The SOC files: Chasing the web shell
ID: ade5b2c6-5017-5e61-ae08-76c91d632647
STIX ID: report--ade5b2c6-5017-5e61-ae08-76c91d632647
Feed Name: Securelist by Kaspersky
Threat Score
This SOC case study describes detection and analysis of a Behinder (Rebeyond/冰蝎) ASPX web shell compromising a government SharePoint server; attackers used certutil with Bashupload to drop payloads, loaded .NET modules in-memory to maintain encrypted C2 and operator control, and achieved SYSTEM via Potato family privilege-escalation tools. The report provides static/memory analysis artifacts, a YARA rule, file/hash IOCs, and practical detection guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
