https://www.pcmag.com/news/366852/hackers-start-exploiting-serious-winrar-flaw-to-spread-malwa?utm_source=email&utm_campaign=whatsnewnow&utm_medium=image
Hackers Start Exploiting Serious WinRAR Flaw to Spread MalwareIf you're running an old version of WinRAR, it's a good time to patch. Hackers appear to be exploiting a serious bug in the file utility software by spreading secretly rigged file archives that install malware on people's PCs.
By Michael Kan (https://www.pcmag.com/author-bio/michael-kan)
- February 27, 2019 3:05PM EST
(https://assets.pcmag.com/media/images/634858-winrar-vulnerability.png?thumb=y&width=810&height=456)
WinRAR users need to watch out. Hackers are starting to exploit a newly disclosed bug in the file-archiving tool to secretly install malware (https://www.pcmag.com/roundup/354226/the-best-malware-removal-and-protection-tools) on Windows PCs.
Chinese security firm Qihoo 360 has uncovered several file archive samples that exploit the WinRAR vulnerability (https://www.pcmag.com/news/366678/winrar-has-serious-flaw-that-can-load-malware-to-pcs) to deliver malware to a victim's computer. One of the attacks was sent over email.
The first sample was detected only two days after the WinRAR bug was publicly disclosed (https://research.checkpoint.com/extracting-code-execution-from-winrar/) by a separate security firm, Check Point. The bug is particularly problematic because WinRAR claims to have over 500 million users. A hacker can exploit the vulnerability to craft seemingly benign RAR archive files that are actually malicious.
According to Qihoo 360's research division, one of the samples it uncovered is a file archive containing pictures of attractive women. "In order to trigger the vulnerability, attackers put inside lots of image files and lure the victim to decompress the archive," the researchers said in their report (https://ti.360.net/blog/articles/upgrades-in-winrar-exploit-with-social-engineering-and-encryption/).
(https://assets.pcmag.com/media/images/634859-winrar-vulnerability-2.png?thumb=y&width=980&height=864)
However, the archive itself has secretly been rigged to exploit the WinRAR bug, which unpacks a file archive to a new destination. In this case, when the archive is decompressed, it'll covertly deliver a malware executable to the PC's Startup Folder. The next time the victim restarts their PC, the malware will run on startup and create a hidden backdoor that can let the hacker take over their computer and install other forms of malware, the researchers warned.
View image on Twitter (https://twitter.com/360TIC/status/1099987939818299392/photo/1)
(https://pbs.twimg.com/media/D0PxLTjU8AA8fEC?format=jpg&name=small) (https://twitter.com/360TIC/status/1099987939818299392/photo/1)
Quote(https://pbs.twimg.com/profile_images/986808190091210753/ZPsSoqjq_normal.jpg) (https://twitter.com/360TIC)
360 Threat Intelligence Center@360TIC
?
Possibly the first malware delivered through mail to exploit WinRAR vulnerability. The backdoor is generated by MSF and written to the global startup folder by WinRAR if UAC is turned off.https://www.virustotal.com/#/file/7871204f2832681c8ead96c9d509cd5874ed38bcfc6629cbc45472b9f388e09c/detection ... (https://t.co/bK0ngP2nIy)
IOC:
hxxp://138.204.171.108/BxjL5iKld8.zip
138.204.171.108:443
244 (https://twitter.com/intent/like?tweet_id=1099987939818299392)
6:02 AM - Feb 25, 2019 (https://twitter.com/360TIC/status/1099987939818299392)
?
192 people are talking about this
?
Twitter Ads info and privacy (https://support.twitter.com/articles/20175256)
?
?
Qihoo 360 also uncovered another sample that appears to target users based in the Middle East. The sample is a file archive that contains a PDF about a job opportunity in Saudi aAmwia. Decompressing the file, however, will deliver a Powershell (https://www.pcmag.com/encyclopedia/term/60099/powershell)-based backdoor to the PC's Startup Folder.
The developers of WinRAR patched the vulnerability starting with a beta release last month. However, it'll be up to users to actually download and install it. The latest WinRAR release, 5.70, rolled out yesterday and can be found here (https://www.rarlab.com/download.htm).
RELATED- Software Patches: You're Doing it Wrong (https://www.pcmag.com/news/366618/software-patches-youre-doing-it-wrong)
Software Patches: You're Doing it Wrong (https://www.pcmag.com/news/366618/software-patches-youre-doing-it-wrong)
- Is iOS Secure After FaceTime Bug Fix? No One Knows (https://www.pcmag.com/commentary/366632/is-ios-secure-after-facetime-bug-fix-no-one-knows)
Is iOS Secure After FaceTime Bug Fix? No One Knows (https://www.pcmag.com/commentary/366632/is-ios-secure-after-facetime-bug-fix-no-one-knows)
- WinRAR Has Serious Flaw That Can Load Malware to PCs (https://www.pcmag.com/news/366678/winrar-has-serious-flaw-that-can-load-malware-to-pcs)
WinRAR Has Serious Flaw That Can Load Malware to PCs (https://www.pcmag.com/news/366678/winrar-has-serious-flaw-that-can-load-malware-to-pcs)
If your PC does accidentally decompress a rigged archive file, antivirus software (https://www.pcmag.com/roundup/256703/the-best-antivirus-protection)might be able to detect it. Qihoo 360 uploaded (https://www.virustotal.com/#/file/7871204f2832681c8ead96c9d509cd5874ed38bcfc6629cbc45472b9f388e09c/detection) one of the uncovered samples to VirusTotal, which shows that 24 out of 56 antivirus engines, including Microsoft's, detected the file as malicious.
UPDATE 2/28/19: Qihoo 360, Check Point (https://blog.checkpoint.com/2019/02/27/protecting-against-winrar-vulnerabilities/) and other security researchers have found more rigged archive files designed to exploit the vulnerability. The new sample found by Qihoo 360 appears to be targeting Ukrainian users.
Thanks @obadelekambon for the article its greatly appreciated. Software flaws and computer vulnerabilities are no joke and should be taken seriously even by people who are not as computer savvy. You can save yourself from malware and virus attacks by updating software and programs on the laptop and as always be careful of websites with malware, spammy links and emails. I hope I didn't stray too much from the original post.