Fake WinRAR downloads hide malware behind a real installer
ID: dfc88115-9fa4-5a73-84e3-24ba526483be
STIX ID: report--dfc88115-9fa4-5a73-84e3-24ba526483be
Feed Name: Malwarebytes Blog
This report analyzes a multi-stage malicious fake WinRAR installer distributed from unofficial Chinese sites that unpacks nested payloads (including a legitimate-looking installer and a malicious HTA), executes memory-only stages, and ultimately drops Winzipper-associated backdoor components (e.g., nimasila360.exe). The author documents static and dynamic analysis techniques, persistence and data-access behavior (Windows Profiles), and provides IOCs (domains and filenames) blocked by Malwarebytes to help detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
