Potential RipZip Attack on Startup Folder (a6976974-ea6f-4e97-818e-ea08625c52cb)
Detects a phishing attack which expands a ZIP file containing a malicious shortcut. If the victim expands the ZIP file via the explorer process, then the explorer process expands the malicious ZIP file and drops a malicious shortcut redirected to a backdoor into the Startup folder. Additionally, the file name of the malicious shortcut in Startup folder contains {0AFACED1-E828-11D1-9187-B532F1E9575D} meaning the folder shortcut operation.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Potential RipZip Attack on Startup Folder (a6976974-ea6f-4e97-818e-ea08625c52cb) | Sigma-Rules | Boot or Logon Autostart Execution - T1547 (1ecb2399-e8ba-4f6b-8ba7-5c27d49405cf) | Attack Pattern | 1 |