CVE

CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along wit

Exploitation IoCs 14

Domain cmpnst[.]info
Domain nfdo[.]shop
Domain rirosh[.]shop
Domain superr[.]buzz
Filename /bin/componist
Filename /bin/nfdo
Filename /bin/rcd
Filename /tmp/lte
SHA-256 2ac2877c9e4cd7d70673c0643eb16805977a9b8d55b6b2e5a6491db565cee1f
SHA-256 4f11db82193aebe710585b2faefd2b904b6fe6636f7dc25541cea0dd31adada4
SHA-256 5441be217e98051c284d584e830f9a7fc2153143fafee0dc9f6af197cec6c8c9
SHA-256 e4edfa8c6891f6815c05e73852212207cc454a42496d1a109e750c660368b5c1
IP 185[.]159[.]82[.]103
IP 185[.]220[.]101[.]34

MITRE ATT&CK TTPs 14

Source Articles