216.73.216.233

More SSH Fun!

· Published 24/12/2024 12:50 · Modified 24/12/2024 13:17

Export JSON

Essential information

Published
24/12/2024 12:50
Modified
24/12/2024 13:17
Tags
2024-12-24 dev tunnels ssh
Related entities
2 observables, 6 techniques (mitre)

Description

A Windows batch file has been discovered that abuses the .exe tool in modern Windows versions to create a backdoor. The script adds a registry entry for persistence and uses to set up a reverse tunnel, allowing remote access. It also downloads and executes a malicious file using a URL, a Microsoft feature similar to ngrok. The script disables host key verification and enables local command execution through . While the specific malicious payload (Ghost.exe) is no longer available, it is suspected to be a Remote Access Trojan (RAT). This technique demonstrates the creative misuse of legitimate tools for malicious purposes.

External references