{"id":1561,"date":"2024-05-08T07:19:25","date_gmt":"2024-05-08T07:19:25","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1561"},"modified":"2024-05-26T10:03:46","modified_gmt":"2024-05-26T10:03:46","slug":"backdoor-php-webshell-indosec","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2024\/05\/08\/backdoor-php-webshell-indosec\/","title":{"rendered":"Backdoor.PHP.WebShell.Indosec"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type:<\/strong> WebShell<br \/>\n<strong>Destruction Level:<\/strong> High<br \/>\n<strong>Prevalence:<\/strong> Moderate<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Malware names<\/strong><\/h3>\n<ul>\n<li>Backdoor.PHP.WebShell.Indosec (Padvish)<\/li>\n<li>PHP \/ Webshell.NHE (ESET-NOD32)<\/li>\n<li>HEUR:Backdoor.PHP.WebShell.gen (Kaspersky)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3>What is WebShell?<\/h3>\n<p style=\"text-align: justify\">WebShell is a malicious script written in scripting languages such as ASP, Python, PHP, or JSP. When injected onto the victim&#8217;s web server, these webshells grant the attacker complete control over the website. These attacks typically exploit security vulnerabilities in vulnerable web servers.<br \/>\nAttackers easily discover and target servers accessible on the Internet. By injecting the web shell into the web server, organizations face serious and sometimes irreparable risks. Therefore, organizations must prioritize these warnings and implement robust security measures.<\/p>\n<p>&nbsp;<\/p>\n<h3 id=\"ipt_kb_toc_4075_3\">What is Backdoor.PHP.WebShell.Indosec?<\/h3>\n<p>This report discusses a sample from the Indosec family of web shells. Using this webshell, intruders can execute a range of malicious actions on the victim&#8217;s server.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>The capabilities of this malware:<\/strong><\/p>\n<ul>\n<li>Uploading files to specific paths<\/li>\n<li>Encrypting files and demanding ransom<\/li>\n<li>Defacing the victim&#8217;s website<\/li>\n<li>Creating files and folders, and modifying them<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2 id=\"ipt_kb_toc_4075_4\">Technical Review<\/h2>\n<h3>Performance Description<\/h3>\n<p>To access the Webshell admin panel, the attacker creates a login page with the username <em><span style=\"color: #993300\">admin<\/span><\/em>, as depicted in the image below the login page.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-4077 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-1-%D8%B5%D9%81%D8%AD%D9%87-login.png\" alt=\" \u0635\u0641\u062d\u0647 login\" width=\"531\" height=\"463\" \/><\/p>\n<p style=\"text-align: center\">Figure 1-\u00a0\u00a0<em>login Page<\/em><\/p>\n<p>Upon successful <span style=\"color: #993300\">login<\/span>, the following page is displayed. As illustrated, the <em><span style=\"color: #993300\">IndoSec<\/span> <span style=\"color: #993300\">Shell<\/span> <\/em>equips attackers with various capabilities.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-4078 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-2-%D9%86%D9%85%D8%A7%DB%8C%DB%8C-%D8%A7%D8%B2-%D8%B3%D8%B1%D8%A8%D8%B1%DA%AF-home.png\" alt=\"\u0646\u0645\u0627\u06cc\u06cc \u0627\u0632 \u0633\u0631\u0628\u0631\u06af home\" width=\"784\" height=\"784\" \/><\/p>\n<p style=\"text-align: center\">Figure 2 &#8211; A view of\u00a0\u00a0<em>home tab<\/em><\/p>\n<ul>\n<li style=\"text-align: justify\">Within the terminal section, as shown in the subsequent figures, this webshell can execute Windows and Linux commands based on the victim&#8217;s server&#8217;s operating system.