20882: Rar

: Look for variations of Rar$Scan[Number].bat .

: The analysis shows a file named Rar$Scan19941.bat being launched from the 20882 directory via cmd.exe . 20882 rar

: The malicious activity was documented on a system running under an "admin" user profile within a Microsoft Corporation environment, indicating a target-agnostic or broad-reaching delivery method. Key Indicators of Compromise (IoCs) : Look for variations of Rar$Scan[Number]

: WinRAR.exe spawning cmd.exe to run .bat scripts from temporary folders. 20882 rar