Tech Support Scam installs RAT (when asked for refund)

Tech Support Scam installs RAT (when asked for refund)

The PC Security Channel

2 года назад

45,721 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@swabbie6150
@swabbie6150 - 11.08.2022 18:13

That Warowl intro really brings back the feels on that video

Ответить
@Your_Local_Weirdo75
@Your_Local_Weirdo75 - 11.08.2022 18:17

M O R T O N

Ответить
@wilfredotorres6628
@wilfredotorres6628 - 11.08.2022 18:44

Hi Leo, it seems more difficult to detect these connections because they use quick over UDP many sites are using quick to connect Wireshark doesn't pick up much of the information. Does process explorer pick up any type of connection? Are there any other tools that would help resolve any type of strange connections?

Ответить
@vuo7ng
@vuo7ng - 11.08.2022 18:54

i heckin love warowl

Ответить
@Im_DJ
@Im_DJ - 11.08.2022 19:34

How important a recovery phone number or email is??

Well let me tell you a short story , when I was a kid , I fell for a free in game reward and gave up my google account , when my device got logged out of account, I immediately looked up the reasons on google and just recovered my account and changed the password. Because I had my mom's phone number linked to it.

Ответить
@PurpleCrow27
@PurpleCrow27 - 11.08.2022 20:15

I can't wait to read a news report about one of these criminal scam centers being bombed. That'd be 'horrible' of course.

Ответить
@chow9893
@chow9893 - 11.08.2022 20:21

this is scary. why did safe browsing or windows defender not alarm when this file was downloaded? also why is the malicious application signed!!?

Ответить
@rudemaldonado9554
@rudemaldonado9554 - 11.08.2022 20:32

Is gaurdio a fake app?! 🤔 going through this now. It's on all of our wireless devices. Such a nightmare. Thanks for the info.

Ответить
@shorts9900
@shorts9900 - 11.08.2022 21:02

Thank you for spreading information

Ответить
@hd9g
@hd9g - 11.08.2022 21:35

Bitdefender missed this

Ответить
@НиколайШерстюк-ы7е
@НиколайШерстюк-ы7е - 11.08.2022 21:54

Refund scam

Ответить
@theowulf7803
@theowulf7803 - 11.08.2022 22:13

Funny, I know this software. We use it for IT support internally. Super easy to uninstall honestly, they have detailed instructions on how to uninstall the software. But yes I can confirm this software can pull any and ALL information from your computer. Not only that but it can run a Backdoor mode where the person on the other side can access a PowerShell and CMD console without the user knowing. This is not a Virus however in the slightest, it is just an abused tool by scammers.

Ответить
@Opt1685
@Opt1685 - 11.08.2022 22:15

I use ConnectWise Control in the IT dept I work at. When used legally, it is a really powerful remote session/access tool for IT support. It's unfortunate that scammers are using it this way...

Ответить
@wernerclaassen4787
@wernerclaassen4787 - 11.08.2022 22:20

i would love Microsoft to call me..... especially as they try their malware on my Linux Mint Debian Edition..... 'you have the windows 13 sir"

Ответить
@RichardPhillips1066
@RichardPhillips1066 - 11.08.2022 22:38

Lol Morton

Ответить
@macewatson3647
@macewatson3647 - 12.08.2022 00:12

I am a network admin / support agent for about 30 users and I get at least one email a week forwarded to me that's a fake invoice for a few hundred dollars with a number to call for a refund

Ответить
@Vilematrix
@Vilematrix - 12.08.2022 03:32

Leo, by default in Windows firewall there is a rule active that allows programs to connect to you for remote help. Is it enough to disable this rule for your network domain profile. Ive tried to change the scope of permitted ip's to the 24 subnet but it asks for a parameter in the predefined rule.

Ответить
@108kitsune
@108kitsune - 12.08.2022 03:35

Isn’t norton more dangerous then morton?

Ответить
@portman8909
@portman8909 - 12.08.2022 17:40

Yet again, Kaspersky reigns supreme with the detection here.

Ответить
@sunbae-nim
@sunbae-nim - 12.08.2022 23:47

Good ol' Warowl

Ответить
@bang1338
@bang1338 - 13.08.2022 05:08

i did with my friend
and i regret it

Ответить
@vedward3954
@vedward3954 - 13.08.2022 13:30

You should contact Jim Browning & Trilogy Media for more information about scammers

Ответить
@zhotpotrecipe
@zhotpotrecipe - 13.08.2022 16:01

Morton 😂

Ответить
@numair3
@numair3 - 13.08.2022 18:00

Nice 👍

Ответить
@guilherme5094
@guilherme5094 - 13.08.2022 21:41

👍

Ответить
@irakli4797
@irakli4797 - 13.08.2022 23:18

Test avira free on malware and ransomware.
Last test on your channel for this product was about 2.5 years ago. Let us see what has changed siince that.

Ответить
@SMblog-ef7ys
@SMblog-ef7ys - 14.08.2022 18:49

How to catch telegram scam group sir ?

