SUSP_JDNIExploit_Indicators_Dec21

Rule Info

Score
70
Name
SUSP_JDNIExploit_Indicators_Dec21
Description
Detects indicators of JDNI usage in log files and other payloads
Av Ratio
10.24
Author
Florian Roth
Tags
['DEMO', 'SUSP']
Modified
2021-12-12
Rule Hash
e057a67136f248469749fe14f3731776
Minimum Yara
2.2.0
Date
2021-12-10
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
15
Suspicious (< 10 engines)
17
Clean (0 engines)
24

Rule Matches

Positives
Hash
Total
Timestamp
VT
1
da3e9e5f35f966c5cc3fef913384493ad514730055a0f4b5ac7dc45177dccaea
57
2022-01-22 21:50:38
4
1b7d6def1dd599f61b7b0d225bafb911ca850805628e418dfd0c5193016911a7
55
2022-01-21 16:16:29
0
44b1816c5bbdea0aba8c62c87abb31427d40e4ecb2980f5f31c71a3efb192b98
57
2022-01-21 12:37:56
1
657597acb38eafb754a012dc2dbbdc32259949d187fd8ef556dd87dd7be90cf8
57
2022-01-20 00:43:54
0
93678ac9ce8ca1637e2bac6009702b8b5c278f2cb75f02bc0a41bd1f5addcf3e
55
2022-01-14 12:01:06
11
ecd167f2191f4e2149359d3bf5f90b86c07aca5b89310409e654f47d15c47c08
56
2022-01-14 11:11:36
2
03d02a7cb2517d81893c67a597b71a41f3727cdf0d4845cb7386ed8bbd504ddf
55
2022-01-12 12:57:50
1
0a48e6b4d12ef8ae41980d7de8e4b907d2f951befcc0e7220831fb2da326ff2e
55
2022-01-12 12:40:01
0
cb536c90a751e66d0ad62823089a9254d2dcc9b02ee08cd804586e8c1ba39bf5
57
2022-01-10 11:46:57
11
ffdde170d837231077e6288af31f4c3155cd63d4e3c50d92fe67af7a79a9681e
58
2021-12-25 16:05:04
1
32f2e865f78a86d9240a2b92b0bba2a948935345d29c7211ab71fdc5769553c0
58
2021-12-25 10:56:28
0
ac46725d732f453d039dba13f410be7016750621551d4e57a2d5b769aebe3191
56
2021-12-24 13:11:12
0
2dd5d4ad8df5b43a035bb9627bb310669b02f019d13a5e7d82011f76cf12eb49
39
2021-12-23 03:20:02
9
a2f8c3878f0af9cfc0e2278aebd71df4a6019cdf5692b7cf7f9b89c4d9160276
57
2021-12-23 03:16:32
0
bfe0002bccbf5ed26a54782ce02c69032b4ed0a13a7c51094cef898262005c6c
51
2021-12-21 12:06:01
2
094da9fb31b753ed07a99720ee6b251f0d0034ae633f81bb21613f0f9f944d70
56
2021-12-21 03:17:39
0
d50fbe7077b1d3f507fea8defe7563791ca37efd6e802d632169a049a90e8994
55
2021-12-21 03:17:39
0
0bdfc81dab816e1dd2327ae7cef236fd445f41b35376ced8debd2d7fdff24aed
57
2021-12-21 00:40:35
0
e2583c5350a164be167b4928f99ae1bb8579bc49437ac27e928131c42f829820
57
2021-12-20 07:22:48
9
dca21162a4237b761ee3a4ae9be880b480f6646d0269a9bc36782d564afd912d
57
2021-12-19 07:34:26
10
e3a31461aed1ed1de1df536fb913274884bea7ea9a9ee2a7a0ce05f506e745d5
57
2021-12-19 07:33:19
18
17f785b1d881ff3c7151fae977bcbf2c71b868ff57abf2780d5e69f560fb7a7b
62
2021-12-18 08:53:25
14
2c76ad86ef6e62403d5a3e522ddd6b681139b4c9f1fb683ce0aeb44121c8ea45
56
2021-12-17 23:47:30
1
6245e1ac4150602a46b67420b44fae3c475a8392dc663f17c3711aa39aaba834
56
2021-12-17 11:14:46
15
602ce22d44a429d4fb5199b09502c39a2c5f84653d27fdac167d92408c5e5e8c
60
2021-12-17 10:58:53
17
01d53048f0316d6928ecf54b2ef576dc645b3b7b0d23aa7d60345ab06b3e0cea
