
Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)
172.16.17.207)svohost.exeC:\temp\service_installer\svohost.exesvchost.exe.C:\Windows\System32\, whereas this binary executed from a user temp path.b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9Trojan/Win64.MalwareX, tagged with cve-2024-49138 privilege escalation exploit.172.16.17.207.185.107.56.1.Victor (172.16.17.207) to block network traversal.| Artifact Type | Value | Description |
|---|
| File Hash (SHA-256) | b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9 | Malicious Exploit Executable |
| C2 IP Address | 185.107.56.1 | Command & Control IP |
| Victim IP | 172.16.17.207 | Compromised Windows 10 Host |
| File Path | C:\temp\service_installer\svohost.exe | Executable Location |