APT Actors Exploiting CVE-2021-44077 in Zoho ManageEngine ServiceDesk Plus
Cosa significa
CISA Cybersecurity Advisories ha pubblicato l'advisory "APT Actors Exploiting CVE-2021-44077 in Zoho ManageEngine ServiceDesk Plus". La fonte segnala sfruttamento attivo e richiede una verifica prioritaria.
Perché conta
La fonte segnala sfruttamento attivo. La priorita dipende dalla presenza della tecnologia interessata nel perimetro; il testo acquisito non consente di dedurre ulteriori impatti tecnici.
Azioni consigliate
- Verificare l'applicabilita dell'advisory e applicare le mitigazioni ufficiali.
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Benefici operativi potenziali
- Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
- Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
- Validazione documentata della capacita di ripristino
Traduzione in elaborazione
Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.
Testo acquisito dalla fonte
Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs. Cybersecurity Advisory APT Actors Exploiting CVE-2021-44077 in Zoho ManageEngine ServiceDesk Plus Last Revised December 06, 2021 Alert Code AA21-336A Summary This joint Cybersecurity Advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework, Version 9. See the ATT&CK for Enterprise framework for referenced threat actor techniques and for mitigations. This joint advisory is the result of analytic efforts between the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) to highlight the cyber threat associated with active exploitation of a newly identified vulnerability (CVE-2021-44077) in Zoho ManageEngine ServiceDesk Plus—IT help desk software with asset management. CVE-2021-44077, which Zoho rated critical, is an unauthenticated remote code execution (RCE) vulnerability affecting all ServiceDesk Plus versions up to, and including, version 11305. This vulnerability was addressed by the update released by Zoho on September 16, 2021 for ServiceDesk Plus versions 11306 and above. The FBI and CISA assess that advanced persistent threat (APT) cyber actors are among those exploiting the vulnerability. Successful exploitation of the vulnerability allows an attacker to upload executable files and place webshells, which enable the adversary to conduct post-exploitation activities, such as compromising administrator credentials, conducting lateral movement, and exfiltrating registry hives and Active Directory files. The Zoho update that patched this vulnerability was released on September 16, 2021, along with a security advisory . Additionally, an e
Indicatori CISA verificabili
51 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.
Ultima verifica: 2026-09-26T06:00:39.047948+00:00
Scarica STIX 2.1| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| domain-name | seed[.]nkn[.]org | |
| MD5 | f54cc5c819060f365f329ecf0ad57cc3 | csvde.exe; ldifldap.lib |
| SHA-1 | c8c950a3be076cc7998d382f0c7ca346c68a37f4 | csvde.exe; ldifldap.lib |
| SHA-256 | 7d2780cd9acc516b6817e9a51b8e2889f2dec455295ac6e6d65a6191abadebff | csvde.exe; ldifldap.lib |
| SHA-512 | f6f2a9af90a1376de56dc70896c57956229638c624eda1f5b80b9a04e6c259e6f7b6bc19acf94c66e297703012f8016be2ca93ceb475de476399c4b9a71dfb31 | csvde.exe; ldifldap.lib |
| SSDEEP | 1536:rCxaaepTj5a24nMKZW8t9jHweAryyTF6tJ8zwv8:rCx0pxdErw8t9jHwewYtJ8zw8 | csvde.exe; ldifldap.lib |
| MD5 | 75614d55fe4115836ab37583ab7cb627 | |
| SHA-1 | 0bfaf17b1150fb81ab50cf17ad416215cf8cabd6 | |
| SHA-256 | d0c3d7003b7f5b4a3bd74a41709cfecfabea1f94b47e1162142de76aa7a063c7 | |
| MD5 | b88f173337ab103181feb33681f0b297 | user64.dll |
| SHA-1 | 6287004d7d40d23809273abde38101a580906db8 | user64.dll |
