From Zero to Purple
ID: 902eb639-33e0-54ad-bd88-da449dedcbe7
STIX ID: report--902eb639-33e0-54ad-bd88-da449dedcbe7
Feed Name: TrustedSec blog
Threat Score
This report demonstrates a practical attack technique where a Windows Internet Shortcut (.url) points to a payload contained in a remotely hosted ZIP (accessible via SMB or WebDAV), describes a proof-of-concept VBScript payload and a Python module to automate creation and hosting of the artifacts, and provides defensive recommendations including Sysmon event detections (events 15, 11, 1/4688) and suspicious execution paths to monitor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
