EXPL_Log4j_CVE_2021_44228_Dec21_OBFUSC

Rule Info

Score
60
Name
EXPL_Log4j_CVE_2021_44228_Dec21_OBFUSC
Description
Detects obfuscated indicators in server logs that indicate an exploitation attempt of CVE-2021-44228
Av Ratio
1.61
Author
Florian Roth
Tags
['OBFUS', 'T1027', 'EXPLOIT', 'CVE_2021_44228']
Modified
2022-01-05
Rule Hash
374c4b93dabf29c0278a53bf1347273a
Minimum Yara
1.7
Date
2021-12-12
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
1
Suspicious (< 10 engines)
18
Clean (0 engines)
36

Rule Matches

Positives
Hash
Total
Timestamp
VT
2
6e32e1cdeb9f01c039a8b6032663a2fcad040d2f2bf2950f8a46746d460e3277
63
2022-01-23 10:25:00
20
546e48de6932caf4c22dca427695afb0958b4e9ff3e0ebb7ae4ec50d643cedb8
68
2022-01-21 07:09:09
1
657597acb38eafb754a012dc2dbbdc32259949d187fd8ef556dd87dd7be90cf8
57
2022-01-20 00:45:00
2
5756b7c922ce633f1ae00b404f58e8a565bfa99db7e95b1a5fae0065dd005a8d
56
2022-01-19 05:06:31
2
2046c50543bae7e9ee03b4af98bfab56d2b0a17e976faa2e5fe0ee97a7c3fdec
57
2022-01-14 16:09:36
2
e5252cbc40ccbcda3834aa31500a5a2503928ad2de164f9bc94e85f3446b9cb2
56
2022-01-14 12:56:22
0
f307f3f33e01dd487c2ad55952a2b49acf6de2f2f0d990004eb6bdf23ebf2f2f
61
2022-01-11 19:04:20
1
a79409dc8dfb29350eb5331e15dc8c6607cd398dc4eccb78bcdb33defee9ced0
68
2022-01-11 19:04:19
1
89eb10301fd2da791f383591b8a9c4b2a7d85864d2fe93dcedd31b0a40c267a6
57
2022-01-09 14:39:06
2
35b1dc9c8c26c6762c9d163dd54e89427b19558249675d2040941c5fddd5848e
58
2022-01-09 12:16:29
0
6737a45eb67f2c6003b04a14c450be78b5dc4185e989cb384699ef48865c88a5
57
2022-01-06 23:26:10
0
ff49760b49fdd7f235bad0fa6cc8dc1bcd34ee5c26d7585e92fd652a26962541
56
2022-01-04 10:07:39
0
8c2ef3804a4701b95857b3b4c5b1a911818536806bb78711973ce81307fb4dc7
57
2022-01-02 05:42:41
0
c7557f8b2242853fa9c91919536246ccc7ce2bc73575c55cc08d361d416f41a9
56
2022-01-01 16:06:54
0
3f2972e7bc64908db29524a2a04c8456058ba28aba6e098104c45a0d6934e0ea
57
2021-12-31 15:12:21
0
83b1f868940a46ee17cbc47ec8461ecd9b85c1951403d5ae43c9ac46631eb2ec
57
2021-12-31 15:12:21
0
eec28fc801f021adf5f56fe037c6d7d84ad002c0aeba4976d2a2a9b658ccd019
52
2021-12-31 15:12:04
1
64478431e36f15fbae8566f716d377d43b2a4fa1e2de8745934a9fca1b963abb
53
2021-12-29 19:07:04
0
c96f6c7308bc0a62f192afcd2b9d5206e6724216c407bd6a1cf4bfa51fce8e17
56
2021-12-28 19:05:47
0
74a98efcbf5d79e99ffa2128a9c3f3d03fba423dd55f4e7624f9acc81ab62fe7
58
2021-12-27 22:06:46
0
f988f98fbd7055b3869e157d06eee01dcc25b998868acb81ba6536e449750738
57
2021-12-27 14:42:53
0
0edf44b87750ed00f511aa59ff05ea355d38c7e984ed59670adc880222b32fa5
57
2021-12-23 13:37:59
0
2dd5d4ad8df5b43a035bb9627bb310669b02f019d13a5e7d82011f76cf12eb49
39
2021-12-23 03:20:02
0
9f1b486ecb28b414f2be6703153baa03d1d2d63e09c0dadd6d15f638a8f349c9
66
2021-12-23 01:48:35
2
3c63c0d5e4f5505a319292ebf18c3842dee83e9f42d931a4fab7ac044c1035cb
56
2021-12-21 18:24:04
3
094da9fb31b753ed07a99720ee6b251f0d0034ae633f81bb21613f0f9f944d70
57
2021-12-21 09:48:17
0
c2d0cebc8c20afc3efa4a42b2be4c1acef1ff2cd580ffbfcd9e108759887bba9
56
2021-12-20 01:27:49
0
d3284cc8c41997cba356da574ebefad504b66b634178952a2ab37f9e7ec88e3d
54
2021-12-18 19:04:57
0
856cae875b1b7f1ea06e1ca94b942fc9dc702b9b23920013392716f1507797e3
56
2021-12-18 01:46:40
0
afab081b22369bf28d63f17b8f8bd31c8bf1f90b9d8a1b9d8b6cc3140d557bf3
55
2021-12-16 17:30:08
0
f32e675d011bff435f224203e226302ae0297c0bcaa30657b19e096d501944fd
58
2021-12-16 10:05:59
2
3bbd3a87fe5403ab4d02378cc1ce2ac0d80e29e82a356e6912da272dd26df513
54
2021-12-16 07:30:09
0
8d280172ab18a45f52213ae4eaeaff6f86c0ff324afe6b1c54d01727fb396af1
59
2021-12-16 04:08:56
2
caee62557f914d5346fb358d61f29cf2c973f6e44c4fd9946a636875c85274a4
58
2021-12-15 18:31:35
2
38a432e6e16430ab03b7a345904b3ffbdf75fb48fa94d835211f83b5454ae0d1
58
2021-12-15 18:24:46
0
20dd3536672f5cd03d5b0c0b9e1e1a2487c653b5e6b96867501e93ac74557673
57
2021-12-15 17:58:44
0
5afdd8f9b33aec097938ee15e77e01328c90892b5df2a12b57a395b04ec77883
57
2021-12-15 16:32:25
0
c745a76fe75363aa0b47f98170442303ce30f7ead01006ef77ebd901b890603c
60
2021-12-15 13:48:41
0
cacbcaaedc0d7fdf744970c741c84c03859eb4ab48dba7fbf22ed34cffba092a
57
2021-12-14 20:19:55
2
1b7d6def1dd599f61b7b0d225bafb911ca850805628e418dfd0c5193016911a7
56
2021-12-14 20:11:07
2
3d138afd0676f62db6b30010f1f7abcca20b7d3d1323654c7aa864b49ebbb98b
58
2021-12-14 19:25:29
2
2abf4856594569dddc9cc1405758d0fe67dd3e62249476a3ac5311afb65a823d
58
2021-12-14 19:24:17
0
2b78008491f788d173191d0532ac6d441654318740c0a75b5eb51b8c5fb029b6
56
2021-12-14 18:32:07
0
da3e9073b363183ad66aa733be7160026ce1b23852687c42e5f4cc7a07f4552a
57
2021-12-14 15:27:31
0
bc07f56c6ca3c35115caf47ae585e43b9628b15237ea07ae716e9a5fe9077229
56
2021-12-14 12:15:59
3
69b824b3b2e094e97e0aa46c9b11d843064e616077ac1afced50ae66ac8395c4
58
2021-12-14 11:30:19
0
0a0663e32f9a9c5e1bb7d4bc75bd50325fedfb5786d41fb2ca3cbe362c77b321
56
2021-12-14 10:54:55
0
171cd4bb38157ca2a9c7e6457a1fecf4bc72196ad53b3c1299b50e1a1a5d7daa
57
2021-12-14 03:33:09
0
9d40520da30d4d507ed2f100ef0627de2cafa58bfcda97eb1dc84dc3877a95ff
57
2021-12-14 01:47:02
0
b45ddf15ca7792e9cbc0e5390ad8a1bc5567d20e8d8dfb80e46e2073164de97e
57
2021-12-13 20:09:57
0
304f2b6338c37cf4ce9b4d8bd8f3de0c2b940a0875ecbfbdd53016023d799d50
56
2021-12-13 17:41:29
0
48b8f6e97fd173755d5941ac017304a1c93948fe9ad0b3404cb1462c674580b2
56
2021-12-13 16:28:39
0
f081ee8673de367c7a9f3c963b42cc75b957f5250213ce9def56bd955b0855bc
57
2021-12-13 15:33:08
0
020628fd94530a28e53d715a4dd5b6e2ebee66694a52522568a99b5860b8b73c
58
2021-12-13 12:30:24
0
b6065c7ed17bcf2471a2a72dfce26f0cdff5e4ba7f02b826fb0093cb94e8efea
56
2021-12-12 14:30:54

Rule Matches per Month (last 24 months)