{"id":2043,"date":"2023-12-12T11:38:24","date_gmt":"2023-12-12T11:38:24","guid":{"rendered":"https:\/\/certera.com\/blog\/?p=2043"},"modified":"2023-12-12T11:43:29","modified_gmt":"2023-12-12T11:43:29","slug":"security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems","status":"publish","type":"post","link":"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/","title":{"rendered":"Security Alert: HrServ Web Shell is Hacked by APT, Breach of Windows Systems"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Cybersecurity specialists at <a href=\"https:\/\/securelist.com\/hrserv-apt-web-shell\/111119\/\">Securelist found<\/a> that the DLL file known as hrserv.dll, a previously unidentified web shell, displays advanced capabilities, including unique encoding techniques for client connection and in-memory execution.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Following the data analysis, comparable variations created in 2021 were found, suggesting a possible connection between these disparate instances of detrimental activity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>A malicious software or program known as a HrServ web shell permits remote server administration, granting unauthorized access and control.<\/em><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hackers target web shells to obtain unauthorized access to a server or website. This allows them to run commands, upload and download data, and modify the system for malevolent objectives such as Theft of data and initiating new malicious activities.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">HrServ Web Shell<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">By generating a &#8220;MicrosoftsUpdate&#8221; scheduled task, PAExec.exe initiates a.BAT file. The script creates a registry service using&#8217; copies $public\\hrserv.dll to System32 and then launches the recently formed service. HrServ first registers a handler for service before utilizing custom encoding to start an HTTP server -Base64, FNV1A64.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The DLL uses the NID cookie in addition to activating certain functionalities in response to the &#8216;cp&#8217; GET parameter in HTTP requests. The naming conventions are like Google&#8217;s and might mask malicious activities in network data, making identification difficult.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Code execution is triggered by a cp value of 6, and in a specific case when the cp value is unknown, a versatile implant initiates in system memory.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Along with Creating a File in &#8220;% temp%,&#8221; it carries out the Subsequent Steps:<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Obtains Registry Information.<\/li>\n\n\n\n<li>Acts in Response to it.<\/li>\n\n\n\n<li>Keeps Track of Output in the File.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"728\" height=\"649\" src=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/12\/image.png\" alt=\"HrServ Web Shell\" class=\"wp-image-2044\" srcset=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/12\/image.png 728w, https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/12\/image-300x267.png 300w\" sizes=\"(max-width: 728px) 100vw, 728px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The researchers found that the sample under analysis is a capable web shell. Based on the compilation timestamps, its origins are at least 2021. This is a more advanced version of malware that can start in-memory operations. When observed, temporary files and registry modifications are used to establish communication.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Notably, the memory implant and web shell use various strings under different scenarios. The memory implant also has a well-designed help message. Furthermore, the memory implant has a well-designed help message. When these elements are considered, the malware&#8217;s traits align with financially motivated fraudulent activity. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That said, there are certain parallels between its operating approach and the behavior of APT. Aside from this, security experts could not relate the TTPs to any identifiable threat actors. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity specialists at Securelist found that the DLL file known as hrserv.dll, a previously unidentified web shell, displays advanced capabilities, including unique encoding techniques for client connection and in-memory execution.\u00a0 Following the data analysis, comparable variations created in 2021 were found, suggesting a possible connection between these disparate instances of detrimental activity. A malicious software<span class=\"morelink d-block mt-3\"><a href=\"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/\">Read More<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":2047,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[48],"tags":[394,395,391,392],"class_list":["post-2043","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-breach","tag-apt-attack","tag-apt-hacks-hrserv-web-shell","tag-hrserv-web-shell","tag-windows-systems-hacks","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.6 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>HrServ Web Shell is Hacked by APT, Breach of Windows Systems<\/title>\n<meta name=\"description\" content=\"A new type of malicious web shell called HrServ has been identified as being used by hackers to hack Windows systems from 2021 to 2023, according to a report by Securelist.