Know Thy Enemy: A Novel November Case | Huntress
ID: cf114efd-13f5-5810-8ac1-717b5424fa64
STIX ID: report--cf114efd-13f5-5810-8ac1-717b5424fa64
Feed Name: Huntress Blog
Threat Score
Huntress SOC investigated multiple intrusions where adversaries brute-forced a public RD-Web/RDP instance to gain access, escalated privileges, used PsExec to run batch scripts that enabled RDP and WDigest credential storage, and deployed a renamed MeshAgent (nvspbind.exe) connecting to 193.46.255.73 for persistent remote access; the report includes associated hashes, IPs, hostnames, and MITRE ATT&CK mappings and highlights detection and hardening recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
