Suspicious Java Class File Created in PaperCut Server Library

Detects creation of Java .class files within the PaperCut NG/MF Application Server library directory. During active exploitation of CVE-2026-82078 (chained with CVE-2026-81578), attackers deliver hex-encoded malicious .class payloads into the PaperCut server/lib path (observed examples include Udydn.class and Moo97.class) so arbitrary bytecode executes inside the PaperCut JVM / Application Server process.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2026/08/28"
  3integration = ["endpoint"]
  4maturity = "production"
  5updated_date = "2026/09/18"
  6
  7[rule]
  8author = ["Elastic"]
  9description = """
 10Detects creation of Java .class files within the PaperCut NG/MF Application Server library directory. During active
 11exploitation of CVE-2026-82078 (chained with CVE-2026-81578), attackers deliver hex-encoded malicious .class payloads
 12into the PaperCut server/lib path (observed examples include Udydn.class and Moo97.class) so arbitrary bytecode executes
 13inside the PaperCut JVM / Application Server process.
 14"""
 15from = "now-9m"
 16index = ["logs-endpoint.events.file-*"]
 17language = "eql"
 18license = "Elastic License v2"
 19name = "Suspicious Java Class File Created in PaperCut Server Library"
 20note = """## Triage and analysis
 21
 22### Investigating Suspicious Java Class File Created in PaperCut Server Library
 23
 24PaperCut NG/MF loads database/driver-related classes from the Application Server classpath. CVE-2026-82078 allows unsafe
 25dynamic class loading when configuration can be manipulated (enabled by CVE-2026-81578 authentication bypass). Huntress
 26recovered attacker `.class` files written under `server\\lib` (for example `Udydn.class`, `Moo97.class`) that decoded
 27commands, wrote output under `server\\data\\content`, then deleted staging files and often `server.log`.
 28
 29#### Possible investigation steps
 30
 31- Inspect `file.path`, `file.name`, `file.size`, and writing `process.executable`/`process.name`. Unexpected short or
 32  random `.class` names under `server/lib` are high confidence.
 33- On the same host, look for companion artifacts under `server/data/content` (`.cmd`, `.out`) and for suspicious
 34  `pc-app.exe` / Java child processes (shells, `whoami`, `tasklist`, `charmap.exe`).
 35- Review PaperCut `server/logs` for hex-encoded blobs, base64 command strings, `jdbc:derby:memory:pwn`, Derby boot paths
 36  containing `\\pwn`, or `ERROR No suitable driver found for jdbc:no:x`. Note missing/truncated `server.log` files.
 37- Confirm whether a PaperCut upgrade or emergency patch was running at `@timestamp`; legitimate upgrades also write
 38  many `.class` files under `server/lib`.
 39- Scope other PaperCut servers for the same file names/paths and review internet exposure of the management interface.
 40
 41### False positive analysis
 42
 43- PaperCut installation, upgrade, and emergency patch operations legitimately create `.class` files under `server/lib`.
 44  Correlate with change tickets, installer process names, and volume of writes before treating as malicious.
 45- Exclude only tightly scoped upgrade processes/paths after validation; do not blanket-exclude the `server/lib` directory.
 46
 47### Response and remediation
 48
 49- Restrict public access to the PaperCut Application Server immediately.
 50- Preserve `server/lib` `.class` files, `server/logs`, `server/data/content`, and process telemetry before cleanup or patch.
 51- Remove unauthorized `.class` payloads after evidence collection; apply PaperCut Emergency Patch Release 2 (or newer).
 52- Hunt for related child-process activity from `pc-app.exe` and rotate credentials if exploitation is confirmed.
 53"""
 54
 55setup = """## Setup
 56
 57This rule is designed for data generated by [Elastic Defend](https://www.elastic.co/security/endpoint-security), which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules.
 58
 59Setup instructions: https://ela.st/install-elastic-defend
 60"""
 61
 62references = [
 63    "https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/",
 64    "https://www.huntress.com/blog/papercut-actively-exploited",
 65]
 66risk_score = 99
 67rule_id = "a2d4508e-e9c2-41f6-9466-0c3aed8cc2c9"
 68severity = "critical"
 69tags = [
 70    "Domain: Endpoint",
 71    "OS: Windows",
 72    "OS: Linux",
 73    "OS: macOS",
 74    "Use Case: Threat Detection",
 75    "Use Case: Vulnerability",
 76    "Tactic: Initial Access",
 77    "Tactic: Execution",
 78    "Tactic: Defense Evasion",
 79    "Data Source: Elastic Defend",
 80    "Resources: Investigation Guide",
 81    "Rule Type: Event Correlation (EQL)",
 82    "Platform: Windows",
 83    "Platform: Linux",
 84    "Platform: macOS",
 85    "Vuln: CVE-2026-81578",
 86    "Vuln: CVE-2026-82078",
 87]
 88timestamp_override = "event.ingested"
 89type = "eql"
 90
 91query = '''
 92file where host.os.type in ("windows", "linux", "macos") and
 93  event.action in ("creation", "overwrite") and
 94  file.extension : "class" and
 95  file.path : (
 96    "?:\\Program Files\\PaperCut*\\server\\lib\\*",
 97    "?:\\Program Files (x86)\\PaperCut*\\server\\lib\\*",
 98    "/opt/papercut/server/lib/*",
 99    "/usr/local/papercut/server/lib/*",
100    "/Applications/PaperCut*/server/lib/*"
101  )
102'''
103
104[rule.investigation_fields]
105field_names = [
106    "@timestamp",
107    "host.id",
108    "host.name",
109    "host.os.type",
110    "user.id",
111    "user.name",
112    "process.name",
113    "process.executable",
114    "file.path",
115    "file.name",
116    "file.size",
117]
118
119[[rule.threat]]
120framework = "MITRE ATT&CK"
121
122[[rule.threat.technique]]
123id = "T1190"
124name = "Exploit Public-Facing Application"
125reference = "https://attack.mitre.org/techniques/T1190/"
126
127[rule.threat.tactic]
128id = "TA0001"
129name = "Initial Access"
130reference = "https://attack.mitre.org/tactics/TA0001/"
131
132[[rule.threat]]
133framework = "MITRE ATT&CK"
134
135[[rule.threat.technique]]
136id = "T1059"
137name = "Command and Scripting Interpreter"
138reference = "https://attack.mitre.org/techniques/T1059/"
139
140[rule.threat.tactic]
141id = "TA0002"
142name = "Execution"
143reference = "https://attack.mitre.org/tactics/TA0002/"
144
145[[rule.threat]]
146framework = "MITRE ATT&CK"
147
148[[rule.threat.technique]]
149id = "T1620"
150name = "Reflective Code Loading"
151reference = "https://attack.mitre.org/techniques/T1620/"
152
153[rule.threat.tactic]
154id = "TA0005"
155name = "Defense Evasion"
156reference = "https://attack.mitre.org/tactics/TA0005/"

Triage and analysis

Investigating Suspicious Java Class File Created in PaperCut Server Library

PaperCut NG/MF loads database/driver-related classes from the Application Server classpath. CVE-2026-82078 allows unsafe dynamic class loading when configuration can be manipulated (enabled by CVE-2026-81578 authentication bypass). Huntress recovered attacker .class files written under server\lib (for example Udydn.class, Moo97.class) that decoded commands, wrote output under server\data\content, then deleted staging files and often server.log.

Possible investigation steps

  • Inspect file.path, file.name, file.size, and writing process.executable/process.name. Unexpected short or random .class names under server/lib are high confidence.
  • On the same host, look for companion artifacts under server/data/content (.cmd, .out) and for suspicious pc-app.exe / Java child processes (shells, whoami, tasklist, charmap.exe).
  • Review PaperCut server/logs for hex-encoded blobs, base64 command strings, jdbc:derby:memory:pwn, Derby boot paths containing \pwn, or ERROR No suitable driver found for jdbc:no:x. Note missing/truncated server.log files.
  • Confirm whether a PaperCut upgrade or emergency patch was running at @timestamp; legitimate upgrades also write many .class files under server/lib.
  • Scope other PaperCut servers for the same file names/paths and review internet exposure of the management interface.

False positive analysis

  • PaperCut installation, upgrade, and emergency patch operations legitimately create .class files under server/lib. Correlate with change tickets, installer process names, and volume of writes before treating as malicious.
  • Exclude only tightly scoped upgrade processes/paths after validation; do not blanket-exclude the server/lib directory.

Response and remediation

  • Restrict public access to the PaperCut Application Server immediately.
  • Preserve server/lib .class files, server/logs, server/data/content, and process telemetry before cleanup or patch.
  • Remove unauthorized .class payloads after evidence collection; apply PaperCut Emergency Patch Release 2 (or newer).
  • Hunt for related child-process activity from pc-app.exe and rotate credentials if exploitation is confirmed.

References

Related rules

to-top