Malicious IIS Worker Process Spawning PowerShell via Gladinet CentreStack Exploit

PremiumReviewedSigma · High · v1
Category
process_creation
Author
HuntRule
Published
2026-09-29
Updated
2026-09-29

ATT&CK techniques

Initial Access → Persistence
  1. Recon

  2. Resource Dev

  3. Priv Esc

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects the IIS worker process w3wp.exe spawning powershell.exe, a web-shell style execution chain observed by Huntress during exploitation of Gladinet CentreStack and Triofox CVE-2025-30406. Attackers leverage a hardcoded machine key ViewState deserialization flaw to run commands as the web application. Because a web worker launching PowerShell is rarely legitimate, this chain is a high-confidence server compromise indicator.

Related detections9 linkedT1190 — drag to rearrange
Exchange Worker Process Spawning Command Shell via OWASSRF
Suspicious PowerShell Out-of-Band Request to Interactsh Domain
Suspicious PowerShell Spawned by SysAid Java Process
Possible Ivanti EPMM In-Memory Java Webshell Access via mifs 403.jsp
Suspicious TOLLBOOTH Webshell URI Access
Suspicious Child Process Spawned by IIS Worker Process w3wp
Suspicious SharePoint Worker Process Spawning Command Interpreter via ToolShell
Malicious IIS Worker Process Spawning Command Shell Reconnaissance
Possible Citrix ShareFile Unauthenticated Upload Path Traversal Webshell (CVE-2023-24489) (via webserver)
Malicious IIS Worker Process Spawning PowerShell via Gladinet CentreStack Exploit
Pivot detection · T1190 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.