{"id":48436,"date":"2022-09-14T00:00:00","date_gmt":"2022-09-14T00:00:00","guid":{"rendered":"urn:uuid:cd8c0752-b3bc-e170-a658-a1ff203bca26"},"modified":"2022-09-14T00:00:00","modified_gmt":"2022-09-14T00:00:00","slug":"a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/","title":{"rendered":"A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/22\/A%20Post-exploitation%20Look%20at%20Coinminers%20Abusing%20WebLogic%20Vulnerabilities_641.jpg\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/22\/A%20Post-exploitation%20Look%20at%20Coinminers%20Abusing%20WebLogic%20Vulnerabilities_641.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<div readability=\"38.5\">\n<div readability=\"22\">\n<h3><span class=\"body-subhead-title\">Using Workload Security to detect WebLogic vulnerability exploitation<\/span><\/h3>\n<p>Workload Security\u2019s correlation of telemetry and detections provided the initial security context in this campaign, which allowed security teams and analysts to track and monitor the malicious actor\u2019s activities.<\/p>\n<p>The following Workload Security modules worked to detect the exploitation of CVE-2020-14882 on vulnerable systems:<\/p>\n<p><b><i>Intrusion prevention system module<\/i><\/b><\/p>\n<p>Workload Security\u2019s intrusion prevention system module can tap into incoming traffic and effectively block and detect malicious network traffic. This module includes multiple IPS rules that can block the vulnerability exploitation of the WebLogic server. One of these is IPS rule 1010590 &#8211; Oracle WebLogic Server Remote Code Execution Vulnerabilities (CVE-2020-14882, CVE-2020-14750 and CVE-2020-14883), which can detect and block the exploitation of vulnerabilities assigned to both CVE-2020-14882\u202fand\u202fCVE-2020-14883.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"34.5\">\n<div readability=\"14\">\n<p>In figure 4, the malicious actor sent a crafted request that attempted to access the <i>console.portal <\/i>resource under the \u201cimages\u201d<i> <\/i>directory. The \u201c<i>%252e%252e<\/i>\u201d is a double URL-encoded string of the \u201c..\u201d directory traversal pattern. Because the class managing the targeted resource did not validate the input, it automatically computed the code that the attacker provided. In this case, the attacker forced the server to read the contents of the <i>wb.xml<\/i> file, which downloaded a shell script with the following contents:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31.5\">\n<div readability=\"8\">\n<p><b><i>Antimalware module<\/i><\/b><\/p>\n<p>This module provides real-time protection against the exploitation of this vulnerability using behavior-monitoring features.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"32.5\">\n<div readability=\"10\">\n<p><b><i>Web reputation module<\/i><\/b><\/p>\n<p>The web reputation module\u202fprotects systems against web threats by blocking access to malicious URLs. In our investigation, this module immediately identified and blocked the <i>wb.sh<\/i> script\u2019s attempt to download the Kinsing malware.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"34.5\">\n<div readability=\"14\">\n<p><b><i>Activity monitoring module<\/i><\/b><\/p>\n<p>This module can detect process, file, and network activities on endpoints that are running the Cloud One Workload Security solution. As seen on figure 13, the activity monitoring module detected the Java process that was attempting to open a bash shell.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"40.5\">\n<div readability=\"26\">\n<h3><span class=\"body-subhead-title\">A closer look at the WebLogic vulnerability exploitation using Trend Micro Vision One and Trend Micro Cloud One<\/span><\/h3>\n<p>In our investigation of this Kinsing campaign, Trend Micro Vision One provided real-time details into the paths and events related to this attack. This section provides insights on the activities performed by the downloaded shell script, the detections provided by the Trend Micro Cloud One and Trend Micro Vision One solutions, and how the said solutions provide information on every step of the malware&#8217;s behavior.<\/p>\n<h2><\/h2>\n<p>After the successful exploitation of the vulnerability, the <i>wb.sh<\/i> file was downloaded into the host machine. In infected machines that do not run Workload Security and Vision One, it would attempt to perform the following malicious actions:<\/p>\n<p>1.&nbsp;&nbsp;&nbsp;&nbsp; The script would check if the \u201c<i>\/tmp\/zzza<\/i>\u201d<b> <\/b>file was present, which would then trigger the script to stop.<b> <\/b>Otherwise, it would create an empty file and would perform the other actions. It is a flag used to verify that two or more instances are not running on the same host. This file can also be used to stop further infections if created manually.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31.5\">\n<div readability=\"8\">\n<p>2.&nbsp;&nbsp;&nbsp;&nbsp; The script would increase the resource limit using the \u201c<i>ulimit<\/i>\u201d<i> <\/i>command and remove the <i>\/var\/log\/syslog<\/i> file.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31\">\n<div readability=\"7\">\n<p>3.&nbsp; &nbsp; &nbsp;It would make multiple files immutable so that it can update them.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31\">\n<div readability=\"7\">\n<p>4.&nbsp; &nbsp; &nbsp;<span>It would also disable multiple security features&nbsp;within the system.<\/span><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"32\">\n<div readability=\"9\">\n<p>5.&nbsp; &nbsp; &nbsp;It would disable&nbsp;\u201dalibaba,\u201d&nbsp;\u201dbydo,\u201d and \u201cqcloud\u201d&nbsp;cloud service agents.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"32\">\n<div readability=\"9\">\n<p>6.&nbsp; &nbsp; &nbsp;Like other cryptocurrency-mining malware, it would start removing or killing off other cryptocurrency miners\u2019 processes within the infected system.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31.5\">\n<div readability=\"8\">\n<p>7.&nbsp;&nbsp;&nbsp;&nbsp; It would also remove some Docker images that belonged to other cryptocurrency-mining malware.