
أداة PowerShell دفاعية للفحص الثابت لأرشيفات RAR واكتشاف شذوذ اجتياز المسار المرتبطة بـ CVE-2025-8088.
تعد أداة RAR Anomaly Inspector أداة PowerShell للقراءة فقط تُستخدم للفحص الثابت لأرشيفات RAR، وهي مصممة لاكتشاف شذوذ اجتياز المسار (Path Traversal) المرتبط بـ CVE-2025-8088 (WinRAR RAR5 Path Traversal).
لا تقوم الأداة باستخراج أو تنفيذ محتويات الأرشيف.
..\)7z.exe (لسرد الملفات الظاهرة للمستخدم).\anom-rar.ps1 .\suspicious.rar
RAR Anomaly Inspector
CVE : CVE-2025-8088 (WinRAR Path Traversal)
Author : Ilham
Source : https://github.com/ilhamrzr/RAR-Anomaly-Inspector
Mode : Static / Read-Only Inspection
Warning : Indicators only - NOT proof of exploitation
ScanTime : 2026-01-11 13:33:05
-------------------------------------------------------
=== Archive File Inventory (7-Zip read-only) ===
Files visible to the user:
- CVE-2025-8088.pdf
=== Suspicious Path Indicators Extraction ===
RAW suspicious path indicators (UNFILTERED):
- ..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\..\..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
Total RAW indicators: 10
Sanitized logical paths (SAFE for copy-paste):
-> AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
=== Summary ===
Result: [!] ARCHIVE REQUIRES FURTHER INVESTIGATION
[!] High-risk archive structure detected (repeated deep traversal / ADS-style metadata)
Manual investigation hint:
- Review archive construction and intent.
- Do NOT execute extracted files directly.
- Treat repeated traversal as HIGH RISK.
Inspection completete.
منخفضة (LOW)
شذوذ بسيط دون استهداف مسارات حساسة
متوسطة (MEDIUM)
تم اكتشاف اجتياز دون وجود مسارات استمرارية واضحة
عالية (HIGH)
اجتياز صريح يستهدف مجلدات حساسة
مستويات المخاطر استرشادية ولا تشير إلى نجاح الاستغلال.
لا تستخرج الأرشيفات
لا تنفذ الملفات
لا تتحقق من صحة الحمولات
لا تضمن إمكانية الاستغلال
مخصصة للتحليل الدفاعي والفرز (Triage)
مناسبة لفرق الدفاع الأزرق (Blue Teams)، والمستجيبين للحوادث، والباحثين
ليست إطارًا للاستغلال
CVE-2025-8088
الإصدار المتأثر: WinRAR لنظام ويندوز ≤ 7.12
تم الإصلاح في: WinRAR 7.13+
تم توفير هذه الأداة لأغراض دفاعية وتعليمية فقط.