Based on the detailed information provided, it appears that a sophisticated cyber attack was being conducted using WebDAV as an initial vector to deliver payloads. The attackers were leveraging LOLBins (Living Off The Land Binaries) such as iediagcmd.exe, route.exe, and others to execute malicious commands without raising suspicion.
Key Points:
-
WebDAV Exploitation:
- WebDAV was used over HTTP port 80 and HTTPS port 443.
- The server hosted various files designed to exploit vulnerabilities in Windows systems, particularly focusing on the absence of specific Microsoft patches (KB5060).
-
LOLBins Usage:
iediagcmd.exewas used as a primary payload launcher.- If
iediagcmd.exeis not present or patched against exploitation, fallback LOLBins such asCustomShellHost.exe,OfficeC2RClient.exe, and others are provided.
-
Exploitation Conditions:
- The presence of specific files (
route.exe) in the WebDAV directory. - Ensuring that certain Microsoft patches (KB5060) were not installed on target systems to
- The presence of specific files (
Read the full article at Rapid7 Blog
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





