216.73.216.6

Investigating A Web Shell Intrusion With Managed XDR

· Published 15/01/2025 08:53 · Modified 15/01/2025 14:18

Export JSON

Essential information

Published
15/01/2025 08:53
Modified
15/01/2025 14:18
Tags
2025-01-15 anydesk command and control data exfiltration iis worker powershell privilege-escalation reverse tcp shell web shell
Related entities
15 techniques (mitre)

Description

This analysis details a intrusion incident where attackers exploited an to exfiltrate data. The attacker uploaded a , created a new account for persistence, modified an existing user's password, and used encoded commands to establish a for command-and-control. The incident was detected by endpoint sensors, triggering an investigation. Multiple payloads were discovered in C:\Users\Public. The attacker performed discovery commands, archived the web server's working directory, and exfiltrated data via GET requests. Additional tools, including , were installed for remote access. The analysis includes technical details of the web shells and recommendations for preventing similar attacks.

External references