CyberWire Daily cover image

An incident response reveals itself as GhostShell tool, ShellClient. [Research Saturday]

CyberWire Daily

00:00

The Shock Riant - What Kind of Commands Does It Have?

The shock riant can do various types of commands from querying the host name for ample, check which type of version of shell plant is actually running. It's able to extract the ip address of the machine, or actually to ping in external ip services and install other things. So it has very robust capabilities when it comes to enabling the thread actor to run various operations. And even have some command that enables it to run lateral movement using w now, one of the interesting aspects of your research here is that you you explored if this was a, how old a version of this is,. trying to determine how far back this goes.

Play episode from 09:20
Transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app