


Background
On March 17, 2019, 360 Threat Intelligence Center intercepted a case of a suspected "Golden Rat" APT organization (APT-C-27) using the WinRAR vulnerability (CVE-2018-20250[6] ) Targeted attack samples targeting the Middle East. The malicious ACE compressed package contains an Office Word document that uses a terrorist attack as a bait to induce the victim to decompress the file. When the victim decompresses the file through WinRAR on the local computer, the vulnerability will be triggered. After the vulnerability is successfully exploited, the vulnerability will be built-in The backdoor program (Telegram Desktop.exe) is released into the user's computer startup directory. When the user restarts or logs in to the system, the remote control Trojan will be executed to control the victim's computer.
360 Threat Intelligence Center discovered through correlation analysis that this attack activity is suspected to be related to the "Golden Rat" APT organization (APT-C-27), and after further tracing and correlation, we also found multiple Malicious samples of the Android platform related to this organization are mainly disguised as some commonly used software to attack specific target groups. Combined with the text content related to the attacker in the malicious code, it can be guessed that the attacker is also familiar with Arabic.
Detection of backdoor program (TelegramDesktop.exe) on VirusTotal
Sample analysis
360 threats The Intelligence Center analyzed the sample that exploited the WinRAR vulnerability. The relevant analysis is as follows.
Using terrorist attacks to induce decompression
##MD5 | 314e8105f28530eb0bf54891b9b3ff69|
---|---|
Decoy document translation content
If the user decompresses the malicious compressed package, the WinRAR vulnerability will be triggered, thereby releasing the built-in backdoor program to the user's startup directory Medium:
The released backdoor program Telegram Desktop.exe will be executed when the user restarts the computer or logs in to the system.
Backdoor(Telegram Desktop.exe)
Telegram Desktop.exe | |||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
SHA256 | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Compilation information | |||||||||||||||||||||||||||||||||||||||||||||||||||||
1cc32f2a351927777fc3b2ae5639f4d5 | ||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
OfficeUpdate2019.apk |
After the Android sample is started, it will induce the user to activate the device manager, then hide the icon and run it in the background: Induces the user to complete the installation Afterwards, the sample will display the following interface: Then the sample will obtain the online IP address and port through Android's default SharedPreferences storage interface. If obtained If not, decode the default hard-coded IP address and port online:
|
The above is the detailed content of Analysis of how to use WinRAR vulnerability to target targeted attack activities in the Middle East. For more information, please follow other related articles on the PHP Chinese website!

WinRAR作为一款优秀的压缩包管理器,是档案工具RAR在Windows环境下的图形界面。WinRAR适用于备份数据,缩减电子邮件附件的大小,解压缩从Internet上下载的RAR、ZIP及其它类型文件,并且可以新建RAR及ZIP格式等的压缩类文件,而WinRAR32位版本则深受广大用户的好评,今天就让小编为大家详细介绍一下WinRAR32位,以及winrar怎么设置中文吧!一、WinRAR32位的由来WinRAR32位的作为Windows版本的RAR压缩文件管理器,这是一个允许你创建、管理和控

小编将为大家介绍加密压缩的三种方法:方法一:加密最简单的加密方法,就是在加密文件时输入想要设置的密码,完成加密和压缩了。方法二:自动加密普通的加密方式,需要我们加密每个文件的时候都需要输入密码,如果你想要加密大量压缩包,并且密码是一样的话,那么我们可以在WinRAR中设置自动加密,之后只要正常压缩文件,WinRAR会给每个压缩包添加密码。方法如下:打开WinRAR,点击选项–设置设置界面中,切换到【压缩】,点击创建默认配置–设置密码在这里输入我们想要设置的密码,点击确定就完成设置了,我们只需要正

