Christmas "Gift" Delivered Through SSH, (Fri, Dec 20th)
ID: 1c89fd29-2793-59fb-b8b6-4b0bfd5d5fc3
STIX ID: report--1c89fd29-2793-59fb-b8b6-4b0bfd5d5fc3
Feed Name: SANS ISC Diary
Threat Score
A security researcher found a malicious .lnk file that launches Windows OpenSSH (ssh.exe) and uses the -o LocalCommand=scp ... pattern to download and execute a PE payload (christmas-sale.exe) from a remote host; the report includes exiftool output showing the exact command line and notes the remote SSH server was offline when tested.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
