What this "Visual Novel" is really doing?

Credibility score: 59/100 — Mixed Credibility. Several questionable claims detected. Watch with healthy skepticism.

BSmeter analyzed "What this "Visual Novel" is really doing?" and rated it 59/100 for credibility (a BS score of 41/100 — mixed credibility), on 2026-06-25. Its weakest claim — "Eric prefaces his critique by saying he's not 'hitting on' these sites." — scored 45/100 and was flagged as loaded language. 13 claims were checked against the video transcript. Scores are produced by BSmeter's AI analysis of the transcript, not independent human verification.

Of 13 claims analyzed: 0 scored under 40, 6 between 40 and 69, and 7 at 70 or above.

Claims analyzed

Eric sets up a 'spot the fake download button' game, then reveals the site cleaned up its act. — Just Vibes (50/100)

At 0:00

Starts with a 'gotcha' question, then immediately deflates it by saying the problem's gone. Classic bait-and-switch for a video topic. 🎣

Why this score: The speaker sets up a challenge ('Where do you click to download?') implying a trap, but then reveals the specific site he was going to use has already removed the malicious ads. This makes the initial 'gotcha' feel a bit moot, as the immediate threat is gone, shifting the focus to a more general issue rather than a specific live example. It's a comedic setup that loses its punch.

Original quote: “Out of body, my name is Eric. And today, I'm going to ask you a question first of all. Where do you click to download? Let's find out. Okay, it looks like you guessed correctly. Mainly cuz I think this site, which was the one that the person who sent this to me initially used has actually gotten…”

Eric insists on making the video despite the initial example being fixed. — No Frame (75/100)

At 0:15

The problem site fixed itself, but the issue is still real. Fair enough, gotta cover the general threat. 🛡️

Why this score: Even though the specific site he intended to use as an example has cleaned up its act, the underlying issue of malicious ad networks on file-sharing sites is a legitimate and ongoing concern. His decision to proceed with the video to educate viewers is a reasonable one, shifting from a specific example to a broader problem.

Original quote: “But we're still going to make this video cuz this is an issue you got to know about.”

Eric prefaces his critique by saying he's not 'hitting on' these sites. — Loaded Language (45/100)

At 0:26

Says he's 'not hitting on' sites right before he's about to hit on them. The classic pre-emptive apology. 😇

Why this score: The speaker uses the phrase 'I'm not hitting on any of these sites' as a disclaimer, which often signals that he is, in fact, about to criticize them. It's a rhetorical softening to manage audience perception before delivering potentially negative information about the sites' practices, especially concerning their 'reputationally' challenged nature.

Original quote: “And this isn't really I'm not hitting on any of these sites. Understand especially for file sharing sites that maybe reputationally”

Suggests file-sharing sites might not know about sketchy ads, a bit of a soft-pedal 🤷‍♀️ — Missing Context (45/100)

At 0:30

Saying they 'don't even know' what's going on is a generous take — or a convenient excuse for shady practices. 🤔

Why this score: The speaker implies ignorance on the part of file-sharing sites regarding the nature of the ads they host. While possible, it also conveniently deflects responsibility from the site owners for potentially malicious advertising, which often generates revenue for them.

Original quote: “sharing sites that maybe reputationally couldn't get with a good ad network. Maybe they I think sometimes they don't they don't even know exactly what's going on.”

Speaker connects CFD domain to 'scamier version of trading futures' without direct evidence for *this* context. — Confidence Mismatch (45/100)

At 4:30

Connects 'CFD domain' to 'scamier trading futures' like it's a given, but then admits they 'get there's another' meaning. Bit of a leap! 😬

Why this score: The speaker initially links the 'CFD domain' to a 'scamier version of trading futures' based on their prior knowledge of CFD in finance. However, they immediately acknowledge there's 'another' meaning (computational fluid dynamics), which suggests their initial confident association might not apply to this specific context. It's a quick jump to a negative connotation without confirming which CFD meaning is relevant here.

Original quote: “and I also do have a static report from Codex that I'll show you about some of the things this is getting up to. So once again, we click the correct button and everything, you know, it seemed like we did everything right. But this one it does give you a download button instead of just popping up…”

Explaining the malware's use of Ethereum blockchain for C2 server resilience. — No Frame (75/100)

At 6:30

Describing a technical detail of the malware's operation. Sounds like a legit explanation of a known technique.

Why this score: The speaker is explaining a technical mechanism (Ether hiding via Ethereum blockchain for C2 server resilience). This is a straightforward technical observation, not a rhetorical trick.