WinRAR是一款功能强大的压缩文件管理工具,提供了丰富的功能和易于使用的界面。WinRAR64位版本特别针对64位操作系统进行了优化,能够更好地利用系统资源和性能。接下来就让小编为大家介绍一下winrar64位以及解答一下winrar怎么解压吧!一、winrar64位是什么软件WinRAR是一款功能强大的压缩包管理器。这款软件可用于备份您的数据,缩减电子邮件附件的大小,解压缩从Internet上下载的RAR、ZIP及其它文件,并且可以新建RAR及ZIP格式的文件。目前最新WINRAR版本为Wi

很多人都听过winrar32位和winrar64位,但是大部分都不知道这两者的区别,甚至不知道winrar32位是什么?其实它就是一款压缩工具的格式,只能用在32位的系统上。winrar32位什么意思答:winrar32位是为普通用户设计的。winrar32位是为不需要大量内存和浮点性能的普通用户而设计的。winrar32位拓展介绍1、winrar32位是为普通用户所设计的,winrar64位的用户多是需要大量内存的。winrar64位的运算速度是winrar32位的两倍。2、winrar64位

winrar不是电脑自带的,它是一个独立的软件,需要下载安装。WinRAR是一款功能强大的压缩包管理器,它是档案工具RAR在Windows环境下的图形界面。WinRAR内置程序可以解开CAB、ARJ、LZH、TAR、GZ、ACE、UUE、BZ2、JAR、ISO、Z和7Z等多种类型的档案文件、镜像文件和TAR组合型文件;对于RAR格式档案文件提供了独有的恢复记录和恢复卷功能。

很多人都知道winrar要怎么压缩文件,但是对于一些需要保密的文件却不知道如何添加密码。对于这种情况,我们只需要在压缩文件中就可以完成操作。winrar如何加密码1、选择需要加密的文件,单击鼠标右键,选择“添加到压缩文件”。2、在“常规”栏中选择“设置密码”选项。3、输入两次密码之后,点击“确定”。如果在此处勾选了加密文件夹,那么压缩出来的文件在之后打开前都要输入密码。4、最后回到“常规”栏,点击“确定”,文件就开始压缩了。等待压缩结束,就完成了文件加密了,快来实践一下吧。

背景2019年3月17日,360威胁情报中心截获了一例疑似“黄金鼠”APT组织(APT-C-27)利用WinRAR漏洞(CVE-2018-20250[6])针对中东地区的定向攻击样本。该恶意ACE压缩包内包含一个以恐怖袭击事件为诱饵的OfficeWord文档,诱使受害者解压文件,当受害者在本地计算机上通过WinRAR解压该文件后便会触发漏洞,漏洞利用成功后将内置的后门程序(TelegramDesktop.exe)释放到用户计算机启动项目录中,当用户重启或登录系统都会执行该远控木马,从而控制受害者

许多小伙伴在使用完WinRAR之后想要删除WinRAR的文件夹,但又担心会对下载的软件程序有影响。那么WinRAR文件夹能不能删除呢,我们一起来看一下吧。winrar文件夹可以删除吗答:WinRAR文件夹可以删除。不会对软件程序造成影响,但是不建议删除。WinRAR文件夹可以删除吗拓展说明1、如果删除的是WinRAR的快捷方式,那么对下载的没有什么影响。2、如果把WinRAR源程序删除了,网络上下载的许多东西都是以压缩包的形式呈现的,删除了以后就不能打开被压缩的软件了。


Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

AI Hentai Generator
Generate AI Hentai for free.

Hot Article

Hot Tools

mPDF
mPDF is a PHP library that can generate PDF files from UTF-8 encoded HTML. The original author, Ian Back, wrote mPDF to output PDF files "on the fly" from his website and handle different languages. It is slower than original scripts like HTML2FPDF and produces larger files when using Unicode fonts, but supports CSS styles etc. and has a lot of enhancements. Supports almost all languages, including RTL (Arabic and Hebrew) and CJK (Chinese, Japanese and Korean). Supports nested block-level elements (such as P, DIV),

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

SublimeText3 Linux new version
SublimeText3 Linux latest version

SublimeText3 English version
Recommended: Win version, supports code prompts!
