More SSH Fun!, (Tue, Dec 24th)
ID: aadc8e54-5217-5416-8d0b-4b0342d20ddf
STIX ID: report--aadc8e54-5217-5416-8d0b-4b0342d20ddf
Feed Name: SANS ISC Diary
Threat Score
The report describes a small Windows batch script (SHA256:3172eb8283a3e82384e006458265b60001ba68c7982fda1b81053705496a999c) that uses C:\Windows\System32\OpenSSH\ssh.exe with options `-o PermitLocalCommand=yes` and `-R 5555` to establish a reverse SOCKS tunnel, run a local command that downloads and executes `Ghost.exe` from a devtunnels.ms URL, and creates a registry Run key for persistence — effectively implementing a backdoor and remote access capability on infected hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