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Alert: HrServ Web Shell is Hacked by APT, Breach of Windows Systems\" \/>\n<meta property=\"og:description\" content=\"A new type of malicious web shell called HrServ has been identified as being used by hackers to hack Windows systems from 2021 to 2023, according to a report by Securelist.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/\" \/>\n<meta property=\"og:site_name\" content=\"EncryptedFence by Certera - Web &amp; Cyber Security Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/certeraLLC\/\" \/>\n<meta property=\"article:published_time\" content=\"2023-12-12T11:38:24+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-12-12T11:43:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/12\/hrserv-web-shell-hacked-by-apt-group-breach-jpg.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"960\" \/>\n\t<meta property=\"og:image:height\" content=\"620\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Janki Mehta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/12\/hrserv-web-shell-hacked-by-apt-group-breach-jpg.webp\" \/>\n<meta name=\"twitter:creator\" content=\"@certera_llc\" \/>\n<meta name=\"twitter:site\" content=\"@certera_llc\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Janki Mehta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\\\/\"},\"author\":{\"name\":\"Janki Mehta\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/person\\\/e5a476aa90d9e02260ebfe4b0bf046b7\"},\"headline\":\"Security Alert: HrServ Web Shell is Hacked by APT, Breach of Windows Systems\",\"datePublished\":\"2023-12-12T11:38:24+00:00\",\"dateModified\":\"2023-12-12T11:43:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\\\/\"},\"wordCount\":398,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/hrserv-web-shell-hacked-by-apt-group-breach-jpg.webp\",\"keywords\":[\"APT attack\",\"APT Hacks HrServ Web Shell\",\"HrServ Web Shell\",\"Windows Systems hacks\"],\"articleSection\":[\"Data Breach\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/certera.com\\\/blog\\\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\\\/#respond\"]}],\"copyrightYear\":\"2023\",\"copyrightHolder\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\\\/\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\\\/\",\"name\":\"HrServ Web Shell is Hacked by APT, Breach of Windows Systems\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/hrserv-web-shell-hacked-by-apt-group-breach-jpg.webp\",\"datePublished\":\"2023-12-12T11:38:24+00:00\",\"dateModified\":\"2023-12-12T11:43:29+00:00\",\"description\":\"A new type of malicious web shell called HrServ has been identified as being used by hackers to hack Windows systems from 2021 to 2023, according to a report by Securelist.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/certera.com\\\/blog\\\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\\\/#primaryimage\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/hrserv-web-shell-hacked-by-apt-group-breach-jpg.webp\",\"contentUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/hrserv-web-shell-hacked-by-apt-group-breach-jpg.webp\",\"width\":960,\"height\":620,\"caption\":\"HRServ Web Shell Hacked by APT Group\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/certera.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security Alert: HrServ Web Shell is Hacked by APT, Breach of Windows Systems\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/\",\"name\":\"EncryptedFence by Certera - Web & Cyber Security Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"},\"alternateName\":\"Certera's EncryptedFence Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/certera.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\",\"name\":\"Certera\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-encryptedfence.svg\",\"contentUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-encryptedfence.svg\",\"caption\":\"Certera\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/certeraLLC\\\/\",\"https:\\\/\\\/x.com\\\/certera_llc\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/certera-llc\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/person\\\/e5a476aa90d9e02260ebfe4b0bf046b7\",\"name\":\"Janki Mehta\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"caption\":\"Janki Mehta\"},\"description\":\"Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web\\\/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.\",\"sameAs\":[\"https:\\\/\\\/certerassl.com\\\/\"],\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/author\\\/certerabguser\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"HrServ Web Shell is Hacked by APT, Breach of Windows Systems","description":"A new type of malicious web shell called HrServ has been identified as being used by hackers to hack Windows systems from 2021 to 2023, according to a report by Securelist.