Severity: High | Hostname: WS-Prod-02 | IP: 172.16.20.69 | Date: Sep 26, 2025
A brute-force RDP campaign against WS-Prod-02 originated from 212.8.243.56, a VPN exit node geolocated in the Netherlands and flagged malicious on AbuseIPDB. The attacker initially attempted to authenticate as admin, but ultimately achieved a successful logon as letsdefendsuc at Sep 26, 2025 01:00 PM.
Following the successful logon, the attacker downloaded and executed EDR-Freeze_1.0.exe (PID 1684) from the Downloads folder. EDR-Freeze is a publicly released proof-of-concept tool that abuses legitimate Windows components to put EDR or antivirus processes into an indefinite suspended (“coma”) state — without crashing or terminating them, and without requiring a vulnerable kernel driver (BYOVD).
WerFaultSecure.exe at WinTCB Protected Process Light (PPL) level, which grants it authority to interact with other PPL-protected processes such as EDR agents.WerFaultSecure.exe to call MiniDumpWriteDump against the target EDR/AV PID — a legitimate API used to capture memory dumps, which suspends all threads in the target as a side effect of ensuring dump consistency.WerFaultSecure.exe itself using NtSuspendProcess.WerFaultSecure.exe completes its dump, but WerFaultSecure.exe is now also suspended and can never finish. The EDR remains frozen indefinitely, with its process still visible but no active monitoring.The observed command line confirms this technique precisely:
WerFaultSecure.exe /h /pid 6080 /tid 6076 /encfile 236 /cancel 300 /type 268310
The combination of /encfile, /cancel, and /type 268310 alongside /pid and /h is the highest-fidelity indicator published for this technique — generic WerFaultSecure crash invocations don’t carry this parameter set together.
| Tactic | Technique | ID |
|---|---|---|
| Credential Access | Brute Force: Password Guessing | T1110.001 |
| Defense Evasion | Valid Accounts | T1078 |
| Defense Evasion | Impair Defenses (platform tag) | T1562.001 |
Analyst note: T1562.001 was selected as the closest available platform tag. EDR-Freeze does not actually disable or modify the EDR binary — it exploits a race condition in legitimate Windows dump tooling to force a suspension deadlock. As of this case date, MITRE has no sub-technique that precisely captures suspension-based “coma state” attacks; this is worth flagging in any future write-up as the technique becomes more prevalent.
| Type | Value |
|---|---|
| Malicious IP | 212.8.243[.]56 (NL, VPN exit node) |
| Compromised account | letsdefendsuc |
| Malicious file | C:\Users\LetsDefend\Downloads\EDR-Freeze_1.0.exe |
| SHA256 | 970c7834e58b6ef22473875167a333dbb33bf7b667d1cb814829f68579cd85f7 |
| EDR-Freeze process | PID 1684 |
| Targeted PID (via WerFaultSecure) | 6080 |
🔍 VirusTotal — SHA256 — confirmed malicious, identified as EDR-Freeze hacking tool
🔍 VirusTotal — IP — 212.8.243.56 reputation check
🌐 AbuseIPDB — IP — 212.8.243.56 flagged malicious, VPN exit node, Netherlands