EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Ransomware

Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications

Fonte ufficiale
Sintesi operativa EudorIA

Cosa significa

Priorità 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Perché conta

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Benefici operativi potenziali

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indicazioni da confermare sul perimetro tecnico e organizzativo del cliente.
Controlli pertinentiVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
DestinatariITSOCCISOManagement
Centro informazioni

Traduzione in elaborazione

CISA

Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.

Testo acquisito dalla fonte

Cybersecurity Advisory Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications Last Revised January 31, 2025 Alert Code AA25-022A Related topics: Organizations and Cyber Safety , Cyber Threats and Response , Incident Response Note: The CVEs in this advisory are unrelated to vulnerabilities (CVE-2025-0282 and CVE-2025-0283) in Ivanti’s Connect Secure, Policy Secure and ZTA Gateways. For more information on mitigating CVE -2025-0282 and CVE-2025-0283, see Ivanti Releases Security Updates for Connect Secure, Policy Secure, and ZTA Gateways . Summary The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory in response to exploitation in September 2024 of vulnerabilities in Ivanti Cloud Service Appliances (CSA): CVE-2024-8963 , an administrative bypass vulnerability; CVE-2024-9379 , a SQL injection vulnerability; and CVE-2024-8190 and CVE-2024-9380 , remote code execution vulnerabilities. According to CISA and trusted third-party incident response data, threat actors chained the listed vulnerabilities to gain initial access, conduct remote code execution (RCE), obtain credentials, and implant webshells on victim networks. The actors’ primary exploit paths were two vulnerability chains. One exploit chain leveraged CVE-2024-8963 in conjunction with CVE-2024-8190 and CVE-2024-9380 and the other exploited CVE-2024-8963 and CVE-2024-9379. In one confirmed compromise, the actors moved laterally to two servers. All four vulnerabilities affect Ivanti CSA version 4.6x versions before 519, and two of the vulnerabilities (CVE-2024-9379 and CVE-2024-9380) affect CSA versions 5.0.1 and below; according to Ivanti, these CVEs have not been exploited in version 5.0.[ 1 ] Ivanti CS

Indicatori CISA verificabili

82 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Copertura parziale: sono mostrati solo gli indicatori verificati e interpretabili. 1 allegati richiedono ancora verifica o un formato supportato.

Ultima verifica: 2026-09-26T04:09:01.177380+00:00

Scarica STIX 2.1

Questo allegato contiene 4 indicatori incompleti o non interpretabili, conservati nell'originale ma esclusi dall'export operativo. I valori mancanti non sono stati dedotti.

