Cryptogram Labs

Cryptogram LabsCryptogram LabsCryptogram Labs
  • Home
  • Services
  • Contact Us
  • New Threats
  • More
    • Home
    • Services
    • Contact Us
    • New Threats

Cryptogram Labs

Cryptogram LabsCryptogram LabsCryptogram Labs
  • Home
  • Services
  • Contact Us
  • New Threats

attack logs on log4j

Download PDF

Threats

eCrime attacks

WIZARD SPIDER, PINCHY SPIDER, CARBON SPIDER, TWISTED SPIDER, GRACEFUL SPIDER, MUMMY SPIDER, DOPPEL SPIDER, VIKING SPIDER, SPRITE SPIDER, TRAVELING SPIDER

TARGET:

WIZARD SPIDER Targets Financial Institutions

A hidden shell command is launch from a running svchost.exe process on a Windows domain controller.

COMMAND USED:

wmic process where name="svchost.exe" get 

processid,name,commandline,sessionid,creationdate

tasklist /v

RECOMENDATIONS:

Monitor unusual behavior from svchost.exe instances, in particular 

the presence of suspicious DLLs leveraging svchost.exe to make unusual network connections to external infrastructure. 


Copyright © 2024 Cryptogram Labs - All Rights Reserved.


Powered by Cryptogram

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept