Can’t Touch This: Data Exfiltration via Finger

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Huntress analysts observed a rarely-seen data exfiltration technique using finger.exe, a native Windows utility originally designed for querying remote user information. A threat actor who had created a webshell on an MS Exchange server used finger.exe to send directory listings and process names to a remote IP via TCP port 79, effectively bypassing security monitoring by blending in with legitimate-looking activity. The technique was first documented in a 2020 advisory by security researcher John Page. The post maps the activity to MITRE ATT&CK techniques T1105 and T1048.003, and recommends monitoring or removing unused LOLBins to reduce attack surface.

4m read timeFrom huntress.com
Post cover image
Table of contents
What Is “Finger”?Data Exfiltration In The WildConclusion