TF-MAL-jsp.godzilla_webshell
📛 Threat Title
Malware family: Godzilla Webshell
Description
ThreatFox malware family `jsp.godzilla_webshell`. Printable name: Godzilla Webshell.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
MalwareBazaar Database This page shows some basic information the YARA rule Godzilla_Webshells_303 including corresponding malware samples. Database Entry
-
web:kerberpoasting.medium.com
This article will investigate and elaborate on the timeline of events leading up to the deployment of the stealthy Godzilla in-memory webshell , as well as provide detailed steps on how to conduct memory analysis of the IIS worker processes (w3wp.exe) to reveal the inner workings of Godzilla and extract additional artifacts which may assist in ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Godzilla Webshell malware family including references, samples and yara signatures.
-
web:thehackernews.com
Cybersecurity researchers are warning of a "notable increase" in threat actor activity actively exploiting a now-patched flaw in Apache ActiveMQ to deliver the Godzilla web shell on compromised hosts. "The web shells are concealed within an unknown binary format and are designed to evade security and signature-based scanners," Trustwave said.
-
web:www.aha.org
This article concludes with defense and mitigation recommendations, which we implore all healthcare organizations to review and action in accordance with their risk mitigation plan. What is Godzilla ? Godzilla webshell is a Chinese-language backdoor created by an individual who goes by the online handle BeichenDream.
-
web:www.broadcom.com
A new Godzilla webshell deployment campaign has been reported in the wild. The attackers are targeting organizations running ASP.NET instances with vulnerable environment settings and leverage ViewState function to distribute malicious webshells into the victim's environment.
-
web:www.darkreading.com
Godzilla Web Shell Attacks Stomp on Critical Apache ActiveMQ Flaw Thousands of vulnerable servers may be open to cyberattacks exploiting the max-severity CVE-2023-46604 bug.
-
web:www.hhs.gov
Prevention, Detection, and Mitigation Due to the high functionality and continuous development of Godzilla , it is not practical to attempt to compile a list of defense and mitigation steps to be implemented over any long period of time. However, we do recommend a report from CISA detailing a campaign leveraging Godzilla , as well as generic webshell defensive resources from the National ...
-
web:www.hipaajournal.com
The Health Sector Cybersecurity Coordination Center (HC3) has issued an Analyst Note to raise awareness of a stealthy backdoor - the Godzilla web shell - The Health Sector Cybersecurity Coordination Center has issued an alert about the stealthy Godzilla webshell , which is being used by Chinese state-sponsored threat actors and could be adopted by ransomware groups.
-
web:www.trendmicro.com
In such an attack, a loader is introduced into a compromised Atlassian server, subsequently activating the Godzilla webshell . Godzilla is a sophisticated Chinese-language backdoor that uses AES encryption for communication and remains in-memory to avoid disk-based detection mechanisms.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.