AhnLab SEcurity intelligence Center (ASEC) reported two attack cases abusing CVE-2019-18935 against unpatched Telerik UI for ASP.NET AJAX servers, where one intruder used a reverse shell, privilege escalation, and a Godzilla-style web shell. Another attacker used the same flaw to launch a Rust-based scanner that searched for exposed WordPress pages and sent results through Telegram. #CVE-2019-18935 #TelerikUI #Godzilla #SweetPotato #Telegram
Keypoints
- ASEC identified two real-world attack cases exploiting CVE-2019-18935 on unpatched Telerik UI for ASP.NET AJAX servers.
- In the first case, the attacker used the vulnerability to obtain a reverse shell, query system details, and attempt privilege escalation.
- Privilege escalation activity involved Potato-family tools, including a modified SweetPotato variant.
- A Godzilla-style memory web shell was installed to maintain access and execute .NET payloads through HTTP requests.
- In the second case, the attacker executed a scanner tool instead of a shell, focusing on discovering external attack targets.
- The scanner was a Rust-based tool that looked for WordPress installation/configuration pages and exfiltrated results to Telegram.
- The article warns that unpatched IIS servers remain exposed and recommends updating Telerik UI and checking for suspicious processes and malware paths.
MITRE Techniques
- [T1190 ] Exploit Public-Facing Application – The attacker abused the Telerik UI vulnerability to gain initial access to the IIS server. [‘exploited a remote code execution vulnerability (CVE-2019-18935) targeting unpatched Telerik UI for ASP.NET AJAX servers’]
- [T1059.003 ] Command and Scripting Interpreter: Windows Command Shell – The attacker launched cmd.exe through the reverse shell to run commands remotely. [‘then launches the cmd.Exe process’]
- [T1055 ] Process Injection – A memory-based web shell was injected into the ASP.NET environment to run inside the web server process. [‘injecting a memory-based web shell into a Telerik-based ASP.NET environment’]
- [T1548.001 ] Abuse Elevation Control Mechanism: Setuid and Setgid / Token Manipulation – Potato-family tools used token spoofing to obtain SYSTEM privileges. [‘These tools use token spoofing techniques, such as PrintSpoofer, to gain SYSTEM privileges’]
- [T1105 ] Ingress Tool Transfer – Malicious payloads and tools such as the scanner and web shell components were delivered to the victim system. [‘created and ran a scanner file on the target system’]
- [T1041 ] Exfiltration Over C2 Channel – The scanner sent discovered WordPress URLs and public IP addresses to Telegram. [‘it sends the URL and public IP address to Telegram’]
- [T1018 ] Remote System Discovery – The attacker queried system name, privileges, and running processes after gaining access. [‘queried the system name, privileges, and running processes’]
Indicators of Compromise
- [IP addresses] C2 and scan infrastructure – 206.82.6.22, 65.98.5.158, and other IPs including 2.59.133.147 and 45.138.16.187
- [URLs] payload and telemetry endpoints – http://206.82.6.22/, http://65.98.5.158:31337/Ins.Txt, and other URLs such as http://api.Telegram.Org/bot8930981923:AAGatbhK2_eiLMNtnWHkq33E6u7clhMPj5Q/sendMessage
- [File hashes] related samples – 0a4be0b6c650ffdcd1c22db56f1c4aec, 10f705728d228ad949b7894c1a85a2b1, and 3 more hashes
- [File names] malicious or referenced files – red.Txt, Ins.Txt, sm.json, and cofuz.json
- [Process names] suspicious execution on IIS servers – cmd.exe, powershell.exe, and w3wp.exe
- [File paths] malware staging locations and WordPress targets – C:UsersPublicDocuments, C:UsersPublic, /wp-admin/setup-config.php, and /wp-admin/install.php
Read more: https://asec.ahnlab.com/en/95561/