1
00:00:06,480 --> 00:00:11,280
- In this lesson 8.2, we're
gonna look at malware attacks.

2
00:00:11,280 --> 00:00:15,600
The malware is a portmanteau
of malicious and software.

3
00:00:15,600 --> 00:00:17,820
That's how we get malware.

4
00:00:17,820 --> 00:00:20,850
The malware is used by
hackers, by cybercriminals,

5
00:00:20,850 --> 00:00:23,130
by hacktivists, by cyber-terrorists,

6
00:00:23,130 --> 00:00:26,970
to either steal information,
harm or disrupt operations,

7
00:00:26,970 --> 00:00:30,390
extort, and or weaponize devices.

8
00:00:30,390 --> 00:00:33,750
Now, malware is an
extraordinarily powerful weapon.

9
00:00:33,750 --> 00:00:37,620
It can be used as an entry
point to a larger attack,

10
00:00:37,620 --> 00:00:39,630
or a more sophisticated attack,

11
00:00:39,630 --> 00:00:43,233
or in and of itself, it can
be a stand-alone exploit.

12
00:00:44,340 --> 00:00:47,400
And there are four
primary malware families.

13
00:00:47,400 --> 00:00:51,510
We have viruses, worms,
Trojans, and rootkits.

14
00:00:51,510 --> 00:00:53,250
A virus is malicious code

15
00:00:53,250 --> 00:00:55,649
whose primary function is to replicate

16
00:00:55,649 --> 00:00:58,230
and to deliver its payload.

17
00:00:58,230 --> 00:01:00,570
Now a virus requires a host,

18
00:01:00,570 --> 00:01:02,790
just like when you and I get
sick and we have a virus,

19
00:01:02,790 --> 00:01:04,980
the virus needs us, we're the host.

20
00:01:04,980 --> 00:01:07,710
So a virus requires a host.

21
00:01:07,710 --> 00:01:09,210
A worm is malicious code

22
00:01:09,210 --> 00:01:11,190
that exploits known vulnerabilities.

23
00:01:11,190 --> 00:01:13,380
Now a worm is self-replicating

24
00:01:13,380 --> 00:01:16,770
and often takes advantage of
network transport features

25
00:01:16,770 --> 00:01:17,603
to spread.

26
00:01:17,603 --> 00:01:19,320
I always just imagine like a little worm,

27
00:01:19,320 --> 00:01:22,320
just slinking all around, right,
moving from place to place.

28
00:01:23,310 --> 00:01:26,670
A Trojan is malicious code
that looks legitimate,

29
00:01:26,670 --> 00:01:29,820
and it actually acts like
a bonafide application.

30
00:01:29,820 --> 00:01:32,970
Like maybe it's really a
game, maybe it's a picture,

31
00:01:32,970 --> 00:01:34,581
maybe it's a music file.

32
00:01:34,581 --> 00:01:37,890
But simultaneously it's
delivering or performing

33
00:01:37,890 --> 00:01:38,970
a malicious action,

34
00:01:38,970 --> 00:01:40,650
like maybe downloading a keylogger,

35
00:01:40,650 --> 00:01:45,033
and then, you know, recording
all of your keystrokes.

36
00:01:46,050 --> 00:01:47,610
And lastly, rootkits.

37
00:01:47,610 --> 00:01:49,950
rootkits are clandestine computer programs

38
00:01:49,950 --> 00:01:53,089
designed to provide
continued privilege access

39
00:01:53,089 --> 00:01:54,540
to a computer,

40
00:01:54,540 --> 00:01:57,090
while actively hiding its presence.

41
00:01:57,090 --> 00:01:58,770
So you wanna make sure that
you know the difference

42
00:01:58,770 --> 00:02:02,043
between viruses, worms,
Trojans, and rootkits.

43
00:02:03,210 --> 00:02:05,040
Now, diving a little bit
deeper into rootkits.

44
00:02:05,040 --> 00:02:06,630
There's a number of
different types of rootkits.

45
00:02:06,630 --> 00:02:08,190
There's firmware rootkits,

46
00:02:08,190 --> 00:02:10,230
there are rootkits known as bootkits.

47
00:02:10,230 --> 00:02:13,440
There are kernel rootkits
and driver rootkits.

