Vulnerability Attack Case: Installation of a Web Shell and Execution of a Scanner by Exploiting a Telerik UI Vulnerability

Vulnerability Attack Case: Installation of a Web Shell and Execution of a Scanner by Exploiting a Telerik UI Vulnerability

The AhnLab SEcurity intelligence Center (ASEC) has identified two vulnerability attack cases that exploited a remote code execution vulnerability (CVE-2019-18935) targeting unpatched Telerik UI for ASP.NET AJAX servers. In the first incident, after exploiting the vulnerability, the attacker executed a reverse shell, attempted to perform privilege escalation, and installed a web shell; in the second incident, the attacker ran a scanner tool to search for additional Attack Targets.

 

1. Telerik UI for ASP.NET AJAX Remote Code Execution Vulnerability (CVE-2019-18935)

Telerik UI for ASP.NET AJAX is a UI component product used for developing Microsoft ASP.NET-based web applications. CVE-2019-18935 is a .NET deserialization vulnerability in RadAsyncUpload, a file upload feature; if exploited, a threat actor can perform remote code execution with the privileges of the w3wp.Exe process on an IIS web server.

In
2020, Red Canary disclosed a vulnerability attack case in which the Blue Mockingbird threat actor exploited the CVE-2019-18935 vulnerability to execute a malicious DLL on a Windows IIS server and conduct Monero cryptocurrency malware distribution. [1] Furthermore, in 2023, CISA, the FBI, and MS-ISAC disclosed a series of attack cases in which multiple threat actors uploaded malicious DLLs and performed remote code execution on IIS servers belonging to US federal agencies; it is reported that the CVE-2019-18935 vulnerability was also exploited in these attack cases. [2]

 

2. Korea Attack Cases – 1

In the first attack case, the attacker executed a reverse shell through the CVE-2019-18935 vulnerability and then queried the system name, privileges, and running processes. During this process, an attempt to perform privilege escalation using Potato-family tools was also detected, and ultimately, a Godzilla-style web shell was installed.

 

[Figure 1] Executing the hostname.Exe command via a reverse shell

 

2.1. Reverse Shell

The reverse shell payload executed during the vulnerability exploitation creates a Windows socket and attempts a TCP connection to port 80 on 206[.]82.6.22. If the connection is successful, it designates the socket as the standard input, output, and error handles, then launches the cmd.Exe process. This allows the threat actor to send commands remotely and receive the execution results through the cmd.Exe process.

 

C2

  • 206.82.6[.]22:80

 

[Figure 2] Reverse shellcode connecting to the C2 server and executing cmd.Exe

 

2.2. Privilege Escalation

Additionally, several modified Potato-family privilege escalation tools—including a version of SweetPotato modified for use in a web shell environment—were detected on the infected system. These tools use token spoofing techniques, such as PrintSpoofer, to gain SYSTEM privileges and then execute processes like cmd.Exe with elevated privileges.

 

[Figure 3] SweetPotato privilege escalation tool

 

2.3. Web Shell

The web shell is installed by injecting a memory-based web shell into a Telerik-based ASP.NET environment. Once the payload DLL is loaded, it searches for an execution environment where Telerik.Web.UI has been loaded in a separate thread and loads the embedded godmemshell.Dll into memory. It then registers a malicious request-handling function with ASP.NET’s VirtualPathProvider, enabling the web shell to run in the web server process’s memory without requiring a separate .Aspx file.

 

[Figure 4] Web Shell Installation Payload

 

The installed web shell is a Godzilla-style web shell that receives and executes .NET payloads through HTTP requests. It distinguishes processing methods based on the request’s Type header and decrypts the encrypted request data. On the initial request, it loads the received .NET payload into memory and stores it in its own cookie-based session; on subsequent requests, it calls the stored payload to perform the requested task. The execution results are re-encrypted and returned as an HTTP response, and the specific follow-up actions depend on the payload provided by the threat actor.

 

[Figure 5] Part of the web shell code

 

3. Korea Attack Cases – 2

In the second attack case, the attacker exploited CVE-2019-18935, which allows for remote code execution, through which they created and ran a scanner file on the target system. Unlike the first case, neither a reverse shell nor a web shell was used, and the vulnerability exploitation payload was found to contain only the command to execute the scanner.

