EXPL_OBFUSC_Log4j_CVE_2021_44228_Dec21

Rule Info

Name
EXPL_OBFUSC_Log4j_CVE_2021_44228_Dec21
Author
Florian Roth
Description
Detects obfuscated indicators in server logs that indicate an exploitation attempt of CVE-2021-44228
Score
60
Date
2021-12-12
Modified
2023-11-22
Minimum Yara
1.7
Rule Hash
374c4b93dabf29c0278a53bf1347273a
Tags
['CVE_2021_44228', 'OBFUS', 'EXPLOIT', 'T1027']
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
2
Suspicious (< 10 engines)
25
Clean (0 engines)
25

Rule Matches

Timestamp
Positives
Total
Hash
VT
2024-03-25 12:11:40
1
60
f9453e7dfb76bfb6ee7a492ac9ada10d62b9d63f477dd5fbf214e828da345f7b
2024-03-25 09:02:26
1
60
ab7f2139fee899b3428a09804b0ddf195bb8efd657409452c423bcd55298cfe7
2024-03-25 05:02:37
0
58
d92c671063fae4be68002ef3eaff98b64fb1bc2b1308396f7718d54961101c96
2024-03-25 04:34:39
1
60
b5757083cf445d01c1e9c01dbda337238ec0175b4fd1eaf2e7a888956b0ffb64
2024-03-25 03:25:35
1
60
325caea05e4d73ca024dd558bdc5cdb22877884d4b46b7d66de387cd16d2cce3
2024-03-25 02:45:25
1
60
4feb7f4802e108f9cd74591ac3cd7d24fd8d2be650505ba8f4fec763b977f03e
2024-03-25 00:00:48
1
59
a59c7e2ea02ccbcf5e24a853677ea44cbef4a7af5f6c9c1cbc857ced8a2440b0
2024-03-24 15:04:46
2
59
5227c0d45e114c08176957719446d5302ee9a1eb9f322e26ba027284d8747c31
2024-03-24 12:04:57
2
59
7aa15cd800890e9521149f8ee8dea985aa54b4b88771d323692ae063e96f8f18
2024-03-24 00:03:53
2
59
d15ee05554cceadf67afd022703dc9eee2e57f82a41898a73eae819394deb7ec
2024-03-22 12:07:40
9
60
dd90a7fcb412b5151e40ebadbab06e25e31744a5e7cdb1cd59224ba74b805db3
2024-03-08 06:09:05
1
59
4a590085ba41fc69439b9f9c40e37600b6be7bb26dd152e1639d8674c07dd19d
2024-03-06 12:08:03
2
58
d7e8b90d0433d69717e49aa261c57f8733cb37b68a04d6c9fdef40fab8b34e29
2024-03-06 09:02:12
2
59
4a29f3a2ead1997ad37761d0051a7ceb37fbb85c49de55ef2136d59be563ab9a
2024-02-18 15:14:00
1
60
fd34e8065137e9f8d915c07d8b4f70cb23487860275aeb7f01814b433877b603
2024-02-04 17:33:32
0
59
cf96c3a217cf4a640bd606ae1157fd9070b3d1802539c5594787b109787b09e7
2024-02-02 19:27:23
22
60
d09222c19a6115b9a46adedf69ce4764904ca20de56acfc7fa10a92d75a45c8d
2024-02-02 18:31:01
0
58
cb126110090ac972382725d8a46b8818e5d9ddc6761af1780eedf61904676cbb
2024-01-21 14:59:11
0
56
a16d0dc96af5e15a85964d13f68cfd3c672a973a05900c33fe15215ad73af3e5
2024-01-18 13:53:22
0
58
643fd02289d3e197e29fe17afa0962eabff0ef77b013a74c83a67dedc1db5c4f
2024-01-18 13:50:53
5
56
ce4a6cf8f4cc4bd4ea17180731ca2768b083c9fd3aa042fcd5183ed9d1a2765e
2024-01-18 11:39:39
22
68
bd8b7f28b92a27685b65f9938b2a61aa36f41d909706ac2180762c04d9106bae
2024-01-03 21:30:01
5
48
11334b118bf00da2239becbe8ff85c54078f172406d4038ddf8ccfd1258809e8
2023-12-27 19:05:18
