SUSP_EXPL_OBFUSC_Dec21_1
Description
Detects obfuscation methods used to evade detection in log4j exploitation attempt of CVE-2021-44228
Query · yara
strings:
/* ${lower:X} - single character match */
$f1 = { 24 7B 6C 6F 77 65 72 3A ?? 7D }
/* ${upper:X} - single character match */
$f2 = { 24 7B 75 70 70 65 72 3A ?? 7D }
/* URL encoded lower - obfuscation in URL */
$x3 = "$%7blower:"
$x4 = "$%7bupper:"
$x5 = "%24%7bjndi:"
$x6 = "$%7Blower:"
$x7 = "$%7Bupper:"
$x8 = "%24%7Bjndi:"
$fp1 = "<html"
condition:
(
1 of ($x*) or
filesize < 200KB and 1 of ($f*)
)
and not 1 of ($fp*)