Automatically translated.View original post

Fake 7-Zip app detected. Downloaded and definitely addicted to malware.

Fake 7-Zip app detected. Downloaded and definitely addicted to malware.

Software for file compression can be called many, but there are only a few familiar ones, such as WinZip, WinRar, and 7-Zip, the latter of which has become an issue, but not from WinZip and WinRar security vulnerabilities, but from negative name impersonators.

According to a report by the official website of anti-malware developer Malwarebytes, a member of the famous web board Reddit inside the r / pcmasterrace room came up with a thread about the detection of fake 7-Zip software, which the PC Builder said downloaded fake 7-Zip software from the 7zip [.] com website after watching a video of the tutorial on Youtube and then acknowledged that the official 7-Zip website was 7-zip.org not the site.

The user also revealed that after downloading the file on the USB drive and installing it on the newly assembled machine, a 32-bit versus 64-bit Error occurred so often that it was uninstalled. After about two weeks, the Windows Defender has a malware detection alert called Trojan: Win32 / Malgent! MSR, making it predictable to come from the fake 7-Zip software.

This fake 7-Zip software. The Installer was checked and found to be a modification of a real installation file called 7zfm.exe. But the file has a Cetificate signed under the fake company name Jozeal Network Technology Co., Limited. The certificate has been detected as Revoke. This file, if installed successfully, will work exactly like a normal 7-Zip, but there are three additional Components included.

Uphero.exe - Service Manager and Update Manager (Update loader)

Hero.exe - A file compiled with the Go language acts as the main Proxy Payload to turn the victim's machine into a Proxy Node so that a third party (3rd Party) can send data by relying on the victim's IP number.

Hero.dll - Library File (Library) Support

The set of files is placed in the System C: WindowsSysWOW64hero folder, a folder that has a high degree of Privilege access permissions, which is often unchecked. It was also found that the set of files used an update channel independent of the installer using the update.7zip [.] com / version / win-service / 1.0.0.2/Uphero.exe.zip channel.

The main malware files.exe retrieves the configuration from the commutated C2 or Command and Control domain, but all under the "smshero" theme to create Outbound Proxy through port 1000 or 1002. In addition, the research team also found that XOR encryption with key 0x70 was used to hide the command message. After the victim's machine became a Proxy Node under the hacker's Infrastructure network, the victim's IP number was taken. These proxy applications will also be resold to other cybercriminals, used for fraud, identity concealment, or for advertising.

In addition to its core capabilities, malware also has the ability to avoid being detected variously, e.g.

Detecting simulated environments like VMware, VirtualBox, QEMU and Parallels.

Anti-Debugging

Verification that Runtime API resolution and PEB are in use

Monitoring of the system environment (Environment), including Process Enumeration and Registry Probing

In addition to that, the research team also found that the malware has support for a variety of encryption systems to protect data traffic (Traffic), such as AES, RC4, Camellia, Chaskey, XOR encoding, and Base64.

Call it that such malware is dangerous, and indeed malicious, so readers must be careful to check the software download source first whenever the download is installed on the machine for safety.

# Trending # Lemon 8 Howtoo # lemon 8 diary # ZIP # freedomhack

3/3 Edited to

... Read moreจากประสบการณ์ของผู้ใช้ทั่วไป การติดตั้งซอฟต์แวร์บีบอัดไฟล์ เช่น 7-Zip เป็นเรื่องที่ช่วยให้จัดการไฟล์ได้สะดวก แต่เมื่อได้มาเจอกับกรณีของแอป 7-Zip ปลอมนี้ ทำให้เราได้เรียนรู้ข้อควรระวังในการดาวน์โหลดและติดตั้งซอฟต์แวร์เพิ่มมากขึ้น โดยเฉพาะอย่างยิ่งเมื่อพบว่าแอปปลอมนี้แอบแฝงมัลแวร์ที่มีความสามารถสูง ทั้งการสร้าง proxy node เพื่อส่งข้อมูลผ่าน IP เครื่องของเรา และยังมีระบบอัปเดตแยกออกมาเพื่อหลีกเลี่ยงการตรวจจับ นอกจากนี้ มัลแวร์ยังมีเทคนิคป้องกันการวิเคราะห์อย่างดี เช่น ตรวจสภาพแวดล้อมจำลอง, ต้านการดีบักดิ้ง, ใช้การเข้ารหัสหลายรูปแบบ รวมถึงวางไฟล์ลงในโฟลเดอร์ระบบที่มีสิทธิ์ระดับสูงอย่าง C:WindowsSysWOW64hero ด้วย การถูกแฝง Trojan:Win32/Malgent!MSR ถือเป็นสัญญาณเตือนที่ควรให้ความสำคัญมาก เพราะการที่เครื่องกลายเป็น Proxy Node หมายความว่า IP ของเราสามารถถูกนำไปใช้ในกิจกรรมที่ผิดกฎหมายอื่น ๆ เช่น การซ่อนตัวตนออนไลน์, การฉ้อโกง หรือการขุดรายได้จากโฆษณาโดยไม่ได้รับอนุญาต สิ่งที่สำคัญที่สุดคือการตรวจสอบแหล่งที่มาของไฟล์ติดตั้งอย่างละเอียดว่าตรงกับเว็บไซต์หลัก 7-zip.org หรือไม่ สำหรับผู้ที่ประกอบหรือดูแลระบบคอมพิวเตอร์เป็นประจำ แนะนำให้ใช้โปรแกรมแอนตี้มัลแวร์ที่มีการอัปเดตฐานข้อมูลล่าสุดอย่างสม่ำเสมอ และควรตั้งค่าการสแกนอัตโนมัติเมื่อมีไฟล์เข้ามาใหม่ ๆ รวมถึงหมั่นตรวจสอบ Certificate ของไฟล์ติดตั้งว่ามีความน่าเชื่อถือหรือไม่ เพื่อป้องกันการถูกหลอกใช้ซอฟต์แวร์ปลอม นอกจากนี้ ความรู้จากการติดตามข่าวสารความปลอดภัยไซเบอร์นั้นถือเป็นสิ่งสำคัญ เพราะจะช่วยให้เรารู้ทันภัยใหม่ ๆ และวิธีรับมืออย่างรวดเร็ว ท้ายที่สุดนี้การดาวน์โหลดซอฟต์แวร์จากแหล่งที่น่าเชื่อถือ รวมถึงการศึกษาวิธีตรวจสอบไฟล์และ Certificate จะช่วยเสริมความปลอดภัยให้กับเครื่องของเรา และลดความเสี่ยงจากมัลแวร์อย่างมั่นใจ ถือเป็นบทเรียนสำคัญสำหรับผู้ที่ใช้งานคอมพิวเตอร์ทุกคนในยุคที่ภัยไซเบอร์มีความซับซ้อนและแฝงตัวมาทุกที่

Related posts

Warning: High levels of silliness detected. Stimming in progress! ⚠️🕺
If you see me vibrating like a glitchy video game character… mind your business, I’m just having a moment! 😂 Being neurospicy means sometimes the "happy" is just too big for my body to hold, so it has to come out in a wiggle, a flap, or a very specific repetitive hum. Honestly? 10/10 rec
Llamazinglooks

Llamazinglooks

1396 likes

Finally attempting this viral transition but with a twist! I turned myself into rumi for the K-pop demon hunters🥰🫰🏼 #fypシ #transition #transitiontutorial #kpopdemonhunters #makeup
aolanymorie

aolanymorie

1618 likes

+it’s less than 80$✨❗️LINK for this item in my bio❗️
Details⬇️: This flip phone smartphone with a flip keyboard design, offering both the convenience of a traditional keypad and the functionality of a modern touchscreen device. With 4GB of internal storage, you'll have plenty of space for apps, photos, and more. The compact 3.5" displa
Atlas

