MAR-10443863-1.v1 CVE-2017-9248 Exploitation in U.S. Government IIS Server
Summary Description CISA received three files for analysis. The files included three webshells written in PHP: Hypertext Preprocessor (PHP), Active Server Pages Extended (ASPX), and .NET Dynamic-Link Library (DLL). The sample “sd.php” is highly obfuscated and uses rot13 algorithm, zlib for compression and base64 encoding for obfuscation. The “osker.aspx” webshell code was padded with […]
MAR-10443863-1.v1 CVE-2017-9248 Exploitation in U.S. Government IIS Server Read More »