A New Shellshock Worm on the Loose
ID: e1cd8dc5-4836-55c9-89e0-dd634b9d969f
STIX ID: report--e1cd8dc5-4836-55c9-89e0-dd634b9d969f
Feed Name: Volexity Blog
Volexity observed a widespread Shellshock exploitation campaign (starting 2015-04-08) using malicious User-Agent payloads to execute commands on vulnerable CGI endpoints, download a tarball (http://109.228.25.87/.ips-80/cc.tar) containing 32-/64-bit scanning binaries (cgiscan32/cgiscan64) and scripts (start, r, print) that propagate scanning and report vulnerable hosts back to .c.php?request=. The report includes file hashes, filenames, the scanning workflow, sample HTTP requests, lists of targeted CGI paths, IDS rule examples, and recommends monitoring/blocking outbound traffic to 109.228.25.87.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
