#winrar — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #winrar, aggregated by home.social.
-
Every Free App You Actually Need Explained (Part 1-4)
https://www.youtube.com/watch?v=pGWSs6laAO0#OpenSource #freeapps #LibreOffice
#VLC Media Player
#DaVinci Resolve
#OBS Studio
#GIMP
#Audacity
#Blender
#Obsidian
#Scratch
#Godot
#Krita
#Photopea
#Inkscape
#LMMS
#Shotcut / Kdenlive
#KeePassXC
#Thunderbird
#Calibre
#Joplin
#MPV
#Affinity
#ProtonVPN
#Bitwarden
#PDF24 Creator
#LocalSend
#VirtualBox
#Notepad++
#FreeCAD
#Ardour
#WinRAR
#Everything
#Syncthing
#Penpot
#Proton Pass
#KDE Connect
#Parsec
#VSCodium
#Scribus
#HandBrake
#7-Zip
#ShareX
#qBittorrent
#Free Download Manager
#totalcommander -
Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.
Pulse ID: 6a7ca262c4921e41ead16a57
Pulse Link: https://otx.alienvault.com/pulse/6a7ca262c4921e41ead16a57
Pulse Author: AlienVault
Created: 2026-08-12 16:42:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault
-
New XWorm 7.1 and Remcos RAT campaigns are abusing trusted #Windows utilities and memory-based execution to evade detection, giving attackers remote access to infected systems. The campaign also exploits a #WinRAR vulnerability to gain initial access.
Read: https://hackread.com/xworm-7-1-remcos-rat-windows-tools-evade-detection/
-
Волк в овечьей шкуре — как атакующие эксплуатируют CVE-2023-38831 в WinRAR
Привет, Хабр! Меня зовут Илья Ефимов, я аналитик-исследователь угроз кибербезопасности в компании R-Vision. Моя статья будет посвящена разбору уязвимости CVE-2023-38831 в архиваторе WinRAR . Эта уязвимость активно используется хакерами в атаках на отечественные компании. В отчете компании BI.ZONE фиксируется информация, что злоумышленники из групп Cobalt Werewolf, Mysterious Werewolf использовали данную уязвимость для доставки вредоносной полезной нагрузки. В этом случае уязвимость эксплуатировала вредоносный архив при доставке фишингового письма. Схожую информацию предоставляют исследователи из Positive Technologies , связав активность группировки ExCobalt с эксплуатацией CVE-2023-38831. Также фиксировались случаи эксплуатации данной уязвимости ВПО Agent Tesla и DarkMe . Стоит отметить, что по данным компании Kaspersky в 2024 году данная уязвимость занимает третье место по частоте эксплуатации атакующими в России и странах СНГ. В своей статье я опишу, в чем заключается суть уязвимости, продемонстрирую её эксплуатацию, а также генерируемые события по активности. Затем я подробно опишу процесс детектирования уязвимости и определю основные артефакты с помощью R-Vision SIEM. Смотреть
https://habr.com/ru/companies/rvision/articles/837632/
#winrar #cve202338831 #уязвимости #siem #correlation_rule #winapi #windbg
-
Proof-of-Concept-#Exploit für #WinRAR-Lücke bringt #VenomRAT-#Malware mit | Security https://www.heise.de/news/Proof-of-Concept-Exploit-fuer-WinRAR-Luecke-bringt-VenomRAT-Malware-mit-9313479.html #ProofOfConcept #PoC