 

[Figure 6] Payload file and scanner tool generated by the vulnerability attack

[Figure 7] Command to run the scanner

 

3.1. Scanner

The scanner is a Rust-based tool that receives a list of targets from a remote server and asynchronously scans for URLs leading to WordPress installation and configuration pages. If a server is identified as having WordPress installed, it sends the URL and public IP address to Telegram in an attachment named “red.Txt.”

 

The criteria for determining whether a server has WordPress installed are based on the 53 candidate paths typically used as web server paths, as shown in [Table 1]. If a path contains /wp-admin/setup-config.Php or /wp-admin/install.Php, the server is deemed to have WordPress installed and to be exposing its configuration page.

 

C2

  • Hxxp://65.98.5[.]158:31337/Ins.Txt (Receiving the list of targets to scan)
  • Hxxp://api.Telegram[.]Org/bot8930981923:AAGatbhK2_eiLMNtnWHkq33E6u7clhMPj5Q/sendMessage (Start scanning, Note)
  • Hxxp://api.Telegram[.]Org/bot8930981923:AAGatbhK2_eiLMNtnWHkq33E6u7clhMPj5Q/sendDocument (Sending scan results)

 

[Figure 8] Receiving the list of items to be scanned from the remote server

/, /Wordpress, /Wordpress, /WORDPRESS, /WordPress, /wp, /Wp, /WP, /old, /Old, /OLD, /oldsite, /new, /New, /NEW, /wp-old, /2022, /2025, /2026, /2023, /2024, /2017, /2020, /2019, /2018, /backup, /test, /Test, /TEST, /demo, /bc, /www, /WWW, /Www, /2021, /main, /old-site, /bk, /Backup, /BACKUP, /SHOP, /Shop, /shop, /bak, /sitio, /bac, /sito, /site, /Site, /SITE, /blog, /BLOG, /Blog

[Table 1] Candidate Paths

 

4. Conclusion

Even after the disclosure of the remote code execution vulnerability (CVE-2019-18935) in Telerik UI for ASP.NET AJAX, vulnerability attack cases targeting unpatched Windows IIS servers continue to be observed. Threat actors exploited the vulnerability to execute a reverse shell, collect system information, and install a Godzilla-based memory web shell; they also deployed various Potato-family privilege escalation tools, including SweetPotato. In another instance, a threat actor ran a Rust-based scanner to search for externally exposed WordPress configuration pages and transmitted the results via Telegram. Once a web shell is installed, the threat actor can remotely control the infected system to install additional malware, engage in Information Theft, and use the scanner to identify new Attack Targets.

 

5. Mitigation Measures

  • Upgrade Telerik UI for ASP.NET AJAX to a version that includes the Vulnerability Patch
    • Telerik UI version: 2020.1.114 Or later (use the latest version if possible)
  • Check for malware located at the following path
    • C:\Users\Public\Documents\
    • C:\Users\Public\
  • Check for abnormal processes running under w3wp.Exe
    • cmd.Exe, powershell.Exe, etc.
  • Restrict access to unnecessarily exposed WordPress installation and configuration pages
    • /wp-admin/setup-config.Php
    • /wp-admin/install.Php

MD5

0a4be0b6c650ffdcd1c22db56f1c4aec
10f705728d228ad949b7894c1a85a2b1
177e34d9174766a1d187a0c82de4c02f
18fb4e070653fc9791e0e408d8cb1c8e
1dbfda02d74b6a7586c4430175204c28
URL

http[:]//2[.]59[.]133[.]147[:]31338/ins[.]txt
http[:]//2[.]59[.]133[.]147[:]31338/sm[.]json
http[:]//206[.]82[.]6[.]22/
http[:]//45[.]138[.]16[.]187[:]31337/bb[.]json
http[:]//45[.]138[.]16[.]187[:]31337/cofuz[.]json

Gain access to related IOCs and detailed analysis by subscribing to AhnLab TIP. For subscription details, click the banner below.