Unraveling a Reverse Shell with Huntress Managed EDR
ID: 8f140984-4d21-51e3-bc89-3333508c1072
STIX ID: report--8f140984-4d21-51e3-bc89-3333508c1072
Feed Name: Huntress Blog
Threat Score
Huntress investigated and decoded an encoded PowerShell reverse-shell delivered via a compromised ScreenConnect RMM instance: the payload contacted the domain onerecovery.click, fetched scripts and an SSH executable, created a scheduled task for persistence, opened firewall rules, and established a reverse SSH connection to 88.119.175.55; the report includes analysis and practical defensive recommendations (2FA on RMM, network monitoring, IDS/IPS, user hygiene).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
