#Meterpreter
Malware/Tool
2018-03-08 • OlympicDestroyer is here to trick the industry
Meterpreter is a backdoor payload from the Metasploit penetration-testing framework that Kimsuky deployed against a poorly managed or unpatched Windows IIS server at a South Korean architecture company. After breaching the server, the operator made the w3wp.exe process invoke PowerShell to download Meterpreter as C:\programdata\img.dat from an external address. Meterpreter provided control of the compromised server and was then used to install an additional Go-based proxy tool, again through PowerShell. The associated infrastructure included an external host and port, while the proxy appeared intended to enable later RDP access into the infected system.
-
3
Tagged Reports
-
2
Unique Authors
-
1,901
Active Days