48
00:02:13,440 --> 00:02:17,280
Firmware rootkits overwrite
the firmware or the BIOS,

49
00:02:17,280 --> 00:02:20,880
so the rootkit can start
before the operating system.

50
00:02:20,880 --> 00:02:21,780
I wanna make a note

51
00:02:21,780 --> 00:02:24,510
that really these firmware
rootkits require a BIOS.

52
00:02:24,510 --> 00:02:27,630
And if you now have a
system that has a UEFI

53
00:02:27,630 --> 00:02:30,639
in place of the BIOS, so
really, a next-generation BIOS,

54
00:02:30,639 --> 00:02:32,970
and you're running Windows Secure Boot,

55
00:02:32,970 --> 00:02:35,973
then you are protected from
these firmware rootkits.

56
00:02:37,350 --> 00:02:40,290
A bootkit replaces the
operating system's bootloader,

57
00:02:40,290 --> 00:02:41,640
which is the piece of software

58
00:02:41,640 --> 00:02:43,320
that starts the operating system,

59
00:02:43,320 --> 00:02:45,000
so that the PC loads the bootkit

60
00:02:45,000 --> 00:02:47,220
before the operating system.

61
00:02:47,220 --> 00:02:48,869
Kernel rootkits replace a portion

62
00:02:48,869 --> 00:02:51,060
of the operating system kernel

63
00:02:51,060 --> 00:02:53,160
so the rootkit can start automatically

64
00:02:53,160 --> 00:02:55,350
when the operating system loads.

65
00:02:55,350 --> 00:02:58,317
Driver rootkits impersonates
a trusted driver

66
00:02:58,317 --> 00:03:01,287
that the operating system
uses to communicate

67
00:03:01,287 --> 00:03:02,790
with the hardware.

68
00:03:02,790 --> 00:03:07,790
Again, also addressed by having
UEFI and Driver Attestation.

69
00:03:10,530 --> 00:03:12,300
So how does malware actually operate?

70
00:03:12,300 --> 00:03:14,640
Well, there are four primary techniques.

71
00:03:14,640 --> 00:03:18,180
Malware can be stealth,
malware can be memory resident,

72
00:03:18,180 --> 00:03:20,760
malware can be known as polymorphic,

73
00:03:20,760 --> 00:03:23,490
or malware can be metamorphic.

74
00:03:23,490 --> 00:03:26,460
The stealth malware is designed
to be really inconspicuous.

75
00:03:26,460 --> 00:03:28,440
It's stealth, it doesn't
wanna be seen, right,

76
00:03:28,440 --> 00:03:30,026
in order to avoid detection

77
00:03:30,026 --> 00:03:32,850
by either concealing the file size

78
00:03:32,850 --> 00:03:35,580
or moving to an alternate location.

79
00:03:35,580 --> 00:03:38,250
Memory resident malware
stays resident in memory

80
00:03:38,250 --> 00:03:39,840
upon execution.

81
00:03:39,840 --> 00:03:42,240
And dangerously, can affect other programs

82
00:03:42,240 --> 00:03:44,490
that are running in
memory, at the same time.

83
00:03:45,450 --> 00:03:49,560
Polymorphic malware evades any
pattern-matching detection,

84
00:03:49,560 --> 00:03:52,590
which is really what most of
our antivirus signatures do,

85
00:03:52,590 --> 00:03:55,623
by frequently changing
identifiable characteristics

86
00:03:55,623 --> 00:03:59,430
like a file name, file
type, or encryption keys.

87
00:03:59,430 --> 00:04:02,340
And metamorphic malware is rewritten

88
00:04:02,340 --> 00:04:04,200
with every single iteration,

89
00:04:04,200 --> 00:04:06,900
so that each succeeding
version of the code

90
00:04:06,900 --> 00:04:08,670
is different from the proceeding one.

91
00:04:08,670 --> 00:04:09,999
So just when we know what it is,

92
00:04:09,999 --> 00:04:12,480
the next time it's used, it's different.

93
00:04:12,480 --> 00:04:15,780
So every time, right, every iteration,

94
00:04:15,780 --> 00:04:17,380
it looks a little bit different.

95
00:04:18,510 --> 00:04:23,043
Stealth, memory resident,
polymorphic and metamorphic.

96
00:04:25,590 --> 00:04:28,710
So, how does the malware
actually get on our systems?