<br \/>\nIn the following two figures, you can observe a command executed under the Windows terminal while the web shell operates in the Windows environment, and a command executed under the Linux terminal while the web shell operates in the Linux environment:<\/li>\n<\/ul>\n<p>\u25ab\ufe0fResult of executing <em><span style=\"color: #99cc00\">ipconfig<\/span>\u00a0<\/em>in a Windows environment:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4079 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-3-%D8%A7%D8%AC%D8%B1%D8%A7%DB%8C-%D8%AF%D8%B3%D8%AA%D9%88%D8%B1-%D9%88%DB%8C%D9%86%D8%AF%D9%88%D8%B2%DB%8C-%D8%AF%D8%B1-%D8%AA%D8%B1%D9%85%DB%8C%D9%86%D8%A7%D9%84.png\" alt=\"\u0627\u062c\u0631\u0627\u06cc \u062f\u0633\u062a\u0648\u0631 \u0648\u06cc\u0646\u062f\u0648\u0632\u06cc \u062f\u0631 \u062a\u0631\u0645\u06cc\u0646\u0627\u0644\" width=\"792\" height=\"297\" \/><\/p>\n<p style=\"text-align: center\">Figure 3 &#8211; Executing a Windows command in the terminal<\/p>\n<p>&nbsp;<\/p>\n<p>\u25ab\ufe0fResult of executing<span style=\"color: #99cc00\"><em> uname -a<\/em><\/span> command in a Linux environment:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4080 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-4-%D8%A7%D8%AC%D8%B1%D8%A7%DB%8C-%D8%AF%D8%B3%D8%AA%D9%88%D8%B1-%D9%84%DB%8C%D9%86%D9%88%DA%A9%D8%B3%DB%8C-%D8%AF%D8%B1-%D8%AA%D8%B1%D9%85%DB%8C%D9%86%D8%A7%D9%84.png\" alt=\"\u0627\u062c\u0631\u0627\u06cc \u062f\u0633\u062a\u0648\u0631 \u0644\u06cc\u0646\u0648\u06a9\u0633\u06cc \u062f\u0631 \u062a\u0631\u0645\u06cc\u0646\u0627\u0644\" width=\"1382\" height=\"116\" \/><\/p>\n<p style=\"text-align: center\">Figure 4: Executing a Linux command in the terminal<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>The <em>informasi<\/em> section displays details about the current system.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4081 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-5-%D8%A7%D8%B7%D9%84%D8%A7%D8%B9%D8%A7%D8%AA-%D9%85%D8%B1%D8%A8%D9%88%D8%B7-%D8%A8%D9%87-%D8%B3%DB%8C%D8%B3%D8%AA%D9%85.png\" alt=\"\u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 \u0633\u06cc\u0633\u062a\u0645\" width=\"303\" height=\"596\" \/><\/p>\n<p style=\"text-align: center\">Figure 5 &#8211; System Information<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li style=\"text-align: justify\">In the subsequent section, the outcomes of each action are displayed. For instance, in the initial login mode, details such as files in the current directory, access types, and actions on the files are displayed, or after running commands in the terminal, the outputs are shown in this field.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-4082 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-6-%D9%86%D9%85%D8%A7%DB%8C%D8%B4-%D8%AF%D8%A7%DB%8C%D8%B1%DA%A9%D8%AA%D9%88%D8%B1%DB%8C-%D8%AC%D8%A7%D8%B1%DB%8C.png\" alt=\"\u0646\u0645\u0627\u06cc\u0634 \u062f\u0627\u06cc\u0631\u06a9\u062a\u0648\u0631\u06cc \u062c\u0627\u0631\u06cc\" width=\"399\" height=\"495\" \/><\/p>\n<p style=\"text-align: center\">Figure 6 &#8211; Displaying the current directory<\/p>\n<p>&nbsp;<\/p>\n<p id=\"ipt_kb_toc_4075_6\"><strong>The various capabilities of the malware are outlined in the table below:<\/strong><\/p>\n<div class=\"table-responsive wprt_style_display\">\n<table class=\"table\" style=\"height: 968px\" border=\"1\">\n<tbody>\n<tr style=\"height: 48px\">\n<td style=\"height: 48px;width: 122px\"><strong>Feature Name<\/strong><\/td>\n<td style=\"height: 48px;width: 543px;text-align: center\"><strong> Feature Description<\/strong><\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"height: 24px;width: 122px;text-align: center\"><em>upload<\/em><\/td>\n<td style=\"height: 24px;width: 543px\">Enables file uploads to desired paths.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"height: 24px;width: 122px;text-align: center\"><em>Bautfile<\/em><\/td>\n<td style=\"height: 24px;width: 543px\">Enables creating new files and adding content to it.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"height: 24px;width: 122px;text-align: center\"><em>Bautfolder<\/em><\/td>\n<td style=\"height: 24px;width: 543px\">Enables creating new folders in desired paths.