Combine cutting-edge XDR technology, multi-signal threat intelligence and 24/7 Elite Threat Hunters to help you build a world-class security operation.
Our team delivers the fastest response time in the industry. Threat suppression within just 4 hours of being engaged.
Cyber risk and advisory programs that identify security gaps and build security strategies to address them.
24/7 SOC-as-a-Service with unlimited threat hunting and incident handling.
XDR with machine learning that eliminates noise, enables real-time detection and response, and automatically blocks threats.
Seamless integration and threat investigation across your existing tech stack.
Proactive threat intelligence, original threat research and a world-class team of seasoned industry veterans.
Extend your team capabilities and prevent business disruption with expertise from eSentire.
We balance automated blocks with rapid human-led investigations to manage threats.
Guard endpoints by isolating and remediating threats to prevent lateral spread.
Defend brute force attacks, active intrusions and unauthorized scans.
Investigation and threat detection across multi-cloud or hybrid environments.
Remediate misconfigurations, vulnerabilities and policy violations.
Investigate and respond to compromised identities and insider threats.
Stop ransomware before it spreads.
Meet regulatory compliance mandates.
Detect and respond to zero-day exploits.
End misconfigurations and policy violations.
Defend third-party and supply chain risk.
Prevent disruption by outsourcing MDR.
Adopt a risk-based security approach.
Meet insurability requirements with MDR.
Protect your most sensitive data.
Build a proven security program.
Operationalize timely, accurate, and actionable cyber threat intelligence.
THE THREAT On November 18th, 2024, Palo Alto disclosed a critical actively exploited authentication bypass zero-day vulnerability impacting Palo Alto Networks PAN-OS. The…
Nov 13, 2024THE THREAT Update: eSentire has observed multiple exploitation attempts targeting CVE-2024-8069. In real-world attacks, threat actors successfully achieved RCE and attempted to…
eSentire is The Authority in Managed Detection and Response Services, protecting the critical data and applications of 2000+ organizations in 80+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events.
We provide sophisticated cybersecurity solutions for Managed Security Service Providers (MSSPs), Managed Service Providers (MSPs), and Value-Added Resellers (VARs). Find out why you should partner with eSentire, the Authority in Managed Detection and Response, today.
Multi-Signal MDR with 300+ technology integrations to support your existing investments.
24/7 SOC-as-a-Service with unlimited threat hunting and incident handling.
Three MDR package tiers are available based on per-user pricing and level of risk tolerance.
The latest security advisories, blogs, reports, industry publications and webinars published by TRU.
Compare eSentire to other Managed Detection and Response vendors to see how we stack up against the competition.
See why 2000+ organizations globally have chosen eSentire for their MDR Solution.
Recently, a hands-on intruder immediately began to attempt lateral movement and gain credential access upon successful abuse of compromised RDP credentials at a legal firm that is an eSentire MDR customer.
After performing initial network discovery with Advanced IP Scanner and PC Hunter (tool that allows kernel manipulations and terminate processes), the intruder deployed mimikatz and attempted to move laterally to five hosts within the network.
Of the five hosts, four were adequately protected and sent security alerts to eSentire‘s 24/7 Security Operations Center (SOC). However, the fifth host was outside of endpoint monitoring scope and the threat actor was able to successfully compromise it.
The threat actor‘s ability to move laterally resulted in them accessing an endpoint-protected host, which resulted in the escalation of the incident to Incident Handlers and eSentire’s Threat Response Unit (TRU). Without endpoint telemetry for the compromised hosts, investigators pivoted to network and log data to pinpoint the cyberattack.
By the time the hands-on attacker was engaged and ejected from the legal firm‘s internal environment, they had attempted to deploy MedusaLocker, but ultimately failed in the deployment.
Analysis of the deployed payload showed that the actor had accidentally deployed the Medusa Unlocker – the decrypter (Figure 1) – instead of the actual ransomware, MedusaLocker (MD5: 908e3b6aab0126ef4efcdc8c4805abd7) (Figure 2). It‘s likely this occurred due to the similarity in names.
As is typical of ransomware intrusion today, the intruder leveraged Cobalt Strike to deploy and manage tools and C2, including mimikatz, to gain credential access for network discovery and lateral movement (Figure 3). The toolset has some overlap with intruders observed deploying ALPHV or BlackCat ransomware.
