logo

More SSH Fun!, (Tue, Dec 24th)

ID: aadc8e54-5217-5416-8d0b-4b0342d20ddf

STIX ID: report--aadc8e54-5217-5416-8d0b-4b0342d20ddf

Feed Name: SANS ISC Diary

Threat Score
65/100

Date Published: 2024-12-24

Date Updated: 2026-04-19

...
...

The report describes a small Windows batch script (SHA256:3172eb8283a3e82384e006458265b60001ba68c7982fda1b81053705496a999c) that uses C:\Windows\System32\OpenSSH\ssh.exe with options `-o PermitLocalCommand=yes` and `-R 5555` to establish a reverse SOCKS tunnel, run a local command that downloads and executes `Ghost.exe` from a devtunnels.ms URL, and creates a registry Run key for persistence — effectively implementing a backdoor and remote access capability on infected hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.