cbcvebase.
CVE-2016-3088
published 2016-06-01

CVE-2016-3088: The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by…

PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-08-10
Exploited in the wild
EPSS
98.52%
99.9th percentile
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

Affected

5 ranges
VendorProductVersion rangeFixed in
apacheactivemq>= 0 < 5.14.0+dfsg-15.14.0+dfsg-1
apacheactivemq>= 0 < 5.14.0+dfsg-15.14.0+dfsg-1
apacheactivemq>= 0 < 5.14.0+dfsg-15.14.0+dfsg-1
apacheactivemq>= 5.0.0 < 5.14.05.14.0
debianactivemq< activemq 5.14.0+dfsg-1 (bookworm)activemq 5.14.0+dfsg-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

hash4ff33180d326765d92e32ec5580f54495bfcdd58a85f908a7ece8d0aedbe5597
hash220c2ebacafde95ebf4af12bf0d8eedb6004edd103ecb1d6363e7eb5a3e62c01
hasha81424ec81849950616f932c79db593147b8a01cc6d06d279fd05d61103abdb7
filenamepro__autolk.sh
filenamepro__automig.sh
filenamepro__autorkt.sh
path/etc/ld.so.preload
commandHTTP PUT followed by HTTP MOVE
  • CVE-2016-3088 exploitation uses an HTTP PUT request to upload a file to the ActiveMQ Fileserver web application, followed by an HTTP MOVE request to relocate and execute it. Detect sequences of PUT+MOVE HTTP methods targeting ActiveMQ Fileserver endpoints.
  • Pro-Ocean (Rocke Group) exploits CVE-2016-3088 on Apache ActiveMQ as part of its worm infection module. Look for exploitation attempts against ActiveMQ instances followed by download of a shell installation script from shop.168bee[.]com.
  • Presence of /etc/ld.so.preload modified by malware (Pro-Ocean rootkit) is a strong post-exploitation indicator on Linux systems targeted via CVE-2016-3088.
  • Xbash also fetches scanning targets via C2 URIs /domain/phpmyadmin, /domain/all, /port/tcp8080, /port/udp1900, and /cidir. Detect HTTP requests matching these URI patterns to external hosts as potential C2 beaconing.
  • Pro-Ocean binary is UPX-packed with the UPX magic string deleted to evade static analysis. Detection tools should not rely solely on UPX header identification; use behavioral or memory-based detection.
  • Xbash fetches C2 domain lists from Pastebin. Monitor for HTTP requests to Pastebin from ActiveMQ or other server processes as a potential indicator of compromise.
  • ·CVE-2016-3088 only affects Apache ActiveMQ 5.x versions before 5.14.0. Systems running 5.14.0 or later are not vulnerable via this specific attack vector.
  • ·Pro-Ocean's exploit list is not static — the malware downloads its infection payload from a remote server, so additional exploits beyond CVE-2016-3088 may be added dynamically by the attacker.
  • ·Pro-Ocean actively uninstalls Alibaba Cloud and Tencent Cloud monitoring agents, meaning agent-based cloud security solutions on these platforms may not detect or alert on the compromise.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.