Skip to content

Node.exe used by Adobe Creative Cloud Experience repetitively does Full Domain User enumeration #2213

@Warlord711

Description

@Warlord711
  • Node.js Version: 6.12.3
  • OS: Win 10
  • Scope (install, code, runtime, meta, other?): other
  • Module (and version) (if relevant):

While investing in an issue with a client system that does domain user enumeration every 30 seconds for like 30 Minutes after going online, I found that the node.exe is doing massive LDAP enumeration targeting both domain controllers and clients at is seems.

I checked the file integrity, it's unaltered, digitally signed and passed virustotal.com scan.
Why does the node.exe need to enumerate all domain users every 30 seconds ?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions