EXPL_Log4j_CallBackDomain_IOCs_Dec21_1

Rule Info

Score
60
Name
EXPL_Log4j_CallBackDomain_IOCs_Dec21_1
Description
Detects IOCs found in Log4Shell incidents that indicate exploitation attempts of CVE-2021-44228
Av Ratio
2.97
Author
Florian Roth
Tags
['DEMO', 'EXPLOIT', 'CVE_2021_44228']
Rule Hash
790752dafd8f11b3356865e224d9b7e8
Minimum Yara
2.2.0
Date
2021-12-12
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
3
Suspicious (< 10 engines)
14
Clean (0 engines)
26

Rule Matches

Positives
Hash
Total
Timestamp
VT
1
7acfe4b98bf8d284f93879ca33c923e03ea9d3f5a34a2520596602bb53419d0c
57
2022-01-14 10:40:21
0
cb536c90a751e66d0ad62823089a9254d2dcc9b02ee08cd804586e8c1ba39bf5
57
2022-01-10 11:46:43
2
35b1dc9c8c26c6762c9d163dd54e89427b19558249675d2040941c5fddd5848e
58
2022-01-09 12:16:29
1
0b6944b57703017eac041812086ae5e376820063e418df2e26a1dfe23aefb276
58
2022-01-07 21:40:16
0
93678ac9ce8ca1637e2bac6009702b8b5c278f2cb75f02bc0a41bd1f5addcf3e
55
2022-01-05 08:31:58
0
4c82c0a5e413245a8b28a517a75a277001fd140e5bda258fa6b6f6c91506aa5d
56
2022-01-03 19:03:28
0
d1e8c08e3444b58245337eb435acc8ff22703fe5896f2775d86b5839a9dab6f3
57
2021-12-31 12:08:35
0
9ed63244cc14540fcf9c907ddaaed0d1475668d9476be0b6f580a6bb960881b8
58
2021-12-30 21:28:04
0
48f8feabb0509204eed1ea1ee8b9834a85fc6eb30a647d26437eb82b08fe7beb
58
2021-12-24 23:44:12
0
ac46725d732f453d039dba13f410be7016750621551d4e57a2d5b769aebe3191
56
2021-12-24 13:11:15
0
b6065c7ed17bcf2471a2a72dfce26f0cdff5e4ba7f02b826fb0093cb94e8efea
58
2021-12-24 13:07:58
0
2c9e2437faaa526c00c65ddb0bd2df518196c2fd72ece4f73add5f1b940ec336
58
2021-12-21 13:10:59
0
ef801abe950cf97b8226761028e776135259c83cab63e85a634b288a9dff828b
58
2021-12-21 13:05:35
2
e798ccba97543ada249ba0240cdcc59e23c190d072de9c39ce879fb7907a34f8
51
2021-12-21 10:17:53
3
094da9fb31b753ed07a99720ee6b251f0d0034ae633f81bb21613f0f9f944d70
57
2021-12-21 09:48:18
0
d50fbe7077b1d3f507fea8defe7563791ca37efd6e802d632169a049a90e8994
55
2021-12-21 03:17:37
1
27472ae94cf677c3eebd7047ff78e581c789f1e635a223a5ca5ebbc4ae4bf5b0
57
2021-12-20 09:44:17
0
aabab7a675d314289bdc37cf95c7d368295f6288a596ec42513168704fcc97d1
58
2021-12-20 08:16:34
0
dc819b2567142b5c828a1ee78bd7290cac562ba45a3155a1f215c73151fc7f47
57
2021-12-19 11:22:17
0
dcfe1f489dbbbe6b752ddfb514cc16c8d78b0b210f3ab08713064aa0e3983be3
58
2021-12-19 10:12:08
0
d745f8a2f21ab3abfdb3d44ef5f9873e287e3b71b52b144961a918250182eb89
58
2021-12-19 09:51:38
0
aeb100cc673027fc32f15da25170651a562111460a5741ad06148d00dee26ca7
57
2021-12-19 07:09:08
0
390bc06ffc54eecc28f2d3539e8326b8aa8481e3c589a2768a67505c55d141ba
56
2021-12-17 19:42:04
0
ff8d89415f242cef7b2e49651631f127294decc00334b501b42aa9ee8945c1a0
54
2021-12-17 18:42:35
0
c9decdb3df040f183af7cdec0f61388bef29c031d217df22d81a088727e3c93d
55
2021-12-17 11:38:28
14
2c76ad86ef6e62403d5a3e522ddd6b681139b4c9f1fb683ce0aeb44121c8ea45
56
2021-12-17 09:42:17
0
61c6099cc4895a19dce1f4c49c2dc92a173adce0fa423741fcf6fed70fcc985d
57
2021-12-16 10:06:12
0
f32e675d011bff435f224203e226302ae0297c0bcaa30657b19e096d501944fd
58
2021-12-16 10:05:59
0
8f808f3f636c486197e9c4e3243091d3cb52d86cbe81a2888c08d5755e121cd2
57
2021-12-16 04:44:46
1
5a0df94349e865723ef7f79040aee15e0d166330160926c658b7951f93e4e173
55
2021-12-15 22:01:18
11
19627c3128e3f598b6e79a4c492bb46d61e626278ea7b6346d36a5d62ab37e92
57
2021-12-15 20:06:02
0
227ac5689f6fba53ad2adabc2b46a96dca96db12f66eca13370d2be0f25bf275
57
2021-12-15 12:44:17
0
13d1cbb80ac3e45e924407e737d5f32366b3165d64d5df944881caf09ace4b20
56
2021-12-15 11:17:40
3
0c269d438b712d0d75ffcfc41d30df8d9a7b30659aadba7641f59b3b0db986cb
57
2021-12-15 07:27:50
3
dd73dbc271b3098272d6eddc53c072ab5191c93ff66201fbb19990604bbaa837
66
2021-12-14 22:37:58
3
7cd855e8b671b1df04dde766a99a0791023571d3ab9901433242bc61be3d8809
66
2021-12-14 21:45:20
0
171cd4bb38157ca2a9c7e6457a1fecf4bc72196ad53b3c1299b50e1a1a5d7daa
57
2021-12-14 03:33:09
10
8bd840119a910f1e8cdd02b521037a78d12adf8828ee37d83536c7ef019985bd
55
2021-12-14 00:28:32
1
2780737e9937864f6b006c1f47ab390e76207111616ede87cc189777103e470d
56
2021-12-13 19:30:40
0
963cf06f2b36d514c7b1ae63a59ea98eea844b3ad32b8c78b6afb3619a2f4fa8
57
2021-12-13 18:01:30
5
8ad328025ec82eefb584e7020c9d0c1db3f0e78602c4fe606f5393f638d22aa0
57
2021-12-13 10:49:08
2
609fb5aaf670c5a53dd3f4ffedcb447c8c7fd20aa9f0b7b58077358303a13894
56
2021-12-13 05:56:54
6
4d9ea905cda378e8537bde96c9808602bedc6dd1c42cc5e0a78f02e82f609137
35
2021-12-13 01:33:48

Rule Matches per Month (last 24 months)