A fresh OTX pulse, corroborated by AhnLab ASEC research, details an active intrusion campaign in which the Blue Mockingbird threat actor exploits CVE-2019-18935 — a remote code execution flaw in Telerik UI for ASP.NET AJAX — to compromise Internet-facing IIS servers, escalate privileges with Potato-family tooling, and install in-memory Godzilla web shells for long-term access. U.S. government organizations are named as targets.
Threat Summary
The attack chain documented in this pulse follows a well-established web-server exploitation playbook:
- Initial Access (T1190 — Exploit Public-Facing Application): The adversary scans for IIS servers running unpatched Telerik UI for ASP.NET AJAX and exploits CVE-2019-18935, an insecure deserialization vulnerability in the
RadAsyncUploadhandler, to achieve remote code execution as the IIS worker process account (w3wp.exe). - Command & Control / Reverse Shell (T1059, T1071): Post-exploitation, the attackers execute a reverse shell connecting back to
206.82.6.22, giving them interactive access to the compromised server. - Privilege Escalation (T1068 — Exploitation for Privilege Escalation): SweetPotato, a Potato-family local privilege escalation tool, is deployed to abuse impersonation tokens (SeImpersonatePrivilege) and elevate from the low-privileged IIS service account to SYSTEM.
- Persistence (T1505.003 — Web Shell): A Godzilla-style memory-resident web shell is installed on the IIS server. Godzilla uses AES-encrypted traffic and loads payload code dynamically in memory, minimizing disk artifacts.
- Post-Compromise Discovery/Collection: A WordPress scanner was also executed, indicating either lateral scanning for secondary targets or staging infrastructure enumeration.
The campaign objective is durable, SYSTEM-level access to government web infrastructure — consistent with Blue Mockingbird's historical operations, which monetize access via cryptomining and, increasingly, by brokering or leveraging footholds for secondary intrusion.
Threat Actor / Malware Profile
Blue Mockingbird
Blue Mockingbird is a financially motivated threat actor first publicly profiled by Red Canary in 2020, known almost exclusively for exploiting Telerik UI deserialization flaws against public-facing ASP.NET applications. The group's tradecraft centers on living off IIS infrastructure: web shells, in-memory payloads, and service-account privilege escalation rather than traditional endpoint malware.
Godzilla Web Shell
- Distribution: Dropped via CVE-2019-18935 deserialization payloads onto IIS servers.
- Behavior: In-memory ASPX web shell. Requests and responses are AES-encrypted with a key embedded in the shell; response bodies are XOR/base64 wrapped, producing distinctive encrypted blobs inside HTTP traffic.
- C2: Interactive operator sessions over HTTP(S) POST to the planted
.aspxshell path. Sessions include a session cookie and an encrypted payload body — no beaconing interval, purely operator-driven. - Persistence: The
.aspxfile itself (or an injected handler) survives reboots; additional persistence via Potato-escalated SYSTEM access (new services, scheduled tasks) has been observed in follow-on stages. - Anti-analysis: Memory-loaded assemblies, encrypted traffic, no static config on disk.
SweetPotato
- Distribution: Uploaded and executed post-exploitation by the reverse shell operator.
- Behavior: Weaponized version of RottenPotato/JuicyPotato lineage. Abuses the DCOM/RPC
IMonikeractivation trick combined withPrintSpooler-triggered NTLM coercion to capture a SYSTEM token and impersonate it. - Detection signal: The IIS worker process (
w3wp.exe) spawningcmd.exe/powershell.exeas SYSTEM is a high-fidelity indicator.
Supporting Infrastructure
The reverse shell callback IP 206.82.6.22 (US) and IPs 45.138.16.187 (NL) and 2.59.133.147 (DE, php-friends gmbh — a low-cost VPS provider frequently abused for adversary staging) constitute the known C2/staging cluster.
IOC Analysis
The pulse contains 23 indicators across the following types:
| Type | Example | Operational Use |
|---|---|---|
| CVE | CVE-2019-18935 | Asset inventory: identify all servers with Telerik UI for ASP.NET AJAX < 2020.1.114 |
| IPv4 | 206.82.6.22, 45.138.16.187, 2.59.133.147, 65.98.5.158 | Egress firewall/proxy blocking; netflow and DNS retro-hunt for outbound reverse shell connections |
| FileHash-MD5 | 0a4be0b6c650ffdcd1c22db56f1c4aec | AV/EDR custom blocklists; file reputation checks on web root writes |
Operationalization guidance:
- Push all IPv4 indicators to perimeter egress block rules and check 90 days of proxy/firewall logs for connections from IIS servers to these IPs — reverse shells originate outbound from the victim.
- Note that duplicate IOC entries (e.g.,
206.82.6.22listed twice,ASN=ASNone) are common in raw OTX data; deduplicate before ingestion into TIP/SIEM pipelines. - Enrich IPs against abuse feeds and VPS provider ranges; the DE-hosted
2.59.133.147on php-friends infrastructure suggests the actor uses disposable VPS staging — monitor neighboring netblocks passively rather than blocking broadly. - Hash-based detection is secondary here: Godzilla is memory-resident, so behavioral and network detections carry more weight than static file signatures.
