Guidance for preventing, detecting, and hunting for CVE-2021-44228 Log4j 2 exploitation

2021-12-11 Microsoft

https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/

Thumbnail for Guidance for preventing, detecting, and hunting for CVE-2021-44228 Log4j 2 exploitation

Microsoft observed broad exploitation of Apache Log4j 2 vulnerabilities, including mass scanning, coin mining, remote shells, Cobalt Strike deployment, credential theft, lateral movement, data exfiltration, and ransomware payloads. In the nation-state section, Microsoft stated that multiple tracked groups from China, Iran, North Korea, and Turkey were testing or implementing Log4Shell, ranging from experimentation to in-the-wild payload deployment and exploitation against targets. The report does not name a specific North Korean actor or payload in the excerpt, so the DPRK-relevant finding is limited to North Korea-origin activity adopting the vulnerability. The broader defensive significance is that Log4Shell quickly became a shared access vector for both commodity and state-linked operators, requiring patching plus hunting for post-exploitation activity on vulnerable systems.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4fbc673742b9ca51a9721c682f404c41 2021-12-11 2021-12-11
DOMAIN w2zmii7kjb81pfj0ped16kg8szyvmk.… 2021-12-11 2021-12-11
DOMAIN service.trendmrcio.com 2021-12-11 2021-12-11
DOMAIN canarytokens.org 2021-12-11 2021-12-11
DOMAIN api.rogerscorp.org 2021-12-11 2021-12-11
IPv4 139.180.217.203 2021-12-11 2021-12-11

Related Reports

« Back