Credential Access
High
- Category
- Privilege Escalation
- Content
|----------|----------|----------| | 🔴 **Reverse Shells** | socket.connect(), pty.spawn(), /dev/tcp | Critical | | 🔴 **Data Exfiltration** | requests.post() to suspicious TLDs | Critical | | 🔴 **Credential Harvest** | Reading ~/.ssh/id_rsa, AWS credentials | Critical | | 🔴 **Obfuscation** | base64.b64decode(exec), chr() chains | Critical | | 🔴 **ClawHavoc IOCs** | glot.io scripts, fake Apple URLs, known C2 IPs | Critical | | 🟠 **Code Execution** | exec(), eval(), subprocess | High |
- Confidence
- 90% confidence
- Finding
- Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