2
59
7137e9c3dbf8651f2d15024e9cc8af2898f540ad512a78cd5bca463d7d2add5c
2023-12-19 23:49:43
0
58
14acae5d710b91cd65843b9f0e971fe3fd36c89825e98dfcdc61b79ea12d5ae9
2023-12-19 22:29:35
0
59
5e34b4b219e76d77ab9125b361b79d2234bdc9b21a34a220e1c64fb2413df460
2023-12-19 22:09:30
0
59
6e0972b38d7f22bc50dfbd4020d8841ddd78990b518231a7bbcd9f126fb5187e
2023-12-19 22:09:27
0
60
87132c6b8a39c923c47121abf1653195f7b0e89057ca823329db5ab97914e240
2023-12-19 22:01:04
0
59
1cda4d4b1ca3d5172a30bb59bbb86d8845be5b772cbcc05a3452ff13c796b118
2023-12-19 21:41:53
0
48
911a4eb99d063125789f18802c431d1a967297328606a9d41f0388eda3ebc5e4
2023-12-19 21:41:52
0
59
d6c9660241cc6f54c98092e662a34dec475da844af7c7a40a9de29fb02a4fe99
2023-12-19 21:31:31
0
59
b403b9ea8adae7faa28013912226c160e1cd1f67ac11790117b88deafe00f384
2023-12-19 21:20:31
0
58
1d2f7f6677b887b5a2302d1dbec0e1a42b273a83fdf7e7e1933829e8c6366bed
2023-12-19 21:09:56
0
59
f2b410e7f168e3868968ce4a598baf913d522e92b5f9ad295b185c9040369ef5
2023-12-19 19:19:52
0
59
fb7b1b79aa19846f2869a0b1f26744254eb127246fdcbe8aba1d6285def5ac16
2023-12-19 19:19:48
0
59
6e3aee99132c3f2cfbe6247b52a94542028fc27870b9275719dc0debe4ca8805
2023-12-19 19:09:38
0
60
373ef9a8e50136cadea0f6c78e67e01895fe28fa478b79d0bbb3cce9a47ffd97
2023-12-19 19:09:37
0
59
cdbda5ef3d879d76ac5808bafc201124ab840e24e710d5dc099a41676167b5c0
2023-12-19 19:01:27
0
59
cd659c0aeaad42eee0ea0159b3749cc0729687bf69c4399d2a6ab7b4fafec768
2023-12-15 10:11:08
0
60
4c5a89e9e1cc63b0a2f7025834b0fe71a5725b7204023772c7f183f49aded655
2023-12-15 10:11:07
0
59
35f7ef90ae27d206b31350dfdff72d39efec96081f1dc4bd64877062a5e33695
2023-12-14 20:21:11
0
58
a866b0e1efa10b652506b9e14b7548c87f2d97f227c9f26145fafed71a891804
2023-12-14 20:21:08
0
48
181bb0bcb0713b22a42b233d01433c970970e478e89633d71635dfc7371178eb
2023-12-14 12:33:33
1
60
939611a9faa296160319f14853b423285f6b926659f32b40f13cf479e69896f6
2023-12-13 04:33:24
0
61
3168d49f74c24cbf53edbe40729444cdc103eefce1aeadd806655a7a88689744
2023-12-07 18:56:12
4
61
49170d558455630f1b3371dac46ff502be5c785f4620209a9653a3777be399e9
2023-12-07 18:55:04
3
59
369f1ee271e102c350b314fac9b1a300b419352049d3aaf641d79496ec12797c
2023-12-07 18:53:59
4
60
76eef755a6fea04667a672a62bb7ac6d52c17c861623ef4cfa1651f44109808e
2023-12-07 18:52:41
3
62
c96ecaaf1c6730b278af0058667e7cc2a618bd7e22ab8671c289e892f1cdbc7d
2023-12-07 18:51:32
4
59
ceb0abac118f3399af987839b1ec706f566c2afac1b28406f3dbfcc73214c0fb
2023-12-07 18:47:51
3
58
704f270f29357563e5e0246b8a0e47a17c5d8950f739123076fe945d0e6b6734
2023-12-07 18:43:01
4
59
c12ea495561abe62e4b6f5e23b160337fca166b31fa1c04b6e8812dfd883d33f

Rule Matches per Month (last 24 months)