command.
And there is nothing to hide.
Moving on to the next one.
So this fake CAPTCHA is hosted on GitHub.
It's called reCAPTCHA-phish.
Maybe it's actually a little demonstration.
I think it's a malware database and someone just posted a CAPTCHA there.
For demonstration purposes.
Go follow this guy or something.
Moving on to the last CAPTCHA of the day
The domain is obviously fake.
It's trying to fake the B here.
And it might be just the same thing.
I just saw it verified me.
It verified me successfully.
Why aren't you moving on to the website then
It downloads another file from the website and then runs the HTA file.
So all these fake CAPTCHAs are live right now and it's a huge problem.
因为浏览器政策会越来越严格 未经授权的剪贴板访问默认都会被网站禁止
Simply because the browser policies are going to become tighter and unauthorized clipboard access is going to be
restricted for websites by default.
Because it's now utilized for scams.
My website uses clipboard access to copy the code into your clipboard.
所以我觉得 navigator剪贴板API可能很快会被弃用
It's going to be really sad
but that's what these scams are utilizing to look more genuine.
bountiful harvest we have reaped.
And I think it's time to start all these commands on this computer.
And run one after another.
I need to turn off the Microsoft Defender.
It's trying to fake a task manager
but I know for sure it's not a task manager.
We all know full well it's not a task manager.
Don't run the real-time protection.
I'm gonna allow everything.
I'm gonna turn off everything.
Why is it... I'm gonna turn off tamper protection as well.
I'm gonna keep that in here.
得到四个HTA框架 还有一堆PowerShell窗口
We get four HTA frames and we get a bunch of PowerShell windows.
Code coverage instrumentation tool.
So it's tailored to developers.
We're gonna let them stew for a bit and then come back to it in like five minutes.
I am not really sure why.
I'm gonna close them off.
It's asking to run it again.
It's downloading something.
Turn on virus protection.
无法访问文件“core data”该文件正被另一进程使用
The process cannot access the file core data because it's being used by another process.
It's trying to call itself the same name and then just fails.
It's like if you close that window
And this kind of reminds me of ransomware.
I think if you guys watched me long enough
you might remember NoMoreRansom.
And whenever you started the sample
it was pesting you to run it with administrator privileges.
This kind of reminds me of that.
HTA剩余部分显示...Windows无法访问指定设备路径或文件
So the rest of HTA can be... Windows cannot access the specified device path or file.
You may not have the appropriate permissions to access the item.
And you would think we have come out victorious after we have run so much malware on our computer.
which is consuming a bunch of CPU right here.
And it's being put on startup
There is z.hta in roaming
which is I guess super cool.
which runs task manager and does something.
Let's check out the startup registry key.
Usually writes itself into HKCU
because it only has access to the current user.
这个条目名为encryptedgenerator64.exe
which is called encryptedgenerator64.exe
that is stored in our camera roll.
I'm not really sure what that file is.
AOMEI partition assistant.
running in the background.
If I viewed the command line
Let's check out the startup folder.
Which is stored in data box under roaming
实际是AppData/StoreBin目录下的coredata.exe程序
Which is coredata.exe under store bin
所以是C盘Windows目录下的 tybd7.exe文件
So it's tybd7.exe under C Windows.
我当时太累了 没注意到其实是在 C盘Windows临时文件夹里
I was too tired to see that it was actually in C Windows temp.
So I was looking into the regular temp folder.
Let's check out the Windows temp folder.
So there is the config run ps1 file.
It disables Windows Defender
You can read the code if you want.
I can't really be bothered.
And these stealers are stealthy.
So you can't use this computer anymore
They don't really show themselves.
Let's go ahead and restart the computer and see what happens.
We have restarted the computer.
I immediately want to check the task manager.
Encrypted generator 64.exe已经在运行了
Encrypted generator 64.exe is already running.
They weren't on startup back when the machine was not infected.
You cannot use this computer anymore.
I would just reinstall personally.
And thank you for watching.
{\blur90\fad(200,200)\fscx185\fscy188\pos(1885.333,840)}在 Youtube 上关注
{\blur10\fad(200,200)\pos(1953.333,496)}原标题:How much malware can you get from fake CAPTCHAs? 原作者:Enderman\N
原视频上传日期:2025年8月8日
{\blur10\fad(200,200)\pos(1909.333,1220)}翻译/压制/字幕制作:HAF半个水果\N
翻译质量权威评价:原来25年就有小拉即用机翻糊弄人了
{\blur10\fad(200,200)\pos(1889.334,1336)}♥本视频在Enderman频道会员有效期内翻译♥\N
如果你喜欢这个视频,请多多支持和评论哒~ o((>ω< ))o\N
字幕制作不易,喜欢的话支持一下我吧!