Skip to content

Hide Navigation Hide TOC

Potential RipZip Attack on Startup Folder (a6976974-ea6f-4e97-818e-ea08625c52cb)

Detects a phishing attack which expands a ZIP file containing a malicious shortcut. If the victim expands the ZIP file via the explorer process, then the explorer process expands the malicious ZIP file and drops a malicious shortcut redirected to a backdoor into the Startup folder. Additionally, the file name of the malicious shortcut in Startup folder contains {0AFACED1-E828-11D1-9187-B532F1E9575D} meaning the folder shortcut operation.

Cluster A Galaxy A Cluster B Galaxy B Level
Potential RipZip Attack on Startup Folder (a6976974-ea6f-4e97-818e-ea08625c52cb) Sigma-Rules Boot or Logon Autostart Execution - T1547 (1ecb2399-e8ba-4f6b-8ba7-5c27d49405cf) Attack Pattern 1