Attackers Exploit Telerik CVE-2019-18935 to Install Web Shells and Scan for Exposed WordPress Pages

· Original article ↗

Summary

AhnLab details two attacks exploiting CVE-2019-18935 on unpatched Telerik servers: one installed a memory-based web shell after running a reverse shell, while another deployed a scanner for exposed WordPress configuration pages.

Key points

  • AhnLab identified two attack cases targeting unpatched Telerik UI for ASP.NET AJAX servers vulnerable to CVE-2019-18935, a .NET deserialization flaw enabling remote code execution on IIS.
  • In one case, attackers used a reverse shell to run commands and gather system information, attempted privilege escalation with modified Potato-family tools, and installed a Godzilla-style memory web shell.
  • The web shell processes encrypted HTTP requests and can load .NET payloads into memory for follow-up actions.
  • In the second case, attackers used the vulnerability to run a Rust-based scanner that searched for exposed WordPress setup and installation pages and sent results to Telegram.
  • AhnLab recommends upgrading Telerik UI for ASP.NET AJAX to version 2020.1.114 or later, checking for malware and abnormal processes under w3wp.exe, and restricting access to exposed WordPress configuration pages.

Article Details

Attack Vectors
  • Attackers exploited CVE-2019-18935 in unpatched Telerik UI for ASP.NET AJAX servers to execute code through RadAsyncUpload deserialization.
  • In the first Korea case, the attacker established a reverse shell, queried system information, attempted privilege escalation with Potato-family tools, and installed a memory-resident Godzilla-style web shell.
  • In the second Korea case, the attacker ran a Rust-based scanner that retrieved a target list, checked for exposed WordPress installation and configuration pages, and sent findings through Telegram.
Defensive Notes
  • Upgrade Telerik UI for ASP.NET AJAX to version 2020.1.114 or later, preferably the latest version.
  • Check C:\Users\Public\Documents\ and C:\Users\Public\ for malware.
  • Investigate abnormal processes, including cmd.Exe or powershell.Exe, running under w3wp.Exe.
  • Restrict unnecessary access to /wp-admin/setup-config.Php and /wp-admin/install.Php.

Indicators of compromise

TypeIndicatorContext
IPV4206[.]82[.]6[.]22C2 address listed for the first case's reverse shell on port 80.
MD50a4be0b6c650ffdcd1c22db56f1c4aecMalicious-file hash listed in the article's IOC section.
MD510f705728d228ad949b7894c1a85a2b1Malicious-file hash listed in the article's IOC section.
MD5177e34d9174766a1d187a0c82de4c02fMalicious-file hash listed in the article's IOC section.
MD518fb4e070653fc9791e0e408d8cb1c8eMalicious-file hash listed in the article's IOC section.
MD51dbfda02d74b6a7586c4430175204c28Malicious-file hash listed in the article's IOC section.
URLhxxp[:]//2[.]59[.]133[.]147:31338/ins[.]txtThreat-related URL listed in the article's IOC section; its specific role is not disclosed.
URLhxxp[:]//2[.]59[.]133[.]147:31338/sm[.]jsonThreat-related URL listed in the article's IOC section; its specific role is not disclosed.
URLhxxp[:]//206[.]82[.]6[.]22/Threat-related URL listed in the article's IOC section on the reverse-shell C2 host.
URLhxxp[:]//45[.]138[.]16[.]187:31337/bb[.]jsonThreat-related URL listed in the article's IOC section; its specific role is not disclosed.
URLhxxp[:]//45[.]138[.]16[.]187:31337/cofuz[.]jsonThreat-related URL listed in the article's IOC section; its specific role is not disclosed.
URLhxxp[:]//65[.]98[.]5[.]158:31337/Ins[.]TxtRemote resource from which the scanner retrieved its target list.
URLhxxp[:]//api[.]telegram[.]org/bot8930981923:AAGatbhK2_eiLMNtnWHkq33E6u7clhMPj5Q/sendDocumentSpecific Telegram bot endpoint used to send scanner results.
URLhxxp[:]//api[.]telegram[.]org/bot8930981923:AAGatbhK2_eiLMNtnWHkq33E6u7clhMPj5Q/sendMessageSpecific Telegram bot endpoint used by the scanner to report scanning activity.

MITRE ATT&CK

CVE

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles