Tuesday, May 23, 2023
  • PRESS RELEASE
  • ADVERTISE
  • CONTACT
Asia Post
No Result
View All Result
  • HOME
  • NEWS
    • INDIA
    • CHINA
    • WORLD
  • DEFENSE
  • POLITICS
  • BUSINESS
  • HEALTH
  • SPORTS
  • ENTRTAINMENT
  • TECHNOLOGY
  • LIFESTYLE
  • TRAVEL
  • OUR TEAM
Asia Post
No Result
View All Result

Microsoft is scanning the inside of password-protected zip files for malware

May 16, 2023
in TECHNOLOGY
0 0
0
Share on FacebookShare on TwitterShare on Email


Black and white close up of sinister-looking male eyes looking suspiciously through the slats of a closed venetian blind. Could be a criminal or a stalker or a watchful home owner.

Microsoft cloud services are scanning for malware by peeking inside users’ zip files, even when they’re protected by a password, several users reported on Mastodon on Monday.

Compressing file contents into archived zip files has long been a tactic threat actors use to conceal malware spreading through email or downloads. Eventually, some threat actors adapted by protecting their malicious zip files with a password the end user must type when converting the file back to its original form. Microsoft is one-upping this move by attempting to bypass password protection in zip files and, when successful, scanning them for malicious code.

While analysis of password-protected in Microsoft cloud environments is well-known to some people, it came as a surprise to Andrew Brandt. The security researcher has long archived malware inside password-protected zip files before exchanging them with other researchers through SharePoint. On Monday, he took to Mastodon to report that the Microsoft collaboration tool had recently flagged a zip file, which had been protected with the password “infected.”

“While I totally understand doing this for anyone other than a malware analyst, this kind of nosy, get-inside-your-business way of handling this is going to become a big problem for people like me who need to send their colleagues malware samples,” Brandt wrote. “The available space to do this just keeps shrinking and it will impact the ability of malware researchers to do their jobs.”

Fellow researcher Kevin Beaumont joined the discussion to say that Microsoft has multiple methods for scanning the contents of password-protected zip files and uses them not just on files stored in SharePoint but all its 365 cloud services. One way is to extract any possible passwords from the bodies of email or the name of the file itself. Another is by testing the file to see if it’s protected with one of the passwords contained in a list.

Advertisement

“If you mail yourself something and type something like ‘ZIP password is Soph0s’, ZIP up EICAR and ZIP password it with Soph0s, it’ll find (the) password, extract and find (and feed MS detection),” he wrote.

Brandt said that last year Microsoft’s OneDrive started backing up malicious files he had stored in one of his Windows folders after creating an exception (i.e., allow listing) in his endpoint security tools. He later discovered that once the files made their way to OneDrive, they were wiped off of his laptop hard drive and detected as malware in his OneDrive account.

“I lost the whole bunch,” he said.

Brandt then started archiving malicious files in zip files protected with the password “infected.” Up until last week, he said, SharePoint didn’t flag the files. Now they are.

Microsoft representatives acknowledged receipt of an email asking about the practices of bypassing password protection of files stored in its cloud services. The company didn’t follow up with an answer.

A Google representative said the company doesn’t scan password-protected zip files, though Gmail does flag them when users receive such a file. My work account managed by Google Workspace also prevented me from sending a password-protected zip.

The practice illustrates the fine line online services often walk when attempting to protect end users from common threats while also respecting privacy. As Brandt notes, actively cracking a password-protected zip file feels invasive. At the same time, this practice almost surely has prevented large numbers of users from falling prey to social engineering attacks attempting to infect their computers.

One other thing readers should remember: password-protected zip files provide minimal assurance that content inside the archives can’t be read. As Beaumont noted, ZipCrypto, the default means for encrypting zip files in Windows, is trivial to override. A more dependable way is to use an AES-256 encryptor built into many archive programs when creating 7z files.