Atlas

443 likes

Study cafe day… but I didn’t type a single thing 😭☕️ Just whispering my notes, ideas, even my to-do list ~ and Typeless from @typelessdotcom organizes everything for me in seconds ✨ It even helps me write emails and translate without lifting a finger Honestly saved me so much time You can dow
emilie.studygram

emilie.studygram

29 likes

#tiktok #fyp #foryoupage #shortdramareview #movie
wiaewn

wiaewn

1 like

easy click for nurses exam NHS exam nclex study guide system nclex exam from uk #NCLEX #nclex #passnclex #ngnnclex #nclexrn
Nclex Assistance

Nclex Assistance

4 likes

A young man smiles in a city street at sunset, with buildings and a clock tower in the background. Overlay text reads 'how to make long distance SUCK a little less'.
A black and white doorbell camera image shows two people hugging, illustrating the tip '1. TRUST' in a long-distance relationship context.
A purple-toned close-up selfie shows two people laughing, representing the tip '2. facetime dates!!' for long-distance relationships.
tips for long distance
Let’s be real, most of the time long distance SUCKS- but it doesn’t always have to. My boyfriend and I have been together a little over a year now, and out of the 13ish months, 10 of them have been long distance. in that time we’ve found some things to make it more fun and continue to build the rel
sarah🪿🫧

sarah🪿🫧

224 likes

No lies detected
#quotestoliveby #truth #fypシ
mandi.

mandi.

55 likes

Tech Tutorial: Recover SD Card Files Using CMD
Want to recover files from an SD card using Command Prompt? This guide explains how to use CMD tools like CHKDSK to repair file system errors and attrib to unhide missing files. Learn when Command Prompt works, when recovery software is needed, and how to restore photos, videos, and documents safel
XanthusTechCore

XanthusTechCore

2 likes

not extreme, just consistent.
these habits made the difference for me😋 #GymTok #gymgirl #caloriedeficit #calorietracking #nutriplan
Lillypark

Lillypark

26 likes

NOTION TOUR ✨how I stay organized w/ notion!
welcome to my notion! I use notion for literally EVERYTHING. it’s a fantastic tool to stay organized with. while notion can feel a little overwhelming at first, templates are a great way to get started. here’s a lil overview of my page: • directory page - I use this page to quickly acces
adrianna

adrianna

59 likes

LEAK SENSORS Find Out Which One Actually Works
🎀 NEED A Product LINK? Head to www.KISSparkles.com! Scroll till you see the cover photo of the video you would like to shop from 🥰 Luckily we found a solution! 🚨 Don't Get Caught Off Guard! Discover the Real Deal in Leak Sensors! 🚨 After a viral sensor let me down, I went on a mission to
KISSparkles

KISSparkles

74 likes

🚀 Unidentified signal detected over the Gulf Coast
High-speed visuals. Deep-space energy. Precision-built execution. Pensacola X® operates at the intersection of AI-driven media, cinematic storytelling, and next-generation marketing—delivering content engineered to capture attention instantly and hold it. Nothing random. Nothing accidental.
PENSACOLA X®

PENSACOLA X®

1 like

No lies detected.
#fortnite #vtuber
Lexi

Lexi

1 like

⚠ BOTMOB SCAN DETECTED Bombast detected. Operator deployed: DJ BOT LA ROCK Link
#AskLemon8 #healthyrelationship #softskills #mentalhealthawareness #BOTMOB
appa juse

appa juse

1 like

#chriseanrock #fyp #baddiesusa #foryou #biglex
Von 🧘🏽‍♀️✨🫶🏽

Von 🧘🏽‍♀️✨🫶🏽

8 likes

Your attention is their oxygen. ⚠ BOTMOB SCAN DETECTED The LEECH
#StudyTips #NameThePressure #ThreatFile #Lemon8Diary #SoftSkills
appa juse

appa juse

0 likes

Distortion Detected
Distortion Detected #clockworkmask #liminalspaces #backrooms #endless #vrchatworldshowcase
Clockworkmask

