Managing Attack Surface | Huntress Blog
ID: e35f92d3-24d6-558c-838c-280f30bdeb25
STIX ID: report--e35f92d3-24d6-558c-838c-280f30bdeb25
Feed Name: Huntress Blog
**Executive summary:** Huntress observed a two-day intrusion attempt where an actor with prior MSSQL credentials enabled xp_cmdshell and used sqlservr.exe to execute PowerShell (and certutil) to download PHP reverse shells from a Github repository (hightidAOaa/azdaz) and attempt callbacks to 0.tcp.eu.ngrok.io; Windows Defender and EDR repeatedly detected and quarantined the webshells (VirTool:PHP/Meterpreter.A!MTB, Trojan:HTML/WebShell!MSR) so the actor did not achieve a working reverse shell.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
