{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Metasploit modules for unauthenticated RCE in emerging LLM stacks pose an immediate risk. A negative result verifies that internet-facing services are not being used for initial access via these specific vectors."
      },
      "name": "Metasploit RCE and AArch64 Payload Delivery",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1105",
        "attack.t1059",
        "discovery",
        "execution",
        "initial access",
        "persistence",
        "privilege escalation"
      ],
      "series": {
        "slug": "metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules",
        "index": 1,
        "title": "Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules",
        "total": 2
      },
      "related": [
        {
          "hunt": "metasploit-privesc-and-persistence",
          "reason": "This hunt focuses on the foothold; a sibling hunt addresses the Linux privilege escalation (snapd) and Windows persistence (Ollama) modules.",
          "relation": "follows"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "This hunt correlates the presence of a vulnerability with specific URI patterns and stack-counted rare fetch behavior, providing the necessary context to confirm an intrusion that a single rule would miss.",
      "coverage": [
        {
          "stage": "unauthenticated-rce-web-services",
          "steps": [
            "vulnerable-hosts-scoping",
            "http-exploit-indicators"
          ],
          "status": "covered"
        },
        {
          "stage": "windows-aarch64-payload-fetch",
          "steps": [
            "rare-fetch-utility-baseline"
          ],
          "status": "covered"
        },
        {
          "stage": "linux-local-privilege-escalation",
          "reason": "Belongs to another part of the 'Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-via-auth-and-config",
          "reason": "Belongs to another part of the 'Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "security-software-discovery",
          "reason": "Belongs to another part of the 'Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Unauthenticated RCE in Web and LLM Services",
            "slug": "unauthenticated-rce-web-services",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "POST requests to /validate endpoint with exec_globals parameter (Langflow)",
              "Modification of FFMPEG Executable Path settings in dizqueTV",
              "Requests to MCP test REST endpoints in LiteLLM proxy",
              "Struts BeanUtils exploitation against N-able N-central"
            ]
          },
          {
            "name": "Windows AArch64 Payload Fetching",
            "slug": "windows-aarch64-payload-fetch",
            "tactic": "execution",
            "techniques": [
              "T1105",
              "T1059"
            ],
            "observables": [
              "Execution of cmd/windows/http/aarch64/exec",
              "Execution of cmd/windows/tftp/aarch64/shell_reverse_tcp",
              "Command-line file transfers via FTP, HTTP, HTTPS, or TFTP on AArch64 Windows systems"
            ]
          },
          {
            "name": "Linux Local Privilege Escalation",
            "slug": "linux-local-privilege-escalation",
            "tactic": "privilege-escalation",
            "techniques": [
              "T1068"
            ],
            "observables": [
              "Exploitation of snap-confine TOCTOU race condition (CVE-2026-3888)",
              "DirtyClone exploit execution (CVE-2026-43503)",
              "Execution as root inside OpenCTI API containers via safeEjs sandbox escape"
            ]
          },
          {
            "name": "Persistence via PAM and Config Tampering",
            "slug": "persistence-via-auth-and-config",
            "tactic": "persistence",
            "techniques": [
              "T1556",
              "T1574.002"
            ],
            "observables": [
              "Upload of malicious .so files into the Linux PAM authentication chain",
              "Path traversal exploitation in Ollama auto-update mechanism (CVE-2026-42249)"
            ]
          },
          {
            "name": "Security Software Discovery",
            "slug": "security-software-discovery",
            "tactic": "discovery",
            "techniques": [
              "T1518.001"
            ],
            "observables": [
              "Execution of post/linux/gather/enum_protections",
              "Automated enumeration of AV/EDR protections on the target system"
            ]
          }
        ],
        "summary": "This campaign involves the exploitation of unauthenticated remote code execution vulnerabilities in LLM-related services and IPTV servers, followed by the delivery of fetch-based payloads to Windows AArch64 systems. Attackers then perform local privilege escalation on Linux systems and establish persistence through configuration tampering or malicious authentication modules."
      },
      "severity": "high",
      "rationale": "Target systems with external exposure running Python or Node.js services, particularly those categorized as LLM proxies or media streaming servers.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is exploiting unauthenticated RCE vulnerabilities in LLM or IPTV web services to run fetch utilities that download AArch64-specific payloads onto Windows systems.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-defined",
            "kind": "manual"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to focus behavioral queries; leave empty for fleet-wide."
        },
        "target_cves": {
          "from": {
            "ref": "rapid7-metasploit-wrapup",
            "kind": "article",
            "observed": "2026-10-09"
          },
          "type": "list[string]",
          "default": [
            "CVE-2026-0770",
            "CVE-2024-58286",
            "CVE-2026-42271",
            "CVE-2026-86218"
          ],
          "description": "CVE identifiers for the targeted web and LLM vulnerabilities."
