Datadog Security Labs · Crawled Jul 25, 2026
The gift that keeps on giving: A new opportunistic Log4j campaign | Datadog Security Labs
14 IoCs 1 Actors 1 Malware 1 CVEs
Read original article ↗
AI Summary
A new opportunistic campaign exploiting the Log4Shell vulnerability (CVE-2021-44228) has been observed targeting vulnerable Java applications. The attack uses obfuscated LDAP requests to deliver a malicious Java class, which downloads and executes a crypto-mining payload (XMRig) and establishes persistence via systemd or cron. The threat actor exfiltrates system information and maintains remote access through encrypted reverse shells using Perl and netcat.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 14 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 185[.]220[.]101[.]34 | Details → |
| IP | 185[.]159[.]82[.]103 | Details → |
| Domain | superr[.]buzz | Details → |
| Domain | cmpnst[.]info | Details → |
| Domain | nfdo[.]shop | Details → |
| Domain | rirosh[.]shop | Details → |
| SHA-256 | e4edfa8c6891f6815c05e73852212207cc454a42496d1a109e750c660368b5c1 | Details → |
| Filename | /tmp/lte | Details → |
| SHA-256 | 5441be217e98051c284d584e830f9a7fc2153143fafee0dc9f6af197cec6c8c9 | Details → |
| Filename | /bin/rcd | Details → |
| SHA-256 | 2ac2877c9e4cd7d70673c0643eb16805977a9b8d55b6b2e5a6491db565cee1f | Details → |
| Filename | /bin/componist | Details → |
| SHA-256 | 4f11db82193aebe710585b2faefd2b904b6fe6636f7dc25541cea0dd31adada4 | Details → |
| Filename | /bin/nfdo | Details → |
MITRE ATT&CK TTPs 72 techniques
T1003.002 Security Account Manager · Credential Access T1012 Query Registry · Discovery T1021.002 SMB/Windows Admin Shares · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1027.002 Software Packing · Defense Evasion T1027.003 Steganography · Defense Evasion T1027.013 Encrypted/Encoded File · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1053.003 Cron · Execution T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1056.002 GUI Input Capture · Collection T1057 Process Discovery · Discovery T1059.001 PowerShell · Execution T1060 T1060 T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1078.001 Default Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1085 T1085 T1089 T1089 T1090 Proxy · Command And Control T1095 Non-Application Layer Protocol · Command And Control T1102.001 Dead Drop Resolver · Command And Control T1105 Ingress Tool Transfer · Command And Control T1106 Native API · Execution T1110 Brute Force · Credential Access T1110.001 Password Guessing · Credential Access T1112 Modify Registry · Defense Evasion T1113 Screen Capture · Collection T1129 Shared Modules · Execution T1133 External Remote Services · Persistence T1135 Network Share Discovery · Discovery T1140 Deobfuscate/Decode Files or Information · Defense Evasion T1160 T1160 T1170 T1170 T1190 Exploit Public-Facing Application · Initial Access T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1197 BITS Jobs · Defense Evasion T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1205.001 Port Knocking · Defense Evasion T1212 Exploitation for Credential Access · Credential Access T1484.001 Group Policy Modification · Defense Evasion T1485 Data Destruction · Impact T1490 Inhibit System Recovery · Impact T1543.001 Launch Agent · Persistence T1543.002 Systemd Service · Persistence T1543.003 Windows Service · Persistence T1548.002 Bypass User Account Control · Privilege Escalation T1548.004 Elevated Execution with Prompt · Privilege Escalation T1555.003 Credentials from Web Browsers · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1564.003 Hidden Window · Defense Evasion T1566 Phishing · Initial Access T1570 Lateral Tool Transfer · Lateral Movement T1574.002 DLL Side-Loading · Persistence T1608.001 Upload Malware · Resource Development T1685 T1685 T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1018 Remote System Discovery · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1055.001 Dynamic-link Library Injection · Defense Evasion T1059.003 Windows Command Shell · Execution T1071.003 Mail Protocols · Command And Control T1087.002 Domain Account · Discovery T1210 Exploitation of Remote Services · Lateral Movement T1218.001 Compiled HTML File · Defense Evasion T1573.001 Symmetric Cryptography · Command And Control