97
00:04:28,710 --> 00:04:30,900
Well, the malware distribution
channel is designed

98
00:04:30,900 --> 00:04:32,880
to entice our users

99
00:04:32,880 --> 00:04:36,630
really, to unwittingly
install malicious code.

100
00:04:36,630 --> 00:04:38,460
Tactics include phishing emails

101
00:04:38,460 --> 00:04:40,800
with embedded web links or attachments,

102
00:04:40,800 --> 00:04:42,510
social media web links

103
00:04:42,510 --> 00:04:44,940
that take you to a
malware distribution site.

104
00:04:44,940 --> 00:04:46,410
Web drive-by downloads;

105
00:04:46,410 --> 00:04:48,660
by just going to a
website that's infected,

106
00:04:48,660 --> 00:04:50,550
you may get malware coming down.

107
00:04:50,550 --> 00:04:54,390
Embedding the malware in
pictures, movies or advertising.

108
00:04:54,390 --> 00:04:57,120
We talked about that
earlier, called malvertising.

109
00:04:57,120 --> 00:04:59,520
Or, embedded in portable
media like the USB,

110
00:04:59,520 --> 00:05:00,353
and we talked about that.

111
00:05:00,353 --> 00:05:01,650
And we talked about social media

112
00:05:01,650 --> 00:05:04,263
and using like a USB for baiting.

113
00:05:07,260 --> 00:05:09,210
There are four common malware attacks

114
00:05:09,210 --> 00:05:10,710
I want you to be able to recognize.

115
00:05:10,710 --> 00:05:13,200
A command and control attack, known C2,

116
00:05:13,200 --> 00:05:15,003
an advanced persistent threat, APT,

117
00:05:16,020 --> 00:05:19,260
a bot or zombie, and then ransomware.

118
00:05:19,260 --> 00:05:22,302
Now, the objective of a C2
or command and control attack

119
00:05:22,302 --> 00:05:24,750
is for the compromised system,

120
00:05:24,750 --> 00:05:26,760
'cause the system's
already been compromised,

121
00:05:26,760 --> 00:05:29,400
to contact a command center,

122
00:05:29,400 --> 00:05:32,280
which then gives the
attacker complete control

123
00:05:32,280 --> 00:05:34,345
over the infected device.

124
00:05:34,345 --> 00:05:37,380
An APT or an advanced persistent threat

125
00:05:37,380 --> 00:05:41,130
is a really sophisticated type of attack.

126
00:05:41,130 --> 00:05:44,640
It's slow, it's stealthy,
and it's a prolonged attack

127
00:05:44,640 --> 00:05:47,100
on a specific target

128
00:05:47,100 --> 00:05:49,560
with the intention to
compromise the system

129
00:05:49,560 --> 00:05:53,880
and or gain information
from or about that target.

130
00:05:53,880 --> 00:05:57,120
Now these truly are sophisticated,
slow and stealthy attacks

131
00:05:57,120 --> 00:05:59,370
with really a limited number of attackers

132
00:05:59,370 --> 00:06:01,680
who can truly pull off an APT.

133
00:06:01,680 --> 00:06:04,560
Generally, we're gonna see
nation states or military

134
00:06:04,560 --> 00:06:05,960
really be able to do an APT.

135
00:06:08,640 --> 00:06:11,550
Bot and zombies, and those
terms are interchangeable,

136
00:06:11,550 --> 00:06:13,230
are just little pieces of code.

137
00:06:13,230 --> 00:06:16,830
They're automated processes
that either have instructions

138
00:06:16,830 --> 00:06:17,940
embedded in them,

139
00:06:17,940 --> 00:06:19,500
or they listen for instructions.

140
00:06:19,500 --> 00:06:21,630
Now, if a bot or zombie is on your system,

141
00:06:21,630 --> 00:06:24,690
it doesn't really care probably
about your system too much.

142
00:06:24,690 --> 00:06:28,110
It's waiting for instructions
to launch an attack

143
00:06:28,110 --> 00:06:29,310
on another system.

144
00:06:29,310 --> 00:06:32,610
And bots and zombies are very often used

145
00:06:32,610 --> 00:06:34,683
in distributed denial of service attacks.

146
00:06:35,544 --> 00:06:38,130
And then lastly, we have
the one that's in the news

147
00:06:38,130 --> 00:06:40,734
almost every day, right
now, which is ransomware.

148
00:06:40,734 --> 00:06:44,460
Ransomware encrypts
files and demands ransom

149
00:06:44,460 --> 00:06:45,870
for the decryption key.

150
00:06:45,870 --> 00:06:48,420
And in a later lesson we're
gonna dissect ransomware

151
00:06:48,420 --> 00:06:49,560
a little bit more,

152
00:06:49,560 --> 00:06:51,930
but that's the one right
now that's, you know,

153
00:06:51,930 --> 00:06:56,223
really plaguing us and
really dangerous and scary.

154
00:06:57,810 --> 00:07:01,410
And then we have what I call
code with bad intentions.

155
00:07:01,410 --> 00:07:02,700
We have programmatic code

156
00:07:02,700 --> 00:07:05,220
and that's code embedded
in the application

157
00:07:05,220 --> 00:07:06,660
by the developer.

158
00:07:06,660 --> 00:07:09,600
Now, if it's a good
developer, then we're fine,

159
00:07:09,600 --> 00:07:13,290
but, you know, if the developer
has some bad intentions,

160
00:07:13,290 --> 00:07:15,450
well, they can develop
code with bad intentions,

161
00:07:15,450 --> 00:07:18,120
and they may have
backdoors or logic bombs.

162
00:07:18,120 --> 00:07:21,720
A backdoor is designed to
bypass access controls.

163
00:07:21,720 --> 00:07:23,760
So that means they can
get back into their code,

164
00:07:23,760 --> 00:07:25,200
bypassing access control,

165
00:07:25,200 --> 00:07:27,780
generally getting back into
the code as an administrator.

166
00:07:27,780 --> 00:07:30,780
And logic bombs are
instructions that execute

167
00:07:30,780 --> 00:07:34,443
either when a certain event
occurs or when a time occurs.

168
00:07:36,270 --> 00:07:37,530
Then we have spyware.

169
00:07:37,530 --> 00:07:39,960
Spyware is software
with malicious behavior

170
00:07:39,960 --> 00:07:43,309
that's really looking to gather
information about a person

171
00:07:43,309 --> 00:07:45,240
or an organization,

172
00:07:45,240 --> 00:07:47,970
and then send it to another entity.

173
00:07:47,970 --> 00:07:50,700
Now, it may be used just because
they're trying to determine

174
00:07:50,700 --> 00:07:52,682
what ads to show you,

175
00:07:52,682 --> 00:07:55,593
or it could be something
even more nefarious.

176
00:07:56,490 --> 00:07:59,190
And then bloatware is unwanted

177
00:07:59,190 --> 00:08:01,050
or potentially harmful software

178
00:08:01,050 --> 00:08:03,780
that's preloaded onto new devices.

179
00:08:03,780 --> 00:08:07,500
It's also known as potentially
unwanted applications

180
00:08:07,500 --> 00:08:08,400
or PUAs.

181
00:08:08,400 --> 00:08:10,481
So you get a new device,

182
00:08:10,481 --> 00:08:12,780
you know, and it's preloaded, it's there.

183
00:08:12,780 --> 00:08:15,600
You don't really want it, but it's there.

184
00:08:15,600 --> 00:08:17,610
So, let's talk a little
bit more about bloatware.

185
00:08:17,610 --> 00:08:20,100
The problem with bloatware,
it seems pretty innocuous,

186
00:08:20,100 --> 00:08:20,933
right,

187
00:08:20,933 --> 00:08:22,680
it's just installed by the manufacturer,

188
00:08:22,680 --> 00:08:26,610
is that it can deplete both
memory and processor resources.

189
00:08:26,610 --> 00:08:29,250
And so there are a variety
of bloatware out there.

190
00:08:29,250 --> 00:08:30,870
They each have their own warning signs.

191
00:08:30,870 --> 00:08:33,510
The program wants you to make a purchase.

192
00:08:33,510 --> 00:08:37,410
A program is hard to uninstall,
the program is useless,

193
00:08:37,410 --> 00:08:40,710
or the program bombards
the users with popups.

194
00:08:40,710 --> 00:08:42,930
Those are all warning signs
that you have bloatware

195
00:08:42,930 --> 00:08:43,763
on your system

196
00:08:43,763 --> 00:08:45,600
that could easily be depleting memory

197
00:08:45,600 --> 00:08:47,040
and processor resources.

