{"id":3637,"date":"2021-11-08T00:15:35","date_gmt":"2021-11-07T18:45:35","guid":{"rendered":"https:\/\/xiarch.com\/blog\/?p=3637"},"modified":"2021-11-08T00:15:39","modified_gmt":"2021-11-07T18:45:39","slug":"microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware","status":"publish","type":"post","link":"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/","title":{"rendered":"Microsoft Exchange ProxyShell Exploits Utilized to Setup Babuk Ransomware"},"content":{"rendered":"\n<p><p style=\"text-align: justify;\">A new threat actor is hacking Microsoft Exchange servers and breaching corporate networks using the ProxyShell vulnerability to deploy the Babuk Ransomware. The ProxyShell attacks against vulnerable Microsoft Exchange servers started several months ago, with LockFile and Conti being among the first ransomware groups to exploit them.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">According to a report by researchers at Cisco Talos, a Babuk ransomware affiliate known as &#8216;Tortilla&#8217; had joined the club in October, when the actor started using the &#8216;China Chopper&#8217; web shell on breached Exchange servers.&nbsp;&nbsp;<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">The name Tortilla is based on malicious executables spotted in campaigns using the name Tortilla.exe.<\/p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How does it Start with Exchange?<\/strong><\/h2>\n\n\n\n<p><p style=\"text-align: justify;\">The Babuk ransomware attack starts with a DLL, or .NET executable dropped on the Exchange server using the ProxyShell vulnerability.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">The Exchange IIS worker process w3wp.exe then executes this malicious payload to execute obfuscated PowerShell command that features endpoint protection bypassing, eventually invoking a web request to fetch a payload loader named &#8216;tortilla.exe.&#8217; This loader will connect to &#8216;pastebin.pl&#8217; and download a payload that is loaded into memory and injected into a NET Framework process, which ultimately encrypts the device with the Babuk Ransomware.<\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-image1-1-1024x755.jpg\" alt=\"Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-image1\" class=\"wp-image-3642\" width=\"600\" height=\"442\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-image1-1-1024x755.jpg 1024w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-image1-1-300x221.jpg 300w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-image1-1-768x566.jpg 768w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-image1-1.jpg 1459w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure><\/div>\n\n\n\n<p><p style=\"text-align: justify;\">Although Cisco analysts found evidence of ProxyShell vulnerability exploitation in most infections, most notably the &#8216;China Chopper&#8217; web shell, the telemetry data reflects a broad spectrum of attempted exploits.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">More specifically, Tortilla followed these pathways to drop the DLL and .NET modules:<\/p><\/p>\n\n\n\n<ul><li>Microsoft Exchange auto-discover server-side request forgery attempt<\/li><li>Atlassian Confluence OGNL injection remote code execution attempt<\/li><li>Apache Struts remote code execution attempt<\/li><li>WordPress wp-config.php access via directory traversal attempt<\/li><li>SolarWinds Orion authentication bypass attempt<\/li><li>Oracle WebLogic Server remote command execution attempt<\/li><li>Liferay arbitrary Java object deserialization attempt<\/li><\/ul>\n\n\n\n<p><p style=\"text-align: justify;\">As these attacks rely on patched vulnerabilities, it is strongly advised that all admins upgrade their servers to the latest versions to prevent them from being exploited in attacks.<\/p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How they Use Babuk in new attacks?<\/strong><\/h2>\n\n\n\n<p><p style=\"text-align: justify;\">Babuk Locker is a ransomware operation launched at the beginning of 2021 when it began targeting businesses and encrypting their data in double-extortion attacks. After conducting an attack on the Washington DC&#8217;s Metropolitan Police Department (MPD), and feeling the heat from U.S. law enforcement, the ransomware gang shut down their operation.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">After the source code for the first version of Babuk and a builder were leaked on hacking forums, other threat actors began utilizing the ransomware to launch their own attacks.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">It is unclear if Tortilla was an affiliate of Babuk back when the RaaS was active or if they just grabbed the strain&#8217;s source code when it came out to conduct new attacks. However, as the ransom note used in these attacks ask for a low $10,000 in Monero, it is likely not conducted by the original Babuk operation, who demanded far larger ransomware in Bitcoin.<\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-image2-1024x753.png\" alt=\"Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-image2\" class=\"wp-image-3640\" width=\"715\" height=\"525\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-image2-1024x753.png 1024w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-image2-300x221.png 300w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-image2-768x565.png 768w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-image2-1536x1130.png 1536w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-image2.png 1600w\" sizes=\"(max-width: 715px) 100vw, 715px\" \/><\/figure><\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Targeting the USA<\/strong><\/h4>\n\n\n\n<p><p style=\"text-align: justify;\">Although Our security researchers found that some attacks in Germany, Thailand, Brazil, and the U.K., most of Tortilla&#8217;s targets are U.S.-based. The I.P. address of the download server is located in Moscow, Russia, which could indicate the origin of these attacks, but there are no attribution conclusions in the report.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">Also, the &#8216;pastebin.pl&#8217; domain used for the unpacking stage has been previously abused by AgentTesla and FormBook distribution campaigns. While a decryptor was previously released for Babuk ransomware, it can only decrypt victims whose private keys were part of the source code leak.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">Therefore, threat actors can proceed to use the Babuk ransomware strain to launch their own operations, such as what we are seeing with the Tortilla threat actor.<\/p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new threat actor is hacking Microsoft Exchange servers and breaching corporate networks using the ProxyShell vulnerability to deploy the Babuk Ransomware. The ProxyShell attacks against vulnerable Microsoft Exchange servers started several months ago, with LockFile and Conti being among the first ransomware groups to exploit them. According to a report by researchers at Cisco [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":3641,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[6],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.11 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Microsoft Exchange ProxyShell Exploits Utilized to Setup Babuk Ransomware - Xiarch Solutions Private Limited<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Microsoft Exchange ProxyShell Exploits Utilized to Setup Babuk Ransomware - Xiarch Solutions Private Limited\" \/>\n<meta property=\"og:description\" content=\"A new threat actor is hacking Microsoft Exchange servers and breaching corporate networks using the ProxyShell vulnerability to deploy the Babuk Ransomware. The ProxyShell attacks against vulnerable Microsoft Exchange servers started several months ago, with LockFile and Conti being among the first ransomware groups to exploit them. According to a report by researchers at Cisco [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/\" \/>\n<meta property=\"og:site_name\" content=\"Xiarch Solutions Private Limited\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/xiarch\/\" \/>\n<meta property=\"article:published_time\" content=\"2021-11-07T18:45:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-11-07T18:45:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-featured-image.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"525\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Xiarch Security\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@xiarch\" \/>\n<meta name=\"twitter:site\" content=\"@xiarch\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Xiarch Security\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/\"},\"author\":{\"name\":\"Xiarch Security\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c\"},\"headline\":\"Microsoft Exchange ProxyShell Exploits Utilized to Setup Babuk Ransomware\",\"datePublished\":\"2021-11-07T18:45:35+00:00\",\"dateModified\":\"2021-11-07T18:45:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/\"},\"wordCount\":604,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\"},\"articleSection\":[\"Vulnerabilities\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/\",\"url\":\"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/\",\"name\":\"Microsoft Exchange ProxyShell Exploits Utilized to Setup Babuk Ransomware - Xiarch Solutions Private Limited\",\"isPartOf\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#website\"},\"datePublished\":\"2021-11-07T18:45:35+00:00\",\"dateModified\":\"2021-11-07T18:45:39+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/xiarch.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Microsoft Exchange ProxyShell Exploits Utilized to Setup Babuk Ransomware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/xiarch.com\/blog\/#website\",\"url\":\"https:\/\/xiarch.com\/blog\/\",\"name\":\"Xiarch Solutions Private Limited\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/xiarch.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\",\"name\":\"Xiarch\",\"url\":\"https:\/\/xiarch.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png\",\"contentUrl\":\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png\",\"width\":300,\"height\":300,\"caption\":\"Xiarch\"},\"image\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/xiarch\/\",\"https:\/\/twitter.com\/xiarch\",\"https:\/\/www.linkedin.com\/company\/xiarch\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c\",\"name\":\"Xiarch Security\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g\",\"caption\":\"Xiarch Security\"},\"sameAs\":[\"https:\/\/xiarch.com\/blog\/\"],\"url\":\"https:\/\/xiarch.com\/blog\/author\/vector\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Microsoft Exchange ProxyShell Exploits Utilized to Setup Babuk Ransomware - Xiarch Solutions Private Limited","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/","og_locale":"en_US","og_type":"article","og_title":"Microsoft Exchange ProxyShell Exploits Utilized to Setup Babuk Ransomware - Xiarch Solutions Private Limited","og_description":"A new threat actor is hacking Microsoft Exchange servers and breaching corporate networks using the ProxyShell vulnerability to deploy the Babuk Ransomware. The ProxyShell attacks against vulnerable Microsoft Exchange servers started several months ago, with LockFile and Conti being among the first ransomware groups to exploit them. According to a report by researchers at Cisco [&hellip;]","og_url":"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/","og_site_name":"Xiarch Solutions Private Limited","article_publisher":"https:\/\/www.facebook.com\/xiarch\/","article_published_time":"2021-11-07T18:45:35+00:00","article_modified_time":"2021-11-07T18:45:39+00:00","og_image":[{"width":1000,"height":525,"url":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Microsoft-Exchange-ProxyShell-Exploits-Utilized-to-Setup-Babuk-Ransomware-featured-image.jpg","type":"image\/jpeg"}],"author":"Xiarch Security","twitter_card":"summary_large_image","twitter_creator":"@xiarch","twitter_site":"@xiarch","twitter_misc":{"Written by":"Xiarch Security","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/#article","isPartOf":{"@id":"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/"},"author":{"name":"Xiarch Security","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c"},"headline":"Microsoft Exchange ProxyShell Exploits Utilized to Setup Babuk Ransomware","datePublished":"2021-11-07T18:45:35+00:00","dateModified":"2021-11-07T18:45:39+00:00","mainEntityOfPage":{"@id":"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/"},"wordCount":604,"commentCount":0,"publisher":{"@id":"https:\/\/xiarch.com\/blog\/#organization"},"articleSection":["Vulnerabilities"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/","url":"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/","name":"Microsoft Exchange ProxyShell Exploits Utilized to Setup Babuk Ransomware - Xiarch Solutions Private Limited","isPartOf":{"@id":"https:\/\/xiarch.com\/blog\/#website"},"datePublished":"2021-11-07T18:45:35+00:00","dateModified":"2021-11-07T18:45:39+00:00","breadcrumb":{"@id":"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/xiarch.com\/blog\/microsoft-exchange-proxyshell-exploits-utilized-to-setup-babuk-ransomware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/xiarch.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Microsoft Exchange ProxyShell Exploits Utilized to Setup Babuk Ransomware"}]},{"@type":"WebSite","@id":"https:\/\/xiarch.com\/blog\/#website","url":"https:\/\/xiarch.com\/blog\/","name":"Xiarch Solutions Private Limited","description":"","publisher":{"@id":"https:\/\/xiarch.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/xiarch.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/xiarch.com\/blog\/#organization","name":"Xiarch","url":"https:\/\/xiarch.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png","contentUrl":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png","width":300,"height":300,"caption":"Xiarch"},"image":{"@id":"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/xiarch\/","https:\/\/twitter.com\/xiarch","https:\/\/www.linkedin.com\/company\/xiarch"]},{"@type":"Person","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c","name":"Xiarch Security","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g","caption":"Xiarch Security"},"sameAs":["https:\/\/xiarch.com\/blog\/"],"url":"https:\/\/xiarch.com\/blog\/author\/vector\/"}]}},"_links":{"self":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/3637"}],"collection":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/comments?post=3637"}],"version-history":[{"count":1,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/3637\/revisions"}],"predecessor-version":[{"id":3643,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/3637\/revisions\/3643"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/media\/3641"}],"wp:attachment":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/media?parent=3637"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/categories?post=3637"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/tags?post=3637"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}