Log4j Strikes Again: New Exploit Deploys Crypto-Mining Malware
ID: b2665862-c5a9-5d29-8877-b0bdfa187ead
STIX ID: report--b2665862-c5a9-5d29-8877-b0bdfa187ead
Feed Name: Cyber Press
Threat Score
A July 2024 honeypot observed exploitation of Log4Shell (CVE-2021-44228) from a Tor exit node (185.220.101.34) where attackers downloaded and executed an obfuscated Bash script to install the XMRig Monero miner, perform system reconnaissance, establish persistence via systemd or cron, and deploy backdoors; observed IOC domains include superr.buzz, cmpnst.info, nfdo.shop, and rirosh.shop with suspicious file writes to /tmp/lte, /bin/rcd, /bin/componist, and /bin/nfdo.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