198
00:08:47,040 --> 00:08:49,043
So you wanna do whatever you
can to get that bloatware

199
00:08:49,043 --> 00:08:51,210
off your system.

200
00:08:51,210 --> 00:08:52,043
All right, my friends,

201
00:08:52,043 --> 00:08:53,850
that brings us to a
three-second challenge.

202
00:08:53,850 --> 00:08:55,800
Five challenge questions,
three seconds each.

203
00:08:55,800 --> 00:08:56,633
Let's do it.

204
00:08:58,050 --> 00:09:00,510
Malicious code that exploits
known vulnerabilities

205
00:09:00,510 --> 00:09:02,403
and is self-replicating.

206
00:09:04,980 --> 00:09:06,903
One, two, three.

207
00:09:07,950 --> 00:09:09,423
That's gonna be a worm.

208
00:09:10,320 --> 00:09:11,160
Number two.

209
00:09:11,160 --> 00:09:13,950
Malware that evades
pattern-matching detection

210
00:09:13,950 --> 00:09:17,493
by frequently changing
identifiable characteristics.

211
00:09:18,570 --> 00:09:20,280
This is gonna be one of the morphics.

212
00:09:20,280 --> 00:09:22,770
Ready? One, two, three.

213
00:09:22,770 --> 00:09:24,273
That's gonna be polymorphic.

214
00:09:26,040 --> 00:09:27,840
Common extortion malware.

215
00:09:27,840 --> 00:09:29,880
Everybody's gonna get
this one right, I'm sure.

216
00:09:29,880 --> 00:09:31,680
One, two, three.

217
00:09:31,680 --> 00:09:32,973
And that is ransomware.

218
00:09:34,500 --> 00:09:36,000
Number four.

219
00:09:36,000 --> 00:09:39,210
Automated processes that either
have instructions embedded

220
00:09:39,210 --> 00:09:41,580
or listen for instructions.

221
00:09:41,580 --> 00:09:43,143
One, two, three.

222
00:09:43,980 --> 00:09:46,743
That's gonna be a bot,
also known as a zombie.

223
00:09:49,230 --> 00:09:51,330
And lastly, number five.

224
00:09:51,330 --> 00:09:55,983
Also known as potentially
unwanted applications or PUAs.

225
00:09:57,300 --> 00:09:59,610
One, two, three.

226
00:09:59,610 --> 00:10:01,620
And that's bloatware.

227
00:10:01,620 --> 00:10:03,510
Right. That takes us
to security-in-action,

228
00:10:03,510 --> 00:10:05,430
so you can practically
apply your knowledge.

229
00:10:05,430 --> 00:10:07,590
This one's about an extortion demand,

230
00:10:07,590 --> 00:10:10,020
but it may not be what you think.

231
00:10:10,020 --> 00:10:12,420
Your organization receives
an extortion threat

232
00:10:12,420 --> 00:10:16,410
demanding a $500,000 payment in Bitcoin.

233
00:10:16,410 --> 00:10:18,000
If the money is not received,

234
00:10:18,000 --> 00:10:21,150
your custom e-commerce
platform will cease to operate

235
00:10:21,150 --> 00:10:25,800
and the same fate will befall
all of your backup copies.

236
00:10:25,800 --> 00:10:29,310
Now, the investigative team
can't find any evidence

237
00:10:29,310 --> 00:10:31,770
or indication of a malware infection,

238
00:10:31,770 --> 00:10:34,800
and there doesn't seem to
be any unusual connections

239
00:10:34,800 --> 00:10:36,810
or activities.

240
00:10:36,810 --> 00:10:38,610
Wow, this is kind of a mystery.

241
00:10:38,610 --> 00:10:43,140
So my question to you is, well,
what do you suspect and why?

242
00:10:43,140 --> 00:10:44,460
So let's go through that again.

243
00:10:44,460 --> 00:10:46,710
Your organization receives
this extortion threat

244
00:10:46,710 --> 00:10:51,710
demanding $500,000 in payment,
half a million dollars.

245
00:10:52,170 --> 00:10:54,720
But it looks like everything's
okay on your system.

246
00:10:55,682 --> 00:10:57,690
There doesn't seem to be any malware,

247
00:10:57,690 --> 00:11:00,000
there doesn't seem to be
any unusual connections,

248
00:11:00,000 --> 00:11:01,888
but they're saying if you don't pay,

249
00:11:01,888 --> 00:11:06,210
your custom e-commerce
application or platform

250
00:11:06,210 --> 00:11:08,340
is gonna just stop operating.