Detection Engineering
---
title: IIS Worker Process Spawning Shell or Potato Tool - Possible Telerik Exploitation
id: 7f3a1c2e-9b4d-4e8a-a1c5-2d6f8e3b9a01
status: experimental
description: Detects w3wp.exe spawning cmd, powershell, or known SweetPotato/JuicyPotato binaries, indicative of CVE-2019-18935 exploitation and post-exploitation privilege escalation per Blue Mockingbird tradecraft.
author: Security Arsenal Threat Intelligence
references:
- https://asec.ahnlab.com/ko/95560/
date: 2026/09/28
tags:
- attack.initial_access
- attack.t1190
- attack.privilege_escalation
- attack.t1068
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: '\w3wp.exe'
selection_child_img:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\net.exe'
- '\net1.exe'
- '\whoami.exe'
selection_child_cli:
CommandLine|contains:
- 'sweetpotato'
- 'juicypotato'
- 'PrintSpoofer'
- '-p cmd'
condition: selection_parent and (selection_child_img or selection_child_cli)
falsepositives:
- Rare; legitimate IIS applications spawning shells should be tuned per environment
level: high
---
title: Outbound Reverse Shell Connection to Blue Mockingbird C2 Infrastructure
id: 8e4b2d3f-0c5e-5f9b-b2d6-3e7a9f4c0b12
status: experimental
description: Detects network connections from web server processes to known Blue Mockingbird reverse shell C2 IPs observed in Telerik CVE-2019-18935 campaigns.
author: Security Arsenal Threat Intelligence
references:
- https://asec.ahnlab.com/ko/95560/
date: 2026/09/28
tags:
- attack.command_and_control
- attack.t1071
logsource:
category: network_connection
product: windows
detection:
selection_ip:
DestinationIp:
- '206.82.6.22'
- '45.138.16.187'
- '2.59.133.147'
- '65.98.5.158'
selection_proc:
Image|endswith:
- '\w3wp.exe'
- '\cmd.exe'
- '\powershell.exe'
condition: selection_ip and 1 of selection_proc*
falsepositives:
- Unlikely; these IPs have no legitimate business purpose
level: critical
---
title: Godzilla Web Shell File Creation in IIS Web Root
id: 9f5c3e4a-1d6f-6a0c-c3e7-4f8b0a5d1c23
status: experimental
description: Detects creation of ASPX/ASHX/ASM files in IIS web root directories by non-deployment processes, consistent with Godzilla web shell installation following Telerik exploitation.
author: Security Arsenal Threat Intelligence
references:
- https://asec.ahnlab.com/ko/95560/
date: 2026/09/28
tags:
- attack.persistence
- attack.t1505.003
logsource:
category: file_event
product: windows
detection:
selection_path:
TargetFilename|contains:
- '\inetpub\wwwroot\'
- '\wwwroot\'
selection_ext:
TargetFilename|endswith:
- '.aspx'
- '.ashx'
- '.asmx'
- '.asp'
filter_deploy:
Image|endswith:
- '\msdeploy.exe'
- '\devenv.exe'
- '\dotnet.exe'
condition: selection_path and selection_ext and not filter_deploy
falsepositives:
- Manual web deployments; tune with known deployment accounts and maintenance windows
level: high
// Hunt for Telerik exploitation + Godzilla/SweetPotato post-exploitation chain
let C2IPs = dynamic(["206.82.6.22", "45.138.16.187", "2.59.133.147", "65.98.5.158"]);
let SuspiciousChildren = dynamic(["cmd.exe", "powershell.exe", "pwsh.exe", "net.exe", "whoami.exe", "nltest.exe"]);
// Stage 1: IIS worker process spawning suspicious child processes (post-exploit / Potato privesc)
let ProcHits = DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFileName =~ "w3wp.exe"
| where FileName in~ (SuspiciousChildren)
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine,
InitiatingProcessCommandLine, ProcessId
| extend Stage = "IIS child process";
// Stage 2: Outbound connections to known C2 from web server hosts
let NetHits = DeviceNetworkEvents
| where TimeGenerated > ago(30d)
| where RemoteIP in (C2IPs)
| project TimeGenerated, DeviceName, InitiatingProcessFileName, RemoteIP, RemotePort, RemoteUrl
| extend Stage = "C2 connection";
// Stage 3: Web shell file writes to web root (requires DeviceFileEvents coverage)
let FileHits = DeviceFileEvents
| where TimeGenerated > ago(30d)
| where FolderPath has_any ("\\inetpub\\wwwroot\\", "\\wwwroot\\")
| where FileName endswith ".aspx" or FileName endswith ".ashx" or FileName endswith ".asmx"
| where InitiatingProcessFileName !in~ ("msdeploy.exe", "devenv.exe", "dotnet.exe")
| project TimeGenerated, DeviceName, FileName, FolderPath, InitiatingProcessFileName, SHA256
| extend Stage = "Web shell write";
union ProcHits, NetHits, FileHits
| order by DeviceName asc, TimeGenerated asc