Ответить
@SMblog-ef7ys
@SMblog-ef7ys - 14.08.2022 18:50

So many scammers group in telegram . They will assure high return in our investment ..I was also one the victim ..plis help me sir

Ответить
@thelonenoob2489
@thelonenoob2489 - 15.08.2022 09:58

Happy independence day scammers

Ответить
@Thomas-cityd5_gixitxs
@Thomas-cityd5_gixitxs - 16.08.2022 00:06

You should also review devices from Hak5 like Wi-Fi coconut and what can be obtained threw Wi-Fi hacking find out if it’s at all possible to create a defense software with a cellular and Wi-Fi dongle that can be used with lab tops or desktop to combat or acknowledge something is using a sniff device for data transmission.
That and a way to stop handshake stealing to other wifi networks wifi security needs more analysis to aid in this battle

Ответить
@Marabu03
@Marabu03 - 16.08.2022 02:25

@The PC Security Channel Hello! could you make a new video about the best free Antiviruses?

Ответить
@sumitmaharjanstudio
@sumitmaharjanstudio - 16.08.2022 13:03

My facebook and instagram got hacked, they also posted some scammy sites in insta photos, how did this happened without downloading anything and not loggin in any sketchy sites?

Ответить
@breakingthe4thwall260
@breakingthe4thwall260 - 17.08.2022 04:35

Hi leo. just wanted to make you aware that the windows C band updates for theend of August are supposed to ad a feature that is supposed to enhance windwos defenders ability to detect, intercept, and prevent ransomware and other advanced attacks. so may want to do another test of it after installing those an see how much difference it does or doesn't make!

Ответить
@kadeembey8367
@kadeembey8367 - 22.08.2022 22:35

Bravo!! to you and that jazz track at the end, You sir are really a beast!!!!!

Ответить
@alanashworth9414
@alanashworth9414 - 23.08.2022 17:23

Gotta love the Morton. Everyone should make their old timer family members aware of these things and keep them in the loop.

Ответить
@trikky2.2
@trikky2.2 - 08.09.2022 23:01

Just wanted to say a big thank you for pointing out Rat programs, Back in 2019 I came across my first one. Usually they just used things like AnyDesk or the others. And I do appreciate all the scam baiters out there, but especially this one. Did not know that the RAT programs were still being used.

Ответить
@mealprep247
@mealprep247 - 12.09.2022 20:07

Wow. Super shady.

Ответить
@agarplays2958
@agarplays2958 - 13.09.2022 21:30

do a yubikey review please

Ответить
@13thravenpurple94
@13thravenpurple94 - 20.09.2022 19:23

Great work! Thank you

Ответить
@leosthrivwithautism
@leosthrivwithautism - 26.09.2022 07:47

One of these D bags called me thinking he could fool me. Long story short he named off all kind of bogus numbers and said there was a warrant for my arrest that would go through if I didn’t pay the money. (You guess it, IRS scam). Coincidence that shortly after I hung up I got the browser hijack saying a virus was detected on my computer and to call a number and speak with a rep. Had an easy fix for that one. Dig up the ip address and put it in my firewall block list. Found out it was coming from India. So I blocked the who range. And blocked the number that called me too. Funny part is I have friends that work security for the government. And they were so happy to get these details. Hahahaha. They picked the wrong guy to mess with. Bunch of D bags.

Ответить
@rogerramjet6429
@rogerramjet6429 - 31.12.2022 11:27

I happened to be in front of a computer that my mother had bought from a local support group for the elderly, when Microsoft Tech Support called.
Guy was telling me how there's unusual activity going out via the internet.
I said to him "wow you people are fking fantastic at your job. Thanks. My mother only just got it yesterday and hasn't even got the internet connected".
Guy was to dumb to recognise my sarcasm and still tried pulling the same, till I got loud and started yelling at him, then told him to fk off.

Ответить
@adrekiy0
@adrekiy0 - 26.01.2023 21:37

i think my mom actually got scammed by some losers that were using connectwise years ago on her old computer

Ответить
@chessdad182
@chessdad182 - 13.02.2023 00:46

They need to catch these guys and force them to run a gauntlet of elderly people armed with their walking canes.

Ответить
@5DimesPlayer
@5DimesPlayer - 15.02.2023 09:29

A scammer almost fooled my uncle. But before he gave out any information, he gave me a call, and I talked with a woman who claimed he was infected with a virus because of a long string after running assoc in the terminal. I have the same string as his PC and I know I'm not infected! The voice changed from a woman's to a man's and they said "fu*k off!!"

Ответить
@Mannard74
@Mannard74 - 18.02.2023 19:45

Why would anyone feel reassured by a NORTON or MCAFEE-looking website? Even the REAL ones. Bloatware!! RUN!!

Ответить
@hysni
@hysni - 25.05.2023 10:50

Indian Accent = Go away (Turn your Phone OFF) Should tell Grandmothers and Granpas to not believe on Funny Accents

Ответить
@SOLEEV8
@SOLEEV8 - 14.08.2023 16:02

Well done, I learned a lot!

Ответить
@richardkojo-ys6qe
@richardkojo-ys6qe - 06.05.2024 00:54

Thank you very much you are very Education very Good keep it UPP

Ответить
@mysticdax
@mysticdax - 23.05.2024 23:23

A tech support scammer tried to get my elderly father yesterday. He had the same accent as the guy in the video, and he also called himself "Sylvester." Gee, what a coincidence. However, this guy said he was from GeekSquad.

Ответить