πNew WriteupβοΈ
βββββββββββββββ
πDate: Wed, 18 Oct 2023 14:27:50 GMT
βββββββββββββββ
βοΈTitle: [HTB] Devel
βββββββββββββββ
πLink: https://medium.com/p/4a205fd1aa25
βββββββββββββββ
Tags: #hackthebox #iis #ftp
βββββββββββββββ
πDate: Wed, 18 Oct 2023 14:27:50 GMT
βββββββββββββββ
βοΈTitle: [HTB] Devel
βββββββββββββββ
πLink: https://medium.com/p/4a205fd1aa25
βββββββββββββββ
Tags: #hackthebox #iis #ftp
Medium
[HTB] Devel
This is a write-up of Devel on Hack The Box without metasploitβββit is for my own learning as well as creating a knowledge bank.
β€· Title: CL-STA-0048: Chinese-Linked APT Targets Telecoms in South Asia
ββββββββββββββββββββββββ
πͺ Author: do son
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 04 Feb 2025 02:35:43 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Malware #apache Tomcat #Chinese APT Groups #CL_STA_0048 #Cobalt Strike #Hex Staging #IIS servers #MSSQL server #SoftEther VPN #SQLcmd #Winos4.0 Downloader
ββββββββββββββββββββββββ
πͺ Author: do son
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 04 Feb 2025 02:35:43 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Malware #apache Tomcat #Chinese APT Groups #CL_STA_0048 #Cobalt Strike #Hex Staging #IIS servers #MSSQL server #SoftEther VPN #SQLcmd #Winos4.0 Downloader
Cybersecurity News
CL-STA-0048: Chinese-Linked APT Targets Telecoms in South Asia
Uncover the details of a newly identified cyberespionage campaign, CL-STA-0048, targeting high-value organizations in South Asia.
β€· Title: shortscan: An IIS short filename enumeration tool
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 09 Feb 2025 00:51:40 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Assessment #IIS short filename enumeration #shortscan
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 09 Feb 2025 00:51:40 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Assessment #IIS short filename enumeration #shortscan
Penetration Testing Tools
shortscan: An IIS short filename enumeration tool
Shortscan is designed to quickly determine which files with short filenames exist on an IIS webserver.
β€· Title: KB5055523 Update Creates Unnecessary inetpub Folder in Windows 11 24H2
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 10 Apr 2025 10:31:19 +0000
ββββββββββββββββββββββββ
β Tags: #Windows #Bug #IIS #inetpub #KB5055523 #Microsoft #update #Windows 11 24H2 #Windows Update
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 10 Apr 2025 10:31:19 +0000
ββββββββββββββββββββββββ
β Tags: #Windows #Bug #IIS #inetpub #KB5055523 #Microsoft #update #Windows 11 24H2 #Windows Update
Daily CyberSecurity
KB5055523 Update Creates Unnecessary inetpub Folder in Windows 11 24H2
The KB5055523 update in Windows 11 24H2 is causing an unexpected inetpub folder to appear. This is not malware and can be safely deleted.
β€· Title: Sophisticated IIS Malware Targets South Korean Web Servers
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 09 May 2025 00:20:49 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #ASEC #china #cyberattack #Gh0st RAT #HijackDriverManager #IIS #malware #south korea #web server #Web Shell #Winkbj.sys
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 09 May 2025 00:20:49 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #ASEC #china #cyberattack #Gh0st RAT #HijackDriverManager #IIS #malware #south korea #web server #Web Shell #Winkbj.sys
Daily CyberSecurity
Sophisticated IIS Malware Targets South Korean Web Servers
A sophisticated campaign deployed malicious IIS modules on South Korean web servers, enabling traffic control and backdoor access. Suspected Chinese actor.
β€· Title: Gold Melody Unleashed: New Stealthy Attacks Exploit Leaked ASP.NET Keys
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 11 Jul 2025 03:15:24 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #ASP.NET #cyberattack #cybersecurity #Gold Melody #IIS #machine keys #memory_only attack #Prophet Spider #UNC961 #ViewState
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 11 Jul 2025 03:15:24 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #ASP.NET #cyberattack #cybersecurity #Gold Melody #IIS #machine keys #memory_only attack #Prophet Spider #UNC961 #ViewState
Penetration Testing Tools
Gold Melody Unleashed: New Stealthy Attacks Exploit Leaked ASP.NET Keys
Gold Melody (Prophet Spider) is exploiting leaked ASP.NET machine keys to launch stealthy, memory-only attacks on global corporate systems.
β€· Title: FortiGuard Labs Uncovers Highly Obfuscated Web Shell βUpdateChecker.aspxβ Targeting Middle East Critical Infrastructure
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 29 Jul 2025 00:19:37 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #C++ #Critical Infrastructure #cybersecurity #FortiGuard Labs #IIS #malware #Middle East #Obfuscation #UpdateChecker.aspx #Web Shell
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 29 Jul 2025 00:19:37 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #C++ #Critical Infrastructure #cybersecurity #FortiGuard Labs #IIS #malware #Middle East #Obfuscation #UpdateChecker.aspx #Web Shell
Penetration Testing Tools
FortiGuard Labs Uncovers Highly Obfuscated Web Shell "UpdateChecker.aspx" Targeting Middle East Critical Infrastructure
FortiGuard Labs exposes UpdateChecker.aspx, a heavily obfuscated web shell targeting Middle East critical infrastructure, capable of stealthy system control via encoded C# and JSON.
