.. /.Ics

Phishing
Double Click

Contributors:

Adithya - @ravooriadithya

Description:

An .ics file absolutely can be harmful. They can contain many calendar events containing weaponized links. The result can be an annoying amount of appointment reminders containing links. Besides attachments, malicious .ICS files can include links to external files (URI option) that could install malware when clicked on

OS:

Windows
Mac
Linux

Recommendation:

User awareness is crucial not to open suspected calendar invites containing malicious links since .ics blocks on email gateways can cause business impact.

Resources:

https://abnormalsecurity.com/blog/calendar-invite-malware-attack

File Samples:

https://www.virustotal.com/gui/url/c720d19495ffb9cc901e2043e41b601e9bc5e3c965eff761e786b95a60ae51d2/detection