Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems
Cosa significa
CISA Cybersecurity Advisories ha pubblicato l'advisory "Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems". La fonte segnala sfruttamento attivo e richiede una verifica prioritaria.
Perché conta
La fonte segnala sfruttamento attivo. La priorita dipende dalla presenza della tecnologia interessata nel perimetro; il testo acquisito non consente di dedurre ulteriori impatti tecnici.
Azioni consigliate
- Verificare l'applicabilita dell'advisory e applicare le mitigazioni ufficiali.
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Benefici operativi potenziali
- Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
- Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
- Validazione documentata della capacita di ripristino
Traduzione in elaborazione
Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.
Testo acquisito dalla fonte
Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs. Cybersecurity Advisory Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems Last Revised July 18, 2022 Alert Code AA22-174A Summary Actions to take today: • Install fixed builds, updating all affected VMware Horizon and UAG systems to the latest versions. If updates or workarounds were not promptly applied following VMware’s release of updates for Log4Shell in December 2021, treat all affected VMware systems as compromised. • Minimize the internet-facing attack surface by hosting essential services on a segregated demilitarized (DMZ) zone, ensuring strict network perimeter access controls, and implementing regularly updated web application firewalls (WAFs) in front of public-facing services The Cybersecurity and Infrastructure Security Agency (CISA) and United States Coast Guard Cyber Command (CGCYBER) are releasing this joint Cybersecurity Advisory (CSA) to warn network defenders that cyber threat actors, including state-sponsored advanced persistent threat (APT) actors, have continued to exploit CVE-2021-44228 (Log4Shell) in VMware Horizon® and Unified Access Gateway (UAG) servers to obtain initial access to organizations that did not apply available patches or workarounds. Since December 2021, multiple threat actor groups have exploited Log4Shell on unpatched, public-facing VMware Horizon and UAG servers. As part of this exploitation, suspected APT actors implanted loader malware on compromised systems with embedded executables enabling remote command and control (C2). In one confirmed compromise, these APT actors were able to move laterally inside the network, gain access to a disaster recovery n
Indicatori CISA verificabili
43 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.
Ultima verifica: 2026-09-26T09:03:14.359204+00:00
Scarica STIX 2.1| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| ipv4-addr | 104[.]155[.]149[.]103 | |
| ipv4-addr | 185[.]136[.]163[.]104 | |
| ipv4-addr | 134[.]119[.]177[.]107 | |
| ipv4-addr | 109[.]248[.]150[.]13 | |
| ipv4-addr | 155[.]94[.]211[.]207 | |
| ipv4-addr | 162[.]245[.]190[.]203 | |
| ipv4-addr | 92[.]222[.]241[.]76 | |
| ipv4-addr | 192[.]95[.]20[.]8 | |
| ipv4-addr | 104[.]223[.]34[.]198 |
Provenienza
Allegato ufficiale CISA · 2022-06-24T18:31:15Z
SHA-512: 807984f5119b2f0a82ffb85bcdf9386b1a042e476a6ac14ff046677903973e11a947d25bb372d103b952cb21584f2ede1a8883429346187ace9cf4cd789d611a
| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| MD5 | df81145680b4deab198d9bba091d86e9 | |
| SHA-1 | 4235d9a934d26ec688c21e3fc2e470178b7b3c21 | |
| SHA-256 | 6589a687e69a182e075f11805a755ac1fabbddae1636c6fea8e80e7414521349 | |
| MD5 | f9e6ca0bdaa43df9ed0449b964e1b8b4 | |
| SHA-1 | 24b983856dfdd4e48eeeafc9372b70d6b53ae722 | |
| SHA-256 | 6e3840f11aa02f391edd7e3e65b214f1af128fa207b4feb7f69e438014a2206d | |
| ipv4-addr | 192[.]95[.]20[.]8 |
Provenienza
Allegato ufficiale CISA · 2022-06-03T19:14:20Z
SHA-512: ec1dc07ae3b0ede9d938e460a6fee745642c6a8580c1c9e76adaf26a77448d42629e50115bbd5a66a35da9983ed791bca4603742d3397aac24d3401dc06e9a97
| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| MD5 | 21fa1a043460c14709ef425ce24da4fd | |
| SHA-1 | 33638da3a83c2688e1d20862b1de0b242a22e87c | |
| SHA-256 | 66966ceae7e3a8aace6c27183067d861f9d7267aed30473a95168c3fe19f2c16 | |
| ipv4-addr | 185[.]136[.]163[.]104 | |
| MD5 | 7b1ce3fe542c6ae2919aa94e20dc860e | |
| SHA-1 | 49a5852783fcefd9513b02d27a0304ae171f4459 | |
| SHA-256 | d071c4959d00a1ef9cce535056c6b01574d8a8104a7c3b00a237031ef930b10f | |
| MD5 | de0d57bdc10fee1e1e16e225788bb8de | |
| SHA-1 | 695d31cdac532be8e6d2a98220c0c55f3385aa0b | |
| SHA-256 | 33b89b8915aaa59a3c9db23343e8c249b2db260b9b10e88593b6ff2fb5f71d2b | |
| ipv4-addr | 134[.]119[.]177[.]107 | |
| MD5 | e9c2b8bd1583baf3493824bf7b3ec51e | |
| SHA-1 | 76f2c5f0312346caf82ed42148e78329f8d7b35a | |
| SHA-256 | 7ea294d30903c0ab690bc02b64b20af0cfe66a168d4622e55dee4d6233783751 | |
| ipv4-addr | 162[.]245[.]190[.]203 | |
| MD5 | 9b071311ecd1a72bfd715e34dbd1bd77 | |
| SHA-1 | 4a3f79d6821139bc1c3f44fb32e8450ee9705237 | |
| SHA-256 | 3c2c835042a05f8d974d9b35b994bcf8d5a0ce19128ebb362804c2d0f3eb42c0 | |
| ipv4-addr | 155[.]94[.]211[.]207 | |
| MD5 | 3e200093f737fcd1e4bd350f6ffb7d56 | |
| SHA-1 | 0e9e98d93463798645cc0a972a4ff6f99977318a | |
| SHA-256 | 28e4e7104cbffa97a0aa2f53b5ebcbcdba360ec416b34bb617e2f8891d204816 | |
| MD5 | 3764a0f1762a294f662f3bf86bac776f | |
| SHA-1 | 6a87d8df99ea58d8612fa58a58b1a3a9512f160e | |
| SHA-256 | f7f7b059b6a7dbd75b30b685b148025a0d4ceceab405e553ca28cacdeae43fab | |
| MD5 | 199a32712998c6d736a05b2dbd24a761 | |
| SHA-1 | 45e0d90bd0283a1262d5afff46232e0ad4227d3b | |
| SHA-256 | 88a5e4b24747648a4e3f0a2d5282b51683260f9208b06788fc858c44559da1e8 |
Provenienza
Allegato ufficiale CISA · 2022-06-03T18:28:03Z
SHA-512: b7fe8d9c874e9cf802d5afaf15460833094eef830c3d1dfb1006441e1edd378e2563c17f94dc7dff170630f8efa6c0d64078c1fffa137e5a7f62e86e2440b4e8
| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| MD5 | 05d38bc82d362dd57190e3cb397f807d | |
| SHA-1 | 52b04d348adf7e42e7c7d6c2ec9aabbcaba07188 | |
| SHA-256 | 4cd7efdb1a7ac8c4387c515a7b1925931beb212b95c4f9d8b716dbe18f54624f | |
| ipv4-addr | 151[.]106[.]30[.]120 |
Provenienza
Allegato ufficiale CISA · 2022-07-11T16:39:56Z
SHA-512: 7f0fa8b27be2ebc33d17105240ba6568ba36690fbcd7a7c19f0906c207d54c5237fdd77e889c9d5d6df08117f917a4b7cb791c26f46a40588b1c33e0fe27247e
- Fonte
- CISA Cybersecurity Advisories
- Entità pubblicatrice
- CISA
- Tipo entità
- Autorità nazionale
- Area
- North America · US
- Lingua originale
- en · traduzione in preparazione
- Pubblicazione
- 18/07/2022 14:00
- Condivisione
- TLP:CLEAR
- MITRE ATT&CK
- T1021.001, T1036.004, T1053.005, T1056.001, T1059.001, T1071.001, T1090, T1105, T1190, T1505.003, T1560.001, T1571, T1573.001, T9803
- CVE
- CVE-2021-44228, CVE-2022-22954, CVE-2022-22960
- Paese indicato
- US
Prodotti e versioni interessati
Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.
Azione indicata dalla fonte
Verificare l'applicabilita dell'advisory e applicare le mitigazioni ufficiali.
Riferimenti tecnici ufficiali
- https://www.cisa.gov/sites/default/files/publications/AA22-174A.stix.xml
- https://www.cisa.gov/sites/default/files/publications/MAR-10382254.r1.v1.WHITE_stix.xml
- https://www.cisa.gov/sites/default/files/publications/MAR-10382580.r1.v1.WHITE_stix.xml
- https://www.cisa.gov/uscert/sites/default/files/MAR-10382580.r2.v1.WHITE_stix.xml
- https://www.cisa.gov/sites/default/files/publications/AA22-174A_Joint_CSA_Malicious_Cyber_Actors_Exploiting_Log4Shell_in_Unpatched_VMware_Horizon_Systems_FINAL.pdf