lotto results

Saturday, February 4, 2023

[New post] Large (hundreds) CVE-2021-21974 ESXi VMware based ESXiArgs (Nevada?) ransomware attacks

Site logo image jpluimers posted: "[Wayback/Archive] Massive ESXiArgs ransomware attack targets VMware ESXi servers worldwide Admins, hosting providers, and the French Computer Emergency Response Team (CERT-FR) warn that attackers actively target VMware ESXi servers unpatched against a t" The Wiert Corner - irregular stream of stuff

Large (hundreds) CVE-2021-21974 ESXi VMware based ESXiArgs (Nevada?) ransomware attacks

jpluimers

Feb 4

Shodan.io results for query html:"We hacked your company successfully" title:"How to Restore Your Files"[Wayback/Archive] Massive ESXiArgs ransomware attack targets VMware ESXi servers worldwide

Admins, hosting providers, and the French Computer Emergency Response Team (CERT-FR) warn that attackers actively target VMware ESXi servers unpatched against a two-year-old remote code execution vulnerability to deploy ransomware.
Tracked as CVE-2021-21974, the security flaw is caused by a heap overflow issue in the OpenSLP service that can be exploited by unauthenticated threat actors in low-complexity attacks.
"As current investigations, these attack campaigns appear to be exploiting the vulnerability CVE-2021-21974, for which a patch has been available since 23 February 2021," CERT-FR said.
"The systems currently targeted would be ESXi hypervisors in version 6.x and prior to 6.7."
To block incoming attacks, admins have to disable the vulnerable Service Location Protocol (SLP) service on ESXi hypervisors that haven't yet been updated.
CERT-FR strongly recommends applying the patch as soon as possible but adds that systems left unpatched should also be scanned to look for signs of compromise.
CVE-2021-21974 affects the following systems:
  • ESXi versions 7.x prior to ESXi70U1c-17325551
  • ESXi versions 6.7.x prior to ESXi670-202102401-SG
  • ESXi versions 6.5.x prior to ESXi650-202102101-SG

[Wayback/Archive] Esxi Ransomware Help and Support Topic (ESXiArgs / .args extension) - Page 2 - Ransomware Help & Tech Support (there are now 4 pages, most victims OVH, likely many more pages to follow)

[Wayback/Archive] How to Disable/Enable the SLP Service on VMware ESXi (76372)

[Wayback/Archive] html:"We hacked your company successfully" title:"How to Restore Your Files" - Shodan Search which resulted in the above image (I tweeted it at [Wayback/Archive] Jeroen Wiert Pluimers @wiert@mastodon.social on Twitter: "@vmiss33")

Commands used in [Wayback/Archive] Jeroen Wiert Pluimers @wiert@mastodon.social on Twitter: "@vmiss33 I did forget to disable SLP on a patched system, but doing that is easy as per kb.vmware.com/s/article/76372":

/etc/init.d/slpd status /etc/init.d/slpd stop esxcli system slp stats get esxcli network firewall ruleset set -r CIMSLP -e 0 chkconfig slpd off chkconfig --list | grep slpd

More links to follow, but I'm away from keyboard for most of the day.

--jeroen

Read more of this post "Large (hundreds) CVE-2021-21974 ESXi VMware based ESXiArgs (Nevada?) ransomware attacks"
Comment
Like
Tip icon image You can also reply to this email to leave a comment.

Unsubscribe to no longer receive posts from The Wiert Corner - irregular stream of stuff.
Change your email settings at manage subscriptions.

Trouble clicking? Copy and paste this URL into your browser:
http://wiert.me/2023/02/04/large-hundreds-cve-2021-21974-esxi-vmware-based-esxiargs-nevada-ransomware-attacks/

Powered by WordPress.com
Download on the App Store Get it on Google Play
at February 04, 2023
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

Forisk Research Quarterly Examines Timberland Value Changes and Ownership Trends

...

  • [New post] Tony Bennett Ft. Lady Gaga – You’re The Top
    Ayonline posted: " American singer, Tony Bennett come through with a new song title You're The Top Feat. Lady Gaga ...
  • [New post] The Z Blog: Money Matters
    sengssk posted: "A favorite expression is "pressure reveals character." Anyone who has played sports has probably...
  • [New post] Former Isidingo actress Kim Engelbrecht gets a nod from the 2022 Emmy Awards
    Porti...

Search This Blog

  • Home

About Me

lotto result
View my complete profile

Report Abuse

Blog Archive

  • April 2026 (1)
  • March 2026 (6)
  • February 2026 (2)
  • January 2026 (3)
  • December 2025 (1)
  • November 2025 (1)
  • September 2025 (5)
  • August 2025 (3)
  • July 2025 (2)
  • June 2025 (3)
  • May 2025 (2)
  • March 2025 (5)
  • February 2025 (3)
  • January 2025 (4)
  • December 2024 (2)
  • November 2024 (1)
  • October 2024 (3)
  • September 2024 (4)
  • June 2023 (176)
  • May 2023 (1209)
  • April 2023 (1076)
  • March 2023 (1208)
  • February 2023 (912)
  • January 2023 (998)
  • December 2022 (1022)
  • November 2022 (1082)
  • October 2022 (1580)
  • September 2022 (1476)
  • August 2022 (1694)
  • July 2022 (1786)
  • June 2022 (1251)
  • May 2022 (1056)
  • April 2022 (1443)
  • March 2022 (1328)
  • February 2022 (1092)
  • January 2022 (1332)
  • December 2021 (1657)
  • November 2021 (3162)
  • October 2021 (3225)
  • September 2021 (3171)
  • August 2021 (3282)
  • July 2021 (1390)
Powered by Blogger.