216.73.217.22

Christmas "Gift" Delivered Through SSH

· Published 20/12/2024 16:28 · Modified 20/12/2024 17:11

Export JSON

Essential information

Published
20/12/2024 16:28
Modified
20/12/2024 17:11
Tags
2024-12-20 lnk file ssh
Related entities
1 observables, 5 techniques (mitre)

Description

A malicious file named "christmas_slab.pdf.lnk" was discovered, utilizing Windows' built-in support to deliver malware. The executes .exe to transfer and run a PE file from a remote server. The attack leverages the /SCP protocol, taking advantage of its widespread availability on modern Windows systems. The malicious payload is downloaded from an IP address belonging to Apple's range, raising suspicions. The 's command line arguments reveal the attacker's intent to bypass host key checking and execute the downloaded malware. This technique demonstrates how threat actors are adapting to use legitimate system tools for malicious purposes.

External references