A security analyst is performing a forensic analysis on a machine that was the subject of some historic SIEM alerts. The analyst noticed some network connections utilizing SSL on non-common ports, copies of svchost.exe and cmd.exe in %TEMP% folder, and RDP files that had connected to external IPs. Which of the following threats has the security analyst uncovered?
slcc99
Highly Voted 5 years, 1 month agomoe1985
Highly Voted 5 years, 3 months agoJeend
Most Recent 2 years, 4 months agoAcrisius
4 years, 5 months agomaps7
5 years agocyber_now
5 years, 2 months agoT_rev93
5 years, 2 months agos3curity
5 years, 5 months agoSamus_7
5 years, 9 months ago