Log4Shell-IOCs

March 4, 2022 · View on GitHub

logo

Log4Shell-IOCs

Members of the Curated Intelligence Trust Group have compiled a list of IOC feeds and threat reports focused on the recent Log4Shell exploit targeting CVE-2021-44228 in Log4j. (Blog | Twitter | LinkedIn)

Analyst Comments:

  • 2021-12-13
    • IOCs shared by these feeds are LOW-TO-MEDIUM CONFIDENCE we strongly recommend NOT adding them to a blocklist
    • These could potentially be used for THREAT HUNTING and could be added to a WATCHLIST
    • Curated Intel members at various organisations recommend to FOCUS ON POST-EXPLOITATION ACTIVITY by threats leveraging Log4Shell (ex. threat actors, botnets)
    • IOCs include JNDI requests (LDAP, but also DNS and RMI), cryptominers, DDoS bots, as well as Meterpreter or Cobalt Strike
    • Critical IOCs to monitor also include attacks using DNS-based exfiltration of environment variables (e.g. keys or tokens), a Curated Intel member shared an example
  • 2021-12-14
  • 2021-12-15
  • 2021-12-16
  • 2021-12-17
  • 2021-12-20
    • ETAC has added MITRE ATT&CK TTPs of Threat Actors leveraging Log4Shell
    • Curated Intel members parsed ALIENVAULT OTX MENTIONS to be MISP COMPATIBLE with the help of the KPMG-Egyde CTI Team
  • 2021-12-21
  • 2021-12-22
    • Curated Intel members added very basic FALSE-POSITIVE FILTERING for threat hunting feed outputs, using selected MISP warning lists, primarily to remove false-positives of large DNS resolvers (among others)
  • 2021-12-29
    • Added Securonix Autonomous Threat Sweep vetted IoC's and TTP's
  • 2022-01-10
    • Updated MSTIC (4) report now tracks a China-based double-extortion ransomware operator, DEV-0401, who deployed NightSky ransomware via VMWare Horizon initial access
  • 2022-01-11
    • SentinelOne shared their analysis of cybercrime actors leveraging Log4j one month since disclosure, with new info on the Emotet botnet using Log4j for payload hosting
  • 2022-03-03
    • Threat hunting feeds updated by KPMG-Egyde CTI

Indicators of Compromise (IOCs)

SourceURL
GreyNoise (1)https://gist.github.com/gnremy/c546c7911d5f876f263309d7161a7217
Malwar3Ninja's GitHubhttps://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228/blob/main/Threatview.io-log4j2-IOC-list
Tweetfeed.live by @0xDanielLopezhttps://twitter.com/0xdaniellopez/status/1470029308152487940?s=21
Azure Sentinelhttps://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Sample%20Data/Feeds/Log4j_IOC_List.csv
URLhaushttps://urlhaus.abuse.ch/browse/tag/log4j/
Malware Bazaarhttps://bazaar.abuse.ch/browse/tag/log4j/
ThreatFoxhttps://threatfox.abuse.ch/browse/tag/log4j/
Cronuphttps://github.com/CronUp/Malware-IOCs/blob/main/2021-12-11_Log4Shell_Botnets
RedDrip7https://github.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs
AbuseIPDBGoogle/Bing Dorks site:abuseipdb.com "log4j", site:abuseipdb.com "log4shell", site:abuseipdb.com "jndi"
CrowdSechttps://gist.github.com/blotus/f87ed46718bfdc634c9081110d243166
Andrew Grealy, CTCIhttps://docs.google.com/spreadsheets/d/e/2PACX-1vT1hFu_VlZazvc_xsNvXK2GJbPBCDvhgjfCTbNHJoP6ySFu05sIN09neV73tr-oYm8lo42qI_Y0whNB/pubhtml#
Bad Packetshttps://twitter.com/bad_packets/status/1469225135504650240
NCSC-NLhttps://github.com/NCSC-NL/log4shell/tree/main/iocs
Costin Raiu, Kasperskyhttps://twitter.com/craiu/status/1470341085734051840?s=21
Kasperskyhttps://securelist.com/cve-2021-44228-vulnerability-in-apache-log4j-library/105210/
SANS Internet Storm Centerhttps://isc.sans.edu/diary/Log4Shell+exploited+to+implant+coin+miners/28124
@cyber__slothhttps://twitter.com/cyber__sloth/status/1470353289866850305?s=21
SuperDuckToeshttps://gist.github.com/superducktoes/9b742f7b44c71b4a0d19790228ce85d8
Nozomi Networkshttps://www.nozominetworks.com/blog/critical-log4shell-apache-log4j-zero-day-attack-analysis/
Miguel Jiménezhttps://hominido.medium.com/iocs-para-log4shell-rce-0-day-cve-2021-44228-98019dd06f35
CERT Italyhttps://cert-agid.gov.it/download/log4shell-iocs.txt
RISKIQhttps://community.riskiq.com/article/57abbfcf/indicators
Infobloxhttps://blogs.infoblox.com/cyber-threat-intelligence/cyber-campaign-briefs/log4j-exploit-harvesting/
Juniper Networks (1)https://blogs.juniper.net/en-us/security/apache-log4j-vulnerability-cve-2021-44228-raises-widespread-concerns
Cyblehttps://blog.cyble.com/2021/12/13/log4j-rce-0-day-vulnerability-in-java-actively-exploited/
Securonixhttps://github.com/Securonix/AutonomousThreatSweep/tree/main/Log4Shell

