Vulnerability Attack Case: Installation of a Web Shell and Execution of a Scanner by Exploiting a Telerik UI Vulnerability

Vulnerability Attack Case: Installation of a Web Shell and Execution of a Scanner by Exploiting a Telerik UI Vulnerability
AhnLab SEcurity intelligence Center (ASEC) reported two attack cases abusing CVE-2019-18935 against unpatched Telerik UI for ASP.NET AJAX servers, where one intruder used a reverse shell, privilege escalation, and a Godzilla-style web shell. Another attacker used the same flaw to launch a Rust-based scanner that searched for exposed WordPress pages and sent results through Telegram. #CVE-2019-18935 #TelerikUI #Godzilla #SweetPotato #Telegram

Keypoints

  • ASEC identified two real-world attack cases exploiting CVE-2019-18935 on unpatched Telerik UI for ASP.NET AJAX servers.
  • In the first case, the attacker used the vulnerability to obtain a reverse shell, query system details, and attempt privilege escalation.
  • Privilege escalation activity involved Potato-family tools, including a modified SweetPotato variant.
  • A Godzilla-style memory web shell was installed to maintain access and execute .NET payloads through HTTP requests.
  • In the second case, the attacker executed a scanner tool instead of a shell, focusing on discovering external attack targets.
  • The scanner was a Rust-based tool that looked for WordPress installation/configuration pages and exfiltrated results to Telegram.
  • The article warns that unpatched IIS servers remain exposed and recommends updating Telerik UI and checking for suspicious processes and malware paths.

MITRE Techniques

  • [T1190 ] Exploit Public-Facing Application – The attacker abused the Telerik UI vulnerability to gain initial access to the IIS server. [‘exploited a remote code execution vulnerability (CVE-2019-18935) targeting unpatched Telerik UI for ASP.NET AJAX servers’]
  • [T1059.003 ] Command and Scripting Interpreter: Windows Command Shell – The attacker launched cmd.exe through the reverse shell to run commands remotely. [‘then launches the cmd.Exe process’]
  • [T1055 ] Process Injection – A memory-based web shell was injected into the ASP.NET environment to run inside the web server process. [‘injecting a memory-based web shell into a Telerik-based ASP.NET environment’]
  • [T1548.001 ] Abuse Elevation Control Mechanism: Setuid and Setgid / Token Manipulation – Potato-family tools used token spoofing to obtain SYSTEM privileges. [‘These tools use token spoofing techniques, such as PrintSpoofer, to gain SYSTEM privileges’]
  • [T1105 ] Ingress Tool Transfer – Malicious payloads and tools such as the scanner and web shell components were delivered to the victim system. [‘created and ran a scanner file on the target system’]
  • [T1041 ] Exfiltration Over C2 Channel – The scanner sent discovered WordPress URLs and public IP addresses to Telegram. [‘it sends the URL and public IP address to Telegram’]
  • [T1018 ] Remote System Discovery – The attacker queried system name, privileges, and running processes after gaining access. [‘queried the system name, privileges, and running processes’]

Indicators of Compromise

  • [IP addresses] C2 and scan infrastructure – 206.82.6.22, 65.98.5.158, and other IPs including 2.59.133.147 and 45.138.16.187
  • [URLs] payload and telemetry endpoints – http://206.82.6.22/, http://65.98.5.158:31337/Ins.Txt, and other URLs such as http://api.Telegram.Org/bot8930981923:AAGatbhK2_eiLMNtnWHkq33E6u7clhMPj5Q/sendMessage
  • [File hashes] related samples – 0a4be0b6c650ffdcd1c22db56f1c4aec, 10f705728d228ad949b7894c1a85a2b1, and 3 more hashes
  • [File names] malicious or referenced files – red.Txt, Ins.Txt, sm.json, and cofuz.json
  • [Process names] suspicious execution on IIS servers – cmd.exe, powershell.exe, and w3wp.exe
  • [File paths] malware staging locations and WordPress targets – C:UsersPublicDocuments, C:UsersPublic, /wp-admin/setup-config.php, and /wp-admin/install.php


Read more: https://asec.ahnlab.com/en/95561/