Posts

Showing posts with the label #firewalls

APT44’s ASPX web shell leverages obfuscation techniques and firewall rule manipulation to evade detection

Image
  Summary From the open and public intelligence, the Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009.   This report is for a new finding of an ASPX web shell in 2024.04. It was relatively rare with the Sandworm Team, which means a new tendency, including the other APT groups, to pay more attention to WEB security, from here opening an entry point and making a persistence technology with web shell as a backdoor.   Technical analysis The sample  md5: 7c33812c068c79190554b797dfd46629   The web shell is very simple but powerful, which can execute system command, create a new Windows Firewall rule, upload and download files, write text content to file, list files in table, read files and delete files and directories recursively. Figure1-the main functio...