CVE
CVE-2021-44228
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along wit
Exploitation IoCs 14
Domain cmpnst[.]info
Domain nfdo[.]shop
Domain rirosh[.]shop
Domain superr[.]buzz
Filename /bin/componist
Filename /bin/nfdo
Filename /bin/rcd
Filename /tmp/lte
SHA-256 2ac2877c9e4cd7d70673c0643eb16805977a9b8d55b6b2e5a6491db565cee1f
SHA-256 4f11db82193aebe710585b2faefd2b904b6fe6636f7dc25541cea0dd31adada4
SHA-256 5441be217e98051c284d584e830f9a7fc2153143fafee0dc9f6af197cec6c8c9
SHA-256 e4edfa8c6891f6815c05e73852212207cc454a42496d1a109e750c660368b5c1
IP 185[.]159[.]82[.]103
IP 185[.]220[.]101[.]34
MITRE ATT&CK TTPs 14
T1059.001 T1071.001 T1082 T1083 T1095 T1105 T1129 T1135 T1140 T1170 T1197 T1205.001 T1485 T1566
PowerShell
Execution
Web Protocols
Command And Control
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Non-Application Layer Protocol
Command And Control
Ingress Tool Transfer
Command And Control
Shared Modules
Execution
Network Share Discovery
Discovery
Deobfuscate/Decode Files or Information
Defense Evasion
T1170
BITS Jobs
Defense Evasion
Port Knocking
Defense Evasion
Data Destruction
Impact
Phishing
Initial Access