Rewterz Threat Advisory – CVE-2021-1359 – Cisco Web Security Appliance Privilege Escalation Vulnerability
July 8, 2021Rewterz Threat Advisory –ICS: Rockwell Automation MicroLogix 1100
July 9, 2021Rewterz Threat Advisory – CVE-2021-1359 – Cisco Web Security Appliance Privilege Escalation Vulnerability
July 8, 2021Rewterz Threat Advisory –ICS: Rockwell Automation MicroLogix 1100
July 9, 2021Severity
High
Analysis Summary
On the Fourth of July weekend, around 200 organizations all over the world were hit with a ransomware attack. Investigators are calling this the “largest ransomware attack in history.” The REvil ransomware group exploited the Kaseya VSA tool used to perform client monitoring and patch management by MSPs. The gang initially compromised the VSA software, and then deployed their ransomware on the on-premise servers of enterprise networks.
This is an ongoing attack and more than 20 MSPs have been compromised as of yet. FBI is helping the company investigate this incident and organizations and vendors affected by the attack have also released advisories on patches and remediations for the attack. The initial ransomware demand was $44,999
Impact
- Data Encryption
Indicators of Compromise
MD5
- 5de6ec9265f79a31a9845c8a504d28f0
SHA-256
- 32fc03caa22bc3bbf778b04da675e528dd7125a61da6f9fc5e532230745bcd8c
SHA1
- 7b6621202ac7795e89891b7bd65e769ba6c267c5
URL
- http[:]//31[.]42[.]177[.]52/dpixel
- http[:]//31[.]42[.]177[.]52/submit[.]php
- http[:]//45[.]153[.]241[.]113/download/pload[.]exe
Remediation
Block all threat indicators at your respective controls.
This tool analyzes a system (either VSA server or managed endpoint) and discovers whether any (IoC) are present. Download the Kaseya VSA Detection Tool.
Search for IOCs in your environment.