Explore tweets tagged as #WebShells
@wtf_brut
Brut ๐Ÿ‡ฎ๐Ÿ‡ณ
2 months
๐ŸšจMulti-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells across large target sets. โœ… โœ… Join Telegram For More Content:
Tweet media one
0
10
61
@Shadowserver
The Shadowserver Foundation
1 month
We are sharing Fortinet FortiWeb instances compromised with webshells likely via CVE-2025-25257. We see 77 cases on 2025-07-15, down from 85 on 2025-07-14. CVE-2025-25257 exploitation activity observed since Jul 11th. Tree map overview (compromised):
Tweet media one
2
11
21
@TweetThreatNews
Cybersecurity News Everyday
20 minutes
A misconfigured public PHP upload page on a Linux server allowed upload of obfuscated web shells and mailer scripts. Missing EDR, unpatched CVEs, and poor logging hindered detection. #WebShells #UploadSecurity #Varonis.
0
0
0
@sicehice
sicehice
8 months
#opendir hosting #CobaltStrike #webshells and #shellcode loader. 152.32.170.129 ๐Ÿ‡ญ๐Ÿ‡ฐ. 121.exe and 12.exe (both CobaltStrike) connect to 152.42.226.16 ๐Ÿ‡ธ๐Ÿ‡ฌ for C2. Interesting payload hosted in Sqlite database (also CobaltStrike)
Tweet media one
Tweet media two
Tweet media three
1
12
72
@inversecos
inversecos
6 months
NEW LAB: Mustang Panda ๐Ÿผ๐Ÿ”. Chinese cyber espionage APT targeting a government body across the U.S, Europe, and APAC. Test your blue team skills on.๐Ÿ‘€ .NET malware.๐Ÿ‘€ DLL Sideloading.๐Ÿ‘€ Webshells .๐Ÿ‘€ Procdumps. Lab Contributors.Adversarial Emulation: @MDSecLabs @offensiveninja
Tweet media one
Tweet media two
6
83
434
@cyb3rops
Florian Roth โšก๏ธ
2 years
Dear DFIR colleagues,.Always be wary of 404 error codes in web server log files. Some webshells intentionally send this error code to deceive you into thinking the request failed.
Tweet media one
Tweet media two
16
236
710
@Shadowserver
The Shadowserver Foundation
30 days
SharePoint situational update: In collaboration with @ValidinLLC & @certbund we improved vhost & version detection of SharePoint instances, resulting in ~17K IPs observed exposed. 840 with CVE-2025-53770 - version based detection only. At least 20 with webshells.
Tweet media one
Tweet media two
1
12
26
@GroupIB_TI
Group-IB Threat Intelligence
3 days
The group's arsenal includes public exploits (CVE-2024-27956), tools like #Cobalt Strike and Metasploit, and Chinese-specific utilities like #Godzilla/Behinder webshells. A key discovery was a custom PowerShell script that archives & exfiltrates specific document types from
Tweet media one
1
1
8
@joevest
Joe Vest
1 year
The Fallout show reminds me of how nerdy I can be. In 2016, I gave a talk on WebShells. The slides were themed as a RobCo terminal, and I'm wearing a hacker Valult Boy shirt.
Tweet media one
1
1
15
@M_haggis
The Haagโ„ข
2 years
I went and extracted keywords from all the known knowns of webshells ๐Ÿš. I then popped them into an array ๐Ÿ“‹ and added a special twist ๐ŸŒ€ to our output in #ShellSweep ๐Ÿ–ฅ. Note ๐Ÿ“: Some of the false positives (FPs) in the Mixed Mode shot there. 'Mixed' is using a lower value for
Tweet media one
Tweet media two
Tweet media three
Tweet media four
1
8
35
@malmoeb
Stephan Berger
1 year