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"33.5\">\n<div readability=\"12\">\n<p>8.&nbsp;&nbsp;&nbsp;&nbsp; Until this point, the script worked as a stager \u2014 it would remove the files and processes that were related to other cryptominers and malware families. It would also disable security features and would modify the attributes of important files so that they can be manipulated. After the script performs all these steps, it would then download the\u202fKinsing<b>\u202f<\/b>malware.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31.5\">\n<div readability=\"8\">\n<p>9.&nbsp;&nbsp;&nbsp;&nbsp; It would check if the user was root or not and would then select the path and utility (wget and curl) to download the malicious binary.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31\">\n<div readability=\"7\">\n<p>10.&nbsp;&nbsp;&nbsp;&nbsp; It would then create a cronjob to download the <i>wb.sh<\/i> script.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"34\">\n<div readability=\"13\">\n<p><b><i>Observed attack techniques (OATs)<\/i><\/b><\/p>\n<p>Observed attack techniques (OATs) are generated from individual events that provide security value. To investigate possible attempts of exploitation using this vulnerability, analysts can look for these OAT IDs from many other helper OAT triggers that can indicate suspicious activities on the affected host.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31.5\">\n<div readability=\"8\">\n<h2><\/h2>\n<p>The Trend Micro Vision One Workbench app helps analysts see the significant correlated events that are intelligently based on the occurrences that happened throughout the entire fleet of workloads.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"38.5\">\n<div readability=\"22\">\n<p>The left side of figure 25 shows the summarized sequence of events. Meanwhile, security analysts can view the different fields of interest that are considered important and provide security value on the right side. The app allows security teams to see compromised assets and isolate those that can be potentially affected while patching and mitigation procedures are in progress.<\/p>\n<p><b><i>Execution profile<\/i><\/b><\/p>\n<p>Execution profile is a Trend Micro Vision One feature that generates graphs for security defenders. Fields like \u201cprocessCmd\u201d and \u201cobjectCmd\u2019 can be expanded from the search app or the threat hunting app to look for different activities in any given period. These activities include process creation, file creation, and inbound and outbound network activity.<\/p>\n<p>If \u201cCheck Execution Profile\u201d is selected, a security analyst can go through the extensive list of actions that a malicious actor has performed.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"52.971880492091\">\n<div class=\"responsive-table-wrap\" readability=\"51.990919742238\">\n<p><b><i>Threat hunting queries<\/i><\/b><\/p>\n<p>To hunt down potential malicious activity within the environment, security analysts can use the following queries using the Trend Micro Vision One search app:<\/p>\n<p>1. To find the potential misuse of Java applications to open bash process: <i>processFilePath:\/bin\/java AND objectFilePath:\/usr\/bin\/bash<\/i>&nbsp;<\/p>\n<p>2. To find the use of curl or wget initiated by Java via bash:<\/p>\n<p><i>a.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; processFilePath:\/bin\/java AND objectFilePath:\/usr\/bin\/bash AND (objectCmd:curl <\/i>or<i> objectCmd:wget)<\/i><\/p>\n<p>3. To find the execution of Base64-decoded string execution by Java via bash:<\/p>\n<p><i>a.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; processFilePath:\/bin\/java AND objectFilePath:\/usr\/bin\/bash AND objectCmd:base64<\/i><\/p>\n<h2><span class=\"body-subhead-title\">How Trend Micro Vision One and Trend Micro Cloud One \u2013 Workload Security can help thwart vulnerability exploitation<\/span><\/h2>\n<p>In this blog entry, we discussed how malicious actors exploited a two-year-old vulnerability and attempted to deploy the Kinsing malware into a vulnerable system. The successful exploitation of this vulnerability can lead to RCE, which can allow attackers to perform a plethora of malicious activities on affected systems. This can range from malware execution, as in the case of our analysis, to theft of critical data, and even complete control of a compromised machine.<\/p>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/services\/managed-xdr.html\">Trend Micro Vision One<\/a>&nbsp;helps security teams gain an overall view of attempts in ongoing campaigns by providing them a correlated view of multiple layers such as email, endpoints, servers, and cloud workloads. Security teams can gain a broader perspective and a better understanding of attack attempts and detect suspicious behavior that would otherwise seem benign when viewed from a single layer alone.<\/p>\n<p>Meanwhile, <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/hybrid-cloud\/cloud-one-workload-security.html\">Trend Micro Cloud One \u2013 Workload Security<\/a>&nbsp;helps defend systems against vulnerability exploits, malware, and unauthorized change. It can protect a variety of environments such as virtual, physical, cloud, and containers. Using advanced techniques like machine learning (ML) and virtual patching, the solution can automatically secure new and existing workloads both against known and new threats.