Image: cdn.builder.io · rights & removal
Reporting by Huntress LabsRead the original at huntress.com
Executive Summary
Facts Only
* A Huntress agent was deployed on an organization targeted by an Akira ransomware attack in September.
* An EDR signal indicated svchost.exe executing from C:\PerfLogs\Temp\ under the SYSTEM account, loading config.dll.
* Windows Event Logs showed threat actor access via Terminal Services/RDP from a non-customer workstation.
* The threat actor stopped Bitdefender services: Service Control Manager/7036;Bitdefender Endpoint Update Service, Service Control Manager/7036;Bitdefender Endpoint Integration Service, and Service Control Manager/7036;Bitdefender Endpoint Protected Service, and Service Control Manager/7036;Bitdefender Endpoint Security Service.
* procdump.exe was run from C:\PerfLogs to potentially dump lsass.exe contents.
* The GOST tunnel tool was deployed approximately four hours after file encryption processes began for persistence.
* RClone was launched from the C:\PerfLogs folder following the deployment of the GOST tunnel.
* Shellbags artifacts indicated access to subfolders beneath a Shares folder before the first Akira command execution.
* PowerShell command line evidence indicated the launch of ransomware and creation of an Akira log file, followed by checking Shared folder subfolders via Windows Explorer three more times.
Full Take
From the original · Huntress Labs
Acknowledgments: Special thanks to Dray Agha for his extensive contributions to this investigation. Background In September, the Huntress agent was deployed on an organization that had been targeted in an Akira ransomware attack.Read the full story at huntress.com
Sentinel — Human
The text reads like an account of a detailed, evidence-based investigation by security researchers, supported by specific artifact references, lending it a high probability of human authorship.
