Abuse of hidden “well-known” directory in HTTPS sites
ID: 0014eeb4-4bd0-5e81-9285-c8d3651920f6
STIX ID: report--0014eeb4-4bd0-5e81-9285-c8d3651920f6
Feed Name: Zscaler Security Research Blog
ThreatLabZ detected hundreds of compromised WordPress and Joomla sites that attackers are abusing the .well-known ACME/pki-validation directories to host and persist malicious content: obfuscated HTML/JavaScript redirectors and ZIPs lead to a packed Shade/Troldesh ransomware binary (delivered via JS and ZIP attachments) that drops a Tor client, registers persistence, and encrypts files using AES-256 and RSA; the report includes infection-chain analysis, artifacts (registry keys, filenames, ransom notes), telemetry on phishing vs. ransomware distribution, and an extensive list of IOCs for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