<\/td>\n<\/tr>\n<tr style=\"height: 120px\">\n<td style=\"height: 120px;width: 122px;text-align: center\"><em>Mass deface<\/em><\/td>\n<td style=\"height: 120px;width: 543px\">Enables the attacker to batch changes index files, resulting in defaced websites on the victim&#8217;s server. This section enables simultaneous content changes to multiple files, so that the target path and file name determined by the attacker. As a result, the content of all files with the specified name (by default index.php ) located in the corresponding path will be changed.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"height: 24px;width: 122px;text-align: center\"><em>Mass delete<\/em><\/td>\n<td style=\"height: 24px;width: 543px\">\u00a0Deletes multiple files simultaneously.<\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td style=\"height: 48px;width: 122px;text-align: center\"><em>jumping<\/em><\/td>\n<td style=\"height: 48px;width: 543px\">Checks for the existence of host management control panels in the system and displays files in associated paths.<\/td>\n<\/tr>\n<tr style=\"height: 200px\">\n<td style=\"height: 200px;width: 122px;text-align: center\"><em>config<\/em><\/td>\n<td style=\"height: 200px;width: 543px\">\n<p>Put path configuration files of various content management systems (CMS) into a file named &#8216;$user_con-$nama_config.txt,&#8217; providing critical information to the attacker including database name and password. Reviewed CMS platforms:<\/p>\n<p><em>Hostbills, Zencart, BoxBilling, WHMCS, Joomla, WordPress, IPB, OsCommerce, MyBB, Vbulletin, Ellislab, OpenCart, Magento, PrestaShop, Drupal, phpBB, Lokomedia, cPanel.<\/em><\/td>\n<\/tr>\n<tr style=\"height: 72px\">\n<td style=\"height: 72px;width: 122px;text-align: center\"><em>adminer<\/em><\/td>\n<td style=\"height: 72px;width: 543px\">Opens the database management page if an &#8216;adminer&#8217; file is present, allowing viewing and modification of databases using the username and password.<\/td>\n<\/tr>\n<tr style=\"height: 96px\">\n<td style=\"height: 96px;width: 122px;text-align: center\"><em>symlink<\/em><\/td>\n<td style=\"height: 96px;width: 543px\">In this part of the code, the contents of the file named.conf or named.txt name are displayed as a table consisting of Domains, Users, and symlink columns, and three different links are created, each of which is for a specific application that will be mentioned in Further Details.<\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td style=\"height: 48px;width: 122px;text-align: center\">Auto reset cPanel<\/td>\n<td style=\"height: 48px;width: 543px\">Resets the password for cPanel in the case that it is used in managing the targeted website.<\/td>\n<\/tr>\n<tr style=\"height: 120px\">\n<td style=\"height: 120px;width: 122px;text-align: center\"><em>ransomware<\/em><\/td>\n<td style=\"height: 120px;width: 543px\">This module encrypts files in desired directories, appending &#8216;.indsc&#8217; extension to file names and adding a payment-related &#8216;index.php&#8217; file next to the files. Encryption currently inactive due to the unavailability of the encryption address: http:\/\/encrypt.indsc.me\/api.php?type=encrypt.<\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td style=\"height: 48px;width: 122px;text-align: center\"><em>smtpgrabber<\/em><\/td>\n<td style=\"height: 48px;width: 543px\">Displays SMTP information such as SMTP Host, Port, User, Pass, Auth, Secure.<\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td style=\"height: 48px;width: 122px;text-align: center\"><em>Bypass cloud flare<\/em><\/td>\n<td style=\"height: 48px;width: 543px\">If the website is equipped with cdn cloudflare, different parts of this could be bypassed and the actual IP of each of the webmail, ftp, cpanel and other servers can be obtained.