{"id":4069,"date":"2021-12-27T11:24:05","date_gmt":"2021-12-27T05:54:05","guid":{"rendered":"https:\/\/xiarch.com\/blog\/?p=4069"},"modified":"2021-12-27T11:24:07","modified_gmt":"2021-12-27T05:54:07","slug":"avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools","status":"publish","type":"post","link":"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/","title":{"rendered":"AvosLocker Ransomware Reboots in Safe Mode to Avoid the Security Tools"},"content":{"rendered":"\n<p><p style=\"text-align: justify;\">In the ongoing attacks, the AvosLocker ransomware group has initiated on focusing on exhausting endpoint security solutions that stand in their way by rebooting the negotiated systems into the Windows Safe Mode.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">This technique makes it easier to encode the victim\u2019s files since most security solutions will be automatically disabled after the Windows devices boot in the safe mode. Their advanced approach comes to be less effective since the number of attacks attributed to the particular group is arriving.<\/p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Encoding in the \u2018Safe Mode<\/strong><\/h2>\n\n\n\n<p><p style=\"text-align: justify;\">AvosLocker operators influence PDQ Setup, an appropriate deployment tool for automating patch management, to drop some Windows batch scripts onto the target machine, which permits them to lay the ground for the attack, as per the report from the security researchers.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">These scripts modify or delete the Registry key that relates to specific endpoint security tools, which includes Windows Defender and products from cybersecurity firms.<\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/12\/AvosLocker-Ransomware-Reboots-in-Safe-Mode-to-Avoid-the-Security-Tools-image1.png\" alt=\"AvosLocker-Ransomware-Reboots-in-Safe-Mode-to-Avoid-the-Security-Tools-image1\" class=\"wp-image-4071\" width=\"512\" height=\"295\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/12\/AvosLocker-Ransomware-Reboots-in-Safe-Mode-to-Avoid-the-Security-Tools-image1.png 758w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/12\/AvosLocker-Ransomware-Reboots-in-Safe-Mode-to-Avoid-the-Security-Tools-image1-300x173.png 300w\" sizes=\"(max-width: 512px) 100vw, 512px\" \/><\/figure><\/div>\n\n\n\n<p><p style=\"text-align: justify;\">The script also generates advance users&#8217; accounts on the negotiated machine, naming it \u2018new admin\u2019 and adding it to the Administrators user group. Moreover, they configure that accounts to automatically log in when the system reboots into Safe Mode with Networking and disable \u201clegal notice\u201d dialog registry keys that could hamper the automatic login.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">At last, the scripts run a reboot command which puts the machine into Safe Mood. Once it\u2019s up again, the ransomware payloads are run from a Domain Controller location. If the automated payload execution process fails, the actor can assume manual control of the process utilizing the AnyDesk remote access tool.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">&#8220;The penultimate step in the infection process is the creation of a &#8216;RunOnce&#8217; key in the Registry that executes the ransomware payload, filelessly, from where the attackers have placed it on the Domain Controller.&#8221;<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">&#8220;This is a similar behavior to what we&#8217;ve seen IcedID and other ransomware do as a method of executing malware payloads without letting the files ever touch the filesystem of the infected computer.&#8221;<\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/12\/AvosLocker-Ransomware-Reboots-in-Safe-Mode-to-Avoid-the-Security-Tools-image2-2-763x1024.png\" alt=\"AvosLocker-Ransomware-Reboots-in-Safe-Mode-to-Avoid-the-Security-Tools-image2\" class=\"wp-image-4074\" width=\"250\" height=\"336\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/12\/AvosLocker-Ransomware-Reboots-in-Safe-Mode-to-Avoid-the-Security-Tools-image2-2-763x1024.png 763w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/12\/AvosLocker-Ransomware-Reboots-in-Safe-Mode-to-Avoid-the-Security-Tools-image2-2-223x300.png 223w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/12\/AvosLocker-Ransomware-Reboots-in-Safe-Mode-to-Avoid-the-Security-Tools-image2-2-768x1031.png 768w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/12\/AvosLocker-Ransomware-Reboots-in-Safe-Mode-to-Avoid-the-Security-Tools-image2-2.png 975w\" sizes=\"(max-width: 250px) 100vw, 250px\" \/><\/figure><\/div>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Safe Mode utilized to easily avoid the Endpoint Security<\/strong><\/h2>\n\n\n\n<p><p style=\"text-align: justify;\">This same Safe Mode execution method was previously used by other ransomware groups, including REvil (with auto-login too), BlackMatter, and Snatch, so this is clearly a security gap that needs to be addressed.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">The whole idea behind putting the machine in Safe Mode is to disable any running security tools since most endpoint protection solutions don&#8217;t run in that mode. Thanks to this simple yet effective trick, even adequately protected machines can be rendered defenseless against ransomware execution chains.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">To avoid arbitrary reboot commands from manifesting on your machines, ensure that your security tools can detect and prevent the addition of suspicious Registry keys. This capability could interfere with legitimate Registry access, but it is well worth the additional trouble for admins.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">As Sophos underlines in its report, no alert should be treated as &#8220;low priority,&#8221; as a small and seemingly innocuous thing could be a pivotal link to a ransomware execution chain.<\/p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the ongoing attacks, the AvosLocker ransomware group has initiated on focusing on exhausting endpoint security solutions that stand in their way by rebooting the negotiated systems into the Windows Safe Mode. This technique makes it easier to encode the victim\u2019s files since most security solutions will be automatically disabled after the Windows devices boot [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":4075,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[6],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.11 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>AvosLocker Ransomware Reboots in Safe Mode to Avoid the Security Tools - Xiarch Solutions Private Limited<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AvosLocker Ransomware Reboots in Safe Mode to Avoid the Security Tools - Xiarch Solutions Private Limited\" \/>\n<meta property=\"og:description\" content=\"In the ongoing attacks, the AvosLocker ransomware group has initiated on focusing on exhausting endpoint security solutions that stand in their way by rebooting the negotiated systems into the Windows Safe Mode. This technique makes it easier to encode the victim\u2019s files since most security solutions will be automatically disabled after the Windows devices boot [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/\" \/>\n<meta property=\"og:site_name\" content=\"Xiarch Solutions Private Limited\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/xiarch\/\" \/>\n<meta property=\"article:published_time\" content=\"2021-12-27T05:54:05+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-12-27T05:54:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/12\/AvosLocker-Ransomware-Reboots-in-Safe-Mode-to-Avoid-the-Security-Tools-featured-image.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"525\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Xiarch Security\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@xiarch\" \/>\n<meta name=\"twitter:site\" content=\"@xiarch\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Xiarch Security\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/\"},\"author\":{\"name\":\"Xiarch Security\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c\"},\"headline\":\"AvosLocker Ransomware Reboots in Safe Mode to Avoid the Security Tools\",\"datePublished\":\"2021-12-27T05:54:05+00:00\",\"dateModified\":\"2021-12-27T05:54:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/\"},\"wordCount\":496,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\"},\"articleSection\":[\"Vulnerabilities\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/\",\"url\":\"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/\",\"name\":\"AvosLocker Ransomware Reboots in Safe Mode to Avoid the Security Tools - Xiarch Solutions Private Limited\",\"isPartOf\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#website\"},\"datePublished\":\"2021-12-27T05:54:05+00:00\",\"dateModified\":\"2021-12-27T05:54:07+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/xiarch.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AvosLocker Ransomware Reboots in Safe Mode to Avoid the Security Tools\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/xiarch.com\/blog\/#website\",\"url\":\"https:\/\/xiarch.com\/blog\/\",\"name\":\"Xiarch Solutions Private Limited\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/xiarch.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\",\"name\":\"Xiarch\",\"url\":\"https:\/\/xiarch.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png\",\"contentUrl\":\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png\",\"width\":300,\"height\":300,\"caption\":\"Xiarch\"},\"image\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/xiarch\/\",\"https:\/\/twitter.com\/xiarch\",\"https:\/\/www.linkedin.com\/company\/xiarch\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c\",\"name\":\"Xiarch Security\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g\",\"caption\":\"Xiarch Security\"},\"sameAs\":[\"https:\/\/xiarch.com\/blog\/\"],\"url\":\"https:\/\/xiarch.com\/blog\/author\/vector\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AvosLocker Ransomware Reboots in Safe Mode to Avoid the Security Tools - Xiarch Solutions Private Limited","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/","og_locale":"en_US","og_type":"article","og_title":"AvosLocker Ransomware Reboots in Safe Mode to Avoid the Security Tools - Xiarch Solutions Private Limited","og_description":"In the ongoing attacks, the AvosLocker ransomware group has initiated on focusing on exhausting endpoint security solutions that stand in their way by rebooting the negotiated systems into the Windows Safe Mode. This technique makes it easier to encode the victim\u2019s files since most security solutions will be automatically disabled after the Windows devices boot [&hellip;]","og_url":"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/","og_site_name":"Xiarch Solutions Private Limited","article_publisher":"https:\/\/www.facebook.com\/xiarch\/","article_published_time":"2021-12-27T05:54:05+00:00","article_modified_time":"2021-12-27T05:54:07+00:00","og_image":[{"width":1000,"height":525,"url":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/12\/AvosLocker-Ransomware-Reboots-in-Safe-Mode-to-Avoid-the-Security-Tools-featured-image.jpg","type":"image\/jpeg"}],"author":"Xiarch Security","twitter_card":"summary_large_image","twitter_creator":"@xiarch","twitter_site":"@xiarch","twitter_misc":{"Written by":"Xiarch Security","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/#article","isPartOf":{"@id":"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/"},"author":{"name":"Xiarch Security","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c"},"headline":"AvosLocker Ransomware Reboots in Safe Mode to Avoid the Security Tools","datePublished":"2021-12-27T05:54:05+00:00","dateModified":"2021-12-27T05:54:07+00:00","mainEntityOfPage":{"@id":"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/"},"wordCount":496,"commentCount":0,"publisher":{"@id":"https:\/\/xiarch.com\/blog\/#organization"},"articleSection":["Vulnerabilities"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/","url":"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/","name":"AvosLocker Ransomware Reboots in Safe Mode to Avoid the Security Tools - Xiarch Solutions Private Limited","isPartOf":{"@id":"https:\/\/xiarch.com\/blog\/#website"},"datePublished":"2021-12-27T05:54:05+00:00","dateModified":"2021-12-27T05:54:07+00:00","breadcrumb":{"@id":"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/xiarch.com\/blog\/avoslocker-ransomware-reboots-in-safe-mode-to-avoid-the-security-tools\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/xiarch.com\/blog\/"},{"@type":"ListItem","position":2,"name":"AvosLocker Ransomware Reboots in Safe Mode to Avoid the Security Tools"}]},{"@type":"WebSite","@id":"https:\/\/xiarch.com\/blog\/#website","url":"https:\/\/xiarch.com\/blog\/","name":"Xiarch Solutions Private Limited","description":"","publisher":{"@id":"https:\/\/xiarch.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/xiarch.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/xiarch.com\/blog\/#organization","name":"Xiarch","url":"https:\/\/xiarch.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png","contentUrl":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png","width":300,"height":300,"caption":"Xiarch"},"image":{"@id":"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/xiarch\/","https:\/\/twitter.com\/xiarch","https:\/\/www.linkedin.com\/company\/xiarch"]},{"@type":"Person","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c","name":"Xiarch Security","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g","caption":"Xiarch Security"},"sameAs":["https:\/\/xiarch.com\/blog\/"],"url":"https:\/\/xiarch.com\/blog\/author\/vector\/"}]}},"_links":{"self":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/4069"}],"collection":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/comments?post=4069"}],"version-history":[{"count":1,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/4069\/revisions"}],"predecessor-version":[{"id":4076,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/4069\/revisions\/4076"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/media\/4075"}],"wp:attachment":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/media?parent=4069"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/categories?post=4069"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/tags?post=4069"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}