logo

The SOC files: Chasing the web shell

ID: ade5b2c6-5017-5e61-ae08-76c91d632647

STIX ID: report--ade5b2c6-5017-5e61-ae08-76c91d632647

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2025-02-28

Date Updated: 2026-04-29

Author: Domenico Caldarella

...
...

This SOC case study describes detection and analysis of a Behinder (Rebeyond/冰蝎) ASPX web shell compromising a government SharePoint server; attackers used certutil with Bashupload to drop payloads, loaded .NET modules in-memory to maintain encrypted C2 and operator control, and achieved SYSTEM via Potato family privilege-escalation tools. The report provides static/memory analysis artifacts, a YARA rule, file/hash IOCs, and practical detection guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.