SVCHost.exe and Internet Sharing Triage
ID: 7fc09ea4-5d7f-5cf1-ab2f-92c592bdb571
STIX ID: report--7fc09ea4-5d7f-5cf1-ab2f-92c592bdb571
Feed Name: On the Hunt
This post describes an investigation into thousands of DNS requests observed from svchost.exe on a corporate laptop; initial attribution to the InfoStealer ViperSoftx was revisited after telemetry and a svchost command-line showed the SharedAccess (ICS) service was in use. Forensics on a svchost process dump revealed HOSTS.ICS entries and domains contacted, leading to the conclusion that a personal device connected via Internet Connection Sharing was the infected host proxying DNS traffic rather than the corporate endpoint being compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
