ThreatLabz analysis - Log4Shell CVE-2021-44228 Exploit Attempts
ID: b041a122-1374-5dca-940d-0e1bed804a71
STIX ID: report--b041a122-1374-5dca-940d-0e1bed804a71
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabz describes active exploitation of the Apache Log4j (CVE-2021-44228) 'Log4Shell' vulnerability, documenting how attackers deliver secondary payloads (Mirai botnet, Kinsing coinminer/rootkit, Monero miners), perform credential theft and persistence, and use various protocols (LDAP, RMI, DNS, HTTP) to fetch malicious components; the report includes payload examples, behavioral analysis, and extensive IOCs (hashes, IPs, domains, download URLs) to support detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