Clockworkmask

0 likes

It’s always something 🤦🏾‍♀️😂 #travrlnurselife #absnstudent #girlmom
Ayonna|Mom content• Lifestyle✨

Ayonna|Mom content• Lifestyle✨

40 likes

How to make your essay sound human 0% AI Detected
#essay #study #aitools #aihumanizer #edu
Self lock

Self lock

9 likes

Returning to NFL Universe 🤯 #nfluniverse #ultimatefootball #roblox #neoskittles
NeoSkittles

NeoSkittles

4 likes

🚨 BREAKING NEWS ALERT 🚨 This just in… travelers across California are reporting unbelievable room deals appearing on the map! 🗺️ Authorities confirm the source is none other than Studio 6 / Motel 6 — where comfortable extended-stay rooms and clean accommodations are now popping up at pric
Motel 6/ studio 6

Motel 6/ studio 6

0 likes

No lies detected 😂
Marqueena Bowdry

Marqueena Bowdry

8 likes

Spartan Race Spear Throw 💥#spartan #spartanrace #spartanrace2026 #metaglass
builtbyanthony_

builtbyanthony_

7 likes

Watch this if you want to level up your content game 🎥🔥 #ugc #ugccreator #contentcreator #contenttips
Krissy

Krissy

7 likes

ANOMOLY DETECTED
#LimitlessSports #FRAMELOCK #alexcaruso #okcthunder
limitless sports

limitless sports

1 like

turning my iPad mini into a gaming console 🎮💕✨ someone recommended the @Razer Kishi & so obvi I ordered it immediately! Let me know if you want a longer term review & please leave your iPad game recs! #ipad #razerkishi #ipadgames #applearcade #ipados26
Chantal 👩🏻‍💻 PaperNRoses

Chantal 👩🏻‍💻 PaperNRoses

54 likes

XDDX_SCOUTSNIP

XDDX_SCOUTSNIP

1 like

n.isabella13

n.isabella13

0 likes

#rainbow6seige #gaming #gamer
𝕯𝖊𝖒𝖎

𝕯𝖊𝖒𝖎

2 likes

Look world as soon I start going live on bingo app Elon Musk and Donald Trump and Mark Zuckerberg and Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers lock my bingo live cause I'm listening to the word of God Jesus Christ God
glentrump359

glentrump359

0 likes

“Everyone does that...” ⚠ BOTMOB SCAN DETECTED ABSTRACTION TRAP
#AskLemon8 #healthyrelationship #softskills #mentalhealthawareness #BOTMOB
appa juse

appa juse

0 likes

CHECK YT LINK IN BIO! #blackops7 #callofdutyblackops #campaign #bo7 #fypviralシ
IIM.NOOT.Q

IIM.NOOT.Q

0 likes

What a hit!
#worldofwarships #battleships #videogames #videogame
Awkward Victoria

Awkward Victoria

5 likes

⚠ BOTMOB SCAN DETECTED Dogpiling: Group Attack Counter: WAR OF THE WORDS
#AskLemon8
appa juse

appa juse

0 likes

“Questions with no intent to listen aren’t questions — they’re weapons.”
#NameThePressure #VisualLearning #AcademicAesthetic #Gaslighting #Narcissist
appa juse

appa juse

0 likes

No lies detected…
#truth #cat #fyp #fyplemon8 #spicy
Kitty Auspex

Kitty Auspex

9 likes

WARNING: Extreme comfort detected! ⚠️🔥
From PSP to Switch, we’ve been there since Level 1. DXRacer is your ultimate power-up for any era of gaming. 🕹️⚡️ #gaming #dxracer #psp #switch
DXRACER

