{\blur10\fad(200,200)}翻译/压制/字幕制作:HAF半个水果
{\blur10\fad(200,200)\pos(1997.334,728)}使用AI工具翻译,如有不准确的地方请在弹幕或评论区指正,谢谢!\N
!!真的有人看不到这行字!!
{\blur10\fad(200,200)\pos(1933.334,564)}翻译质量权威评价:原来25年就有小拉即用机翻糊弄人了
{\blur10\fad(200,200)\pos(1937.334,548)}♥本视频在Enderman频道会员有效期内翻译♥
but this time with a twist.
The domain is definitely not plausible
but you can probably tell where it is going already.
And let's confirm the suspicions.
we get a real CAPTCHA by Cloudflare.
And you would think it's that beautiful
fake Cloudflare CAPTCHA that I was looking for.
click on this pretty plausible-looking reCAPTCHA.
Confirm you're not a bot.
You can actually scroll and everything.
It looks pretty fine to an untrained eye.
So let's try clicking on that checkbox.
Complete these verification steps.
To confirm you're not a robot
please follow these steps.
Press and hold the Windows key plus R In the verification window
press Control plus V to paste the copied data.
Press Enter to complete the verification.
These CAPTCHAs are pretty rare
because the ones I have visited weren't super well made.
So let's see what it's asking us to execute.
And that's what I expected in the last video
when it actually ran MSHTA.
It invokes the web request to this website here
and then runs it via MSHTA.
{\fs95}And the idea why it runs the command via MSHTA is because MSHTA is very vulnerable.
{\blur10\pos(2044,1212)\fad(200,200)}MSHTA同样是一种已知的lolbin\N
(活体二进制文件,英文全称:Living-Off-the-Land Binaries\N
直译为:生活在陆地上的二进制,白名单文件利用技术),\N
常被恶意软件用作间接层以模仿可信行为
And there are a lot of holes
a lot of exploits you can employ to break out of the HTA box.
So let's see what that website has to offer.
Let's copy the bookvrff.com
see what it has on the website.
显示该站点已被微软Defender SmartScreen标记为不安全
as unsafe by Microsoft Defender SmartScreen.
So let's continue to the unsafe site
and we get service unavailable.
But what happens when we actually run this command?
I'm gonna run the command prompt for that.
I'm gonna run this as an admin.
Let's paste that real quick and see what happens.
Then it executes a couple other PowerShell scripts
Let's check the task manager.
It keeps downloading stuff.
There might be a couple indirections here.
所以当你看到PowerShell脚本在某个应用程序工具窗口弹出时
So once you see PowerShell scripts popping up in some application tool window
and they have the real CAPTCHA at the beginning.
the file it has downloaded from bookvrff.com.
So we have to open AppData.
It saved itself into the R folder.
{\move(1920,2018,1916,1606,1550,1850)}这里有个名为z.hta的文件
{\move(1920,2110,1916,1702,1550,1850)}And there is a file called z.hta.
{\blur10\pos(2180,1824)}* 在 X 上关注!
{\move(1952,1594,1948,2002,430,730)}用记事本打开看看内容
{\move(1952,1690,1952,2098,430,730)}Let's open it with Notepad and see what this is.
And it's basically a VBS file running on your computer.
you can already see where this is going.
It's downloading an exe file.
Let's see what this file is.
That's a randomly generated name
Check out the properties.
Stub.exe is the original file name.
Let's see what else it does.
It puts itself into the startup folder.
I think there is a shell command for that.
So here's what we've got here.
That's where it dropped the link.
Let's see what this link does.
There's another exe file we have on our computer.
And that's just from running MSHTA
So let's check out Roaming\DataBox.
It just downloaded itself as launs.
They're turning off Windows Defender
and doing everything to stop the anti-malware from working.
because I haven't seen anything ruin this Defender.
Temporary folder tybd7.exe.
It doesn't exist anymore.
It was deleted by that script.
I have an exe file that runs on every computer startup
and it surely does nothing good.
这就是运行一个来自假YouTube页面的不明命令的下场
So this is what happens when you run an executable served
to you by a fake YouTube capture.
Don't fall victim to such a scam
and thank you for watching.
It's running in the background
I have to end it first before deleting it.
{\blur90\fad(200,200)\fscx185\fscy188\pos(1885.333,840)}在 Youtube 上关注
{\blur10\fad(200,200)\pos(1953.333,496)}原标题:What happens if you click a Fake Captcha 原作者:Enderman\N
原视频上传日期:2025年8月6日
{\blur10\fad(200,200)\pos(1909.333,1220)}翻译/压制/字幕制作:HAF半个水果\N
翻译质量权威评价:原来25年就有小拉即用机翻糊弄人了
{\blur10\fad(200,200)\pos(1889.334,1336)}♥本视频在Enderman频道会员有效期内翻译♥\N
如果你喜欢这个视频,请多多支持和评论哒~ o((>ω< ))o\N
字幕制作不易,喜欢的话支持一下我吧!