¡Estuve A PUNTO DE SER HACKEADO por abrir un pdf!

¡Estuve A PUNTO DE SER HACKEADO por abrir un pdf!

🎙 EDteam 👥 1.0M 📅 September 20, 2025 ⏱ 16 min 👁 90K 📄 expert opinion 🧭 2026-08-03
Available in: English (current) Français

Keywords

phishingSVGmalwaresocial engineeringcybersecurity

Summary

In this video, the host of EDteam recounts a recent phishing attempt targeting him via email. The email contained a file that appeared to be a PDF but was actually an SVG (Scalable Vector Graphics) file, which can embed JavaScript. Recognizing the danger, he avoided opening it directly and instead analyzed the code in a text editor. He discovered heavily obfuscated JavaScript that, when executed in a browser, would decode a fake webpage mimicking the Colombian Fiscalía General de la Nación. That page would prompt the victim to download a password-protected ZIP file containing a Windows executable and DLLs, which would install malware. The host used ChatGPT to help analyze the malicious code, which confirmed the attack chain. He also demonstrated how to safely view the SVG by converting it to PNG, which revealed a QR code leading to the same fake site. The video emphasizes the importance of vigilance, checking file extensions, and not acting on panic. It also includes a cautionary tale about a previous hack of their YouTube channel via a similar technique. The host provides practical advice on what to do if such a file is opened, such as disconnecting from the network and scanning for malware.

201 words

Critical Evaluation

The video is a valuable educational resource on cybersecurity, specifically focusing on phishing and malicious file types. The host’s approach is commendable: he demonstrates a real-world attack scenario and walks viewers through his analytical process, from recognizing red flags to safely inspecting the malicious code. The use of ChatGPT for code analysis is a modern and effective technique, showcasing how AI can assist in cybersecurity. The explanation of the attack chain is clear and detailed, making it accessible to a general audience while still providing technical depth. The host’s credibility is enhanced by his expertise in SVG (he has a course on it) and his previous experience with a channel hack. However, the video lacks formal citations or references to external sources, relying primarily on anecdotal evidence. The advice given is practical and aligns with standard cybersecurity practices, but it could be more comprehensive, such as recommending specific security tools or steps for reporting phishing attempts. The title is accurate and engaging, and the content delivers on its promise. Overall, the video is informative and well-executed, though it could benefit from more structured references and a broader discussion of preventive measures. The public comments reflect appreciation for the detailed explanation and the real-world relevance, with many viewers sharing similar experiences. The video effectively raises awareness about a common threat and provides actionable insights.

223 words

Title / Content Match

The title accurately reflects the content: the host describes a close call with a phishing attack via a malicious PDF-like file, and the video delivers on this promise with a detailed breakdown.

Quality & Reliability

8/10

The video provides a detailed, first-hand account of a phishing attempt, with a thorough technical analysis of the malicious SVG file, including code inspection and AI-assisted reverse engineering. The explanation is clear and practical, though it relies on anecdotal evidence and lacks formal citations. The use of AI for analysis is innovative and adds credibility, but the video is primarily educational and not peer-reviewed.

Key Moments

Cited Sources

Concurring Sources

  • Phishing - Wikipedia — General information on phishing, consistent with the video's explanation.
  • SVG - Wikipedia — Details on SVG format, supporting the video's claim that SVG can contain scripts.

Contribution & Novelties

The video provides a unique, real-world case study of a phishing attack using an SVG file, demonstrating the entire attack chain from email to malware delivery. It showcases a practical method for safely analyzing malicious code using text editors and AI tools like ChatGPT, which is an innovative approach for a general audience. The video also emphasizes the psychological manipulation aspect of phishing, highlighting how attackers exploit panic and urgency.

Pour aller plus loin :

115 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, indicating that the video is accessible yet informative. The balance suggests a well-rounded educational content.

Reliability 8/10

💬 Très positif. Les 30 commentaires analysés expriment une grande appréciation pour la clarté de l'explication et la valeur éducative, plusieurs partageant des expériences similaires et remerciant l'auteur.