251
00:11:08,340 --> 00:11:12,360
And the same fate is gonna
befall all of your backup copies.

252
00:11:12,360 --> 00:11:13,320
So put me on pause,

253
00:11:13,320 --> 00:11:16,270
think about what your hypothesis
is, and then come on back.

254
00:11:17,190 --> 00:11:19,050
So this one's really kind of a mystery.

255
00:11:19,050 --> 00:11:21,540
Let's talk through our hypothesis.

256
00:11:21,540 --> 00:11:22,890
Based on the following,

257
00:11:22,890 --> 00:11:25,890
one, there's no indication
of any installed malware.

258
00:11:25,890 --> 00:11:27,390
We're don't seeing infected files.

259
00:11:27,390 --> 00:11:29,100
It's not ransomware, right?

260
00:11:29,100 --> 00:11:31,443
And we're not seeing any unusual activity.

261
00:11:33,120 --> 00:11:36,240
And the e-commerce platform,
though, has been customized.

262
00:11:36,240 --> 00:11:39,030
Hmm. That might set off some alarm bells.

263
00:11:39,030 --> 00:11:40,560
We've had some programmers involved

264
00:11:40,560 --> 00:11:42,243
in the e-commerce platform.

265
00:11:43,290 --> 00:11:46,380
And the fact that the claim
that the backup copies

266
00:11:46,380 --> 00:11:49,530
are gonna be similarly
impacted, that's interesting.

267
00:11:49,530 --> 00:11:52,830
So our e-commerce platform
is gonna cease to operate,

268
00:11:52,830 --> 00:11:55,620
and if we install any backup
copies of the platform,

269
00:11:55,620 --> 00:11:57,333
that's not gonna operate either.

270
00:11:59,040 --> 00:12:00,510
Hmm. What do you think?

271
00:12:00,510 --> 00:12:03,210
Well, I think a hypothesis
worth investigating

272
00:12:03,210 --> 00:12:05,520
is the insertion of a logic bomb

273
00:12:05,520 --> 00:12:09,156
that's programmed to execute
when a certain event occurs,

274
00:12:09,156 --> 00:12:11,220
or at a certain time.

275
00:12:11,220 --> 00:12:14,880
Which is why it's going to
affect both the current platform

276
00:12:14,880 --> 00:12:16,410
and your backup copies.

277
00:12:16,410 --> 00:12:19,590
And it's why we're not
seeing any unusual activity,

278
00:12:19,590 --> 00:12:22,950
because that logic bomb was
installed programmatically

279
00:12:22,950 --> 00:12:25,200
when that code was developed,

280
00:12:25,200 --> 00:12:27,180
and it will either go
off at a certain time,

281
00:12:27,180 --> 00:12:29,273
or when a certain event occurs.

282
00:12:29,273 --> 00:12:31,710
What do you think about that hypothesis?

283
00:12:31,710 --> 00:12:33,150
Probably not the one you were expecting

284
00:12:33,150 --> 00:12:35,190
when you saw an extortion demand.

285
00:12:35,190 --> 00:12:36,990
But you know, we have to
really be always ready

286
00:12:36,990 --> 00:12:38,340
to think outside the box

287
00:12:38,340 --> 00:12:40,811
because, you know, our
adversaries and attackers

288
00:12:40,811 --> 00:12:42,660
are pretty clever.

289
00:12:42,660 --> 00:12:45,273
And that, my friends,
is security-in-action.

290
00:12:46,830 --> 00:12:48,450
There's your word cloud,
it's a pretty big one.

291
00:12:48,450 --> 00:12:50,040
Make sure that you can
go through all of these,

292
00:12:50,040 --> 00:12:51,990
you can identify them, you're comfortable,

293
00:12:51,990 --> 00:12:53,280
you're confident with the terms.

294
00:12:53,280 --> 00:12:54,810
If not, go back through the lesson.

295
00:12:54,810 --> 00:12:56,340
You'll find them right there.

296
00:12:56,340 --> 00:12:58,110
And when you're ready,
head to the next lesson.

297
00:12:58,110 --> 00:12:59,310
I'll be waiting for you.
