Threat Actors Hacking NGINX Servers to Redirect Web Traffic to Malicious Servers
ID: e87af944-5d61-5dfd-b880-4c81d27e65f9
STIX ID: report--e87af944-5d61-5dfd-b880-4c81d27e65f9
Feed Name: cybersecurityNews.com
A sophisticated campaign is actively compromising NGINX servers (frequently those managed with the Baota/BT panel) by injecting malicious location blocks that use proxy_pass and crafted headers to redirect legitimate web traffic to attacker-controlled domains. The report enumerates the attack scripts (zx.sh, bt.sh, 4zdh.sh, zdh.sh, ok.sh), known malicious domains (for example xzz.pier46.com, ide.hashbank8.com, th.cogicpt.org), an associated IP (158.94.210.227), and recommends administrators search NGINX configs for unexpected proxy_pass directives pointing to these indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
