Bullseye: A Story of a Targeted Cyberattack | Huntress
ID: 256a7900-364c-5181-a999-4cf43c7db8b9
STIX ID: report--256a7900-364c-5181-a999-4cf43c7db8b9
Feed Name: Huntress Blog
Threat Score
This Huntress analysis describes a targeted PowerShell-based persistent backdoor that used a scheduled task to run obfuscated PowerShell which downloaded segmented Base64/GZIP payloads, reflectively loaded a .NET DLL to invoke Win32 APIs, patched AmsiScanBuffer to bypass AMSI, and attempted to establish an Empire beacon via a typosquatted vendor-like C2 domain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
