logo

Trial, Error, and Typos: Why Some Malware Attacks Aren't as 'Sophisticated' as You Think

ID: 19a3d2b3-71f3-5904-ba44-26422b4b5574

STIX ID: report--19a3d2b3-71f3-5904-ba44-26422b4b5574

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2025-12-22

Date Updated: 2026-04-28

...
...

This report analyzes three related IIS-hosted intrusions observed by Huntress in November where attackers exploited web application flaws to run commands via w3wp.exe, attempted to download and execute Golang trojans (agent.exe/815.exe), and deployed SparkRAT and ShellcodeRunner. Telemetry (Sysmon, EDR, Windows Event Logs) shows the attackers repeatedly adapted—using certutil for downloads, mis-typed commands, adding Windows Defender exclusions via PowerShell in later incidents, and attempting service-based persistence—while defenders mitigated with quarantine and endpoint isolation; the report includes IOC hashes and client IP addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.