TGViewer
📜 Чтиво 📜 📜 Чтиво 📜 @chtivvvo · 137 subscribers
Post #1447 145
Malware Dropped Through a ZPAQ Archive

[...]

The file was called "Purchase Order pdf.zpaq" (SHA256:1c33eef0d22dc54bb2a41af485070612cd4579529e31b63be2141c4be9183eb6). The fact that the archive is using an "exotic" compress algorithm, the VT score is null! I tried the classic tools on a stock Windows operating systems, including 7Zip and no one was able to decompress the archive. This is a strange because it reduces the number of potential victims! On Windows, you can use PeaZip.
  • 🔥 2
More from @chtivvvo
  1. Dec 3, 2024Novel phishing campaign uses corrupted Word documents to evade security A novel phishing a…
  2. Nov 18, 2024Phishing emails increasingly use SVG attachments to evade detection Threat actors increasi…
  3. Nov 3, 2024https://arstechnica.com/information-technology/2024/11/microsoft-warns-of-8000-strong-botn…
  4. Oct 31, 2024https://sharpsec.run/rce-vulnerability-in-qbittorrent/
  5. Oct 11, 2024https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/
  6. Oct 9, 2024https://www.bleepingcomputer.com/news/security/european-govt-air-gapped-systems-breached-u…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →