EXPL_Log4j_CVE_2021_44228_Dec21_Hard

Rule Info

Score
80
Name
EXPL_Log4j_CVE_2021_44228_Dec21_Hard
Description
Detects indicators in server logs that indicate the exploitation of CVE-2021-44228
Av Ratio
3.94
Author
Florian Roth
Tags
['DEMO', 'EXPLOIT', 'CVE_2021_44228']
Modified
2021-12-12
Rule Hash
d8e8ce230cccc21fdcd4b3304dd68220
Minimum Yara
2.2.0
Date
2021-12-10
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
7
Suspicious (< 10 engines)
13
Clean (0 engines)
39

Rule Matches

Positives
Hash
Total
Timestamp
VT
0
304f2b6338c37cf4ce9b4d8bd8f3de0c2b940a0875ecbfbdd53016023d799d50
56
2022-01-20 10:19:05
0
da3e9073b363183ad66aa733be7160026ce1b23852687c42e5f4cc7a07f4552a
56
2022-01-20 09:07:38
0
61c6099cc4895a19dce1f4c49c2dc92a173adce0fa423741fcf6fed70fcc985d
57
2022-01-14 12:02:14
0
66adf30e744f72906e1f07aae82d8326159f3b26ca7befaf8f144030d345e78a
58
2022-01-12 09:27:23
1
22611b4a70d19eabd1971b191d6965fb880651d52c6c7da437b9f52e19e2fa21
57
2022-01-10 19:18:05
0
cb536c90a751e66d0ad62823089a9254d2dcc9b02ee08cd804586e8c1ba39bf5
57
2022-01-10 11:46:43
1
b906deb8ae83616fab2f1190472f54f114862903feda360bfa6b494dcce34f71
58
2022-01-10 05:02:04
1
89eb10301fd2da791f383591b8a9c4b2a7d85864d2fe93dcedd31b0a40c267a6
57
2022-01-09 14:39:06
0
93678ac9ce8ca1637e2bac6009702b8b5c278f2cb75f02bc0a41bd1f5addcf3e
55
2022-01-05 08:31:58
0
4c82c0a5e413245a8b28a517a75a277001fd140e5bda258fa6b6f6c91506aa5d
56
2022-01-03 19:03:28
0
83b1f868940a46ee17cbc47ec8461ecd9b85c1951403d5ae43c9ac46631eb2ec
57
2021-12-31 15:12:21
0
d1e8c08e3444b58245337eb435acc8ff22703fe5896f2775d86b5839a9dab6f3
57
2021-12-31 12:08:35
0
e2f5bbe2a3871929c17fdd8b4db52d80cf95ff79573fc2c6825a9152b8625c48
58
2021-12-29 09:03:19
0
1a6e61690df52dc61f090fd237cddbd2127663309c1340064ac211aa5b762c80
55
2021-12-28 20:40:23
11
ffdde170d837231077e6288af31f4c3155cd63d4e3c50d92fe67af7a79a9681e
58
2021-12-25 16:05:05
0
df797fc7a9fb519e23d88a94a929a538d54e7195ef67774454e51b709ccc00df
58
2021-12-25 01:02:22
0
48f8feabb0509204eed1ea1ee8b9834a85fc6eb30a647d26437eb82b08fe7beb
58
2021-12-24 23:44:12
1
54eff90297dc533f121580e1d3989884c79350253853c3a65cab30c69685aaa2
57
2021-12-24 13:05:54
0
e851968b3af789c085367d894a9843c0f249fb295ebd477aef70cb2195f389f2
58
2021-12-24 05:27:32
1
8ed1af41fca7a41c12af08272d3eec4c0986a4095cce634443fc626d28b55825
57
2021-12-22 19:21:04
0
6bcc72c197d2f551021f2afa110ea49f86a8e81f795f2a3007bdd1beb39cd4a4
58
2021-12-22 00:22:41
0
5442701fe1afb043111a9f07c2025148705037fd25b6a7615adc51e137ba1338
57
2021-12-21 18:19:04
0
2c9e2437faaa526c00c65ddb0bd2df518196c2fd72ece4f73add5f1b940ec336
58
2021-12-21 13:10:59
0
ef801abe950cf97b8226761028e776135259c83cab63e85a634b288a9dff828b
58
2021-12-21 13:05:35
0
4c3642a75ac8a08343e79416ad2eca6d3b6e09d3b40ce38f6b5b7c3538de93e5
56
2021-12-21 12:25:53
2
e798ccba97543ada249ba0240cdcc59e23c190d072de9c39ce879fb7907a34f8
51
2021-12-21 10:17:52
3
094da9fb31b753ed07a99720ee6b251f0d0034ae633f81bb21613f0f9f944d70
57
