ISIT Security LabsIncident response training

STAAH Technologies · STAAH Portal (portal.staah-internal.example)

EC2 Web Shell Investigation

Intermediate30 minCloud Security / Web Security / Incident Response
Now: Case briefing. Read the ticket and environment first. Do not open logs until you know what you are looking for.

Ticket summary

On 19 August 2026 the STAAH SOC opened IR-2026-0819-141 after GuardDuty raised a HIGH-severity finding against web-prod-01, the production EC2 instance hosting the STAAH Portal. Web server logs show unusual traffic patterns from an external IP, and the host telemetry indicates unexpected process activity from the Apache process. You are the analyst assigned to investigate.

STAAH Technologies runs a PHP-based portal on an EC2 instance (web-prod-01) in ap-south-1. The application handles internal bookings and is accessible over HTTPS. Apache and PHP are the primary web stack.

At approximately 14:00 UTC the application was serving normal traffic. By 14:27 UTC the GuardDuty detector raised a Backdoor:EC2/C&CActivity.B!DNS finding. Shortly before the finding, host telemetry shows unusual process activity originating from the Apache process.

The ticket includes seven evidence exports: a GuardDuty finding, Apache access logs, Apache error logs, Linux process and file-system events, DNS query logs, the EC2 instance metadata, and a CloudTrail slice. Your task is to reconstruct the attack chain, identify the initial access method, determine the scope of post-compromise activity, and assess whether persistence was achieved.