| SHA-256 | e391c2d3e8e4860e061f69b894cf2b1ba578a3e91de610410e7e9fa87c07304c | user64.dll |
| MD5 | eb1d1ffe82fe0b45b239211004c79c3d | |
| SHA-1 | d56b0d300e16109b5057d4377ef6c12fce41e71e | |
| SHA-256 | 7e4038e18b5104683d2a33650d8c02a6a89badf30ca9174576bf0aff08c03e72 | |
| MD5 | f87bc58e35d016df4415f14045d7f068 | |
| SHA-1 | 531f96a53f3132c371ecf9d18b2e3922f6d44998 | |
| SHA-256 | 342a6d21984559accbc54077db2abf61fd9c3939a4b09705f736231cbc7836ae | |
| MD5 | 53ff174fbeff97b6b5240bb0c6fc787f | |
| SHA-1 | 230cde320203402bc8a92a850586f47c662d6d3d | |
| SHA-256 | 3f868ac52916ebb6f6186ac20b20903f63bc8e9c460e2418f2b032a207d8f21d | |
| MD5 | 2ec83e10f64e17bf2fbf63937387ecb9 | |
| SHA-1 | 0b6ed86959a895609ef5d346bf11ac7d4bc9f0f8 | |
| SHA-256 | 5b8c307c424e777972c0fa1322844d4d04e9eb200fe9532644888c4b6386d755 | |
| MD5 | 8a9e05ffd1bc86dfefa4f69944f43db8 | |
| SHA-1 | 66128391cf66844359ab7cc58c5f61f5761eb94b | |
| SHA-256 | 3da8d1bfb8192f43cf5d9247035aa4445381d2d26bed981662e3db34824c71fd | |
| MD5 | aedebba95462e9db10b834551e3abc03 | |
| SHA-1 | 551c8f9200aa77d9bc94260a516522619016e2b7 | |
| SHA-256 | 805b92787ca7833eef5e61e2df1310e4b6544955e812e60b5f834f904623fd9f | |
| SHA-256 | 342e85a97212bb833803e06621170c67f6620f08cc220cf2d8d44dff7f4b1fa3 | |
| SHA-256 | 083bdabbb87f01477f9cf61e78d19123b8099d04c93ef7ad4beb19f4a228589a | |
| SHA-256 | 009d23d85c1933715c3edcccb46438690a66eebbcccb690a7b27c9483ad9d0ac | |
| MD5 | d5fb8672ddf488180f10d4d10da22ffe | reports.jsp |
| SHA-1 | 92fe8e978d5d5e92bed4a00dc0efeeb5dd22367a | reports.jsp |
| SHA-256 | 5475aec3b9837b514367c89d8362a9d524bfa02e75b85b401025588839a40bcb | reports.jsp |
| SHA-256 | 75574959bbdad4b4ac7b16906cd8f1fd855d2a7df8e63905ab18540e2d6f1600 | |
| SHA-256 | ce310ab611895db1767877bd1f635ee3c4350d6e17ea28f8d100313f62b87382 | |
| SHA-256 | a44a5e8e65266611d5845d88b43c9e4a9d84fe074fd18f48b50fb837fa6e429d | |
| SHA-256 | 262cf67af22d37b5af2dc71d07a00ef02dc74f71380c72875ae1b29a3a5aa23d | |
| SHA-256 | 759bd8bd7a71a903a26ac8d5914e5b0093b96de61bf5085592be6cc96880e088 | |
| SHA-256 | 67ee552d7c1d46885b91628c603f24b66a9755858e098748f7e7862a71baa015 | |
| MD5 | e7fb52c90fcc75f9b25e2d56d67a4209 | msiexec.exe |
| SHA-1 | d2291a1e58d35642aeacfc20fb98e33f48dc6ddd | msiexec.exe |
| SHA-256 | ecd8c9967b0127a12d6db61964a82970ee5d38f82618d5db4d8eddbb3b5726b7 | msiexec.exe |
| SHA-256 | bec067a0601a978229d291c82c35a41cd48c6fca1a3c650056521b01d15a72da | |
| SHA-256 | b4162f039172dcb85ca4b85c99dd77beb70743ffd2e6f9e0ba78531945577665 | |
| SHA-256 | 3c90df0e02cc9b1cf1a86f9d7e6f777366c5748bd3cf4070b49460b48b4d4090 | |
| MD5 | 182c7aefcce4cec2aa65ea2518fbbb13 | |
| SHA-1 | 18e17923508f7859b154e1fd4ed48c23519756ce | |
| SHA-256 | 068d1b3813489e41116867729504c40019ff2b1fe32aab4716d429780e666324 |
Provenienza
Allegato ufficiale CISA · 2021-12-03T20:44:15Z
SHA-512: e828a14711a50ca12f27a543df8f8ca56020c8a47303d498b2648cd514adc003191b6580716a12d5930e504301c980df9529c2c5e5d21442f8542a9ed6518c17
- Fonte
- CISA Cybersecurity Advisories
- Entità pubblicatrice
- CISA
- Tipo entità
- Autorità nazionale
- Area
- North America · US
- Lingua originale
- en · traduzione in preparazione
- Pubblicazione
- 06/12/2021 13:00
- Condivisione
- TLP:CLEAR
- MITRE ATT&CK
- T1003, T1003.003, T1027, T1047, T1070.004, T1087.002, T1136, T1140, T1190, T1218, T1505.003, T1560.001, T1573.001
- CVE
- CVE-2021-44077
- Classificazione
- Critica
- Paese indicato
- US
Prodotti e versioni interessati
Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.
Azione indicata dalla fonte
Verificare l'applicabilita dell'advisory e applicare le mitigazioni ufficiali.