Can’t Touch This: Data Exfiltration via Finger
ID: 01d75d74-3216-5b68-b38e-5f7891eba283
STIX ID: report--01d75d74-3216-5b68-b38e-5f7891eba283
Feed Name: Huntress Blog
Threat Score
Huntress observed threat actors leveraging the native Windows finger.exe utility to download files and exfiltrate unencrypted data from a compromised MS Exchange server (example commands and an associated malicious IP 185.56.83.82 are provided); the report maps the activity to MITRE ATT&CK techniques (T1105, T1048.003) and recommends monitoring or removing unused LOLBins and tuning detection to identify such abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