55
2021-12-17 10:58:52
25
e969c878334bf0af177cd2be2c43377327164c6d085e1071d09ba6c8505f75f5
61
2021-12-17 10:58:52
26
3acc3088be26262923510cd87916a36c9ae4b28182cb5053c8702cd95f97ea54
60
2021-12-17 10:58:52
24
9bbe681c3c4be5b3c371da145de98e94983da47688268415ae1791cb3a85cb96
61
2021-12-17 10:57:49
25
12de06b32dbb246bc033ce25738354d6336874c8969b480aac36fe5607d9bcd1
61
2021-12-17 10:57:49
23
5bfbb3d4505918b3e1d95bf1e2123a21abf5ffdc35801823cacfb9d44fc84aa6
61
2021-12-17 04:03:44
25
105a12429011b7041862ae26ab6f79610e8144b13a70f1ecb22bfc0ac8641afe
61
2021-12-16 23:52:44
20
2da8510ac4fea01dab7a702de7d25a41147bba6624d2459ea5ce8367248b5e28
58
2021-12-16 23:12:24
21
5f0db9a4d16ae13ee931a52e8ef5e8461b2c1ac2b78226002036b16227122e74
62
2021-12-16 22:07:41
3
bf8d19b107c97c87848a76f58606d570e6b515f9f10dd77a4f83654afd02e70c
53
2021-12-16 17:22:49
0
61c6099cc4895a19dce1f4c49c2dc92a173adce0fa423741fcf6fed70fcc985d
57
2021-12-16 10:06:13
0
f32e675d011bff435f224203e226302ae0297c0bcaa30657b19e096d501944fd
58
2021-12-16 10:05:59
8
b66c55252cc5a047a65d3693078e1d75a1f87b665b846bc798771f58d4072040
57
2021-12-16 02:19:06
0
8f808f3f636c486197e9c4e3243091d3cb52d86cbe81a2888c08d5755e121cd2
57
2021-12-15 13:29:43
0
2594e824e6dc5be478c434f85573e492ec283c5a2eb78d9615044034517bc3cb
56
2021-12-15 11:56:37
0
65e1ed73651cc83d711b9832d7c162659bbf71a343038e094667983b29014243
57
2021-12-14 17:09:34
1
2780737e9937864f6b006c1f47ab390e76207111616ede87cc189777103e470d
56
2021-12-13 19:30:32
0
6b5b251a8ccc3892eb6838b4af44924aaabb99181e95f7e175472b788cac7404
56
2021-12-13 08:27:28
7
e1c46ec8b9f8c57d3d193379849d84fca73dcc4684bf1397ae129b6c8d811529
57
2021-12-13 07:26:07
0
a939b1db7a329a41dc80282f57a6f99d71a6086655ffdca25917a80a2f2bc9a2
56
2021-12-13 07:17:22
1
332b6dc17abf9ad6ef9860db7139dc1d481f8d4091ee001c94e79ec42ab9792c
56
2021-12-13 07:15:00
2
464dc763c817efdd80f93da98eaa45a3feb667d63902735301490461ee41c279
61
2021-12-12 22:49:17
0
dd2eff8ee8d8a5e5cfb5adf9f575ccb92d6faa570ee6e0241dfb33ebd2343ea2
56
2021-12-12 07:26:49
0
b5808176e1f4d67f1ac4599f137035944c399df92e0cb5fcebc34287c99d03bb
56
2021-12-12 07:25:48
0
c85db5d0eb26979a95cd653e28d6fab134f5ce03574c21b74791de75e5a67de8
56
2021-12-12 07:21:36
0
633b0b7efede0053e4b4ab0aee3a511d459c0eb2f78a3389cbe2aebc12cd38a5
57
2021-12-12 07:20:32
0
6ddb9de34b860ccd16143e71d9a6f24baafe78c36c885499a991e6143c7981e4
55
2021-12-12 07:17:17
1
ce06ed30774e245c4eead6b62e4a173c886a87b7d8b9fe7ba5d7c4b0b72fe08e
57
2021-12-12 07:02:25
0
4fa7b29c5546c65fa743a68a1d93b79dca6ee1ee1d4ecdb90ff9bd13250716d9
56
2021-12-12 06:59:10
0
171cd4bb38157ca2a9c7e6457a1fecf4bc72196ad53b3c1299b50e1a1a5d7daa
56
2021-12-12 02:30:55
0
0f6eaec34516e9645410d704dd6accaa381dd23ac2aba3801e208f59d296923a
54
2021-12-11 18:51:56

Rule Matches per Month (last 24 months)