logo

A Little Bit Pivoting: What Web Shells are Attackers Looking for?, (Tue, Apr 7th)

ID: 20cbe043-b22f-54f8-a850-4961310e4897

STIX ID: report--20cbe043-b22f-54f8-a850-4961310e4897

Feed Name: SANS ISC Diary

Threat Score
50/100

Date Published: 2026-04-07

Date Updated: 2026-04-19

...
...

This SANS-style note documents scanning activity for webshells (notably /turkshell.php) from four IPs apparently assigned to Microsoft, lists the top probed URLs and a long catalog of 287 filename indicators commonly used as webshells or for fingerprinting (many WordPress-related), and recommends mitigations such as removing RCE/file upload vulnerabilities, restricting document-root write permissions, and monitoring filesystem changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.