<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Windows on DEATH.sk</title><link>http://death.sk/tags/windows/</link><description>Recent content in Windows on DEATH.sk</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 12 Apr 2026 15:00:48 +0200</lastBuildDate><atom:link href="http://death.sk/tags/windows/index.xml" rel="self" type="application/rss+xml"/><item><title>Understanding EDR Telemetry: Virtual Disk Mount</title><link>http://death.sk/posts/iso_mount/</link><pubDate>Sun, 12 Apr 2026 15:00:48 +0200</pubDate><guid>http://death.sk/posts/iso_mount/</guid><description>&lt;p&gt;In 2022 Microsoft &lt;a href="https://learn.microsoft.com/en-gb/microsoft-365-apps/security/internet-macros-blocked"&gt;announced&lt;/a&gt; auto-blocking of macros in Office documents downloaded from the Internet, a popular initial access method for threat actors. This forced threat actors to turn to other less common methods of malware delivery. One of the methods that &lt;a href="https://unit42.paloaltonetworks.com/brute-ratel-c4-tool/"&gt;quickly&lt;/a&gt; &lt;a href="https://thedfirreport.com/2022/04/25/quantum-ransomware/"&gt;gained&lt;/a&gt; &lt;a href="https://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/"&gt;traction&lt;/a&gt; was distribution through ISO-mounted files.&lt;/p&gt;
&lt;p&gt;User double-clicks the ISO file, mounting it as a CD-ROM drive. The mounted drive contains a lure commonly in form of a LNK file masquerading as a document. When the victim executes the LNK lure it executes (often while utilizing additional tricks such as DLL-sideloading) a payload that is also placed on the mounted ISO drive. The payload and any other files except the lure file have hidden attribute set to avoid raising suspicion.&lt;/p&gt;</description></item></channel></rss>