Title:Phishing Pattern ISO in Archive Status:test Description:Detects cases in which an ISO files is opend within an archiver like 7Zip or Winrar, which is a sign of phishing as threat actors put small ISO files in archives as email attachments to bypass certain filters and protective measures (mark of web) References: -https://twitter.com/1ZRR4H/status/1534259727059787783 -https://app.any.run/tasks/e1fe6a62-bce8-4323-a49a-63795d9afd5d/ Author: Florian Roth (Nextron Systems) Date: 2022-06-07 modified:None Tags:
condition:selection Falsepositives:
-Legitimate cases in which archives contain ISO or IMG files and the user opens the archive and the image via clicking and not extraction Level:high