JELAJAH SOC
YO

ALT-2432 · Web Server

Web shell uploaded to public web server

A .aspx file was written to /wwwroot/uploads and immediately requested with a cmd parameter.

Back to queue
highInvestigatingconfidence 67% · 1969-12-31 18:29:00Z · rule DET-0221 Web Directory Script Write

Detection summary

A .aspx file was written to /wwwroot/uploads and immediately requested with a cmd parameter.

Affected host
WS-FIN-014
Affected user
s.hartono
Source IP
10.20.2.84
Detection rule
DET-0221 Web Directory Script Write
Log source
Web Server
Assignee
R. Wijaya

Recommended actions

  • Quarantine the file
  • Snapshot the server
  • Review all upload endpoints

Analyst decision

Triage checklist

  • 1. Confirm the detection logic matched genuine activity.
  • 2. Check user and asset context for expected behaviour.
  • 3. Pivot on host, user, IP and hash in the Log Explorer.
  • 4. Enrich IOCs with threat intelligence.
  • 5. Set a verdict and record your reasoning.