CVE
CVE-2017-12611
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
Exploitation IoCs 3
Domain cdnorigin[.]net
SHA-1 31c69b3e12936abca770d430066f379ec1d997ec
IP 209[.]99[.]186[.]235
MITRE ATT&CK TTPs 8
T1059.001 T1078.001 T1090 T1133 T1210 T1220 T1566 T1659
PowerShell
Execution
Default Accounts
Defense Evasion
Proxy
Command And Control
External Remote Services
Persistence
Exploitation of Remote Services
Lateral Movement
XSL Script Processing
Defense Evasion
Phishing
Initial Access
Content Injection
Initial Access