Ausnahme gefangen: SSL certificate problem: certificate is not yet valid 📌 Malicious WinRAR SFX Files Slipping Past Traditional AV Solutions

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 Malicious WinRAR SFX Files Slipping Past Traditional AV Solutions


💡 Newskategorie: Hacking
🔗 Quelle: blackhatethicalhacking.com

Malicious WinRAR SFX Files Slipping Past Traditional AV Solutions

Premium Content

Patreon
Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes

Cybersecurity Researchers at CrowdStrike Uncover New Technique for Evading Detection

Researchers from cybersecurity firm CrowdStrike have discovered that hackers are adding malicious functionality to self-extracting archives (SFX) created with compression software like WinRAR or 7-Zip. By including harmless decoy files in the SFX files, attackers can plant backdoors without triggering the security agent on the target system.

SFX files are essentially executables that contain archived data along with a built-in decompression stub, which is the code used for unpacking the data. These files can be password-protected to prevent unauthorized access and simplify distribution of archived data to users who do not have a utility to extract the package.

Password-protected SFX created with 7-ZipPassword-protected SFX created with 7-Zip
source: CrowdStrike

 

CrowdStrike’s analysis discovered an adversary that used stolen credentials to abuse ‘utilman.exe’ and launch a password-protected SFX file that had been planted on the system previously. Utilman is an accessibility application that can be executed before user login, often abused by hackers to bypass system authentication.

 

The utilman tool on login screenThe utilman tool on login screen
source: CrowdStrike

See Also: So you want to be a hacker?
Offensive Security, Bug Bounty Courses

Attackers Exploit WinRAR’s Advanced Options to Run Malicious Scripts with System Privileges

The SFX file triggered by utilman.exe is password-protected and contains an empty text file that serves as a decoy. The real function of the SFX file is to abuse WinRAR’s setup options to run PowerShell, Windows command prompt (cmd.exe), and task manager with system privileges.

The attacker customized the SFX archive so that no dialog or window was displayed during the extraction process. The threat actor also added instructions to run PowerShell, command prompt, and task manager. WinRAR offers a set of advanced SFX options that allow adding a list of executables to run automatically before or after the process, as well as overwrite existing files in the destination folder if entries with the same name exist.

SFX archive backdoor from WinRAR setup commandsCommands in WinRAR SFX setup that allow backdoor access
source: CrowdStrike

Unlikely to be flagged by AV

As this type of attack is unlikely to be caught by traditional antivirus software that is looking for malware inside of an archive, CrowdStrike advises users to pay particular attention to SFX archives and use appropriate software to check the content of the archive and look for potential scripts or commands scheduled to run upon extraction.

Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com

Source: bleepingcomputer.com

Source Link

Merch

Offensive Security & Ethical Hacking Course

Begin the learning curve of hacking now!


Information Security Solutions

Find out how Pentesting Services can help you.

The post Malicious WinRAR SFX Files Slipping Past Traditional AV Solutions first appeared on Black Hat Ethical Hacking. ...



📌 Malicious WinRAR SFX Files Slipping Past Traditional AV Solutions


📈 113.22 Punkte

📌 Silverstone: Günstiges SFX- und leistungsstarkes SFX-L-Netzteil


📈 39.04 Punkte

📌 Enermax Revolution SFX: Neue SFX-Netzteilserie nach über 10 Jahren


📈 39.04 Punkte

📌 Silverstone: Günstiges SFX- und leistungsstarkes SFX-L-Netzteil


📈 39.04 Punkte

📌 Enermax Revolution SFX: Neue SFX-Netzteilserie nach über 10 Jahren


📈 39.04 Punkte

📌 Ion SFX Gold: Fractal Design präsentiert kompakte SFX-L-Netzteile


📈 39.04 Punkte

📌 Fractal Design Ion SFX-L im Test: 500-Watt-Netzteil im SFX-L-Format


📈 39.04 Punkte

📌 Forgotten motherboard driver turns out to be perfect for slipping Windows ransomware past antivirus checks


📈 37.56 Punkte

📌 Proofpoint: Social engineering attacks slipping past users


📈 37.56 Punkte

📌 Shadow data slipping past security teams


📈 37.56 Punkte

📌 WinRAR SFX archives can run PoweShell without being detected


📈 34.95 Punkte

📌 WinRAR SFX archives can run PowerShell without being detected


📈 34.95 Punkte

📌 Rogue iOS App Gets Boot After Slipping into App Store


📈 25.4 Punkte

📌 Rogue iOS App Gets Boot After Slipping into App Store


📈 25.4 Punkte

📌 West Africa’s Democratic Progress is Slipping Away, Even as Region’s Significance Grows


📈 25.4 Punkte

📌 US Is Slipping Toward Measles Being Endemic Once Again, Says Study


📈 25.4 Punkte

📌 America's Air Quality Is Slipping After Years of Improvement


📈 25.4 Punkte

📌 Rogue Actors Slipping Through The Cracks Into Business’ Internal Networks


📈 25.4 Punkte

📌 State Data Privacy Laws | It "Keeps on Slipping" | Identity Innovation: Passwordless & B2C - ESW285


📈 25.4 Punkte

📌 Storage Vendors Are Quietly Slipping SMR Disks Into Consumer Hard Drives


📈 25.4 Punkte

📌 It "Keeps on Slipping": Navigating the SEC's New Timeline for Incident Reporting - ESW #285


📈 25.4 Punkte

📌 UN Warns Key Warming Threshold Slipping From Sight


📈 25.4 Punkte

📌 Instagram Impersonators Target Thousands, Slipping by Microsoft's Cybersecurity


📈 25.4 Punkte

📌 Eric Schmidt Warns US Technology Edge Over China Slipping


📈 25.4 Punkte

📌 When traditional AV solutions are not enough


📈 24.72 Punkte

📌 Discover Why Proactive Web Security Outsmarts Traditional Antivirus Solutions


📈 24.72 Punkte

📌 NETGEAR unveils 4G and 5G wireless solutions as an alternative to traditional wired broadband


📈 24.72 Punkte

📌 Virustotal says that the WinRAR executable from the official download page is malicious. What to think of this ?


📈 24.35 Punkte

📌 A "DHCP is Broken" story, and a Blast from the Past (or should I say "Storm" from the past), (Thu, Jul 14th)


📈 24.31 Punkte

📌 Hackers Deliver Malicious DLL Files Chained With Legitimate EXE Files


📈 23.06 Punkte

📌 Use Doppler instead of traditional .env files 🍕


📈 22.92 Punkte

📌 How To Hack or Unlock WinZip | WinRAR Files Password On PC


📈 22.5 Punkte

📌 WinRAR 0-Day That Uses Poisoned JPG And TXT Files Under Exploit Since April


📈 22.5 Punkte











matomo