EXPL_Log4j_CVE_2021_44228_Dec21_Soft
Description
Detects indicators in server logs that indicate an exploitation attempt of CVE-2021-44228
Query · yara
strings:
$x01 = "${jndi:ldap:/"
$x02 = "${jndi:rmi:/"
$x03 = "${jndi:ldaps:/"
$x04 = "${jndi:dns:/"
$x05 = "${jndi:iiop:/"
$x06 = "${jndi:http:/"
$x07 = "${jndi:nis:/"
$x08 = "${jndi:nds:/"
$x09 = "${jndi:corba:/"
$fp1 = "<html"
$fp2 = "/nessus}"
condition:
1 of ($x*) and not 1 of ($fp*)