<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Natacha Bakir on Senthorus Blog</title><link>https://blog.senthorus.ch/author/natacha-bakir/</link><description>Recent content in Natacha Bakir on Senthorus Blog</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Tue, 16 Jan 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.senthorus.ch/author/natacha-bakir/index.xml" rel="self" type="application/rss+xml"/><item><title>Ivanti VPN Zero-Day Exploits: CVE-2023-46805 &amp; CVE-2024-21887</title><link>https://blog.senthorus.ch/posts/cve_2023_46805_cve_2024_21887/</link><pubDate>Tue, 16 Jan 2024 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/cve_2023_46805_cve_2024_21887/</guid><description>&lt;img src="https://blog.senthorus.ch/CVE_2023_46805_CVE_2024_21887_0.png" alt="Featured image of post Ivanti VPN Zero-Day Exploits: CVE-2023-46805 &amp; CVE-2024-21887" />&lt;p>On January 10, 2024, Volexity reported an active exploitation of two zero-day vulnerabilities in Ivanti VPN devices. The 9.x, 22.x versions of Connect Secure (ICS), also known as Pulse Connect Secure and Ivanti Policy Secure gateways are affected by the &lt;a class="link" href="https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" target="_blank" rel="noopener"
>CVE-2023-46805&lt;/a> and the &lt;a class="link" href="https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" target="_blank" rel="noopener"
>CVE-2024-21887&lt;/a>.&lt;/p>
&lt;p>While the CVE-2023-46805 allows for Authentication Bypass in the web component of Ivanti Connect Secure (ICS), the CVE-2024-21887 is a command injection vulnerability. As the exploitation of these two combined vulnerabilities allow for remote execution across the VPN devices, it represents a serious risk of compromission, including keylogging, configuration data exfiltration, existing files modification, reverse tunnel enabling from the Virtual Private Network (VPN) appliance, and so on.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_46805_CVE_2024_21887_1.png"
loading="lazy"
alt="Volexity Report"
>&lt;/p>
&lt;p>Source: Volexity&lt;/p>
&lt;h2 id="how-the-incident-and-the-forensics-analysis-revealed-the-attack-chain">How the Incident and the Forensics analysis revealed the attack chain
&lt;/h2>&lt;p>During the second week of December 2023, Volexity detected suspicious lateral movement on the network of one of his customers. During their analysis, the Volexity Incident responders found webshells on multiple internal and external-facing web servers. Their incident response investigation revealed that the logs of the Ivanti VPN appliances had been wiped and their logging features had been disabled. After analyzing suspicious inbound and outbound communications from its management IP address, Volexity found that this activity originated from the device itself.&lt;/p>
&lt;p>Following an acquisition of disk and memory images, the forensic examination of the gathered data revealed valuable information about the attacker’s tools, malware, and operating methods. This forensics analysis uncovered two zero-day vulnerabilities, and allowed Volexity to discover the timeline of the attack and recreate two proof-of-concept exploits. Moreover, based on the tools and techniques used, such as the GLASSTOKEN webshell and specific credential harvesting techniques, Volexity attributes this attack to an unknown threat actor it tracks under the alias UTA0178.&lt;/p>
&lt;h2 id="mitre-attck">MITRE ATT&amp;amp;CK
&lt;/h2>&lt;ul>
&lt;li>T1056.001 – Keylogging&lt;/li>
&lt;li>T1068 – Privilege Escalation&lt;/li>
&lt;li>T1021 – Lateral Movement&lt;/li>
&lt;li>T1212 – Credential Access&lt;/li>
