Archive Sidestepping: Emotet Botnet Pushing Self-Unlocking Password-Protected RAR
released on 2022-10-21 @ 01:47:40 PM
The SpiderLabs team noticed an interesting attachment in a recent spam campaign. Disguised as an invoice, the attachment in either ZIP or ISO format, contained a nested self-extracting (SFX) archive. The first archive is an SFX RAR (RARsfx) whose sole purpose is to execute a second RARsfx contained within itself. The second RARsfx is password-protected but despite that, no user input is necessary to extract and execute its content. In some samples, the nested SFX archive is encapsulated further in another archive.