.. /.Pyz

Executable
Script
External

Author:

mr.d0x

Description:

PYZ or Python Zipped Executable files are Python script files. By default Python is not installed on Windows. Usually, once Python is installed, .pyz files are executed via the Python interpreter upon being double clicked.

OS:

Windows
Mac
Linux

Recommendation:

Block the execution of PYZ files. Whitelist users/groups when required.

Resources:

https://www.cyborgsecurity.com/cyborg_labs/python-malware-on-the-rise/

File Samples:

Contributions: