logo

ThreatLabz analysis - Log4Shell CVE-2021-44228 Exploit Attempts

ID: b041a122-1374-5dca-940d-0e1bed804a71

STIX ID: report--b041a122-1374-5dca-940d-0e1bed804a71

Feed Name: Zscaler Security Research Blog

Threat Score
88/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz describes active exploitation of the Apache Log4j (CVE-2021-44228) 'Log4Shell' vulnerability, documenting how attackers deliver secondary payloads (Mirai botnet, Kinsing coinminer/rootkit, Monero miners), perform credential theft and persistence, and use various protocols (LDAP, RMI, DNS, HTTP) to fetch malicious components; the report includes payload examples, behavioral analysis, and extensive IOCs (hashes, IPs, domains, download URLs) to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.