Great #malware sample caught by @k3dg3 #threatintel

Exploits #ZippyReads (read only file for bypass of Mark-of-the-Web) and #DefenderExplode, a large file zero day in Microsoft Defender AV which breaks their telemetry and detection.

Targets Italy. Calls michaelpagerecruitment-ukoffers.]com

https://www.virustotal.com/gui/file/13846a9778f224ae692edddcc90746d0e619f872733c2c880188c36797b2c4e7

VirusTotal

VirusTotal

@GossiTheDog @k3dg3 WHY.DOES.WINDOWS.ALLOW.SCRIPTS.IN.LNK.FILES!?!?!

People say LNK files are the Windows equivalent of Unix symbolic links. No - No they are not...