logo

Investigating Intrusions From Intriguing Exploits

ID: 3688fcff-a448-5348-b737-7b462a5534cd

STIX ID: report--3688fcff-a448-5348-b737-7b462a5534cd

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Huntress detected and contained exploitation of a zero‑day in GoAnywhere MFT that led to retrieval and attempted execution of a signed Truebot DLL (gamft.dll); analysts recovered file hashes, C2 domain (qweastradoc.com) and host IPs, mapped TTPs (certutil, rundll32, scheduled tasks) and linked the activity to the Silence/Truebot ecosystem and TA505 with likely ransomware intent.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.