EXPL_LOG_CommVault_CVE_2025_57791_Indicator_Shell_Drop_Aug25
Description
Detects suspicious log lines that indicate web shell drops into the Apache root folder of a Commvault installation
Query · yara
strings:
$xr1 = /Results written to \[[C-Z]:\\Program Files\\Commvault\\ContentStore\\Apache\\webapps\\ROOT\\[^\\]{1,20}\.jsp\]/ // https://regex101.com/r/KV8iK6/1
condition:
$xr1