Can’t Touch This: Data Exfiltration via Finger
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Huntress analysts observed a rarely-seen data exfiltration technique using finger.exe, a native Windows utility originally designed for querying remote user information. A threat actor who had created a webshell on an MS Exchange server used finger.exe to send directory listings and process names to a remote IP via TCP port 79, effectively bypassing security monitoring by blending in with legitimate-looking activity. The technique was first documented in a 2020 advisory by security researcher John Page. The post maps the activity to MITRE ATT&CK techniques T1105 and T1048.003, and recommends monitoring or removing unused LOLBins to reduce attack surface.