Skip to content

Opening book details…

About this document

Cyber Actors Access Web Shell on US Network by Brandon A. Moses is a document available to read on EtoBox.

(U//FOUO) Unidentified cyber actors accessed a web shell on a US municipal government web portal between January 5-11, 2021 using a Bangladesh IP address. They scanned the server for vulnerabilities and removed and created files. The document provides indicators of compromise, including the IP address and web shell file names, to help detect and mitigate this activity. It recommends layered prevention and detection techniques as outlined in a 2015 CISA alert to defend against web shells.

Author
Brandon A. Moses
Language
EN