An executable was written and executed by a web server
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
2 Hours
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Webshell Analytics
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Server Software Component: Web Shell (T1505.003)
Severity
Low
Description
Web server process had written an executable file that was executed shortly after.
Attacker's Goals
Gaining the ability to execute commands on the host, as well as persistence.
Investigative actions
Investigate the web server access logs for suspicious behavior.
Check if the dropped file contains malicious content.
Was this helpful?
