logo

Lets Open(Dir) Some Presents: An Analysis of a Persistent Actor’s Activity

ID: 680bf003-50b1-54a4-90ea-da3690a9a5bc

STIX ID: report--680bf003-50b1-54a4-90ea-da3690a9a5bc

Feed Name: The DFIR Report

Threat Score
78/100

Date Published: 2023-12-18

Date Updated: 2026-04-19

Author: editor

...
...

This report analyzes an open directory revealing over a year of activity from a persistent threat actor who scanned and exploited numerous public-facing services across government, defense, finance, telecoms and other sectors using open-source tooling (httpx, nuclei, sqlmap, ghauri), commodity C2 frameworks (Sliver, Metasploit), and exploit scripts for multiple CVEs; observed actions include SQL injection data theft, remote code execution against Exchange, VMware, WebLogic and other services, deployment of web shells, lateral movement, credential harvesting (LSA/NTDS/DCSync/Golden Ticket), and resource hijacking via xmrig crypto-miner, with extracted IOCs (domains, IPs, hashes, Sliver beacons) and detailed MITRE-mapped TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.