Scans for EncystPHP Webshell, (Mon, Apr 13th)
2026-04-14T01:23:50Z•895326b8d331a53f88daf233154afd33d7d07411e5e2a5620dc4d6176f4f7383
CISACiscoEncystPHPFreePBXTeamPCPTrivyUNC6780credential‑thefthoneypot‑fingerprintingmalicious‑JSobfuscated‑javascriptpasswordspersistencephishingscanningsupply‑chainsupply‑chain‑compromisethreat‑intelwebshell
What happened
SANS ISC diaries from early–mid April 2026 report multiple active threats: scanning activity for the EncystPHP web shell (noted as commonly used against vulnerable FreePBX instances) with attackers shifting to harder‑to‑guess credentials; continued emphasis on web shells as persistence (arbitrary file write/RCE) and poor/default passwords; increased honeypot‑fingerprinting scans; a malicious obfuscated JavaScript payload (cbmjlzan.JS, SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) delivered in a RAR with low AV detection; and a significant TeamPCP supply‑chain update:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 895326b8d331a53f88daf233154afd33d7d07411e5e2a5620dc4d6176f4f7383
- Enrichment time
- 2026-04-14T01:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.