Today > 1 Critical | 3 Medium vulnerabilities   -   You can now download lists of IOCs here!

Information Stealer Masquerades as LDAPNightmare (CVE-2024-49113) PoC Exploit

Jan. 10, 2025, 5:12 p.m.

Description

A fake proof-of-concept exploit for the LDAPNightmare vulnerability (CVE-2024-49113) is being used to distribute information-stealing malware. The malicious repository, disguised as a fork from the original creator, contains an executable file that, when run, drops and executes a PowerShell script. This script creates a Scheduled Job that downloads and executes another script from Pastebin. The malware collects various system information, compresses it, and exfiltrates it to an external FTP server. This attack capitalizes on a trending issue, potentially affecting a large number of victims. To protect against such threats, users are advised to download from trusted sources, be cautious of suspicious content, and review repository details carefully.

Date

Published: Jan. 10, 2025, 5:04 p.m.

Created: Jan. 10, 2025, 5:04 p.m.

Modified: Jan. 10, 2025, 5:12 p.m.

Attack Patterns

T1120

T1048.003

T1053.005

T1059.001

T1012

T1016

T1082

T1057

T1105

T1083

T1560