Fuzzing RDP: Holding the Stick at Both Ends
Tags
attack-pattern: | Data Powershell - T1059.001 Remote Desktop Protocol - T1021.001 Server - T1583.004 Server - T1584.004 Vulnerabilities - T1588.006 Powershell - T1086 Remote Desktop Protocol - T1076 |
Common Information
Type | Value |
---|---|
UUID | 7f6e5853-f1d4-4942-8b61-5c53d0ddab07 |
Fingerprint | 2e14d89244a16f95 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Aug. 27, 2021, midnight |
Added to db | Dec. 18, 2024, 7:59 p.m. |
Last updated | Dec. 23, 2024, 2:07 p.m. |
Headline | Fuzzing RDP: Holding the Stick at Both Ends |
Title | Fuzzing RDP: Holding the Stick at Both Ends |
Detected Hints/Tags/Attributes | 52/1/14 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | File | 107 | c:\windows\system32\svchost.exe |
|
Details | File | 18 | audiodg.exe |
|
Details | File | 2 | rdpinput.exe |
|
Details | File | 1 | rdpendp.dll |
|
Details | Windows Registry Key | 2 | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService |
|
Details | Domain | 143 | shodan.io |
|
Details | File | 4 | afl-fuzz.exe |
|
Details | File | 1 | winafl.dll |
|
Details | File | 82 | mstsc.exe |
|
Details | File | 7 | mstscax.dll |
|
Details | File | 2 | vmconnect.exe |
|
Details | File | 1 | c:\windows\system32\termsrv.dll |
|
Details | File | 19 | termsrv.dll |
|
Details | File | 1199 | svchost.exe |