CyberzSOC

Publication detail
← Back to advisories & guidance

Known Indicators of Compromise Associated with Androxgh0st Malware ↗ source

January 16, 2024 CISA Advisory
Co-sealed by: CISA, CSA, FBI

Summary

tactics, techniques, and procedures (TTPs) associated • Review and ensure only necessary with threat actors deploying Androxgh0st malware. servers and services are exposed to Multiple, ongoing investigations and trusted third party the internet. reporting yielded the IOCs and TTPs, and provided • Review platforms or services that information on Androxgh0st malware’s ability to have credentials listed in .env files establish a botnet that can further identify and for unauthorized access or use. compromise vulnerable networks.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2017-9841 9.8 Critical PHPUnit PHPUnit PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on…
CVE-2018-15133 8.1 High Laravel Laravel Framework Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be e…
CVE-2021-41773 7.5 High Apache HTTP Server Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories conf…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.