logo

Command Injection Exploit For PHPUnit before 4.8.28 and 5.x before 5.6.3 [Guest Diary], (Tue, Dec 17th)

ID: f05d8fda-c836-58a3-a7bf-2ee13c15d029

STIX ID: report--f05d8fda-c836-58a3-a7bf-2ee13c15d029

Feed Name: SANS ISC Diary

Threat Score
75/100

Date Published: 2024-12-19

Date Updated: 2026-04-19

...
...

**Executive Summary:** This report details active exploitation of PHPUnit CVE-2017-9841 and related activity by the Androxgh0st Python-based malware family: attackers scan and POST payloads to eval-stdin.php and exposed /.env files to achieve RCE, harvest AWS and other credentials, deploy web shells/backdoors, and build botnets; the report includes observed IOCs (malicious IP 83.222.191.62, targeted endpoints), impact analysis, and practical detection/prevention recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.