Trial, Error, and Typos: Why Some Malware Attacks Aren't as 'Sophisticated' as You Think
ID: 19a3d2b3-71f3-5904-ba44-26422b4b5574
STIX ID: report--19a3d2b3-71f3-5904-ba44-26422b4b5574
Feed Name: Huntress Blog
This report analyzes three related IIS-hosted intrusions observed by Huntress in November where attackers exploited web application flaws to run commands via w3wp.exe, attempted to download and execute Golang trojans (agent.exe/815.exe), and deployed SparkRAT and ShellcodeRunner. Telemetry (Sysmon, EDR, Windows Event Logs) shows the attackers repeatedly adapted—using certutil for downloads, mis-typed commands, adding Windows Defender exclusions via PowerShell in later incidents, and attempting service-based persistence—while defenders mitigated with quarantine and endpoint isolation; the report includes IOC hashes and client IP addresses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