β€· Title: PoC Published for Remote Code Execution Flaw in Microsoft IIS Web Deploy
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 03 Sep 2025 04:15:55 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #cybersecurity #Deserialization #IIS Web Deploy #Microsoft #rce #Remote Code Execution
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 03 Sep 2025 04:15:55 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #cybersecurity #Deserialization #IIS Web Deploy #Microsoft #rce #Remote Code Execution
Daily CyberSecurity
PoC Published for Remote Code Execution Flaw in Microsoft IIS Web Deploy
A critical RCE flaw (CVE-2025-53772) in IIS Web Deploy allows an authenticated attacker to execute arbitrary code. A PoC is public, and patching is urgent.
β€· Title: Phantom Taurus: New Chinese APT Emerges with Fileless NET-STAR Backdoor Targeting Global Governments and Telecoms
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 01 Oct 2025 02:32:34 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Chinese APT #Espionage #Fileless Malware #IIS Backdoor #NET_STAR #Phantom Taurus #Telecommunications #Unit 42
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 01 Oct 2025 02:32:34 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Chinese APT #Espionage #Fileless Malware #IIS Backdoor #NET_STAR #Phantom Taurus #Telecommunications #Unit 42
Daily CyberSecurity
Phantom Taurus: New Chinese APT Emerges with Fileless NET-STAR Backdoor Targeting Global Governments and Telecoms
Unit 42 uncovers Phantom Taurus, a new Chinese APT using the fileless NET-STAR backdoor to target SQL databases and IIS servers in global espionage campaigns.
β€· Title: Phantom Taurus: New Chinese APT Emerges with Fileless NET-STAR Backdoor Targeting Global Governments and Telecoms
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 02 Oct 2025 03:24:32 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Chinese APT #Espionage #Fileless Malware #IIS Backdoor #NET_STAR #Phantom Taurus #Telecommunications #Unit 42
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 02 Oct 2025 03:24:32 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Chinese APT #Espionage #Fileless Malware #IIS Backdoor #NET_STAR #Phantom Taurus #Telecommunications #Unit 42
Penetration Testing Tools
Phantom Taurus: New Chinese APT Emerges with Fileless NET-STAR Backdoor Targeting Global Governments and Telecoms
Unit 42 uncovers Phantom Taurus, a new Chinese APT using the fileless NET-STAR backdoor to target SQL databases and IIS servers in global espionage campaigns.
β€· Title: UAT-8099: Chinese Group Uses BadIIS Malware on Compromised Servers for SEO Fraud and Credential Theft
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 03 Oct 2025 01:42:17 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #BadIIS #Cisco Talos #Cobalt Strike #Credential Theft #Cybercrime #IIS #SEO Fraud #UAT_8099
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 03 Oct 2025 01:42:17 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #BadIIS #Cisco Talos #Cobalt Strike #Credential Theft #Cybercrime #IIS #SEO Fraud #UAT_8099
Daily CyberSecurity
UAT-8099: Chinese Group Uses BadIIS Malware on Compromised Servers for SEO Fraud and Credential Theft
Cisco Talos exposed UAT-8099, a Chinese group compromising IIS servers for SEO fraud, using BadIIS malware and Cobalt Strike to steal credentials and manipulate search rankings.
β€· Title: Cisco Talos Exposes UAT-8099: Chinese Group Uses BadIIS Malware on Compromised Servers for SEO Fraud and Credential Theft
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 06 Oct 2025 02:02:52 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #BadIIS #Cisco Talos #Cobalt Strike #Credential Theft #cybercrime #IIS #SEO Fraud #UAT_8099
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 06 Oct 2025 02:02:52 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #BadIIS #Cisco Talos #Cobalt Strike #Credential Theft #cybercrime #IIS #SEO Fraud #UAT_8099
Penetration Testing Tools
Cisco Talos Exposes UAT-8099: Chinese Group Uses BadIIS Malware on Compromised Servers for SEO Fraud and Credential Theft
Cisco Talos exposed UAT-8099, a Chinese group compromising IIS servers for SEO fraud, using BadIIS malware and Cobalt Strike to steal credentials and manipulate search rankings.
β€· Title: Chinese Hackers Exploit Exposed ASP.NET Keys to Deploy TOLLBOOTH IIS Backdoor and Kernel Rootkit
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 23 Oct 2025 00:26:42 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #ASP.NET Machine Key #China APT #IIS Backdoor #Kernel Rootkit #SEO Cloaking #TOLLBOOTH #Web Shell
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 23 Oct 2025 00:26:42 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #ASP.NET Machine Key #China APT #IIS Backdoor #Kernel Rootkit #SEO Cloaking #TOLLBOOTH #Web Shell
Daily CyberSecurity
Chinese Hackers Exploit Exposed ASP.NET Keys to Deploy TOLLBOOTH IIS Backdoor and Kernel Rootkit
Elastic exposed Chinese threat actors exploiting public ASP.NET machine keys to deploy TOLLBOOTH IIS backdoor and HIDDENDRIVER kernel rootkit. The malware performs stealthy SEO cloaking.