Showing posts with label Compress Files. Show all posts
Showing posts with label Compress Files. Show all posts

Friday, 2 October 2015

Symantec: WinRAR Flaw Less Serious Than Thought




A vulnerability in the popular WinRAR archiving progam which no update is available, and for which recently the National Cyber ​​Security Center (NCSC), the government warned is less severe than thought, say Symantec and developer RARLAB.

WinRAR is a very popular program for packing and unpacking files. Besides the standard RAR archive, the software can also make a Self Able Extract (SFX) archives. In this case the archive file is unpacked automatically when the user opens the file, regardless of whether they have installed WinRAR or not. SFX archives are basically just exe files and consist of the packed file and the un pack module WinRAR. By letting users open a malicious SFX archive an attacker could execute arbitrary code with the rights of the logged-in user, as this video shows.

The vulnerability makes it possible to be carried out when opening the SFX archive automatic code of the attacker, like downloading and installing malware. Contrary to some media reports, the problem not only for users of WinRAR, but to all Windows users who receive a malicious SFX archives. Symantec and RARLAB, developer of WinRAR, users need to open exe files, whether it is an SFX archive or not, always be careful.

RARLAB said in a statement that there are much simpler ways to attack users via a malicious SFX archive. Users also are advised not to open unexpected files or files from unknown or untrusted sources. The developer of WinRAR is therefore no plans to remove the option is now displayed where the use of attack, as this only legitimate users would hit.

Saturday, 7 March 2015

Ransomware Spreads Via Malicious Help Files


Cyber ​​criminals have been distributed in the Netherlands emails containing malicious help files that contain the CryptoWall-ransomware. Before that warns the Romanian antivirus company BitDefender. The e-mails contain a .chm file as an attachment. This stands for Microsoft Compressed HTML Help, and is the successor to the help files in Windows.

Chm files are highly interactive and can contain various technologies, such as JavaScript. This makes it possible to automatically download a file when the .chm file is opened. According to analyst Catalin Cosoi is a logical choice for cybercriminals to use chm files. "The less user interactions, the greater the risk of infection." In addition, users will these files may not be regarded as suspect.

The e-mails in question occur among others as e-mail messages from a fax machine. Once opened the ransomware can encrypt files on the computer and then asks for a certain amount of users to decrypt them. According Bitdefender however the attackers with this spam run would have to provide companies and attempting to infiltrate corporate networks. Over the past several months, let companies know that they are the victim of ransomware became.

Thursday, 19 February 2015

Desert Falcons Malware: "Million Files Stolen By Rtlo-Trick And RAR Attachments"


A group of cyber spies has managed through various social engineering tricks more than 3,000 computers to infect, with about 1 million files were stolen. Also in the Netherlands observed one or more infections, as reported anti-virus firm Kaspersky Lab.

The attackers, who would operate from the Middle East, had to cater to political and military intelligence. To infect victims were applied various tricks. So were sent spear phishing mails with attached RAR files. This RAR files contained and SCR and EXE files. The attackers used a trick with shortcuts.

Targets were given a RAR file sent to that extracted yielded several files, including two .doc files. One file, however, was a shortcut. Once users opened the shortcut malware was performed. Another trick used was using rtlo, which stands for Right-to-Left Override and ensures that through a special Unicode character sequence of characters of a filename can be reversed.


This will SexyPictureGirlAl [rtlo] gpj.exe appear in Windows as SexyPictureGirlAlexe.jpg. In the case of these attacks did the malware via rtlo for as a PDF document includes corresponding icon, but was in fact an executable SCR file. Users can recognize rtlo attacks by setting the detail view in Windows folders. Behind the file name also appears the file type. In this case there would be stated that this was an application.

The attackers were also active on Facebook, where she targets via the social networking approached. Once the trust was won were sent RAR files that contained malware. For large-scale infections among activists and political figures Facebook was also used. In this case, Facebook Messages posted there were pointing to malicious pages that malware was offered. Or again, the attackers to a page with an example being censored video. To view the video had offered "RealPlayer plug-in" installation. The file offered, however, was malware.


After the new computers were infected targets were divided into groups. Next, a list of all XLS, DOC, JPG and WAV files on the hard drive and connected USB sticks sent to the attackers. The attackers then used to connect to the computer to steal interesting photos and images. Also gathered there chats and screenshots. Depending on the targeted surveillance was then intensified or discontinued. In total, the attackers managed to steal more than 800,000 files from hard drives and more than 80,000 files from USB sticks.