DXRACER

0 likes

A lethal detected
Skye@gotnochill

Skye@gotnochill

1 like

This image introduces automating business tasks using ChatGPT and Zapier, showing a desk setup with monitors displaying code and the logos of both tools. It highlights that all steps and prompts are included below for weekly task automation.
This image illustrates how AI, specifically ChatGPT and Zapier, can automate content idea generation for social media. It outlines a workflow from Google Sheets to Notion for consistent content planning, ensuring users never run out of ideas.
This image demonstrates automating lead follow-up with ChatGPT and Zapier. It shows how new leads trigger personalized messages sent via email or HubSpot, saving significant time by turning prospects into instant replies.
Business Tasks You Can Automate w/ ChatGPT
If you’re still doing these manually, you’re wasting hours every week. Here’s how I use ChatGPT + Zapier to automate my workflow. All steps & prompts below ⸻ ⤷ Step 1: Automate Lead Capture & Follow-Up Stop copying emails into spreadsheets — ChatGPT + Zapier can message every new le
Deft Point Consulting

Deft Point Consulting

36 likes

Health Talk - YOUR Zip Code Matters ⚠️
Welcome, Health, Wellness, & Tech Enthusiasts! It’s your favorite Health Signal Decoder 🌍 ⚕️ Health Talk | Community Signals Most people think health is about: • eating better • exercising more • “trying harder” But what if I told you your environment was already shaping your outco
Healthy Insights HQ🎙️

Healthy Insights HQ🎙️

52 likes

No lies detected 👊🏽👊🏽
Mizzotta

Mizzotta

23 likes

Villagers SPLIT The Village in HALF Against Iron Golems!
torque.test

torque.test

0 likes

An AI control room showing facial recognition, biometric analysis, and crowd surveillance, illustrating how AI helps catch criminals.
Two individuals in a van using experimental AI systems to map people's movements inside a house using Wi-Fi signals, demonstrating "Wi-Fi X-ray vision."
A woman observing screens displaying AI gait analysis, identifying a suspect from their walk pattern and body shape, even with their face covered, using stride tracking technology.
FOLLOW&LIKE&4MORE CONTENT🎥 I POST FOR THE COMMENTS🤣💭 #trending #viral #exp
FOLLOW&LIKE&4MORE CONTENT🎥 I POST FOR THE COMMENTS🤣💭 #trending #viral #explore
RobTFA

RobTFA

20 likes

POV potty time is when you learn the most🐾
#dogs #puppies
BooBoo Buddy app

BooBoo Buddy app

0 likes

Las mejores cámaras de seguridad 🩷 @tapo.us #tapo #securitycamera #tapolife #taposecurity
Naty Suarez

Naty Suarez

2 likes

No lies detected
no whitewashing
Kokovah C

Kokovah C

3 likes

What would your life look like if you actually became the person you know you’re supposed to be? Cosmiq helps you: Plan your days Build momentum Track habits Stay accountable Level up like a game Your future self is waiting. Comment “LOCKED IN” for early access
darryl_graham

darryl_graham

0 likes

A tutorial title card for 'Free Retro Console Games on MacOS' featuring a browser window showing 'OpenEmu.org' and illustrations of a retro handheld console and a joystick.
A screenshot of the OpenEmu website (openemu.org) in a Firefox browser, with an arrow pointing to the 'Download Now' button for 'Step 1: Download OpenEmu Emulator'.
A screenshot showing a Finder window with OpenEmu files, a pop-up to 'Move to Applications folder', and instructions for 'Step 2: Unzip and Open app' and 'Step 3: Move to Applications Folder', including security settings advice.
✨Retro Game Emulator for MacOS✨
Hey gamers! Setting up a game emulator on MacOS can seem daunting, but I've got you covered! I've created a step-by-step guide to help you get started. 🎮✨ Swipe through the photos above to see detailed screenshots with instructions. Whether you're a newbie or a seasoned gamer, thi
Miroak

Miroak

64 likes

“Everyone does that…” ABSTRACTION TRAP ⚠ BOTMOB SCAN DETECTED
#AskLemon8 #healthyrelationship #softskills #mentalhealthawareness #BOTMOB
appa juse

appa juse

0 likes

See more