Commonly Probed Webshell URLs, (Sun, Mar 9th)
ID: 4d1f3cb6-2f23-5cde-8275-ec613db8be3b
STIX ID: report--4d1f3cb6-2f23-5cde-8275-ec613db8be3b
Feed Name: SANS ISC Diary
Threat Score
This advisory warns that attackers commonly deploy web shells via file uploads or remote code execution, lists several observed webshell filenames/paths (for example: teorema505, upl.php, /download/powershell/, alive.php, and mentions '/struts/webconsole.html'), and urges administrators to inspect servers for unexpected files and avoid leaving unauthenticated development consoles accessible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
