TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

New Campaign Targeting Apache Struts 2, WebLogic Deploys Malware Using VBScript

2018-06-21 · Read original ↗

ATT&CK techniques detected

3 predictions
T1190Exploit Public-Facing Application
98%
"new campaign targeting apache struts 2, weblogic deploys malware using vbscript figure 1 : apache struts 2 campaign attempting to download and execute windows executable around the same timeframe, the same threat actor added the oracle weblogic wls - wsat rce exploit while trying…"
T1190Exploit Public-Facing Application
98%
"weblogic, iis webdav, clipbucket streaming server, and gpon routers. the operation prowli campaign4 actively targets joomla k2, wordpress, hp data protector, and a variety of dsl modems. with the vast availability of new exploits and the competition for victims ’ resources follow…"
T1204.002Malicious File
97%
". unavailable malware files combined with the fact that these were non - bot machines indicates the possibility that this operation is still under development and a full botnet infrastructure has not been deployed yet. spearhead vbscript while vbscript is commonly used by attacke…"

Summary

With the vast availability of new exploits and the competition for victims’ resources, the multi-exploit trend continues to be popular among attackers.