&lt;li>T1211 – Defense Evasion&lt;/li>
&lt;li>T1003 – Credential Access&lt;/li>
&lt;li>T1005 – Collection&lt;/li>
&lt;li>T1056 – Collection, Credential Access&lt;/li>
&lt;li>T1002 – Defense Evasion&lt;/li>
&lt;/ul>
&lt;h2 id="iocs">IOCs
&lt;/h2>&lt;h3 id="ip-addresses-and-hostnames">IP addresses and hostnames
&lt;/h3>&lt;table>
&lt;thead>
&lt;tr>
&lt;th>Value&lt;/th>
&lt;th>Entity type&lt;/th>
&lt;th>Description&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>206.189.208.156&lt;/td>
&lt;td>ipaddress&lt;/td>
&lt;td>DigitalOcean IP address tied to UTAO178&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>gpoaccess[.]com&lt;/td>
&lt;td>hostname&lt;/td>
&lt;td>Suspected UTA0178 domain discovered via domain registration patterns&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>webb-institute[.]com&lt;/td>
&lt;td>hostname&lt;/td>
&lt;td>Suspected UTA0178 domain discovered via domain registration patterns&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>symantke[.]com&lt;/td>
&lt;td>hostname&lt;/td>
&lt;td>UTAO178 domain used to collect credentials from compromised devices&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>75.145.243.85&lt;/td>
&lt;td>ipaddress&lt;/td>
&lt;td>UTA0178 IP address observed interacting with compromised devices&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>47.207.9.89&lt;/td>
&lt;td>ipaddress&lt;/td>
&lt;td>UTA0178 IP address tied to Cyberoam proxy network&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>98.160.48.170&lt;/td>
&lt;td>ipaddress&lt;/td>
&lt;td>UTA0178 IP address tied to Cyberoam proxy network&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>173.220.106.166&lt;/td>
&lt;td>ipaddress&lt;/td>
&lt;td>UTA0178 IP address tied to Cyberoam proxy network&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>73.128.178.221&lt;/td>
&lt;td>ipaddress&lt;/td>
&lt;td>UTA0178 IP address tied to Cyberoam proxy network&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>50.243.177.161&lt;/td>
&lt;td>ipaddress&lt;/td>
&lt;td>UTA0178 IP address tied to Cyberoam proxy network&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>50.213.208.89&lt;/td>
&lt;td>ipaddress&lt;/td>
&lt;td>UTA0178 IP address tied to Cyberoam proxy network&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>64.24.179.210&lt;/td>
&lt;td>ipaddress&lt;/td>
&lt;td>UTA0178 IP address tied to Cyberoam proxy network&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>75.145.224.109&lt;/td>
&lt;td>ipaddress&lt;/td>
&lt;td>UTA0178 IP address tied to Cyberoam proxy network&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>50.215.39.49&lt;/td>
&lt;td>ipaddress&lt;/td>
&lt;td>UTA0178 IP address tied to Cyberoam proxy network&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>71.127.149.194&lt;/td>
&lt;td>ipaddress&lt;/td>
&lt;td>UTA0178 IP address tied to Cyberoam proxy network&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>173.53.43.7&lt;/td>
&lt;td>ipaddress&lt;/td>
&lt;td>UTA0178 IP address tied to Cyberoam proxy network&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table>
&lt;h2 id="yara-rule">Yara Rule
&lt;/h2>&lt;p>The Yara rule is available &lt;a class="link" href="https://forums.ivanti.com/s/article/Recovery-Steps-Related-to-CVE-2023-46805-and-CVE-2024-21887?language=en_US" target="_blank" rel="noopener"
>here&lt;/a>.&lt;/p>
&lt;h2 id="conclusion-and-remediation-steps">Conclusion and Remediation steps
&lt;/h2>&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_46805_CVE_2024_21887_2.png"
loading="lazy"
alt="VPN attack detailed"
>&lt;/p>
&lt;h3 id="so-what-should-you-do-now">So, what should you do now?
