THREAT OPS › Threat News › Weaponizing Windows Updates with NotWSUSpicious
Weaponizing Windows Updates with NotWSUSpicious
<p class="wp-block-paragraph"><em><strong>TL;DR</strong>: <code>NotWSUSpicious</code> is a tool repo to aid in creating custom updates after gaining access to a WSUS database server. The <code>Turning Enterprise Update Servers Into Backdoor Factories (0_o)</code> series covers how the database takeover works. This blog strictly covers how to use the tooling.</em></p>
<p class="wp-block-paragrap
MITRE ATT&CK techniques
Indicators of compromise
- d776cb981073e50a4f15e9e2b214ebe0949193d6sha1
- 0xD776CB981073E50A4F15E9E2B214EBE0949193D6eth
- 13bLmBBz5QpPFenishTr4JSRk9Ybtc
- http://MSSQLClient.pyurl
- http://mssqlclient.pyurl
- http://NotWSUSpicious.pyurl
- http://198.51.100.1:8000/Specter.exe.txt>url
- https://specter.local></upd:SupportUrl><upd:SecurityBulletinID></upd:SecurityBulletinID><upd:KBArticleID>5006103</upd:KBArticleID></upd:Properties><upd:LocalizedPropertiesCollection><upd:LocalizedProperties><upd:Language>en</upd:Language><upd:Title>Specter</upd:Title><upd:Description>Installurl
- https://specter.local></upd:MoreInfoUrl><upd:SupportUrl><https://specter.local></upd:SupportUrl></upd:LocalizedProperties></upd:LocalizedPropertiesCollection><upd:Relationships><upd:Prerequisites><upd:AtLeastOneurl
- https://specter.local>&lt;/MoreInfoUrl&gt;&lt;SupportUrl&gt;<https://specter.local>&lt;/SupportUrl&gt;&lt;/LocalizedProperties&gturl
- https://specter.local>&lt;/SupportUrl&gt;&lt;SecurityBulletinID&gt;&lt;/SecurityBulletinID&gt;&lt;KBArticleID&gt;5006103&lt;/KBArticleID&gt;&lt;/ExtendedProperties&gturl
- http://BitsWebServer.pyurl
- 198.51.100.1ipv4