logo

Log4j Strikes Again: New Exploit Deploys Crypto-Mining Malware

ID: b2665862-c5a9-5d29-8877-b0bdfa187ead

STIX ID: report--b2665862-c5a9-5d29-8877-b0bdfa187ead

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2024-08-22

Date Updated: 2026-05-05

Author: Kaaviya

...
...

A July 2024 honeypot observed exploitation of Log4Shell (CVE-2021-44228) from a Tor exit node (185.220.101.34) where attackers downloaded and executed an obfuscated Bash script to install the XMRig Monero miner, perform system reconnaissance, establish persistence via systemd or cron, and deploy backdoors; observed IOC domains include superr.buzz, cmpnst.info, nfdo.shop, and rirosh.shop with suspicious file writes to /tmp/lte, /bin/rcd, /bin/componist, and /bin/nfdo.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.