        },
        "lookback_days": {
          "from": {
            "ref": "default",
            "kind": "manual",
            "observed": "2026-10-09"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules",
          "name": "Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules"
        }
      ],
      "blind_spots": [
        {
          "id": "http-body-blindness",
          "risk": "Many exploits, including Langflow's exec_globals, pass parameters in the JSON body, which the HTTP surface does not capture, leading to misses on URI-only inspection.",
          "owner": "Network Engineering",
          "stage": "unauthenticated-rce-web-services",
          "question": "whether the exploit payload was delivered in a POST body",
          "requires": "hb_http_activity with full request body",
          "remediation": "Deploy a WAF with body inspection for sensitive LLM endpoints."
        },
        {
          "id": "architecture-context",
          "risk": "The hunt targets fetch utilities common to all Windows hosts; without architecture context, we cannot confirm if the host matches the specific platform for the new Metasploit payloads.",
          "owner": "Endpoint Security",
          "stage": "windows-aarch64-payload-fetch",
          "question": "whether the host is specifically AArch64",
          "requires": "hb_process_activity with CPU architecture",
          "remediation": "Include host architecture in the endpoint inventory or process telemetry."
        }
      ]
    },
    "name": "Metasploit RCE and AArch64 Payload Delivery",
    "description": "This hunt identifies initial access and execution attempts matching new Metasploit modules. The hunt first identifies vulnerable Langflow, vLLM, and dizqueTV instances via vulnerability findings. It then correlates HTTP traffic matching known exploit URIs with rare process behavior involving Windows fetch utilities like FTP, TFTP, and Certutil. An agent weighs the vulnerability context against the observed behavior to identify successful compromises."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules",
          "index": 1,
          "title": "Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules",
          "total": 2
        },
        "coverage": [
          {
            "stage": "unauthenticated-rce-web-services",
            "steps": [
              "vulnerable-hosts-scoping",
              "http-exploit-indicators"
            ],
            "status": "covered"
          },
          {
            "stage": "windows-aarch64-payload-fetch",
            "steps": [
              "rare-fetch-utility-baseline"
            ],
            "status": "covered"
          },
          {
            "stage": "linux-local-privilege-escalation",
            "reason": "Belongs to another part of the 'Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-via-auth-and-config",
            "reason": "Belongs to another part of the 'Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "security-software-discovery",
            "reason": "Belongs to another part of the 'Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is exploiting unauthenticated RCE vulnerabilities in LLM or IPTV web services to run fetch utilities that download AArch64-specific payloads onto Windows systems.",
        "blind_spots": [
          {
            "id": "http-body-blindness",
            "risk": "Many exploits, including Langflow's exec_globals, pass parameters in the JSON body, which the HTTP surface does not capture, leading to misses on URI-only inspection.",
            "owner": "Network Engineering",
            "stage": "unauthenticated-rce-web-services",
            "question": "whether the exploit payload was delivered in a POST body",
            "requires": "hb_http_activity with full request body",
            "remediation": "Deploy a WAF with body inspection for sensitive LLM endpoints."
          },
          {
            "id": "architecture-context",
            "risk": "The hunt targets fetch utilities common to all Windows hosts; without architecture context, we cannot confirm if the host matches the specific platform for the new Metasploit payloads.",
            "owner": "Endpoint Security",
            "stage": "windows-aarch64-payload-fetch",
            "question": "whether the host is specifically AArch64",
            "requires": "hb_process_activity with CPU architecture",
            "remediation": "Include host architecture in the endpoint inventory or process telemetry."
          }
        ],
        "scoping_notes": "Target systems with external exposure running Python or Node.js services, particularly those categorized as LLM proxies or media streaming servers.",
        "beyond_detection": "This hunt correlates the presence of a vulnerability with specific URI patterns and stack-counted rare fetch behavior, providing the necessary context to confirm an intrusion that a single rule would miss."
      }
    },
    {
      "id": "vulnerable-hosts-scoping",
      "type": "query",
      "label": "Scope vulnerable LLM and Web services",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, cve_uid, affected_package_name, severity, title FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0 OR LOWER(title) LIKE '%langflow%' OR LOWER(affected_package_name) LIKE '%dizquetv%'",
        "surface": "hb_vulnerability_finding",
        "description": "The hunt identifies hosts with reported vulnerabilities corresponding to the new Metasploit modules to prioritize behavioral analysis.",
        "expected_signal": "A list of device UIDs that are vulnerable to the targeted exploits. A negative result verifies that internet-facing services are not being used for initial access via these specific vectors."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope vulnerable LLM and Web services",
        "reads": [
          "device_uid",
          "cve_uid",
          "affected_package_name",
          "severity",
          "title"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, cve_uid, affected_package_name, severity, title FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0 OR LOWER(title) LIKE '%langflow%' OR LOWER(affected_package_name) LIKE '%dizquetv%'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of device UIDs that are vulnerable to the targeted exploits. A negative result verifies that internet-facing services are not being used for initial access via these specific vectors.",
        "verified": "dry-run",
        "verified_at": "2026-10-10"
      }
    },
    {
      "id": "http-exploit-indicators",
      "type": "query",
      "label": "HTTP exploit patterns for LLM services",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "web",
        "content": "SELECT device_hostname, url_path, url_query, src_endpoint_ip, time FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%/validate%' OR LOWER(url_path) LIKE '%/mcp/%' OR LOWER(url_path) LIKE '%ffmpeg%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "The hunt detects exploit attempts in URL paths and queries targeting Langflow, LiteLLM, and dizqueTV endpoints.",
        "expected_signal": "HTTP requests targeting specific vulnerable URIs. Silence suggests no URI-based exploitation occurred within the lookback window."
