Attackers Exploit Telerik CVE-2019-18935 to Install Web Shells and Scan for Exposed WordPress Pages

Summary
AhnLab details two attacks exploiting CVE-2019-18935 on unpatched Telerik servers: one installed a memory-based web shell after running a reverse shell, while another deployed a scanner for exposed WordPress configuration pages.
Key points
- AhnLab identified two attack cases targeting unpatched Telerik UI for ASP.NET AJAX servers vulnerable to CVE-2019-18935, a .NET deserialization flaw enabling remote code execution on IIS.
- In one case, attackers used a reverse shell to run commands and gather system information, attempted privilege escalation with modified Potato-family tools, and installed a Godzilla-style memory web shell.
- The web shell processes encrypted HTTP requests and can load .NET payloads into memory for follow-up actions.
- In the second case, attackers used the vulnerability to run a Rust-based scanner that searched for exposed WordPress setup and installation pages and sent results to Telegram.
- AhnLab recommends upgrading Telerik UI for ASP.NET AJAX to version 2020.1.114 or later, checking for malware and abnormal processes under w3wp.exe, and restricting access to exposed WordPress configuration pages.
Article Details
- Attack Vectors
- Attackers exploited CVE-2019-18935 in unpatched Telerik UI for ASP.NET AJAX servers to execute code through RadAsyncUpload deserialization.
- In the first Korea case, the attacker established a reverse shell, queried system information, attempted privilege escalation with Potato-family tools, and installed a memory-resident Godzilla-style web shell.
- In the second Korea case, the attacker ran a Rust-based scanner that retrieved a target list, checked for exposed WordPress installation and configuration pages, and sent findings through Telegram.
- Defensive Notes
- Upgrade Telerik UI for ASP.NET AJAX to version 2020.1.114 or later, preferably the latest version.
- Check C:\Users\Public\Documents\ and C:\Users\Public\ for malware.
- Investigate abnormal processes, including cmd.Exe or powershell.Exe, running under w3wp.Exe.
- Restrict unnecessary access to /wp-admin/setup-config.Php and /wp-admin/install.Php.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 206[.]82[.]6[.]22 | C2 address listed for the first case's reverse shell on port 80. |
| MD5 | 0a4be0b6c650ffdcd1c22db56f1c4aec | Malicious-file hash listed in the article's IOC section. |
| MD5 | 10f705728d228ad949b7894c1a85a2b1 | Malicious-file hash listed in the article's IOC section. |
| MD5 | 177e34d9174766a1d187a0c82de4c02f | Malicious-file hash listed in the article's IOC section. |
| MD5 | 18fb4e070653fc9791e0e408d8cb1c8e | Malicious-file hash listed in the article's IOC section. |
| MD5 | 1dbfda02d74b6a7586c4430175204c28 | Malicious-file hash listed in the article's IOC section. |
| URL | hxxp[:]//2[.]59[.]133[.]147:31338/ins[.]txt | Threat-related URL listed in the article's IOC section; its specific role is not disclosed. |
| URL | hxxp[:]//2[.]59[.]133[.]147:31338/sm[.]json | Threat-related URL listed in the article's IOC section; its specific role is not disclosed. |
| URL | hxxp[:]//206[.]82[.]6[.]22/ | Threat-related URL listed in the article's IOC section on the reverse-shell C2 host. |
| URL | hxxp[:]//45[.]138[.]16[.]187:31337/bb[.]json | Threat-related URL listed in the article's IOC section; its specific role is not disclosed. |
| URL | hxxp[:]//45[.]138[.]16[.]187:31337/cofuz[.]json | Threat-related URL listed in the article's IOC section; its specific role is not disclosed. |
| URL | hxxp[:]//65[.]98[.]5[.]158:31337/Ins[.]Txt | Remote resource from which the scanner retrieved its target list. |
| URL | hxxp[:]//api[.]telegram[.]org/bot8930981923:AAGatbhK2_eiLMNtnWHkq33E6u7clhMPj5Q/sendDocument | Specific Telegram bot endpoint used to send scanner results. |
| URL | hxxp[:]//api[.]telegram[.]org/bot8930981923:AAGatbhK2_eiLMNtnWHkq33E6u7clhMPj5Q/sendMessage | Specific Telegram bot endpoint used by the scanner to report scanning activity. |
MITRE ATT&CK
T1057 · Process DiscoveryAfter establishing the reverse shell, the attacker queried running processes.T1059.003 · Windows Command ShellThe reverse shell launched cmd.Exe with its input, output, and error handles connected to an attacker-accessible socket.T1071.001 · Web ProtocolsThe installed web shell received .NET payloads through HTTP requests and returned execution results in HTTP responses.T1082 · System Information DiscoveryAfter establishing the reverse shell, the attacker queried the system name.T1134 · Access Token ManipulationDetected Potato-family tools used token spoofing techniques in an attempt to obtain SYSTEM privileges.T1190 · Exploit Public-Facing ApplicationAttackers exploited CVE-2019-18935 in unpatched Telerik UI for ASP.NET AJAX servers to execute code.T1505.003 · Web ShellThe attacker installed a Godzilla-style web shell that handled HTTP requests in the ASP.NET server process without a separate .Aspx file.T1567 · Exfiltration Over Web ServiceThe scanner sent discovered URLs and public IP addresses to Telegram in an attachment named red.Txt.T1595 · Active ScanningThe scanner checked remote targets for exposed WordPress installation and configuration pages to identify further attack targets.
CVE
Threat Actors
Malware
Vendors
Products
IISa threat actor can perform remote code execution with the privileges of the w3wp.Exe process on an IIS web server.Telerik UI for ASP.NET AJAXThe AhnLab SEcurity intelligence Center (ASEC) has identified two vulnerability attack cases that exploited a remote code execution vulnerability (CVE-2019-18935) targeting unpatched Telerik UI for ASP.NET AJAX servers.WordPressThe scanner is a Rust-based tool that receives a list of targets from a remote server and asynchronously scans for URLs leading to WordPress installation and configuration pages.
Tools
PrintSpooferThese tools use token spoofing techniques, such as PrintSpoofer, to gain SYSTEM privileges and then execute processes like cmd.Exe with elevated privileges.SweetPotatoAdditionally, several modified Potato-family privilege escalation tools—including a version of SweetPotato modified for use in a web shell environment—were detected on the infected system.