Potential RipZip Attack on Startup Folder
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects a phishing attack which expands a ZIP file containing a malicious shortcut. If the victim expands the ZIP file via the explorer process, then the explorer process expands the malicious ZIP file and drops a malicious shortcut redirected to a backdoor into the Startup folder. Additionally, the file name of the malicious shortcut in Startup folder contains {0AFACED1-E828-11D1-9187-B532F1E9575D} meaning the folder shortcut operation.
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "File Created or Modified" AND ((FILENAME contains "\Microsoft\Windows\Start Menu\Programs\Startup" AND FILENAME contains ".lnk.{0AFACED1-E828-11D1-9187-B532F1E9575D}") OR (OBJECTNAME contains "\Microsoft\Windows\Start Menu\Programs\Startup" AND OBJECTNAME contains ".lnk.{0AFACED1-E828-11D1-9187-B532F1E9575D}")) AND PROCESSNAME endswith "\explorer.exe" select Action1.HOSTNAME,Action1.MESSAGE,Action1.USERNAME,Action1.DOMAIN,Action1.OBJECTNAME,Action1.FILENAME,Action1.PROCESSNAME
Detection
Execution Mode
realtime
Log Sources
Windows
Author
Greg (rule)


