Making Friends By Proactive Notification
Full article446 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, May 17, 2016 12:39
This blog post is authored by Tazz.
Talos has continued to observe ongoing attacks leveraging the use of JBoss exploits. Through our research efforts, we have identified an additional 600 or so compromised hosts which contain webshells due to adversaries compromising unpatched JBoss environments. In response to this, Talos has been working to notify victims of these compromised hosts so that appropriate remediation may take place.This blog post outlines the notification process and provides additional indicators which you can use to review your own JBoss environments, such as a list of the 500 most common webshells we have observed in the wild.
If your organization hasn't reviewed its contact information on file with your Internet Registrar lately, now would be a great time to do that. If you're not sure who your registrar is, you can find them here https://www.iana.org/numbers.
- AFRINIC - Africa Region
- APNIC - Asia/Pacific Region
- ARIN - Canada, USA, and some Caribbean Islands
- LACNIC - Latin America and some Caribbean Islands
- RIPE NCC - Europe, the Middle East, and Central Asia
Is This Everything?
We found individual hosts with more than 100 different webshells.Our notification process is providing only the top 10 webshells for the sake of expediency. We are also providing a list of the top 500+ webshells we observed within the IOC section below. Since most organizations track vulnerabilities or incidents per host, we are sending one email per IP address. As a result, you may receive multiple emails with the same email subject. Please pay close attention to the body of the email. It is possible that from the time we identified a webshell on a host and the time we were able to notify you, additional webshells may have been installed on the same host or other hosts accessible from the compromised asset. It is highly recommended that a full investigation be conducted to determine the scope of access bad actors may have to your network and other resources.
We do understand that at times organizations are not able to share information. If this is the case, then if at all possible, we would greatly appreciate it if you can close the loop with us and let us know when a host has been remediated by sending an email to t[email protected] and include the IP address(es).
For more information on what to do for/with the compromised host, please see the Recommended Remediation section of our previous blog post on JBoss Backdoor:
http://blog.talosintel.com/2016/04/jboss-backdoor.html
IOCs
Here is a list of over 500 webshells we have detected. The format if you want to check for one of the webshells on your host is http://<ip_address>/<webshell>
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/jboss-notifications/