Scans for EncystPHP Webshell, (Mon, Apr 13th)

2026-04-14T01:23:50Z895326b8d331a53f88daf233154afd33d7d07411e5e2a5620dc4d6176f4f7383
CISACiscoEncystPHPFreePBXTeamPCPTrivyUNC6780credential‑thefthoneypot‑fingerprintingmalicious‑JSobfuscated‑javascriptpasswordspersistencephishingscanningsupply‑chainsupply‑chain‑compromisethreat‑intelwebshell

What happened

SANS ISC diaries from early–mid April 2026 report multiple active threats: scanning activity for the EncystPHP web shell (noted as commonly used against vulnerable FreePBX instances) with attackers shifting to harder‑to‑guess credentials; continued emphasis on web shells as persistence (arbitrary file write/RCE) and poor/default passwords; increased honeypot‑fingerprinting scans; a malicious obfuscated JavaScript payload (cbmjlzan.JS, SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) delivered in a RAR with low AV detection; and a significant TeamPCP supply‑chain update:

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
895326b8d331a53f88daf233154afd33d7d07411e5e2a5620dc4d6176f4f7383
Enrichment time
2026-04-14T01:23:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.