Close Menu
    Facebook X (Twitter) Instagram
    Nintendo-Power
    • Home
    • Top News
    • Tech
    • Nintendo
    • Downloads
    • Contact Form
    Nintendo-Power
    Home»Top News»Transfer interval is automatically exploited – Security and Data Security – Funkshow
    Top News

    Transfer interval is automatically exploited – Security and Data Security – Funkshow

    Beatrice AshfordBy Beatrice AshfordApril 21, 2021No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Transfer interval is automatically exploited - Security and Data Security - Funkshow
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft Exchange vulnerabilities are still a problem: security analysts summarize one of the many attacks they have seen and explain how the hackers went about it.

    Vulnerabilities in Microsoft Exchange servers were discovered in early March. These are of course exploited by cyber criminals, and Microsoft, the BSI and security companies are calling for a crackdown. Other gaps have been found to need to be glued urgently. What happens if companies do nothing in this regard is illustrated in the following example of an attack based on these vulnerabilities.

    According to Unit 42’s blog post, on March 6, 2021, unknown cybercriminals used vulnerabilities in the Microsoft Exchange server to install a web shell on a server at a financial institution in the EMEA region. Although Unit 42 does not have WebShell access, security analysts suspect that the WebShell server side may be a variant of “Jascript China Chopper”.

    The blog post of the Palo Alto Networks malware research group describes the sequence of the attack: On March 12, 2021, six days after it was installed, the attackers used the installed web shell to execute the PowerShell commands, collect information and active directory from the local server and compromise the transaction from the server. Cybercriminals compressed files related to the collection of information and credentials by creating cabinet files stored in a folder accessible to the Internet by the Internet Information Services (IIS) server. The cast attempted to oust these cabinet files by directing them on March 12 and 13, 2021.

    Security analysts analyzed the IP addresses of incoming requests to execute commands via the installed web shell, as well as requests to download the resulting files. None of the observed IP addresses appear to be attackers’ own infrastructure, and they may be the choice of free proxies, VPNs, and compromised servers. The IP addresses viewed in the logs provided no trace of further action.

    Hackers automate their attacks

    Unit 42 researchers believe the attackers automated interactions with the webshell to run two separate power shell scripts. These were released every three seconds and contained two different incoming IP addresses. Automation also seems to involve deliberately changing IP addresses in a way that makes it difficult to analyze and communicate with the process. Automation provided a hint that the actors carried out this particular attack as part of a larger offensive campaign.

    Attack attempts to collect credentials from the affected financial institution in the EMEA region failed because incoming requests to download the memory image from the Local Security Authority Subsidiary Service (LSASS) process failed. As an added security measure, it was installed on the Cortex XDR transfer server with an enabled password theft protection module. This removed the pointers to the desired access data from the memory dummy, which would attack the ability to extract access data from the memory dummy even if the file could be successfully downloaded.


    1. The transmission interval is automatically exploited

    2. Suspected of being a major attack campaign


    Share on Facebook


    Share on Twitter

    Share in the center

    Share via mail

    You may be interested

    German companies are particularly popular targets for cybercriminals

    The most popular bait of fishermen

    The new holes put the Microsoft Exchange server at risk

    The security hole is still open on every second server

    Blackmailers demand $ 50 million from Acer

    Related Articles

    Microsoft, Palo Alto Networks GmbH

    Beatrice Ashford

    Beatrice Ashford is a contributor at Nintendo-power.com, covering a wide range of topics including news, politics, business, technology, sport, entertainment, and lifestyle. She focuses on delivering clear, balanced reporting and useful information that helps readers stay informed about current events and emerging developments. Her work highlights stories that matter to everyday audiences, with an emphasis on accuracy, relevance, and accessible journalism that keeps readers connected to the issues shaping the world around them.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Acrylic Nails for the Modern Professional: Balancing Style and Practicality

    September 6, 2024

    The Majestic Journey of the African Spurred Tortoise: A Guide to Care and Habitat

    September 2, 2024

    Choosing Between a Russian and a Greek Tortoise: What You Need to Know

    June 21, 2024
    Leave A Reply Cancel Reply

    Navigate
    • Home
    • Top News
    • Tech
    • Nintendo
    • Downloads
    • Contact Form
    Pages
    • About Us
    • Contact Us
    • DMCA
    • Editorial Policy
    • Privacy Policy
    • Nintendo Power – Latest Gaming News, Reviews & Retro Updates
    Recent
    • Xbox Free Play Days: GTA Online, Planet Zoo and Dragon Ball Xenoverse 2 Headline Weekend Gaming Line-up
    • Windows 11 July Update: Five New Features UK Users Should Try
    • Farnborough Airshow Set for Take-Off Despite High-Profile Absences
    • Games Done Quick Reveals Flame Fatales 2026 Schedule Supporting Malala Fund
    • 17,000 Brain Scans Reveal Unexpected Ethnic Differences in Alzheimer’s Disease Biology
    • About Us
    • Contact Us
    • DMCA
    • Editorial Policy
    • Privacy Policy
    • Nintendo Power – Latest Gaming News, Reviews & Retro Updates
    © 2026 Nintendo Power. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.