logo

Threat Intel Accelerates Detection and Response

ID: e75ff67b-83fb-5c23-9e44-0a07f1e9d448

STIX ID: report--e75ff67b-83fb-5c23-9e44-0a07f1e9d448

Feed Name: Huntress Blog

Threat Score
50/100

Date Published: 2024-02-15

Date Updated: 2026-04-28

...
...

This Huntress report details discovery of reconnaissance activity against a legacy MSExchange installation: the attacker used OWA/powershell endpoints to execute commands (finger.exe, encoded PowerShell, whoami) that contacted IP 185.56.83.82. Huntress correlated Windows Defender detections, MSExchange CmdletLogs, and IIS logs to validate the indicators of compromise, mapped the behavior to OWASSRF exploitation, and advised immediate Exchange patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.