# Blue Mockingbird / Godzilla Web Shell Hunt - run on IIS servers or via remote sweep
# Checks web roots for recent web shells, suspicious scheduled tasks/services, and C2 connections
$C2IPs = @("206.82.6.22", "45.138.16.187", "2.59.133.147", "65.98.5.158")
$Md5IOC = "0a4be0b6c650ffdcd1c22db56f1c4aec"
$WebRoots = @("C:\inetpub\wwwroot")
Write-Host "=== [1] Recent ASPX/ASHX files in web roots (last 60 days) ===" -ForegroundColor Cyan
foreach ($root in $WebRoots) {
if (Test-Path $root) {
Get-ChildItem -Path $root -Recurse -Include *.aspx,*.ashx,*.asmx,*.asp -ErrorAction SilentlyContinue |
Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-60) } |
Select-Object FullName, LastWriteTime, Length | Format-Table -AutoSize
}
}
Write-Host "=== [2] Hash check against known IOC ===" -ForegroundColor Cyan
foreach ($root in $WebRoots) {
if (Test-Path $root) {
Get-ChildItem -Path $root -Recurse -File -ErrorAction SilentlyContinue | ForEach-Object {
$h = (Get-FileHash -Path $_.FullName -Algorithm MD5 -ErrorAction SilentlyContinue).Hash
if ($h -and $h.ToLower() -eq $Md5IOC) {
Write-Host "[ALERT] IOC hash match: $($_.FullName)" -ForegroundColor Red
}
}
}
}
Write-Host "=== [3] Active/established connections to C2 IPs ===" -ForegroundColor Cyan
Get-NetTCPConnection -ErrorAction SilentlyContinue |
Where-Object { $C2IPs -contains $_.RemoteAddress } |
ForEach-Object {
$proc = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
Write-Host "[ALERT] $($_.LocalAddress):$($_.LocalPort) -> $($_.RemoteAddress):$($_.RemotePort) [$($_.State)] PID $($_.OwningProcess) ($($proc.ProcessName))" -ForegroundColor Red
}
Write-Host "=== [4] Suspicious scheduled tasks running as SYSTEM (SweetPotato follow-on) ===" -ForegroundColor Cyan
Get-ScheduledTask | Where-Object {
$_.Principal.UserId -match "SYSTEM" -and
($_.Actions.Execute -match "cmd|powershell|pwsh|\.tmp|AppData")
} | Select-Object TaskName, TaskPath, @{N='Action';E={$_.Actions.Execute}} | Format-Table -AutoSize
Write-Host "=== [5] Services created in last 30 days (privesc persistence check) ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{LogName='System'; Id=7045; StartTime=(Get-Date).AddDays(-30)} -ErrorAction SilentlyContinue |
Select-Object TimeCreated, @{N='Service';E={($_.Properties[0].Value)}}, @{N='Binary';E={($_.Properties[1].Value)}} |
Format-Table -AutoSize
Write-Host "=== [6] w3wp.exe child process events (last 7 days, if Sysmon installed) ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=1; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
Where-Object { $_.Message -match "w3wp.exe" } |
Select-Object TimeCreated, Message | Format-List
Response Priorities
Immediate (0-4 hours):
- Block the four C2 IPs (
206.82.6.22,45.138.16.187,2.59.133.147,65.98.5.158) at egress firewalls, proxies, and DNS resolvers; retro-hunt 90 days of netflow for connections from web server segments. - Inventory all IIS servers for Telerik UI for ASP.NET AJAX installations; any version prior to R1 2020 (2020.1.114) is vulnerable to CVE-2019-18935 and must be treated as potentially compromised until patched and verified.
- Run the PowerShell hunt script against all public-facing IIS hosts; deploy the Sigma rules to EDR/SIEM.
24 hours:
- While this campaign is not credential-theft focused, SYSTEM-level compromise of a government web server implies domain exposure: reset service account credentials for any compromised IIS host, review AD for accounts created or modified from affected servers, and check for Kerberos ticket abuse (Potato tooling enables token impersonation that can be chained into domain escalation).
- Isolate any server showing Godzilla web shell artifacts; capture memory before remediation — Godzilla is memory-resident and volatile evidence is lost on reboot.
- Review IIS logs for POST requests to unexpected
.aspxpaths with uniform, encrypted-looking bodies.
1 week:
- Patch or remove Telerik UI components across the estate; where patching is delayed, apply the vendor mitigation (disable
RadAsyncUploadhandler) and place vulnerable apps behind a WAF with a virtual patch rule for CVE-2019-18935 deserialization payloads. - Enforce application allow-listing on IIS servers to block
cmd.exe/powershell.exechildren ofw3wp.exe. - Segment public-facing web servers from internal AD; restrict outbound traffic from the DMZ to explicit allow-lists — this single control breaks the reverse shell stage of this attack chain.
- Disable
Spoolerservice where not required to blunt SweetPotato/PrintSpoofer-style privilege escalation.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.