Drupalgeddon 2: Profiting from Mass Exploitation
ID: ace258fe-7d63-502f-a99f-0c298cc9e8e3
STIX ID: report--ace258fe-7d63-502f-a99f-0c298cc9e8e3
Feed Name: Volexity Blog
Volexity observed widespread automated scanning and exploitation of the critical Drupal vulnerability CVE-2018-7600 ("Drupalgeddon 2") beginning after public exploit code was released; successful exploitation yields unauthenticated remote code execution and has been used to install XMRig Monero miners and other backdoors. The report includes an HTTP POST exploit example, the dropper shell script that fetches a miner binary and config, a Monero wallet tied to earnings, IDS signatures (Suricata/Snort), extensive network IOCs (URLs and IPs), and recommends immediate patching of Drupal 7.x and 8.x instances and log review for signs of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