TipoIndicatore (non cliccabile)File
domain-namecri07nnrg958pkh6qhk0yrgy1e76p1od6[.]oast[.]fun
domain-namecri07nnrg958pkh6qhk0977u8c83jog6t[.]oast[.]fun
MD51b20e9310ca815f9e2bd366fb94e147f
MD5dd975310201079cacd4cde6facab8c1d
MD586b62ffd33597fd635e01b95f08bb996
MD5f7f81ae880a17975f60e1e0fe1a4048b
MD553c5b7d124f13039eb62409e1ec2089d
ipv4-addr104[.]168[.]133[.]228
ipv4-addr149[.]154[.]176[.]41
MD530f57e14596f1bcad7cc4284d1af4684
MD562a611f0f1a418876b11c9df3b56885b
MD5cacc30e2a5b2683e19e45dc4f191cebc
MD5c7d20ca6fe596009afaeb725fec8635f
MD5c2becc553b96ba27d60265d07ec3bd6c
MD5aa69300617faab4eb39b789ebfeb5abe
MD5698a752ec1ca43237cb1dc791700afde
MD5a50660fb31df96b3328640fdfbeea755
ipv4-addr45[.]141[.]215[.]17
MD5061e5946c9595e560d64d5a8c65be49eview.php
SHA-1cb6be7d4e741864817bd965ea4652364cccc9045view.php
SHA-256dcd04c0ac081fff41021d08cd882bcf70b696aa7824361ef23849e26f395148bview.php
SSDEEP3:hTEd8x+QWp0SRJkHAhen:FE2x+QWuHoeview.php
MD54895e11d30aa070fe45243a4e8b0e9ddbrokerDebug
SHA-120fecae6d41cce7a1f74313a3aeb97f7fa26895fbrokerDebug
SHA-256e35cf026057a3729387b7ecfb213ae62a611f0f1a418876b11c9df3b56885bedbrokerDebug
ipv4-addr64[.]176[.]49[.]160
ipv4-addr185[.]40[.]4[.]38
MD5c894f55c8fa9d92e2dd2c78172cff745
MD5f82847bccb621e6822a3947bc9ce9621
MD5ae51c891d2e895b5ca919d14edd42c26
ipv4-addr155[.]138[.]215[.]144
ipv4-addr188[.]172[.]229[.]15
ipv4-addr185[.]220[.]69[.]83
ipv4-addr185[.]199[.]103[.]196
ipv4-addr89[.]187[.]178[.]179
ipv4-addr216[.]73[.]162[.]56
ipv4-addr136[.]144[.]17[.]133
ipv4-addr136[.]144[.]17[.]145
ipv4-addr82[.]197[.]182[.]161
ipv4-addr154[.]213[.]185[.]230
ipv4-addr208[.]105[.]190[.]170
ipv4-addr185[.]40[.]4[.]95
ipv4-addr142[.]11[.]217[.]3
ipv4-addr134[.]195[.]90[.]71
MD5d13f71e51b38ffef6b9dc8efbed27615
MD5d88bfac2b43509abdc70308bef75e2a6
SHA-10f024f8487a9b908a8e81db7f6b4d85b70bbc212
SHA-2563d0def685838f95a056d4fb5267b17ec3cc1c7a75fae0e4526b305cb964a1b88
MD578cc672218949a9ec87407ad3bcb5db6
SHA-125b79b4984a567b501e71fb3c43530a9b65d1c6e
SHA-2567cc4ed7bfd2a6f56ee1427a951bac36ad4e4e23fb66002d2befd2305e2d01bf3
domain-nametxt[.]xj[.]hk
domain-namegggg[.]oyr2ohrm[.]eyes[.]sh
domain-nameggg[.]oyr2ohrm[.]eyes[.]sh
domain-namegg[.]oyr2ohrm[.]eyes[.]sh
urlhttps://file[.]io/frdZ9L18R7Nx
urlhttps://file[.]io/RBKuU8gicWt
urlhttps://file[.]io/E50vtqmJP5aa
ipv4-addr203[.]160[.]72[.]174
ipv4-addr67[.]217[.]228[.]83
ipv4-addr108[.]174[.]199[.]200
domain-namecdn[.]private-api[.]us[.]kg
urlhttps://pan[.]xj[.]hk/d/6401646e701f5f47518ecef48a308a36/redis
urlhttps://file[.]io/1zqvMYY1dpkk
ipv4-addr107[.]173[.]89[.]16
ipv4-addr38[.]207[.]159[.]76
ipv4-addr23[.]236[.]66[.]97
ipv4-addr216[.]131[.]75[.]53
ipv4-addr205[.]169[.]39[.]11
ipv4-addr154[.]64[.]226[.]166
ipv4-addr142[.]171[.]217[.]195
ipv4-addr156[.]234[.]193[.]18
ipv4-addr98[.]101[.]25[.]30
ipv4-addr206[.]189[.]156[.]69
ipv4-addr192[.]42[.]116[.]210
MD560d5648d35bacf5c7aa713b2a0d267d3rar.exe
SHA-1a62af4ac233d914a25e79ec0705e2a187ebd7567rar.exe
SHA-2564b16ea1b1273f8746cf399c71bfc1f5bff7378b5414b4ea044c55e0ee08c89d3rar.exe
SSDEEP12288:uPOMr1m/l86iW/YdYMl1trfDGbkg5eJmc1MziflRyHPTVL:uWMrE/a6iW/GYMljfDG4g5Xc+y7yHPThrar.exe
ipv4-addr203[.]160[.]86[.]69
domain-namebook[.]hacktricks[.]xyz
domain-nameip[.]sb

Provenienza

Allegato ufficiale CISA · 2025-01-21T18:42:13Z

SHA-512: c7080932f97c1ce2846cb6dcc9f33c7a38ed4dce5b255837f77f81d361d95e55a5b7c4c4bc93a6d8c01ce0c707927ecfd85ba0ffceefa0f02559105edf5846ff

Fonte
CISA Cybersecurity Advisories
Entità pubblicatrice
CISA
Tipo entità
Autorità nazionale
Area
North America · US
Lingua originale
en · traduzione in preparazione
Pubblicazione
31/01/2025 13:00
Condivisione
TLP:CLEAR
MITRE ATT&CK
T1059, T1068, T1071.001, T1140, T1190, T1210, T1219, T1505.003, T1548.003, T1552.001, T1556, T1564.002, T1595.002
CVE
CVE-2025-0282, CVE-2025-0283, CVE-2024-8963, CVE-2024-9379, CVE-2024-8190, CVE-2024-9380, CVE-2024-9381
Classificazione
Media
Paese indicato
US
Perimetro tecnico

Prodotti e versioni interessati

Verifica in corso
Informazione non ancora acquisita.

Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.

Azione indicata dalla fonte

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Riferimenti tecnici ufficiali

Apri la fonte originale