winrar? not! a malware!

Dirk41

Level 17
Thread author
Verified
Top Poster
Mar 17, 2016
797
2,496
1,568
Earth
Hi everyone!

probably many of you already read the news that during last summer official winrare websites (details in the link) from Belgium and Italy served malwares insted of the real installer.

I downloaded it before the summer but (and this could be helpfull for other users) I'd like to know if checksum would be enough to understand if the installer is safe and how to do that (I did it only with linux iso).
and ,just to be sure, how is it possibile to check if I/someone don't have anymore the installer but only the app already installed? (which winrar files I should check?

looking forward to hearing from you

thank you you anyone who replies
 
Winrar is digitally signed. If you find winrar on your pc and right click on it and click properties you should see a tab called Digital signatures. There you will see this 2 for winrar.
http://i.imgur.com/WGJ2HuA.png

If you have the installer then yes checking the hash of the installer will be sufficient. I do it with hashtab so i have an extra tab in the same location as the digital signature(different tab) showing the hash of the file.
http://implbits.com/products/hashtab/
 
thank you! i downloaded it in April, or even before, so I don't have the installer anymore.
yes I see as in your picture.

but: is not possible to know the entire hash of my winrar,in order to compare it with the original? and where can i find the original hash? I can't find it on winrar.it
 
Yeah, winrar developer doesn't give the hash of the file as far as i can see but as long as it's digitally signed you are fine.
 
The scam was quite obvious, the malware address ...

Not in Italy "
The major difference here is that we didn’t record redirections to ralrab[.]com, but it appears the site directly served StrongPity trojanized installers:"
 
Last edited by a moderator:
Do you mind to link me where you find the hash, thank you , sorry for bothering
I've uploaded my installer here:
http://onlinemd5.com and I've compared the checksum with the one on the page "Prelievo" of winrar.it.
Assuming that today the problem is solved, my installer is the same as the one on the site.

Screenshot_2016-10-13-06-30-25.png
 
Ok ok I know, I use ita version too, I supposed that the hash was the same in every language . Thank you
 
  • Like
Reactions: LabZero
Just out of curiosity
The hash is the same of the installer I have from winrar.it (the main issues was there).
From winrar.com i don't know because I use Ita version.

And do you have version 5.40 installed ?

Because probably I have an older version





Anyway , just of curiosity , do you think ( everyone can reply) that if winrar was a backdoor , I would see strange connections using command netstat -b ?
 
Nice try for those scammers.

People should be aware not only on the URL link but also the design of websites, usually those possible grammatical errors are clearly shown.
 
  • Like
Reactions: askmark
Just out of curiosity


And do you have version 5.40 installed ?

Because probably I have an older version





Anyway , just of curiosity , do you think ( everyone can reply) that if winrar was a backdoor , I would see strange connections using command netstat -b ?
Yes, I use V 5.40 64-bit.
The story is quite confusing, however, according to the analysis by kaspersky (dates back to 2016 may), very probably, the infected Italian versions certainly are V 5.30/5.31, and the various beta of V 5.40.
In any case, currently StrongPity is detected by Kaspersky and probably by most of the AVs, then you just need a good full scan and maybe even with Zemana.
 
  • Like
Reactions: Dirk41 and askmark