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"height: 24px;width: 122px;text-align: center\"><em>keluar<\/em><\/td>\n<td style=\"height: 24px;width: 543px\">Exit the program and returns to the login page.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h4><\/h4>\n<h4 id=\"ipt_kb_toc_4075_7\">Further Details<\/h4>\n<p><em><strong>?\u00a0Mass deface<\/strong><\/em><\/p>\n<p style=\"text-align: justify\">Upon selection of this option, the replacement content intended for the original file will be written in the respective directory files. Subsequently, the contents of all files with the specified name in the <span style=\"color: #993300\"><em>NamaFile<\/em><\/span> section within the directory will be altered.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-4083 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-7-%D9%85%D8%AD%D8%AA%D9%88%D8%A7%DB%8C-%D8%B5%D9%81%D8%AD%D9%87-Mass-deface.png\" alt=\"\u0645\u062d\u062a\u0648\u0627\u06cc \u0635\u0641\u062d\u0647 Mass deface\" width=\"688\" height=\"699\" \/><\/p>\n<p style=\"text-align: center\">Figure 7 &#8211; Contents of Mass Deface page<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-4084 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-8-%D9%84%DB%8C%D8%B3%D8%AA-%D9%81%D8%A7%DB%8C%D9%84%E2%80%8C%D9%87%D8%A7%DB%8C-%D8%AA%D8%BA%DB%8C%DB%8C%D8%B1-%D8%AF%D8%A7%D8%AF%D9%87-%D8%B4%D8%AF%D9%87-%D8%A8%D9%87-%D9%88%D8%B3%DB%8C%D9%84%D9%87-Mass-deface.png\" alt=\"\u0644\u06cc\u0633\u062a \u0641\u0627\u06cc\u0644\u200c\u0647\u0627\u06cc \u062a\u063a\u06cc\u06cc\u0631 \u062f\u0627\u062f\u0647 \u0634\u062f\u0647 \u0628\u0647 \u0648\u0633\u06cc\u0644\u0647 Mass deface\" width=\"695\" height=\"418\" \/><\/p>\n<p style=\"text-align: center\">Figure 8 &#8211; List of files changed by Mass deface<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4085 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-9-%D8%B5%D9%81%D8%AD%D9%87-deface-%D8%B4%D8%AF%D9%87.png\" alt=\"\u0635\u0641\u062d\u0647 deface \u0634\u062f\u0647\" width=\"703\" height=\"167\" \/><\/p>\n<p style=\"text-align: center\">Figure 9 \u2013 The defaced page<\/p>\n<p>&nbsp;<\/p>\n<p><em><strong>?\u00a0Jumping<\/strong><\/em><\/p>\n<p style=\"text-align: justify\">In the Jumping section, the presence of host management control panels in the system is checked, and the associated path files are displayed. This section operates as follows:<br \/>\n\u2022 If an H-sphere control panel exists on the system, a jump link will be established for the following path based on system user numbers and existing URLs:<\/p>\n<p><span style=\"color: #993300\">hsphere\/local\/home\/$user\/$url<\/span><\/p>\n<p>\u2022 If H-sphere is not present on the system, it will navigate to the vhosts directory and create a jump link for different URLs for the following path:<\/p>\n<p><span style=\"color: #993300\">\/var\/www\/vhosts\/$url\/httpdocs<\/span><\/p>\n<p>\u2022 Lastly, a jump link is created for each user for <span style=\"color: #993300\">home\/$user_pro_jump\/public_html\/<\/span>. The executed sample displayed below, highlighted in green, has read-only access type.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4086 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-10-%D8%AE%D8%B1%D9%88%D8%AC%DB%8C-jumping.png\" alt=\"\u062e\u0631\u0648\u062c\u06cc jumping\" width=\"806\" height=\"264\" \/><\/p>\n<p style=\"text-align: center\">Figure 10 &#8211; Jump Output<\/p>\n<p>&nbsp;<\/p>\n<p>?\u00a0<strong><em>Adminer<\/em><\/strong><\/p>\n<p style=\"text-align: justify\">Adminer is a database management tool. The malware checks for its presence on the system and, if present, it displays the database login page. In this section, the attacker gains easy access to the database if login credentials are obtained:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4087 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-11-%D9%86%D9%85%D8%A7%DB%8C%D8%B4-%D8%B5%D9%81%D8%AD%D9%87-adminer.png\" alt=\"\u0646\u0645\u0627\u06cc\u0634 \u0635\u0641\u062d\u0647 adminer\" width=\"590\" height=\"323\" \/><\/p>\n<p style=\"text-align: center\">Figure 11 \u2013 Displaying the Adminer Page<\/p>\n<p>&nbsp;<\/p>\n<p>?