Information Stealer Masquerades as LDAPNightmare (CVE-2024-49113) PoC Exploit
ID: d9382d2d-8444-5c0f-a1f6-b1c9f3232366
STIX ID: report--d9382d2d-8444-5c0f-a1f6-b1c9f3232366
Feed Name: infostealers.com
This Trend Micro blog describes two critical Windows LDAP vulnerabilities (CVE-2024-49112 — RCE, and CVE-2024-49113 — DoS) and documents a malicious repository that replaced expected Python PoC files with a UPX-packed poc.exe which, when executed, drops PowerShell scripts that create scheduled jobs, download additional scripts from Pastebin, collect system and user data (process lists, directories, network info, installed updates), compress the data and exfiltrate it to an external FTP server using hardcoded credentials; the report includes technical indicators, hunting queries, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
