title: Exploited CVE-2020-10189 Zoho ManageEngine id: 846b866e-2a57-46ee-8e16-85fa92759be7 status: test description: Detects the exploitation of Zoho ManageEngine Desktop Central Java Deserialization vulnerability reported as CVE-2020-10189 references: - https://www.fireeye.com/blog/threat-research/2020/03/apt41-initiates-global-intrusion-campaign-using-multiple-exploits.html - https://vulmon.com/exploitdetails?qidtp=exploitdb&qid=48224 author: Florian Roth (Nextron Systems) date: 2020-03-25 modified: 2023-01-21 tags: - attack.initial-access - attack.t1190 - attack.execution - attack.t1059.001 - attack.t1059.003 - attack.s0190 - cve.2020-10189 - detection.emerging-threats logsource: category: process_creation product: windows detection: selection: ParentImage|endswith: 'DesktopCentral_Server\jre\bin\java.exe' Image|endswith: - '\cmd.exe' - '\powershell.exe' - '\pwsh.exe' - '\bitsadmin.exe' - '\systeminfo.exe' - '\net.exe' - '\net1.exe' - '\reg.exe' - '\query.exe' condition: selection falsepositives: - Unknown level: high