&lt;/h3>&lt;p>Volexity said: &amp;ldquo;It is critically important that organizations immediately apply the available mitigation from Ivanti and the patch that will follow. However, applying mitigations and patches will not resolve past compromise. It is important that organizations running ICS VPN appliances review their logs, network telemetry, and Integrity Checker Tool results (past and present) to look for any signs of successful compromise.&amp;rdquo;&lt;/p>
&lt;p>Wiped logs and disabled log features are an easy to check and solid indication of compromise of the appliance. Also, Integrity Checker should return only SYS32100 events. If the integrity checker returns events such as SYS32039 and SYS32040, the chances are very high that the appliance is compromised.&lt;/p>
&lt;p>Mitigation actions can also be taken at the firewall level by denying traffic coming and going from/to the known IP IOCs. Appliances that are not used or with very low legit traffic should be disabled.&lt;/p>
&lt;h3 id="ivanti-remediation-steps-source-ivanti">Ivanti Remediation steps (source: Ivanti)
&lt;/h3>&lt;p>If exploitation has occurred, we believe it is likely that the threat actor has taken an export of your running configurations at time of exploit and left behind a Web shell file enabling backdoor future access. The mitigation we have provided blocks both the vulnerabilities and the webshell currently being used in the post-advisory activity we are currently tracking. We highly recommend doing the following:&lt;/p>
&lt;ul>
&lt;li>Backup the configuration of the appliance&lt;/li>
&lt;li>Factory reset the appliance
&lt;ul>
&lt;li>&lt;a class="link" href="https://forums.ivanti.com/s/article/Recovery-Steps-Related-to-CVE-2023-46805-and-CVE-2024-21887?language=en_US" target="_blank" rel="noopener"
>KB22964 - How to Reset a PCS/ICS Device to the Factory Default Settings via the Serial Console&lt;/a>&lt;/li>
&lt;/ul>
&lt;/li>
&lt;li>Once factory reset is complete, upgrade the appliance to the same version that you were running prior to factory reset.&lt;/li>
&lt;li>Restore the appliance configuration from backup
&lt;ul>
&lt;li>&lt;a class="link" href="https://forums.ivanti.com/s/article/Recovery-Steps-Related-to-CVE-2023-46805-and-CVE-2024-21887?language=en_US" target="_blank" rel="noopener"
>KB44759 - How to Backup &amp;amp; Restore the Binary configuration using Archiving Server&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://forums.ivanti.com/s/article/Recovery-Steps-Related-to-CVE-2023-46805-and-CVE-2024-21887?language=en_US" target="_blank" rel="noopener"
>KB44172 - Backup/restore binary configuration using REST API&lt;/a>&lt;/li>
&lt;/ul>
&lt;/li>
&lt;li>Revoke and reissue any stored certs that were on the appliance(s) impacted&lt;/li>
&lt;li>Reset the admin enable password&lt;/li>
&lt;li>Reset API keys stored on the appliance&lt;/li>
&lt;li>Reset the password of any local user defined on the gateway&lt;/li>
&lt;li>Reset license server credentials&lt;/li>
&lt;/ul>
&lt;p>ELCASecurity and Senthorus continue to monitor the situation and are fully available to their customers for technical support and incident response if necessary.&lt;/p>
&lt;h2 id="references">References
&lt;/h2>&lt;ul>
&lt;li>&lt;a class="link" href="https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/" target="_blank" rel="noopener"
>Volexity Blog&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" target="_blank" rel="noopener"
>Ivanti CVE-2023-46805 and CVE-2024-21887 Advisory&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://forums.ivanti.com/s/article/Recovery-Steps-Related-to-CVE-2023-46805-and-CVE-2024-21887?language=en_US" target="_blank" rel="noopener"
>Ivanti Recovery Steps&lt;/a>&lt;/li>
&lt;/ul></description></item><item><title>Cloud Snooper Threat Report</title><link>https://blog.senthorus.ch/posts/cloud_snooper_threat_report/</link><pubDate>Sat, 07 Oct 2023 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/cloud_snooper_threat_report/</guid><description>&lt;img src="https://blog.senthorus.ch/Hermetic_Wiper_Threat_Report.png" alt="Featured image of post Cloud Snooper Threat Report" />&lt;p>&lt;a class="link" href="Cloud_Snooper_Threat_Report.pdf" >Read the PDF&lt;/a>&lt;/p></description></item><item><title>Hermetic Wiper Threat Report</title><link>https://blog.senthorus.ch/posts/hermetic_wiper_threat_report/</link><pubDate>Tue, 26 Sep 2023 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/hermetic_wiper_threat_report/</guid><description>&lt;img src="https://blog.senthorus.ch/Hermetic_Wiper_Threat_Report.png" alt="Featured image of post Hermetic Wiper Threat Report" />&lt;p>&lt;a class="link" href="Hermetic_Wiper_Threat_Report.pdf" >Read the PDF&lt;/a>&lt;/p></description></item></channel></rss>