Guidance for preventing, detecting, and hunting for CVE-2021-44228 Log4j 2 exploitation
2021-12-11 • Microsoft •
Microsoft observed broad exploitation of Apache Log4j 2 vulnerabilities, including mass scanning, coin mining, remote shells, Cobalt Strike deployment, credential theft, lateral movement, data exfiltration, and ransomware payloads. In the nation-state section, Microsoft stated that multiple tracked groups from China, Iran, North Korea, and Turkey were testing or implementing Log4Shell, ranging from experimentation to in-the-wild payload deployment and exploitation against targets. The report does not name a specific North Korean actor or payload in the excerpt, so the DPRK-relevant finding is limited to North Korea-origin activity adopting the vulnerability. The broader defensive significance is that Log4Shell quickly became a shared access vector for both commodity and state-linked operators, requiring patching plus hunting for post-exploitation activity on vulnerable systems.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 4fbc673742b9ca51a9721c682f404c41 | 2021-12-11 | 2021-12-11 |
| DOMAIN | w2zmii7kjb81pfj0ped16kg8szyvmk.… | 2021-12-11 | 2021-12-11 |
| DOMAIN | service.trendmrcio.com | 2021-12-11 | 2021-12-11 |
| DOMAIN | canarytokens.org | 2021-12-11 | 2021-12-11 |
| DOMAIN | api.rogerscorp.org | 2021-12-11 | 2021-12-11 |
| IPv4 | 139.180.217.203 | 2021-12-11 | 2021-12-11 |