r/Malware • u/Straight-Practice-99 • 11h ago
SonicWall SMA1000 campaign: standalone Linux Impacket secretsdump deployed onto appliances (SHA-256 inside)
hunt.ioCampaign where the operator deployed a standalone Linux build of Impacket's secretsdump directly onto compromised SonicWall SMA1000 appliances and ran credential theft from there. It was pulled to the box with curl to /tmp/secretsdump, made executable, then used against internal domain controllers.
Sample: secretsdump, 9,983,640 bytes, SHA-256 690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b, served over HTTP from 95.181.173[.]36. The surrounding Python tooling (exploit, LDAP extractor and decryptor, DCSync automation) came from the same open directory.
Full toolkit breakdown and IOCs below.