Malicious PHASEJAM Web Shell Written Into Ivanti CGI Endpoints (via file_event)

PremiumReviewedSigma · High · v1
Product
linux
Category
file_event
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects modification of the Ivanti Connect Secure getComponent.cgi or restAuth.cgi files, into which the PHASEJAM web shell was injected during zero-day exploitation. Writes to these trusted CGI endpoints grant persistent remote command execution on the appliance.

Related detections9 linkedT1505.003 — drag to rearrange
Possible GhostContainer Exchange Backdoor C2 Request via OWA (via webserver)
Suspicious Command Shell Spawned by MSSQL Server Process Indicating Webshell
Suspicious Exchange IIS Worker Loading GhostContainer Module (via image_load)
Malicious MOVEit Transfer Exploitation via X-siLock HTTP Headers (via webserver)
Malicious IIS w3wp Worker Spawning Command Interpreter via SharePoint Web Shell
Suspicious Single-Character Named Executable Launched by Web Server Process (via process_creation)
Malicious MOVEit human2.aspx Web Shell Dropped in wwwroot (via file_event)
Malicious ASPX Web Shell Written to SharePoint LAYOUTS Directory (via file_event)
Suspicious PHP Webshell in Netscaler VPN Theme Directory
Malicious PHASEJAM Web Shell Written Into Ivanti CGI Endpoints (via file_event)
Pivot detection · T1505.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.