logo

Unraveling a Reverse Shell with Huntress Managed EDR

ID: 8f140984-4d21-51e3-bc89-3333508c1072

STIX ID: report--8f140984-4d21-51e3-bc89-3333508c1072

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-04-23

Date Updated: 2026-04-28

...
...

Huntress investigated and decoded an encoded PowerShell reverse-shell delivered via a compromised ScreenConnect RMM instance: the payload contacted the domain onerecovery.click, fetched scripts and an SSH executable, created a scheduled task for persistence, opened firewall rules, and established a reverse SSH connection to 88.119.175.55; the report includes analysis and practical defensive recommendations (2FA on RMM, network monitoring, IDS/IPS, user hygiene).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.