What
A brute force SSH attack from 149[.]88[.]25[.]133 successfully authenticated as local user analyst on host Kristine (172[.]16[.]17[.]129). Following access, the attacker performed post-exploitation recon, created a backdoor local account (letsdefend1), and modified /etc/sudoers via visudo to grant that account unrestricted ALL:ALL sudo privileges. The backdoor account had not yet been used when the host was contained.
When
| Timestamp (UTC) | Event |
|---|
| 2024-09-20 06:33 AM | SSH brute force attempt begins; multiple usernames sprayed |
| 2024-09-20 06:33:48 | Successful login as analyst from 149[.]88[.]25[.]133:64646 |
| 2024-09-20 06:33:48 | whoami — identity recon |
| 2024-09-20 06:34:24 | sudo useradd -m letsdefend1 — backdoor account created |
| 2024-09-20 06:34:32 | sudo passwd letsdefend1 — password set |
| 2024-09-20 06:34:57 | sudo -l — sudo privilege enumeration |
| 2024-09-20 06:35:12 | sudo cat /etc/sudoers — sudoers read (alert triggered) |
| 2024-09-20 06:35:26 | sudo visudo — sudoers modified; ALL:ALL granted to letsdefend1 |
| 2024-09-20 06:36:03 | sudo cat /etc/sudoers — modification confirmed |
| 2024-09-20 06:36:13 | groups letsdefend1 / getent passwd — account enumeration |
Where
- Host: Kristine
- Internal IP:
172[.]16[.]17[.]129
- Attack source:
149[.]88[.]25[.]133
Who
- Attacker IP:
149[.]88[.]25[.]133
- Compromised account:
analyst
- Backdoor account created:
letsdefend1
Why
The attacker brute-forced SSH credentials, gaining access via the analyst account. They immediately conducted local recon (whoami, sudo -l) to assess privileges, then created a new local user and granted it full passwordless sudo access by editing /etc/sudoers. This establishes persistent root-equivalent access that survives password changes on the analyst account. The attack was interrupted prior to the backdoor account being used.
MITRE ATT&CK
| Technique ID | Tactic | Technique |
|---|
| T1110.001 | Credential Access | Brute Force: Password Guessing |
| T1078 | Defense Evasion / Persistence | Valid Accounts |
| T1059.004 | Execution | Command and Scripting Interpreter: Unix Shell |
| T1087.001 | Discovery | Account Discovery: Local Account |
| T1069.001 | Discovery | Permission Groups Discovery: Local Groups |
| T1136.001 | Persistence | Create Account: Local Account |
| T1548.003 | Privilege Escalation | Abuse Elevation Control Mechanism: Sudo and Sudo Caching |
IOCs
| Type | Value | Notes |
|---|
| IP Address | 149[.]88[.]25[.]133 | SSH brute force source |
| Username | letsdefend1 | Attacker-created backdoor account |
| File | /etc/sudoers | Modified to grant ALL:ALL to letsdefend1 |