NAPLISTENER: more bad dreams from developers of SIESTAGRAPH
ID: 04e301a7-98f0-5c0b-9b63-ff6efc5be1b7
STIX ID: report--04e301a7-98f0-5c0b-9b63-ff6efc5be1b7
Feed Name: Elastic Security Labs
### Executive summary Elastic Security Labs analyzed NAPLISTENER, a C# HTTP-listener backdoor deployed as Wmdtc.exe that masquerades as Msdtc.exe to persist as a Windows service. The implant accepts base64-encoded .NET assemblies via a web path (/ews/MsExgHealthCheckd/) and executes them in memory, intentionally bypassing IIS logs and network-based detection; the report includes analysis of behavior, setup prerequisites (SSL cert binding), a YARA detection rule, and links to similar public code that likely influenced the implant.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
