logo

From Zero to Purple

ID: 902eb639-33e0-54ad-bd88-da449dedcbe7

STIX ID: report--902eb639-33e0-54ad-bd88-da449dedcbe7

Feed Name: TrustedSec blog

Threat Score
50/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report demonstrates a practical attack technique where a Windows Internet Shortcut (.url) points to a payload contained in a remotely hosted ZIP (accessible via SMB or WebDAV), describes a proof-of-concept VBScript payload and a Python module to automate creation and hosting of the artifacts, and provides defensive recommendations including Sysmon event detections (events 15, 11, 1/4688) and suspicious execution paths to monitor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.