Shellshock Attacks Spotted In Wild [Updated Sept 26]
ID: a429fb50-cb1c-54df-a38d-de7fdac219aa
STIX ID: report--a429fb50-cb1c-54df-a38d-de7fdac219aa
Feed Name: Zscaler Security Research Blog
Threat Score
Zscaler ThreatLabZ reports active exploitation of the GNU Bash 'Shellshock' vulnerability (CVE-2014-6271) where attackers target Apache and Nginx servers (via mod_cgi) to download ELF backdoor binaries (named e.g. "apache" or "nginx") that contain hardcoded C2 information (e.g. 162.253.66.76:53) and provide DDoS, brute-force and backdoor capabilities; the advisory includes sample malicious headers, detection checks and patching guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