\u00a0<strong>Symlink<\/strong><\/p>\n<p>Symlinks are files that act as pointers to other files, containing no content of their own but pointing to the original files. Deleting the original file renders the symlink unusable.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-4088 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/1111%D9%85%D8%A7%DA%98%D9%88%D9%84-Symlink-%D8%A7%DB%8C%D9%86-%D8%A8%D8%AF%D8%A7%D9%81%D8%B2%D8%A7%D8%B1-%D8%B4%D8%A7%D9%85%D9%84-%D9%85%D9%88%D8%A7%D8%B1%D8%AF-%D8%B2%DB%8C%D8%B1-%D8%A7%D8%B3%D8%AA.png\" alt=\"\u0645\u0627\u0698\u0648\u0644 Symlink \u0627\u06cc\u0646 \u0628\u062f\u0627\u0641\u0632\u0627\u0631 \u0634\u0627\u0645\u0644 \u0645\u0648\u0627\u0631\u062f \u0641\u0648\u0642 \u0627\u0633\u062a:\" width=\"864\" height=\"490\" \/><\/p>\n<p style=\"text-align: center\">Figure 12: Malware Symlink Module<\/p>\n<h4 id=\"ipt_kb_toc_4075_8\"><\/h4>\n<h4 id=\"ipt_kb_toc_4075_9\">According to the above figure the Symlink module of this malware includes:<\/h4>\n<p style=\"text-align: justify\">1\ufe0f\u20e3<em><strong>\u00a0Bypass Read<\/strong><\/em>: Selecting this option displays <em>named.conf<\/em> file contents with read access in the output. Pressing save key, saves this content in <em>named.txt<\/em> in the path to execute the original file.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4089 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/Bypass-Read.png\" alt=\" Bypass Read\" width=\"866\" height=\"472\" \/><\/p>\n<p style=\"text-align: center\">Figure 13: Bypass Read in the Symlink module<\/p>\n<p style=\"text-align: justify\">2\ufe0f\u20e3\u00a0<em><strong>Symlink404<\/strong><\/em>:\u00a0 A symlink file can be created from the target file in the <em>indosec_sym404<\/em> directory with the desired name. To Test the path one of the <em>WordPress<\/em> files entered as the <em>Target<\/em> file and<em>\u00a0txt.12<\/em> as the symlink file name and is displayed upon clicking on the link <em>&gt;&gt;Sukses&lt;&lt;.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4090 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-12-%D8%A8%D8%AE%D8%B4-Symlink404.png\" alt=\"\u0628\u062e\u0634 Symlink404\" width=\"707\" height=\"465\" \/><\/p>\n<p style=\"text-align: center\">Figure 14- Symlink404 Section<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4091 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-13-%D8%A7%D9%85%DA%A9%D8%A7%D9%86-%D9%86%D9%85%D8%A7%DB%8C%D8%B4-%D9%85%D8%AD%D8%AA%D9%88%D8%A7%DB%8C-%D9%81%D8%A7%DB%8C%D9%84-Target.png\" alt=\"\u0627\u0645\u06a9\u0627\u0646 \u0646\u0645\u0627\u06cc\u0634 \u0645\u062d\u062a\u0648\u0627\u06cc \u0641\u0627\u06cc\u0644 Target\" width=\"642\" height=\"553\" \/><\/p>\n<p style=\"text-align: center\">Figure 15 &#8211; Ability to display the contents of the <em>Target<\/em> file<\/p>\n<p>&nbsp;<\/p>\n<p>3\ufe0f\u20e3<em><strong>\u00a0Symlink Bypass<\/strong><\/em>: This displays <em>etc\/passwd<\/em> file contents, containing system account information. Choosing <em>Symlink<\/em> saves its content as <em>passwd.txt<\/em> in the current path.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-4092 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/Symlink-Bypass.png\" alt=\"Symlink Bypass\" width=\"803\" height=\"447\" \/><\/p>\n<p style=\"text-align: center\">Figure 16 &#8211; Symlink Bypass<\/p>\n<p>&nbsp;<\/p>\n<p><strong>?\u00a0Ransomware<\/strong>:<\/p>\n<p>This refers to the ability to execute ransomware. for this section, as depicted in the red box 1 below, the target file is read from the chosen path, encoded with the <em>base64<\/em> algorithm, and sent to the attacker&#8217;s server. The returned packet includes an encrypted file, decoded and placed in $_ENC variable.