Analysis of a Hijacked Site (Part II)
ID: cc8c0061-2998-5fb0-b84c-306875d08431
STIX ID: report--cc8c0061-2998-5fb0-b84c-306875d08431
Feed Name: Zscaler Security Research Blog
This report details a widespread spam campaign that deployed obfuscated PHP pages (e.g., page.php/news.php) to host fake "Hot Video" pages and thousands of spam pages under a *.cch/* directory, while also leaving dangerous webshells (.sys.php requiring a specific key and uncensored g------.php variants) on hundreds of mostly e-commerce sites; these backdoors permit remote code execution, command execution, and arbitrary file uploads, increasing risk of data theft and further malware distribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