<\/p>\n<p><b>MITRE ATT&amp;CK Technique IDs<\/b><\/p>\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\">\n<tbody readability=\"8.5\">\n<tr>\n<td><b>Technique<\/b><\/td>\n<td><b>ID<\/b><\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Exploit Public-Facing Application<\/td>\n<td>T1190<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Command and Scripting Interpreter:\u202fUnix Shell<\/td>\n<td>T1059.004<\/td>\n<\/tr>\n<tr>\n<td>Resource Hijacking<\/td>\n<td>T1496<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Indicator Removal on Host: Clear Linux or Mac System Logs<\/td>\n<td>T1070.002<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td>File and Directory Permissions Modification: Linux and Mac File and Directory Permissions Modification<\/td>\n<td>T1222.002<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Impair Defenses: Disable or Modify System Firewall<\/td>\n<td>T1562.004<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>\u202fIndicator Removal on Host: File Deletion<\/td>\n<td>T1070.004<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Scheduled Task\/Job:\u202fCron<\/td>\n<td>T1053.003<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Impair Defenses:\u202fDisable Cloud Logs<\/td>\n<td>T1562\/008<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><b>IOCs<\/b><\/p>\n<p><b>URLs:<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/91[.]241[.]19[.]134\/wb.sh<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/185[.]14[.]30[.]35\/kinsing<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/185[.]14[.]30[.]35\/wb.sh<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/195[.]2[.]79[.]26\/kinsing<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/195[.]2[.]79[.]26\/wb.sh<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/195[.]2[.]78[.]230\/wb.sh<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/193[.]178[.]170[.]47\/wb.sh<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/178[.]20[.]40[.]200\/wb.sh<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/94[.]103[.]89[.]159\/wb.sh<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/185[.]231[.]153[.]4\/wb.sh<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/195[.]2[.]85[.]171\/wb.sh<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/80[.]92[.]204[.]82\/wb.sh<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/195[.]2[.]84[.]209\/kinsing<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/193[.]178[.]170[.]47\/kinsing<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hxxp:\/\/178[.]20[.]40[.]200\/kinsin<\/span>g<\/li>\n<\/ul>\n<p><b>File hashes<\/b><\/p>\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\">\n<tbody readability=\"3\">\n<tr>\n<td><b>SHA-256<\/b><\/td>\n<td><b>Detection name<\/b><\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>020c14b7bf5ff410ea12226f9ca070540bd46eff80cf20416871143464f7d546<\/td>\n<td>Trojan.SH.CVE20207961.SM<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>5D2530B809FD069F97B30A5938D471DD2145341B5793A70656AAD6045445CF6D<\/td>\n<td>Trojan.Linux.KINSING.USELVCR22<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li><b>IP addresses<\/b><\/li>\n<li><span class=\"rte-red-bullet\">212[.]22[.]77[.]79<\/span><\/li>\n<li><span class=\"rte-red-bullet\">185[.]234[.]247[.]8<\/span><\/li>\n<li><span class=\"rte-red-bullet\">185[.]154[.]53[.]140<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<p>Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/i\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerab.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This blog entry details how Trend Micro Cloud One\u2122 \u2013 Workload Security and Trend Micro Vision One\u2122 effectively detected and blocked the abuse of the CVE-2020-14882 WebLogic vulnerability in affected endpoints. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":48437,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9508,9555,9509],"class_list":["post-48436","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-endpoints","tag-trend-micro-research-exploitsvulnerabilities","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-09-14T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/22\/A%20Post-exploitation%20Look%20at%20Coinminers%20Abusing%20WebLogic%20Vulnerabilities_641.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities\",\"datePublished\":\"2022-09-14T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\\\/\"},\"wordCount\":1422,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/09\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities.jpg\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Endpoints\",\"Trend Micro Research : Exploits&amp;Vulnerabilities\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\\\/\",\"name\":\"A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/09\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities.jpg\",\"datePublished\":\"2022-09-14T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/09\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/09\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities.jpg\",\"width\":641,\"height\":427},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/","og_locale":"en_US","og_type":"article","og_title":"A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-09-14T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/22\/A%20Post-exploitation%20Look%20at%20Coinminers%20Abusing%20WebLogic%20Vulnerabilities_641.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities","datePublished":"2022-09-14T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/"},"wordCount":1422,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/09\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities.jpg","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Endpoints","Trend Micro Research : Exploits&amp;Vulnerabilities","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/","url":"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/","name":"A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/09\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities.jpg","datePublished":"2022-09-14T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/09\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/09\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities.jpg","width":641,"height":427},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerabilities\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/48436","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=48436"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/48436\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/48437"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=48436"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=48436"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=48436"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}