CVE
CVE-2021-23758
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
Exploitation IoCs 13
Domain adminapi[.]tippusoni[.]in
Filename back.bat
Filename back.txt
Filename bai.bat
Filename check_paths.py
Filename deploy_implant.py
Filename dll.zip
Filename prcc1.rar
Filename sss.ashx
Filename svchosts.exe
Filename up.ashx
Filename user.bat
IP 139[.]180[.]197[.]150