mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
name: Domain Group Discovery With Net
|
||||
id: f2f14ac7-fa81-471a-80d5-7eb65c3c7349
|
||||
version: 4
|
||||
date: '2024-11-26'
|
||||
version: 5
|
||||
date: '2024-12-11'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -22,6 +22,7 @@ tags:
|
||||
- Prestige Ransomware
|
||||
- Graceful Wipe Out Attack
|
||||
- Rhysida Ransomware
|
||||
- Cleo File Transfer Software
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 30
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Nishang PowershellTCPOneLine
|
||||
id: 1a382c6c-7c2e-11eb-ac69-acde48001122
|
||||
version: 4
|
||||
date: '2024-09-30'
|
||||
version: 5
|
||||
date: '2024-12-11'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -30,6 +30,7 @@ drilldown_searches:
|
||||
tags:
|
||||
analytic_story:
|
||||
- HAFNIUM Group
|
||||
- Cleo File Transfer Software
|
||||
asset_type: Endpoint
|
||||
confidence: 60
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: NLTest Domain Trust Discovery
|
||||
id: c3e05466-5f22-11eb-ae93-0242ac130002
|
||||
version: 4
|
||||
date: '2024-09-30'
|
||||
version: 5
|
||||
date: '2024-12-11'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
- Active Directory Discovery
|
||||
- Qakbot
|
||||
- Rhysida Ransomware
|
||||
- Cleo File Transfer Software
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 30
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: PowerShell 4104 Hunting
|
||||
id: d6f2b006-0041-11ec-8885-acde48001122
|
||||
version: 7
|
||||
date: '2024-10-17'
|
||||
version: 8
|
||||
date: '2024-12-11'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -33,6 +33,7 @@ tags:
|
||||
- CISA AA24-241A
|
||||
- Braodo Stealer
|
||||
- Lumma Stealer
|
||||
- Cleo File Transfer Software
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: System Information Discovery Detection
|
||||
id: 8e99f89e-ae58-4ebc-bf52-ae0b1a277e72
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: 6
|
||||
date: '2024-12-11'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -29,6 +29,7 @@ tags:
|
||||
- Windows Discovery Techniques
|
||||
- Gozi Malware
|
||||
- BlackSuit Ransomware
|
||||
- Cleo File Transfer Software
|
||||
asset_type: Windows
|
||||
confidence: 50
|
||||
impact: 30
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Java Spawning Shells
|
||||
id: 28c81306-5c47-11ec-bfea-acde48001122
|
||||
version: 5
|
||||
date: '2024-10-17'
|
||||
version: 6
|
||||
date: '2024-12-11'
|
||||
author: Michael Haag, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -24,6 +24,7 @@ tags:
|
||||
analytic_story:
|
||||
- Log4Shell CVE-2021-44228
|
||||
- SysAid On-Prem Software CVE-2023-47246 Vulnerability
|
||||
- Cleo File Transfer Software
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
cve:
|
||||
|
||||
@@ -0,0 +1,20 @@
|
||||
name: Cleo File Transfer Software
|
||||
id: 058be65c-f007-4a3a-90f6-d2604f98a18b
|
||||
version: 1
|
||||
date: '2024-12-11'
|
||||
author: Michael Haag, Splunk
|
||||
description: This analytic story addresses the exploitation of Cleo file transfer software products (LexiCom, VLTrader, and Harmony) through CVE-2024-50623. This vulnerability allows unauthenticated attackers to execute arbitrary system commands through the web interface, potentially leading to remote code execution and system compromise.
|
||||
narrative: In December 2024, threat actors began actively exploiting a critical vulnerability (CVE-2024-50623) in Cleo's file transfer software suite. The vulnerability affects multiple Cleo products including LexiCom, VLTrader, and Harmony. Attackers can exploit this flaw to execute system commands without authentication through the web interface, typically leveraging PowerShell commands for payload delivery and execution. The exploitation often involves accessing the software's autorun functionality and web interface to deploy malicious commands, potentially leading to data theft, ransomware deployment, or establishment of persistent access. Common installation paths include C:\LexiCom, C:\VLTrader, and C:\Harmony, with critical activity logged in their respective XML log files.
|
||||
references:
|
||||
- https://www.rapid7.com/blog/post/2024/12/10/etr-widespread-exploitation-of-cleo-file-transfer-software-cve-2024-50623/
|
||||
- https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild
|
||||
tags:
|
||||
category:
|
||||
- Adversary Tactics
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
usecase: Advanced Threat Detection
|
||||
cve:
|
||||
- CVE-2024-50623
|
||||
Reference in New Issue
Block a user