Investigating Intrusions From Intriguing Exploits
ID: 3688fcff-a448-5348-b737-7b462a5534cd
STIX ID: report--3688fcff-a448-5348-b737-7b462a5534cd
Feed Name: Huntress Blog
Threat Score
Huntress detected and contained exploitation of a zero‑day in GoAnywhere MFT that led to retrieval and attempted execution of a signed Truebot DLL (gamft.dll); analysts recovered file hashes, C2 domain (qweastradoc.com) and host IPs, mapped TTPs (certutil, rundll32, scheduled tasks) and linked the activity to the Silence/Truebot ecosystem and TA505 with likely ransomware intent.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