In a recent investigation, a customer contacted us because an AV scanner detected webshells in a web root accessible from the Internet. While investigating the incident, we found out that the jQuery-File-Upload widget is reachable from the Internet as well, without
Tweet media one
3
19
72
@_SaudSubaie
ุณุนูˆุฏ ุฃุจูˆุดูŠุจู‡
1 year
Webshell ุจุดูƒู„ ู…ูˆุฌุฒ ู…ุน ุฎุทูˆุงุช ุชูˆุถุญ ู„ูƒ ูƒูŠู ูŠุชู… ุงูƒุชุดุงูู‡ ูƒู…ุญู„ู„ ุงู…ู† ุณูŠุจุฑุงู†ูŠ . ู‡ูˆ ุนุจุงุฑุฉ ุนู† ุจุฑู†ุงู…ุฌ ู†ุตูŠ ุฃูˆ ุจุฑู†ุงู…ุฌ ุถุงุฑ ูŠุชู… ุชุญู…ูŠู„ู‡ ุฅู„ู‰ ุฎุงุฏู… ูˆูŠุจ Web Server ู…ุฎุชุฑู‚ุŒ .ู…ู…ุง ูŠุณู…ุญ ู„ู„ู…ู‡ุงุฌู… ุจุงู„ูˆุตูˆู„ ุบูŠุฑ ุงู„ู…ุตุฑุญ ุจู‡ ูˆุงู„ุชุญูƒู… ููŠ ุงู„ุฎุงุฏู…. ุบุงู„ุจู‹ุง ู…ุง ูŠุณุชุฎุฏู… ุงู„ู…ู‡ุงุฌู…ูˆู† Webshells ู„ุชู†ููŠุฐ ุฃูˆุงู…ุฑ ุนุดูˆุงุฆูŠุฉ ูˆู…ุนุงู„ุฌุฉ
Tweet media one
1
29
182
@abdul__alamri
Abdulrahman Alamri
5 months
ุชุฌู†ูŠุฏ ู„ู„ู‡ุงูƒุฑุฒ ุนู„ู‰ ุงู„ุนู„ู† ๐Ÿ˜. ุชู… ุงู„ุชูˆุงุตู„ ู…ุนูŠ ู…ู† ู‚ุจู„ ุดุฎุต ูŠุญุงูˆู„ ุชุฌู†ูŠุฏ ุฃูุฑุงุฏ ููŠ ู…ุฌุงู„ #ุงู„ุฃู…ู†_ุงู„ุณูŠุจุฑุงู†ูŠ ู„ุงุฎุชุฑุงู‚ ู…ูˆุงู‚ุน ุฅู„ูƒุชุฑูˆู†ูŠุฉ ู…ุณุฌู‘ู„ุฉ ููŠ ุงู„ุตูŠู†ุŒ ู…ู‚ุงุจู„ ุฑุงุชุจ ุดู‡ุฑูŠ ู‚ุฏ ูŠุตู„ ุฅู„ู‰ 100,000 ุฏูˆู„ุงุฑ. ุทู„ุจ ู…ู†ูŠ ุฅุซุจุงุช ุงู„ู‚ุฏุฑุฉ ุนุจุฑ ุฒุฑุน 3 webshells ุญู‚ูŠู‚ูŠุฉ ููŠ ู†ุทุงู‚ุงุช ุตูŠู†ูŠุฉุŒ ู‚ุจู„ ู…ู†ุงู‚ุดุฉ ุชูุงุตูŠู„ โ€œุงู„ุชุนุงูˆู† ุทูˆูŠู„
Tweet media one
Tweet media two
Tweet media three
3
15
34
@KudelskiSec
Kudelski Security
2 months
Hackers are hitting ASP . Net apps, exploiting exposed MachineKeys for RCE and stealthy webshells like Godzilla. Theyโ€™re pivoting fast to tools like Cobalt Strike and chasing privilege escalation. Scan, patch, stay ahead. #CyberSecurity #KudelskiSecurity
Tweet media one
0
2
3
@M_haggis
The Haagโ„ข
4 months
๐Ÿšจ SAP NetWeaver Webshells Spotted: CVE-2025-31324 in the Wild ๐Ÿšจ. Multiple reports confirmed active exploitation of SAP NetWeaver Visual Composer vulnerabilities (CVE-2025-31324). Attackers are dropping lightweight JSP webshells like the ones shared by Onapsis, captured by
Tweet media one
Tweet media two
Tweet media three
0
7
17
@bearstech
bearstech
1 year
Chasse ร  la menace sur Linux, utiliser Sysmon et auditd et dรฉtecter des webshells. ->
Tweet media one
1
43
85
@Shadowserver
The Shadowserver Foundation
2 years
We continue to report out daily lists of Citrix ADC/Gateway IPs that are known to be compromised with webshells installed (CVE-2023-3519 attacks). We now see 1486 instances on 2023-08-17. Big thank you to @DIVDnl & @foxit for the collaboration. Data in
Tweet media one
1
21
41
@CISACyber
CISA Cyber
1 month
Update: See newly added info to our #ToolShell Alert. Weโ€™ve included info on ransomware deployment, new webshells involved in exploitation, & detection guidance ๐Ÿ‘‰
Tweet media one
3
38
75
@mbuckbee
Michael Buckbee
2 years
Something I find terrifying that few other devs seem to are requests hitting sites like "/gecko.php". It's easy to think "I don't have that file on my site" or "I'm not running PHP so I don't need to care.". But webshells like Gecko are designed to be snuck into your
Tweet media one
Tweet media two
1
4
14