Ticket summary
On 19 August 2026 the STAAH SOC opened IR-2026-0819-141 after GuardDuty raised a HIGH-severity finding against web-prod-01, the production EC2 instance hosting the STAAH Portal. Web server logs show unusual traffic patterns from an external IP, and the host telemetry indicates unexpected process activity from the Apache process. You are the analyst assigned to investigate.
STAAH Technologies runs a PHP-based portal on an EC2 instance (web-prod-01) in ap-south-1. The application handles internal bookings and is accessible over HTTPS. Apache and PHP are the primary web stack.
At approximately 14:00 UTC the application was serving normal traffic. By 14:27 UTC the GuardDuty detector raised a Backdoor:EC2/C&CActivity.B!DNS finding. Shortly before the finding, host telemetry shows unusual process activity originating from the Apache process.
The ticket includes seven evidence exports: a GuardDuty finding, Apache access logs, Apache error logs, Linux process and file-system events, DNS query logs, the EC2 instance metadata, and a CloudTrail slice. Your task is to reconstruct the attack chain, identify the initial access method, determine the scope of post-compromise activity, and assess whether persistence was achieved.