winrar malware

Are you using WinRAR? WinRAR exploited

Imagine opening a file with WinRAR, and install a malicious one on you στο σύστημά σας. Η εφαρμογή WinRAR, ένα ένα ευρέως χρησιμοποιούμενο βοηθητικό πρόγραμμα and data decompression. But according to the latest information from THN a flaw allows hackers to distribute malware. A security researcher from Israel, Danor Cohen (An7i) found that a feature allows spoofing in data that compresses the application. Let's see how.

winrar-malware

The hacker states that by modifying a file and its extension within the traditional archive, it can hide binary malicious code inside a file, pretending to be .jpg, or .txt, or any other format.

Using one s Hex, analyzed a ZIP file and noticed that the application adds some custom properties to a file, which usually has two name references in the properties. The first name is the original file name (FAX.png) and the second name is again the file name (FAX.png). The file properties are displayed in the WinRAR GUI window.

Danor renamed the file to FAX.EXE and extended the malicious FAX.EXE file to FAX.PNG. After everything is easy, prepare a separate ZIP file, which contained a malware file "FAX.exe", but displayed it as "FAX.png" to the end user.
The IntelCrawler security firm also published a report that reveals that cybercriminals use this zero-day vulnerability to target aerospace companies, military subcontractors, embassies, and many other companies.

Using this technique, an attacker can install any malware in a very convincing way in the systems he chooses.

Danor managed to run it successfully applied to the 4.20 version of the application, but IntelCrawler has confirmed that the vulnerability is compatible with all versions of the popular application including the latest V.5.1.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).