FAsset ▲
just now10/04 · 12:30 UTCCriticalHigh-confidence malicious persistence is present via the auto-start service `CTS4743HavocCircus`, backed by on-disk `HavocCircus.exe`, a service account logon (`HavocCircus`) at boot, repeated Service Control Manager `7036` running events through 2026-06-17, and a still-present config containing hard-coded SQL credentials, S3 credentials, DNS TXT trigger logic, PuTTY tooling paths, and a private key. No suspicious user-writable driver loads were found. Other persistence surfaces were default or benign, including AWS EC2Launch wallpaper startup scripts, default Winlogon/AppInit values, and routine...fin-etl-04i-000672e12ac745f49
just now10/04 · 08:08 UTCHighA boot-triggered scheduled task named \dont steal my token bro persists PowerShell with HighestAvailable under sec699-20\student_dadm. The task XML explicitly states "Run powershell as domain admin because yolo", Task Scheduler Operational logs show registration on 2024-06-04 and execution on 2026-05-29, and Sysmon corroborates svchost.exe spawning powershell.exe for that user. No attacker-relevant IFEO/SilentProcessExit abuse or user-writable driver persistence was found. Elastic EDR components are present, but the ElasticEndpoint service points to a now-missing executable, which is an inconclusive...fin-etl-20i-0ef5a2c81aa62dcfc
just now10/04 · 03:46 UTCHighA local-GPO startup script and a boot-triggered scheduled job named PacketBuffer persist PowerShell that runs packet_buffer.ps1, launches frida.exe against lsass.exe with tls.js to harvest TLS secrets, and starts dumpcap.exe writing rotating pcaps to \\10.10.200.40\pcaps\WIN-HOST-1. A common Startup shortcut, disable-defender.lnk, repeatedly launches a now-missing disable_defender.ps1 bootstrap, and Microsoft Defender real-time monitoring registry values are disabled. The script comments and AWS/Immersive Labs context suggest a lab/range host, but the playbook still requires high severity because active...fin-etl-21i-0f9c47f65b1138527
just now10/03 · 23:24 UTCCriticalHigh-suspicion persistence is present. The strongest anchor is a user logon scheduled task that launches hidden PowerShell with ExecutionPolicy Bypass to keep a local CUA command server alive via `python -m computer_server --port 5000`, paired with additional logon persistence for an OpenClaw gateway containing hardcoded API keys. Separately, two user-authored scheduled tasks are configured to run as `S-1-5-18` and execute `C:\Windows\Temp\download.ps1` and `C:\Windows\Temp\enc.ps1` through `powershell.exe -ExecutionPolicy Bypass`; the scripts stage data from Google Cloud Storage and password-...fin-etl-13i-00385254a97499583
just now10/03 · 14:40 UTCHighA malicious scheduled-task persistence anchor was recovered. `\AutoMailJob` launches `powershell.exe -ExecutionPolicy Bypass -File "C:\scripts\gdrive_mail.ps1"` as Administrator with HighestAvailable privileges. The persisted script downloads content from Google Drive, stores it under `C:\scripts\file.txt`, and emails the result out through a hard-coded Gmail account/app password. PowerShell event logs show 29 launches referencing `gdrive_mail.ps1` from 2026-10-02T02:11:07Z through 2026-10-02T02:16:04Z, supporting repeated execution rather than a one-off test. No comparable IFEO, WMI permanen...fin-etl-19i-0ee99d8a17036d6e9
just now10/03 · 05:57 UTCHighHigh suspicion is driven by an auto-start custom service (`CTS4743HavocCircus`) that persists `HavocCircus.exe` under `C:\Program Files\CTS 4373\Services\Havoc Circus\`, stores a dedicated local service account, embeds database and AWS credentials in its config, bundles an SSH private key, and references PuTTY `plink.exe`/`pscp.exe` for remote operations against `ec2-user@linux1.cts4743.edu`. Repeated System 7031 crashes in 2023 and 2025 show the service continued launching and failing long after installation. No suspicious user-writable driver load, IFEO/SilentProcessExit abuse, WMI permanent...fin-etl-15i-08f69935ab49d017a
just now10/03 · 01:35 UTCMediumHigh-confidence malicious persistence is present. The strongest anchor is an auto-start service (`DBUTIL`) that loads `\??\C:\Users\Administrator\Downloads\DBUtil_2_3.sys` from a user-writable Downloads path; the file is present and hashable, and the DBUtil family is widely associated with BYOVD abuse. A second service (`UmPass`) points to `\??\C:\Windows\Temp\WKL\OBJINFO.sys`, which is a user-writable/non-standard driver path but the exact file is missing in the snapshot. Separately, offensive tooling traces are strong: `cobaltstrike.exe` and its `update.bat` remain on disk, UserAssist shows...crown-app-17i-0a4f9e2d26cf4b45b