2021-12-21 09:48:17
20
f3a96395e92828d8ae0c352d9afe3623a9e4e31866b8b3b0cb9fd341a2e61291
61
2021-12-20 20:25:31
2
ed90dc5cfbf507f5cb698cc8d21a80ecec08ca176996e065594d0df0cac9ddb2
40
2021-12-20 20:20:43
2
68002d212e725e1477ae5a345677a9fed74c4ca7542a3b26eec0f064ea9c97bd
60
2021-12-20 20:15:36
1
27472ae94cf677c3eebd7047ff78e581c789f1e635a223a5ca5ebbc4ae4bf5b0
57
2021-12-20 09:44:17
0
41e71020c34f223c016aab8051c853f5b6e5c4fd4f161dadde6c740d38303957
57
2021-12-20 08:19:58
0
aabab7a675d314289bdc37cf95c7d368295f6288a596ec42513168704fcc97d1
58
2021-12-20 08:16:34
0
dc819b2567142b5c828a1ee78bd7290cac562ba45a3155a1f215c73151fc7f47
57
2021-12-19 11:22:17
0
dcfe1f489dbbbe6b752ddfb514cc16c8d78b0b210f3ab08713064aa0e3983be3
58
2021-12-19 10:12:07
0
d745f8a2f21ab3abfdb3d44ef5f9873e287e3b71b52b144961a918250182eb89
58
2021-12-19 09:51:38
9
dca21162a4237b761ee3a4ae9be880b480f6646d0269a9bc36782d564afd912d
57
2021-12-19 07:33:19
10
e3a31461aed1ed1de1df536fb913274884bea7ea9a9ee2a7a0ce05f506e745d5
57
2021-12-19 07:33:19
0
aeb100cc673027fc32f15da25170651a562111460a5741ad06148d00dee26ca7
57
2021-12-19 07:09:08
5
9759a200b1d2c39812691047ce9c74fb07d21d07374b02b31c7b08c68b61c17a
58
2021-12-18 01:31:07
0
cf68eceb7fbb38acae643fb47e46f15068489e74a54ebb8b7471b2c9ed575ca1
57
2021-12-17 22:06:01
0
ff8d89415f242cef7b2e49651631f127294decc00334b501b42aa9ee8945c1a0
54
2021-12-17 18:42:35
0
8f9bbb7adf483195badbcecb14e0b83070fb87627e05e0fb1c66946bf08c63af
58
2021-12-17 12:30:55
0
c9decdb3df040f183af7cdec0f61388bef29c031d217df22d81a088727e3c93d
55
2021-12-17 11:38:28
14
2c76ad86ef6e62403d5a3e522ddd6b681139b4c9f1fb683ce0aeb44121c8ea45
56
2021-12-17 09:42:17
28
f4569a814068271e93edcdd53bced7511b5639f162b268cdc73710fc211692aa
67
2021-12-17 08:32:12
0
35b4322106fddf45815aa543b2831dd0a9e213494d0b68534d114e15ce8b17c3
54
2021-12-16 14:18:07
0
2ee30d9258bd1796521e0deaa144ca9be66de86becdd5a25a7f656a5cf6483a8
57
2021-12-16 14:18:07
11
a2d333a9a9c67a5c990b1274dd75b7925b5b6ccaedcb9911fdcd5739e40e0115
55
2021-12-15 20:12:29
11
94c687b00bd7320eebb035f150fac7980cbefbb0df74d72e23fa07611c63f9ec
57
2021-12-15 20:12:27
0
20dd3536672f5cd03d5b0c0b9e1e1a2487c653b5e6b96867501e93ac74557673
57
2021-12-15 17:58:44
0
13d1cbb80ac3e45e924407e737d5f32366b3165d64d5df944881caf09ace4b20
56
2021-12-15 11:17:40
0
0b00c80518fe9eba95dc528414c2d2e4227d355e67cda3976d3e1ead885291b7
57
2021-12-15 07:25:30
3
dd73dbc271b3098272d6eddc53c072ab5191c93ff66201fbb19990604bbaa837
66
2021-12-14 22:37:58
0
a1370fb3525071beac73a468b2629e0522cbc6128feca82a9a7d587bc85ec54b
60
2021-12-14 11:15:51
0
ded74dbd20b39cdbd27b1d2967eb40d2d30e83dbac0a909bb851951e87086b06
57
2021-12-13 12:10:44
0
b6065c7ed17bcf2471a2a72dfce26f0cdff5e4ba7f02b826fb0093cb94e8efea
56
2021-12-12 14:30:54
0
171cd4bb38157ca2a9c7e6457a1fecf4bc72196ad53b3c1299b50e1a1a5d7daa
56
2021-12-12 02:30:56
0
30c54cfcf088fdcc349dcc7f58b73794afb83b675dfde152617d2a121ec49ad8
57
2021-12-11 04:16:07

Rule Matches per Month (last 24 months)