
GroundWorm: The hunt for SandWorm | Hack The Box workshops
Source: YouTube · Hack The Box · published Jun 27, 2025 · 40:20
The video demonstrates a Sandworm attack simulation called "Worm" designed for defenders to gain insights into cyber threats and defensive strategies 0:02-0:16.
Key Takeaways:
• The attacker exploited the SMTP service (Exim mail transfer agent) running on port 25 using CVE-2019-10149 for initial access 2:54-4:42
• The attacker sent exactly 32 lines of data to successfully exploit the vulnerability 5:36-6:40
• Persistence was established through a "syslogsd.service" file that activates after reboot and a cron job for reverse shell 8:02-9:56
• The attacker moved laterally using the Impacket toolkit, targeting "desktop-batman" first through Windows Management Instrumentation 15:21-26:42
• The attacker captured the administrator's password "P@ssw0rd1" using keylogging and encrypted files with a 16-byte hex key "deadbeefdeadbeefdeadbeefdeadbeef" 29:02-38:44
The simulation provides valuable defensive insights by showing how monitoring specific Windows APIs can help defenders detect and mitigate such attacks 39:01-39:48.
Sources:
- 0:02-0:16 Introduction to the Sandworm attack simulation
- 2:54-4:42 SMTP service exploitation details
- 5:36-6:40 Data lines sent for exploitation
- 8:02-9:56 Persistence mechanisms
- 15:21-26:42 Lateral movement analysis
- 29:02-38:44 Credential theft
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hey guys, my name is Karthik Durk and uh today in this demo I'll be walking you through one of my very own shelllock called worm which is an attack simulation of samberm ad uh designed for defenders to uh get some defensive insights. Uh before we begin uh sorry a little bit about myself uh I'm currently working as a defensive content engineer at hack the box. I've been working here since two plus years and uh I've been in this cyber security industry since 8 plus years from different fields starting as a blue teamer and going to going and becoming a red teamer. Um and some of the sherlocks that I created for hack the box are like superstar neural Noel uh the ransomware that is in opt 5 uh horse band sapotier bubbles frocknet and uh so on. Um so the scenario for this Sherlock is imaginary a…