Threat Alert: Tracking Real-World Apache Log4j Attacks
ID: 15a4296a-45f7-5c6a-8033-a82fb9bd4aae
STIX ID: report--15a4296a-45f7-5c6a-8033-a82fb9bd4aae
Feed Name: Aqua Security Blog
Threat Score
This report documents real-world exploitation of the critical Log4j (CVE-2021-44228) vulnerability observed by Aqua Security via honeypots: multiple botnets and attackers exploited JNDI lookups to deliver malware (Muhstik, Mirai), open reverse shells, and execute payloads directly in memory to evade detection; the report includes IoCs (IPs, MD5 hashes, sample payloads) and recommends detection via a Java Trace-Agent hooking the JNDI lookup.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
