logo

Attacks from Malicious IP Hit Multiple Machines in Several Countries

ID: b2b0debe-94b5-557d-842e-a98b8d87493a

STIX ID: report--b2b0debe-94b5-557d-842e-a98b8d87493a

Feed Name: Symantec Threat Intel

Threat Score
35/100

Date Published: 2020-05-27

Date Updated: 2026-07-28

Author: Threat Intel

...
...

Attacks from IP 45.77.78.133 repeatedly targeted fewer than 40 machines in the U.S., Canada, and Mexico using PowerShell scripts (Invoke-Adios/Invoke-Mimikatz), LSASS memory dumps, firewall/registry changes to enable RDP, and a PowerShell backdoor; Symantec Endpoint Protection consistently blocked the attempts and no confirmed full breaches were observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.