EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Ransomware

Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG

Official source
EudorIA operational summary

What it means

Priority 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Why it matters

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISOManagement
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Cybersecurity Advisory Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG Last Revised May 11, 2023 Alert Code AA23-131A Related topics: Malware, Phishing, and Ransomware , Cyber Threats and Response , Securing Networks SUMMARY The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) in response to the active exploitation of CVE-2023-27350 . This vulnerability occurs in certain versions of PaperCut NG and PaperCut MF and enables an unauthenticated actor to execute malicious code remotely without credentials. PaperCut released a patch in March 2023. According to FBI observed information, malicious actors exploited CVE-2023-27350 beginning in mid-April 2023 and continuing through the present. In early May 2023, also according to FBI information, a group self-identifying as the Bl00dy Ransomware Gang attempted to exploit vulnerable PaperCut servers against the Education Facilities Subsector. This joint advisory provides detection methods for exploitation of CVE-2023-27350 as well and indicators of compromise (IOCs) associated with Bl00dy Ransomware Gang activity. FBI and CISA strongly encourage users and administrators to immediately apply patches, and workarounds if unable to patch. FBI and CISA especially encourage organizations who did not patch immediately to assume compromise and hunt for malicious activity using the detection signatures in this CSA. If potential compromise is detected, organizations should apply the incident response recommendations included in this CSA. Download the PDF version of this report (653kb): AA23-131A_Malicious_Actors_Exploit_CVE-2023-27350_in_PapercCut_MF_and_NG.pdf (PDF, 652.93 KB ) For a downloadable copy of IOCs (55kb), see: AA

Indicatori CISA verificabili

45 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Copertura parziale: sono mostrati solo gli indicatori verificati e interpretabili.

Ultima verifica: 2026-09-26T05:00:46.950764+00:00

Scarica STIX 2.1

Questo allegato contiene 1 indicatori incompleti o non interpretabili, conservati nell'originale ma esclusi dall'export operativo. I valori mancanti non sono stati dedotti.

TipoIndicatore (non cliccabile)File
MD5e574ad52562fce9ea506f47e79516a52socks.exe
SHA-1d9f7a36db2a5117d73712fb93df23e3c2fc693fbsocks.exe
SHA-2566bb160ebdc59395882ff322e67e000a22a5c54ac777b6b1f10f1fef381df9c15socks.exe
domain-namestudy[.]abroad[.]ge
ipv4-addr89[.]105[.]216[.]106
ipv4-addr80[.]94[.]95[.]103
ipv4-addr5[.]8[.]18[.]233
ipv4-addr46[.]4[.]20[.]30
ipv4-addr206[.]197[.]244[.]75
ipv4-addr198[.]50[.]191[.]95
ipv4-addr195[.]123[.]246[.]20
ipv4-addr194[.]87[.]82[.]7
ipv4-addr176[.]97[.]76[.]163
ipv4-addr172[.]106[.]112[.]46
ipv4-addr102[.]130[.]112[.]157
email-addrprepalkeinuc0u[@]gmx[.]com
email-addrmain-office[@]data-highstream[.]com
email-addrfimaribahundqf[@]gmx[.]com
email-addrdecrypt[.]support[@]privyonline[.]com
MD5f0c715e8318bb8a57b7072144753acacupdate.dll
SHA-1587bbb7ef50a72954d4ef9b22b27d4a377adc2faupdate.dll
SHA-2560ce7c6369c024d497851a482e011ef1528ad270e83995d52213276edbe71403fupdate.dll
ipv4-addr92[.]118[.]36[.]199
email-addrtpyrcne[@]onionmail[.]org
ipv4-addr192[.]184[.]35[.]216
urlhttp://192[.]184[.]35[.]216:443/4591187629[.]exe
domain-nameupd488[.]windowservicecemter[.]com
domain-namewinserverupdates[.]com
domain-namewindowservicecenter[.]com
domain-namewindowservicecentar[.]com
domain-namewindowservicecemter[.]com
domain-namewindowcsupdates[.]com
domain-nameupdateservicecenter[.]com
domain-namenetviewremote[.]com
domain-nameanydeskupdates[.]com
domain-nameanydeskupdate[.]com
MD546fe07c07fd0f45ba45240ef9aae2a4446fe07c07fd0f45ba45240ef9aae2a44; undefined.exe
SHA-1b918f97c7c6ebc9594de3c8f2d9d75ecc292d02b46fe07c07fd0f45ba45240ef9aae2a44; undefined.exe
SHA-256c0f8aeeb2d11c6e751ee87c40ee609aceb1c1036706a5af0d3d78738b6cc412546fe07c07fd0f45ba45240ef9aae2a44; undefined.exe
domain-nameupd343[.]winserverupdates[.]com
domain-nameber6vjyb[.]com
ipv4-addr216[.]122[.]175[.]114
ipv4-addr5[.]8[.]18[.]240
ipv4-addr5[.]188[.]206[.]14
ipv4-addr192[.]160[.]102[.]164

Provenance

Allegato ufficiale CISA · 2023-05-13T04:30:45Z

SHA-512: ce50ed9c3ffc91458110bbbf621f993ed0b058559fbcb61fc18b3e707348a5b1096646dad1bc14300b0b7e5f06585aab621838bb0c60576054c9e9ebbf03a850

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
11/05/2023 14:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1033, T1059.001, T1059.003, T1068, T1486
CVE
CVE-2023-27350
Classification
Critical
Stated country
US
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Action indicated by the source

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Official technical references

Open the original source