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/","og_locale":"en_US","og_type":"article","og_title":"Security Alert: HrServ Web Shell is Hacked by APT, Breach of Windows Systems","og_description":"A new type of malicious web shell called HrServ has been identified as being used by hackers to hack Windows systems from 2021 to 2023, according to a report by Securelist.","og_url":"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/","og_site_name":"EncryptedFence by Certera - Web &amp; Cyber Security Blog","article_publisher":"https:\/\/www.facebook.com\/certeraLLC\/","article_published_time":"2023-12-12T11:38:24+00:00","article_modified_time":"2023-12-12T11:43:29+00:00","og_image":[{"width":960,"height":620,"url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/12\/hrserv-web-shell-hacked-by-apt-group-breach-jpg.webp","type":"image\/jpeg"}],"author":"Janki Mehta","twitter_card":"summary_large_image","twitter_image":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/12\/hrserv-web-shell-hacked-by-apt-group-breach-jpg.webp","twitter_creator":"@certera_llc","twitter_site":"@certera_llc","twitter_misc":{"Written by":"Janki Mehta","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/#article","isPartOf":{"@id":"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/"},"author":{"name":"Janki Mehta","@id":"https:\/\/certera.com\/blog\/#\/schema\/person\/e5a476aa90d9e02260ebfe4b0bf046b7"},"headline":"Security Alert: HrServ Web Shell is Hacked by APT, Breach of Windows Systems","datePublished":"2023-12-12T11:38:24+00:00","dateModified":"2023-12-12T11:43:29+00:00","mainEntityOfPage":{"@id":"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/"},"wordCount":398,"commentCount":0,"publisher":{"@id":"https:\/\/certera.com\/blog\/#organization"},"image":{"@id":"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/#primaryimage"},"thumbnailUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/12\/hrserv-web-shell-hacked-by-apt-group-breach-jpg.webp","keywords":["APT attack","APT Hacks HrServ Web Shell","HrServ Web Shell","Windows Systems hacks"],"articleSection":["Data Breach"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/#respond"]}],"copyrightYear":"2023","copyrightHolder":{"@id":"https:\/\/certera.com\/blog\/#organization"}},{"@type":"WebPage","@id":"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/","url":"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/","name":"HrServ Web Shell is Hacked by APT, Breach of Windows Systems","isPartOf":{"@id":"https:\/\/certera.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/#primaryimage"},"image":{"@id":"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/#primaryimage"},"thumbnailUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/12\/hrserv-web-shell-hacked-by-apt-group-breach-jpg.webp","datePublished":"2023-12-12T11:38:24+00:00","dateModified":"2023-12-12T11:43:29+00:00","description":"A new type of malicious web shell called HrServ has been identified as being used by hackers to hack Windows systems from 2021 to 2023, according to a report by Securelist.","breadcrumb":{"@id":"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/#primaryimage","url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/12\/hrserv-web-shell-hacked-by-apt-group-breach-jpg.webp","contentUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/12\/hrserv-web-shell-hacked-by-apt-group-breach-jpg.webp","width":960,"height":620,"caption":"HRServ Web Shell Hacked by APT Group"},{"@type":"BreadcrumbList","@id":"https:\/\/certera.com\/blog\/security-alert-hrserv-web-shell-is-hacked-by-apt-breach-of-windows-systems\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/certera.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Security Alert: HrServ Web Shell is Hacked by APT, Breach of Windows Systems"}]},{"@type":"WebSite","@id":"https:\/\/certera.com\/blog\/#website","url":"https:\/\/certera.com\/blog\/","name":"EncryptedFence by Certera - Web & Cyber Security Blog","description":"","publisher":{"@id":"https:\/\/certera.com\/blog\/#organization"},"alternateName":"Certera's EncryptedFence Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/certera.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/certera.com\/blog\/#organization","name":"Certera","url":"https:\/\/certera.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/certera.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/08\/logo-encryptedfence.svg","contentUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/08\/logo-encryptedfence.svg","caption":"Certera"},"image":{"@id":"https:\/\/certera.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/certeraLLC\/","https:\/\/x.com\/certera_llc","https:\/\/www.linkedin.com\/company\/certera-llc\/"]},{"@type":"Person","@id":"https:\/\/certera.com\/blog\/#\/schema\/person\/e5a476aa90d9e02260ebfe4b0bf046b7","name":"Janki Mehta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","caption":"Janki Mehta"},"description":"Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web\/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.","sameAs":["https:\/\/certerassl.com\/"],"url":"https:\/\/certera.com\/blog\/author\/certerabguser\/"}]}},"_links":{"self":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/2043","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/comments?post=2043"}],"version-history":[{"count":3,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/2043\/revisions"}],"predecessor-version":[{"id":2049,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/2043\/revisions\/2049"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/media\/2047"}],"wp:attachment":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/media?parent=2043"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/categories?post=2043"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/tags?post=2043"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}