<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CVE-2024-6473 on bubka hacks stuff</title><link>https://hexpysya.github.io/tags/cve-2024-6473/</link><description>Recent content in CVE-2024-6473 on bubka hacks stuff</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Thu, 05 Feb 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://hexpysya.github.io/tags/cve-2024-6473/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB-EasyMoney</title><link>https://hexpysya.github.io/investigations/htb-easymoney/</link><pubDate>Thu, 05 Feb 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/htb-easymoney/</guid><description>Administrator executed a malicious shortcut that triggered a hidden PowerShell command, downloading and executing payload and gaining a shell access. The attacker enumerated installed software, identified a vulnerable Yandex Browser (CVE-2024-6473), and exploited DLL hijacking by planting a malicious library that acts as a dropper. This dropper deployed a Sliver C2 implant establishing persistence via a scheduled task and maintaining communication</description></item></channel></rss>