EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Avviso tecnico

APT Actors Exploiting CVE-2021-44077 in Zoho ManageEngine ServiceDesk Plus

Fonte ufficiale
Sintesi operativa EudorIA

Cosa significa

Priorità 95/100

CISA Cybersecurity Advisories ha pubblicato l'advisory "APT Actors Exploiting CVE-2021-44077 in Zoho ManageEngine ServiceDesk Plus". La fonte segnala sfruttamento attivo e richiede una verifica prioritaria.

Perché conta

La fonte segnala sfruttamento attivo. La priorita dipende dalla presenza della tecnologia interessata nel perimetro; il testo acquisito non consente di dedurre ulteriori impatti tecnici.

Benefici operativi potenziali

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indicazioni da confermare sul perimetro tecnico e organizzativo del cliente.
Controlli pertinentiVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
DestinatariITSOCCISO
Centro informazioni

Traduzione in elaborazione

CISA

Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.

Testo acquisito dalla fonte

Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs. Cybersecurity Advisory APT Actors Exploiting CVE-2021-44077 in Zoho ManageEngine ServiceDesk Plus Last Revised December 06, 2021 Alert Code AA21-336A Summary This joint Cybersecurity Advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework, Version 9. See the ATT&CK for Enterprise framework for referenced threat actor techniques and for mitigations. This joint advisory is the result of analytic efforts between the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) to highlight the cyber threat associated with active exploitation of a newly identified vulnerability (CVE-2021-44077) in Zoho ManageEngine ServiceDesk Plus—IT help desk software with asset management. CVE-2021-44077, which Zoho rated critical, is an unauthenticated remote code execution (RCE) vulnerability affecting all ServiceDesk Plus versions up to, and including, version 11305. This vulnerability was addressed by the update released by Zoho on September 16, 2021 for ServiceDesk Plus versions 11306 and above. The FBI and CISA assess that advanced persistent threat (APT) cyber actors are among those exploiting the vulnerability. Successful exploitation of the vulnerability allows an attacker to upload executable files and place webshells, which enable the adversary to conduct post-exploitation activities, such as compromising administrator credentials, conducting lateral movement, and exfiltrating registry hives and Active Directory files. The Zoho update that patched this vulnerability was released on September 16, 2021, along with a security advisory . Additionally, an e

Indicatori CISA verificabili

51 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Ultima verifica: 2026-09-26T06:00:39.047948+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
domain-nameseed[.]nkn[.]org
MD5f54cc5c819060f365f329ecf0ad57cc3csvde.exe; ldifldap.lib
SHA-1c8c950a3be076cc7998d382f0c7ca346c68a37f4csvde.exe; ldifldap.lib
SHA-2567d2780cd9acc516b6817e9a51b8e2889f2dec455295ac6e6d65a6191abadebffcsvde.exe; ldifldap.lib
SHA-512f6f2a9af90a1376de56dc70896c57956229638c624eda1f5b80b9a04e6c259e6f7b6bc19acf94c66e297703012f8016be2ca93ceb475de476399c4b9a71dfb31csvde.exe; ldifldap.lib
SSDEEP1536:rCxaaepTj5a24nMKZW8t9jHweAryyTF6tJ8zwv8:rCx0pxdErw8t9jHwewYtJ8zw8csvde.exe; ldifldap.lib
MD575614d55fe4115836ab37583ab7cb627
SHA-10bfaf17b1150fb81ab50cf17ad416215cf8cabd6
SHA-256d0c3d7003b7f5b4a3bd74a41709cfecfabea1f94b47e1162142de76aa7a063c7
MD5b88f173337ab103181feb33681f0b297user64.dll
SHA-16287004d7d40d23809273abde38101a580906db8user64.dll
SHA-256e391c2d3e8e4860e061f69b894cf2b1ba578a3e91de610410e7e9fa87c07304cuser64.dll
MD5eb1d1ffe82fe0b45b239211004c79c3d
SHA-1d56b0d300e16109b5057d4377ef6c12fce41e71e
SHA-2567e4038e18b5104683d2a33650d8c02a6a89badf30ca9174576bf0aff08c03e72
MD5f87bc58e35d016df4415f14045d7f068
SHA-1531f96a53f3132c371ecf9d18b2e3922f6d44998
SHA-256342a6d21984559accbc54077db2abf61fd9c3939a4b09705f736231cbc7836ae
MD553ff174fbeff97b6b5240bb0c6fc787f
SHA-1230cde320203402bc8a92a850586f47c662d6d3d
SHA-2563f868ac52916ebb6f6186ac20b20903f63bc8e9c460e2418f2b032a207d8f21d
MD52ec83e10f64e17bf2fbf63937387ecb9
SHA-10b6ed86959a895609ef5d346bf11ac7d4bc9f0f8
SHA-2565b8c307c424e777972c0fa1322844d4d04e9eb200fe9532644888c4b6386d755
MD58a9e05ffd1bc86dfefa4f69944f43db8
SHA-166128391cf66844359ab7cc58c5f61f5761eb94b
SHA-2563da8d1bfb8192f43cf5d9247035aa4445381d2d26bed981662e3db34824c71fd
MD5aedebba95462e9db10b834551e3abc03
SHA-1551c8f9200aa77d9bc94260a516522619016e2b7
SHA-256805b92787ca7833eef5e61e2df1310e4b6544955e812e60b5f834f904623fd9f
SHA-256342e85a97212bb833803e06621170c67f6620f08cc220cf2d8d44dff7f4b1fa3
SHA-256083bdabbb87f01477f9cf61e78d19123b8099d04c93ef7ad4beb19f4a228589a
SHA-256009d23d85c1933715c3edcccb46438690a66eebbcccb690a7b27c9483ad9d0ac
MD5d5fb8672ddf488180f10d4d10da22ffereports.jsp
SHA-192fe8e978d5d5e92bed4a00dc0efeeb5dd22367areports.jsp
SHA-2565475aec3b9837b514367c89d8362a9d524bfa02e75b85b401025588839a40bcbreports.jsp
SHA-25675574959bbdad4b4ac7b16906cd8f1fd855d2a7df8e63905ab18540e2d6f1600
SHA-256ce310ab611895db1767877bd1f635ee3c4350d6e17ea28f8d100313f62b87382
SHA-256a44a5e8e65266611d5845d88b43c9e4a9d84fe074fd18f48b50fb837fa6e429d
SHA-256262cf67af22d37b5af2dc71d07a00ef02dc74f71380c72875ae1b29a3a5aa23d
SHA-256759bd8bd7a71a903a26ac8d5914e5b0093b96de61bf5085592be6cc96880e088
SHA-25667ee552d7c1d46885b91628c603f24b66a9755858e098748f7e7862a71baa015
MD5e7fb52c90fcc75f9b25e2d56d67a4209msiexec.exe
SHA-1d2291a1e58d35642aeacfc20fb98e33f48dc6dddmsiexec.exe
SHA-256ecd8c9967b0127a12d6db61964a82970ee5d38f82618d5db4d8eddbb3b5726b7msiexec.exe
SHA-256bec067a0601a978229d291c82c35a41cd48c6fca1a3c650056521b01d15a72da
SHA-256b4162f039172dcb85ca4b85c99dd77beb70743ffd2e6f9e0ba78531945577665
SHA-2563c90df0e02cc9b1cf1a86f9d7e6f777366c5748bd3cf4070b49460b48b4d4090
MD5182c7aefcce4cec2aa65ea2518fbbb13
SHA-118e17923508f7859b154e1fd4ed48c23519756ce
SHA-256068d1b3813489e41116867729504c40019ff2b1fe32aab4716d429780e666324

Provenienza

Allegato ufficiale CISA · 2021-12-03T20:44:15Z

SHA-512: e828a14711a50ca12f27a543df8f8ca56020c8a47303d498b2648cd514adc003191b6580716a12d5930e504301c980df9529c2c5e5d21442f8542a9ed6518c17

Fonte
CISA Cybersecurity Advisories
Entità pubblicatrice
CISA
Tipo entità
Autorità nazionale
Area
North America · US
Lingua originale
en · traduzione in preparazione
Pubblicazione
06/12/2021 13:00
Condivisione
TLP:CLEAR
MITRE ATT&CK
T1003, T1003.003, T1027, T1047, T1070.004, T1087.002, T1136, T1140, T1190, T1218, T1505.003, T1560.001, T1573.001
CVE
CVE-2021-44077
Classificazione
Critica
Paese indicato
US
Perimetro tecnico

Prodotti e versioni interessati

Verifica in corso
Informazione non ancora acquisita.

Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.

Azione indicata dalla fonte

Verificare l'applicabilita dell'advisory e applicare le mitigazioni ufficiali.

Riferimenti tecnici ufficiali

Apri la fonte originale