Potential RipZip Attack on Startup Folder

 Original Source: [Sigma source]
Title: Potential RipZip Attack on Startup Folder
Status: test
Description:Detects a phishing attack which expands a ZIP file containing a malicious shortcut. If the victim expands the ZIP file via the explorer process, then the explorer process expands the malicious ZIP file and drops a malicious shortcut redirected to a backdoor into the Startup folder. Additionally, the file name of the malicious shortcut in Startup folder contains {0AFACED1-E828-11D1-9187-B532F1E9575D} meaning the folder shortcut operation.
References:
  -https://twitter.com/jonasLyk/status/1549338335243534336?t=CrmPocBGLbDyE4p6zTX1cg&s=19
Author: Greg (rule)
Date: 2022-07-21
modified:2023-01-05
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1547'
Logsource:
  • category: file_event
  • product: windows
Detection:
  selection:
    TargetFilename|contains|all:
      -'\Microsoft\Windows\Start Menu\Programs\Startup'
      -'.lnk.{0AFACED1-E828-11D1-9187-B532F1E9575D}'

    Image|endswith: '\explorer.exe'
  condition:selection
Falsepositives:
  -Unknown
Level: high