Original quote: “And now we've gone to Ether hiding, which means it's using the Ethereum blockchain so that the C2 server doesn't have to die.”

Static report says persistence, but dynamic analysis shows none. Confidence mismatch on malware behavior. — Confidence Mismatch (45/100)

At 8:30

The static report said one thing, but the live test shows the opposite. That's a pretty big 'oops' for malware persistence. 😬

Why this score: The speaker notes a discrepancy between the static analysis report, which indicated persistence, and their dynamic observation, where the malware did not exhibit persistent behavior after a restart. This highlights a confidence mismatch between reported capabilities and observed reality, suggesting the malware might have anti-analysis features or simply didn't execute that path in this specific run.

Original quote: “And now I did just want to restart to see if we can if there's persistency cuz that's like the only thing I haven't really looked at. The static report said there was persistency, but I haven't seen it. So, that's why I'm kind of curious. Uh the It was found statically that there is a code path for…”

Explaining the malware's unpacking process and payload delivery. — No Frame (75/100)

At 10:30

Just walking through the technical steps of how the malware unpacks itself. Straightforward explanation. 🤓

Why this score: The speaker is detailing the technical process of how the malicious payload is decrypted and extracted, leading to the stealer. This is a factual description of the malware's behavior, not a rhetorical trick.

Original quote: “XOR decrypts that into a zip archive and extracts the zip contents into temp. This is that where we have this printer driver uh and a bunch of DLLs, one of which is malicious and triggers the stealer.”

Claims other ad blockers don't reliably block this malware because it's not a legitimate ad network. — Confidence Mismatch (45/100)

At 12:30

Says 'I have seen' as if it's universal truth, then explains why it *might* be true. The confidence is doing overtime. 🚩

Why this score: The speaker starts with a confident assertion ('I have seen AdBlock... not reliably blocking this') but then shifts to a speculative explanation ('a part of that is because this is not a legitimate ad network'). While the explanation makes sense, the initial claim is based on personal observation, not a comprehensive test or data, yet presented with high certainty. It's a leap from anecdote to general rule.

Original quote: “I have seen AdBlock and some of the other ad blockers not reliably blocking this and a part of that is because this is not a legitimate ad network, you know, they're not going to make any effort at disclosing the legitimacy. Right? Like a lot of the ways like ad blockers will, for example, if a if…”

Declaring it's a 'stealer' and advising to change credentials. — No Frame (75/100)

At 14:30

Straight-up warning about malware. No tricks, just good advice if you've been exposed. 🚨

Why this score: The speaker is giving a direct, actionable warning based on their analysis that the software is a 'stealer.' This is a clear statement of fact within the context of their video's purpose (analyzing malicious software). It's not manipulative or misleading; it's a conclusion presented as a direct consequence of their findings, which aligns with the video's overall theme of cybersecurity analysis. The advice to change credentials is a standard, appropriate response to a 'stealer' infection.

Original quote: “It is a stealer, so change all credentials,”

Declares the software a 'stealer' and advises changing credentials. — No Frame (75/100)

At 14:30

Straight-up warning about malware and how to deal with it — no tricks, just good advice. 🚨

Why this score: The speaker is giving a direct, actionable warning based on their analysis of the software. There's no loaded language or missing context; it's a clear statement of risk and mitigation.

Original quote: “It is a stealer, so change all credentials, and you should be good. That's all for me for now. Bye.”

Declares the software a 'stealer' and advises changing credentials. — No Frame (75/100)

At 14:30

Straight-up warning about malware and a practical fix. No tricks, just good advice. 🚨

Why this score: The speaker is directly stating the nature of the software (a stealer) and providing clear, actionable steps to mitigate the risk (change all credentials). This is a straightforward, helpful statement without any apparent rhetorical manipulation. It's a direct observation and recommendation based on their analysis.

Original quote: “It is a stealer, so change all credentials, and you should be good. That's all for me for now. Bye.”

Declares the software a 'stealer' and advises changing credentials. — No Frame (75/100)

At 14:30

Straight-up warning about malware and a practical step to take. No frills, just facts. 🚨

Why this score: The speaker is giving a direct, actionable warning based on their analysis that the 'visual novel' software is actually a credential stealer. This is a clear, unembellished statement of fact and advice, not a rhetorical trick. It's a public service announcement, basically.

Original quote: “It is a stealer, so change all credentials, and you should be good. That's all for me for now. Bye.”

See the full analysis with timestamps →