logo

Scans for EncystPHP Webshell, (Mon, Apr 13th)

ID: 84b910c5-f4e3-5e69-b2f3-e89b6f9ff998

STIX ID: report--84b910c5-f4e3-5e69-b2f3-e89b6f9ff998

Feed Name: SANS ISC Diary

Threat Score
65/100

Date Published: 2026-04-13

Date Updated: 2026-04-19

...
...

Attackers are scanning FreePBX deployments for the EncystPHP webshell (requests using an `md5` parameter) and delivering a payload that installs the webshell and adds multiple backdoor Linux accounts. Probes were observed from 160.119.76.250 and the payload was fetched from 45.95.147.178; administrators should audit the listed accounts and investigate any matching indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.