logo

Exploitation of Public-Facing Web Application Leading to Web Shell Deployment

ID: b2b511ae-3d42-42ac-810b-8acd69f3ee75

STIX ID: report--b2b511ae-3d42-42ac-810b-8acd69f3ee75

Threat Score

70/100

Uploaded: 2026-04-13

Created by: Report Uploader

TLP:GREEN
...
...
On 9 April 2026 attackers exploited a vulnerable file upload on a public customer portal to install a JSP web shell (/uploads/support/logo_help.jsp). The adversary executed system commands via HTTP POST, created a database export archive (/tmp/client_backup_20260409.tar.gz), and initiated outbound connections to 198.51.100.24:8080 (user agent curl/8.5.0), indicating collection and likely exfiltration of data.