      },
      "parents": [
        {
          "id": "vulnerable-hosts-scoping"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "HTTP exploit patterns for LLM services",
        "reads": [
          "device_hostname",
          "url_path",
          "url_query",
          "src_endpoint_ip",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_path, url_query, src_endpoint_ip, time FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%/validate%' OR LOWER(url_path) LIKE '%/mcp/%' OR LOWER(url_path) LIKE '%ffmpeg%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "HTTP requests targeting specific vulnerable URIs. Silence suggests no URI-based exploitation occurred within the lookback window.",
        "verified": "dry-run",
        "verified_at": "2026-10-10"
      }
    },
    {
      "id": "rare-fetch-utility-baseline",
      "type": "query",
      "label": "Rare fetch utility command lines",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT process_cmd_line, device_hostname, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\ftp.exe' OR LOWER(process_name) LIKE '%\\tftp.exe' OR LOWER(process_name) LIKE '%\\certutil.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line, device_hostname HAVING host_count <= 5",
        "surface": "hb_process_activity",
        "description": "The hunt baselines the use of Windows fetch utilities to find rare download commands that deliver payloads.",
        "expected_signal": "Rare command lines using FTP, TFTP, or Certutil on Windows. Commands involving external IPs or suspicious paths indicate potential payload delivery."
      },
      "parents": [
        {
          "id": "vulnerable-hosts-scoping"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare fetch utility command lines",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT process_cmd_line, device_hostname, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\ftp.exe' OR LOWER(process_name) LIKE '%\\tftp.exe' OR LOWER(process_name) LIKE '%\\certutil.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line, device_hostname HAVING host_count <= 5",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Rare command lines using FTP, TFTP, or Certutil on Windows. Commands involving external IPs or suspicious paths indicate potential payload delivery.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_cmd_line"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-10-10"
      }
    },
    {
      "id": "triage-intrusion",
      "type": "analytic",
      "label": "Assess intrusion markers",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "vulnerable-hosts-scoping",
          "http-exploit-indicators",
          "rare-fetch-utility-baseline"
        ],
        "objective": "Correlate vulnerability scoping, HTTP exploit traffic, and rare fetch commands to determine if a host was successfully compromised.",
        "description": "Correlate vulnerability scoping, HTTP exploit traffic, and rare fetch commands to determine if a host was successfully compromised.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict of malicious if a host is vulnerable and shows both exploit traffic and subsequent rare fetch activity.",
        "success_criteria": "A per-host verdict of malicious, suspicious, or benign with cited evidence from all three sources."
      },
      "parents": [
        {
          "id": "http-exploit-indicators",
          "kind": "merge"
        },
        {
          "id": "rare-fetch-utility-baseline",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route based on intrusion verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one host",
        "condition": "the triage verdict is malicious for at least one host",
        "blind_spot": "http-body-blindness",
        "confidence": "high",
        "description": "Direct the workflow to containment if an intrusion is confirmed or to manual review if findings are inconclusive.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-intrusion"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "The action contains the potentially compromised endpoint to prevent further payload execution or lateral movement.",
        "instructions": "Isolate the host immediately. Review the command line from the rare-fetch-utility-baseline step to identify the downloaded payload.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-validation",
      "type": "task",
      "label": "Analyst validation",
      "config": {
        "assignee": "analyst",
        "description": "The analyst verifies the agent findings and identifies the specific file retrieved by the fetch utility.",
        "instructions": "Review the process_cmd_line and url_path. Confirm if the fetch utility was directed at the same source IP seen in the HTTP exploit logs. Retrieve the downloaded file for forensic analysis."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "remediation-and-closeout",
      "type": "task",
      "label": "Remediation and closeout",
      "config": {
        "assignee": "analyst",
        "description": "Ensure the vulnerable software is updated and document the hunt results.",
        "instructions": "Update Langflow, vLLM, and dizqueTV to the latest versions. Audit any LiteLLM or N-central exposures. Record the findings and consider promoting the HTTP URI patterns to a standing detection rule."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-validation"
        }
      ]
    }
  ]
}