Source link

Tags: filesmalwareMicrosoftPasswordProtectedScanningzip
ShareTweetSend

Related Posts

TECHNOLOGY

Sources: activist investor TCS Capital, which owns 4%+ of Yelp's common stock, urges the recommendation site to explore strategic alternatives, including a sale (Lauren Thomas/Wall Street Journal)

May 23, 2023
TECHNOLOGY

Intel Reveals Details on Its Plans to Make Chip for AI Computing by 2025 Against Rivals Nvidia, AMD

May 22, 2023
TECHNOLOGY

Dell Technologies expands APEX portfolio

May 22, 2023
TECHNOLOGY

Apple Hiring AI ChatGPT Bard Rival Details

May 22, 2023
TECHNOLOGY

Apple Supplier Wistron Stops Making iPhones In India: Here’s Why

May 22, 2023
TECHNOLOGY

Sony’s WH-1000XM5 ANC headphones fall back to $348 at Amazon

May 22, 2023
Load More
Next Post

Govt to challenge HC order cancelling 36,000 primary teachers' jobs: Mamata

Pakistan: 16 people killed in clash between 2 tribes in Kohat region | Details

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest

Dried-up contact lenses that have seen Taylor Swift Eras Tour concert up for sale, guess the price

May 14, 2023

Temasek Holdings: Singapore’s Temasek pips KKR to buy Manipal Hospitals; valuation hits Rs 29,000 crore

April 7, 2023

Ministry of Culture and Youth Undersecretary reviews country’s experience in empowering youth in China

April 3, 2023

Asia Cup 2023 Latest News If India Doesn’t Come To Pakistan, We Won’t Be Going To India For World Cup: PCB Chief Najam Sethi

May 13, 2023

Bharti Airtel Q4 results: Key takeaways for investors

May 16, 2023

7 flyers hurt as Air India Delhi-Sydney flight encounters severe turbulence | India News

May 17, 2023

IMDB ‘Review bombing’ of trending shows and movies like She-Hulk and Turning Red is ruining the credibility of online ratings

September 1, 2022

Best Instant Female Arousal Pills – Best sex pills for woman-Health News , Firstpost

May 18, 2023

Tanu Weds Manu 3 on cards? Kangana Ranaut has a special request from Aanand L Rai | Deets Inside

May 23, 2023

Newcastle back in Champions League

May 23, 2023

Fund-raising by Indian IPOs declining quicker than global peers in 2023

May 23, 2023

Nearly 400 coins dating back to Mughal era found in Saharanpur

May 23, 2023

Trial data of oral weight-loss drug comparable to Wegovy, ET HealthWorld

May 23, 2023

Outcry as World Health Organization locks out Taiwan under pressure from China | Taiwan

May 23, 2023

Bengal Cabinet Nod to 30-acre Land for ECL for Reopening Abandoned Mines

May 23, 2023

Woman draped in colours of the Ukrainian flag pours fake blood on herself at Cannes red carpet-Entertainment News , Firstpost

May 23, 2023
Asia Post

Get the latest news and follow the coverage of breaking news, local news, national, politics, and more from the Asia's top trusted sources.

Categories

  • BUSINESS
  • CHINA
  • DEFENSE
  • ENTRTAINMENT
  • HEALTH
  • INDIA
  • INDIA-NORTHEAST
  • LIFESTYLE
  • POLITICS
  • SPORTS
  • TECHNOLOGY
  • TRAVEL
  • WORLD

Recent News

  • Tanu Weds Manu 3 on cards? Kangana Ranaut has a special request from Aanand L Rai | Deets Inside
  • Newcastle back in Champions League
  • Fund-raising by Indian IPOs declining quicker than global peers in 2023
  • Home
  • Disclaimer
  • DMCA
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Our Team
  • Contact

Copyright © 2021 Asia Post.
Asia Post is not responsible for the content of external sites.

No Result
View All Result
  • HOME
  • NEWS
    • INDIA
    • CHINA
    • WORLD
  • DEFENSE
  • POLITICS
  • BUSINESS
  • HEALTH
  • SPORTS
  • ENTRTAINMENT
  • TECHNOLOGY
  • LIFESTYLE
  • TRAVEL
  • OUR TEAM

Copyright © 2021 Asia Post.
Asia Post is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In