060c523563e6d33bc8d0576aa18cf835ecac460c9980246e055508f980e14f9b - Medusa Unlocker - c:\users\prolaw\pictures\64\56771.exe ca5952b6e5d4aeb9263afe91b3524ac9cc654b88a7c90b41ec75e3506c6aa570 - webbrowserpassview.exe ad6b98c01ee849874e4b4502c3d7853196f6044240d3271e4ab3fc6e3c08e9a4 - psexec64.exe 3337e3875b05e0bfba69ab926532e3f179e8cfbf162ebb60ce58a0281437a7ef - psexec.exe 6a87226ed5cca8e072507d6c24289c57757dd96177f329a00b00e40427a1d473 - netpass (1).exe 6d924d92e3084190ed4bb9fed5435f5280f738e5842b8bb3fa6df5f408d2009d - pchunter64_s.exe 0ad926fa666acba562446f68c77199b5b2dc79b68245a04e3b6efd2a88ceae9a - pchunter64_у1.exe 8846c8be509a4b274d6d1465e9cc14d44cfb0a51f917d3a00ce00fa0b35a4284 - mimikatz.dll bee3d0ac0967389571ea8e3a8c0502306b3dbf009e8155f00a2829417ac079fc - mimidrv.sys d9770865ea739a8f1702a2651538f4f4de2d92888d188d8ace2c79936f9c2688 - mimilib.dll 96632f716df30af567da00d3624e245d162d0a05ac4b4e7cbadf63f04ca8d3da - mimispool.dll
Figure 3: Tools deployed to compromised endpoints
The C2 infrastructure leveraged by the threat actor was a Windows Virtual Private Service (VPS) with RDP and WinRM open (Figure 4) bearing self-signed certs with the hostname: RUTHERFORD. Windows RDP configurations for C2 have been observed before, leveraged by various affiliates deploying ransomware – notably Diavol, Conti, and Lockbit.
In some cases, threat actors are able to register these machines with the victim organization‘s network, leveraging Cobalt Strike as a reverse proxy since the machine names can sometimes be tracked. For example, the system name WIN-LIVFRVQFMKO appeared in a similar incident intercepted by TRU in Summer 2022. The system name also appeared in Conti leaks chat and a LockBit ransomware incident. These re-used hostnames could be the result of malicious infrastructure providers, such as Deep Cack and vps_crack_team, helping their customers by avoiding individual identifiers.
In the case of MedusaLocker, the machine name choice, RUTHERFORD, was likely an artifact of the Virtual Private Service (VPS) provider the hackers used. Selectel, a Russian based IT infrastructure provider supports RDP Windows machines and uses naming conventions of historical physicists and mathematicians for their hostnames, such as RUTHERFORD , NEWTON, HILBERT, and LOBACHEVSKY.
Although it's not yet known why Selectel does not use an individual naming scheme for leased RDP infrastructure, the end result is the same as malicious infrastructure providers – uniquely identifying infrastructure use becomes more complex.
As the adversarial TTPs grow in sophistication, they lead to a certain level of difficulty at which critical business decisions must be made. Preventing the various attack paths utilized by modern threat actors requires actively monitoring the threat landscape, developing, and deploying endpoint detection, and the ability to investigate logs & network data during active intrusions. To increase your resilience against cyber threats like this, we recommend:
eSentire’s Threat Response Unit (TRU) is a world-class team of threat researchers who develop new detections enriched by original threat intelligence and leverage new machine learning models that correlate multi-signal data and automate rapid response to advanced threats.
If you are not currently engaged with an MDR provider, eSentire MDR can help you reclaim the advantage and put your business ahead of disruption.
Learn what it means to have an elite team of Threat Hunters and Researchers that works for you. Connect with an eSentire cybersecurity specialist.
The eSentire Threat Response Unit (TRU) is an industry-leading threat research team committed to helping your organization become more resilient. TRU is an elite team of threat hunters and researchers that supports our 24/7 Security Operations Centers (SOCs), builds threat detection models across the eSentire XDR Cloud Platform, and works as an extension of your security team to continuously improve our Managed Detection and Response service. By providing complete visibility across your attack surface and performing global threat sweeps and proactive hypothesis-driven threat hunts augmented by original threat research, we are laser-focused on defending your organization against known and unknown threats.