<\/p>\n<p>Following this step, the <span style=\"color: #993300\"><em>INDSC<\/em><\/span>. extension is added to the file name, and a <em>SUCCESS<\/em> message appears in the output. However, actual encryption and extension changes were not performed during malware analysis due to server unavailability.<\/p>\n<p>In box 2, the operation related to displaying the <em>PAYMENT<\/em> page is preformed, and an <em>INDEX.HTML<\/em> file is created as <em>PAYMENT<\/em>, with the content displayed below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-4115 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-14-%D9%85%D8%AD%D8%AA%D9%88%D8%A7%DB%8CHTML-%D9%85%D8%B1%D8%A8%D9%88%D8%B7-%D8%B5%D9%81%D8%AD%D9%87-payment-1.png\" alt=\"\u0645\u062d\u062a\u0648\u0627\u06ccHTML \u0645\u0631\u0628\u0648\u0637 \u0635\u0641\u062d\u0647 payment\" width=\"1131\" height=\"751\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4094 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-144-%D9%85%D8%AD%D8%AA%D9%88%D8%A7%DB%8CHTML-%D9%85%D8%B1%D8%A8%D9%88%D8%B7-%D8%B5%D9%81%D8%AD%D9%87-payment.png\" alt=\"\u0645\u062d\u062a\u0648\u0627\u06ccHTML \u0645\u0631\u0628\u0648\u0637 \u0635\u0641\u062d\u0647 payment \" width=\"715\" height=\"484\" \/><\/p>\n<p style=\"text-align: center\">Figure 17: The <em>HTML<\/em> content of the <em>payment<\/em> page<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4095 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/%D8%AA%D8%B5%D9%88%DB%8C%D8%B1-15-%D8%B5%D9%81%D8%AD%D9%87-payment.png\" alt=\"\u0635\u0641\u062d\u0647 payment \" width=\"550\" height=\"734\" \/><\/p>\n<p style=\"text-align: center\">Figure 18 &#8211; The <em>payment<\/em> page<\/p>\n<p>&nbsp;<\/p>\n<h2>How to deal with and clean the system?<\/h2>\n<p>Padvish Antivirus detects this malware. To avoid infection by such malware, it is recommended to:<\/p>\n<p>\u2705 Fully and securely configure your web server.<\/p>\n<p>\u2705 Block unused ports and services.<\/p>\n<p>\u2705 Use complex passwords and change them regularly.<\/p>\n<p>\u2705 Consistently apply security updates.<\/p>\n<p>\u2705 Considering the escalating cyber threats, for network and system security against advanced persistent threats and cyber-attacks, alongside adhering to<span style=\"color: #3366ff\"> <a style=\"color: #3366ff\" href=\"https:\/\/kb.amnpardaz.com\/en\/2022\/584\/padvish-security-recommendation-against-ransomware-and-other-cyber-threats\/\">security recommendations<\/a><\/span>, use <span style=\"color: #ff00ff\">Padvish Managed Detection and Response (Padvish MDR)<\/span>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: WebShell Destruction Level: High Prevalence: Moderate &nbsp; Malware names Backdoor.PHP.WebShell.Indosec (Padvish) PHP \/ Webshell.NHE (ESET-NOD32) HEUR:Backdoor.PHP.WebShell.gen (Kaspersky) &nbsp; What is WebShell? WebShell is a malicious script written in scripting languages such as ASP, Python, PHP, or JSP. When injected onto the victim&#8217;s web server, these webshells grant the attacker complete control over the&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[47,73],"tags":[74,75],"class_list":["post-1561","post","type-post","status-publish","format-standard","hentry","category-malware","category-webshell","tag-backdoor-php-webshell-indosec","tag-webshell"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1561","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1561"}],"version-history":[{"count":7,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1561\/revisions"}],"predecessor-version":[{"id":1576,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1561\/revisions\/1576"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1561"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1561"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1561"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}