Threat Reports

SourceThreatURL
@GelosSnakeKinsinghttps://twitter.com/GelosSnake/status/1469341429541576715
@an0n_r0Kinsinghttps://twitter.com/an0n_r0/status/1469420399662350336?s=20
@zom3y3Muhstikhttps://twitter.com/zom3y3/status/1469508032887414784
360 NetLab (1)Mirai, Muhstikhttps://blog.netlab.360.com/threat-alert-log4j-vulnerability-has-been-adopted-by-two-linux-botnets/
MSTIC (1)Cobalt Strikehttps://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/
CronupKinsing, Katana-Mirai, Tsunami-Muhstikhttps://twitter.com/1zrr4h/status/1469734728827904002?s=21
Cisco TalosKinsing, Miraihttps://blog.talosintelligence.com/2021/12/apache-log4j-rce-vulnerability.html
ProferoKinsinghttps://medium.com/proferosec-osm/log4shell-massive-kinsing-deployment-9aea3cf1612d
CERT.chKinsing, Mirai, Tsunamihttps://www.govcert.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/
IronNetMirai, Cobalt Strikehttps://www.ironnet.com/blog/log4j-new-software-supply-chain-vulnerability-unfolding-as-this-holidays-cyber-nightmare
@CuratedIntelTellYouThePass Ransomwarehttps://www.curatedintel.org/2021/12/tellyouthepass-ransomware-via-log4shell.html
@Laughing_MantisLog4j Wormhttps://twitter.com/Laughing_Mantis/status/1470168079137067008
LaceworkKinsing, Miraihttps://www.lacework.com/blog/lacework-labs-identifies-log4j-attackers/
360 NetLab (2)Muhstik, Mirai, BillGates (Elknot), XMRig, m8220, SitesLoader, Meterpreterhttps://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/
Trend MicroCobalt Strike, Kirabash, Swrort, Kinsing, Miraihttps://www.trendmicro.com/en_us/research/21/l/patch-now-apache-log4j-vulnerability-called-log4shell-being-acti.html
BitDefenderKhonsari Ransomware, Orcus RAT, XMRig, Muhstikhttps://businessinsights.bitdefender.com/technical-advisory-zero-day-critical-vulnerability-in-log4j2-exploited-in-the-wild
MSTIC (2)PHOSPHORUS, HAFNIUM, Initial Access Brokershttps://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/
Cado Security (1)Mirai, Muhstik, Kinsinghttps://www.cadosecurity.com/analysis-of-initial-in-the-wild-attacks-exploiting-log4shell-log4j-cve-2021-44228/
Cado Security (2)Khonsari Ransomwarehttps://www.cadosecurity.com/analysis-of-novel-khonsari-ransomware-deployed-by-the-log4shell-vulnerability/
ValtixKinsing, Zgrabhttps://valtix.com/blog/log4shell-observations/
FastlyGafgythttps://www.fastly.com/blog/new-data-and-insights-into-log4shell-attacks-cve-2021-44228
Check PointStealthLoaderhttps://research.checkpoint.com/2021/stealthloader-malware-leveraging-log4shell/
Juniper Networks (2)XMRighttps://blogs.juniper.net/en-us/threat-research/log4j-vulnerability-attackers-shift-focus-from-ldap-to-rmi
AdvIntelContihttps://www.advintel.io/post/ransomware-advisory-log4shell-exploitation-for-initial-access-lateral-movement
@JakubKroustekNanoCore RAThttps://twitter.com/JakubKroustek/status/1471621708989837316
MSTIC (3)Meterpreter, Bladabindi (njRAT), HabitsRAT, Webtooshttps://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/#ransomware-update
CryptolaemusDridex, Meterpreterhttps://www.bleepingcomputer.com/news/security/log4j-vulnerability-now-used-to-install-dridex-banking-malware/
CyberSoldiersDridexhttps://github.com/CyberSoldiers/IOCs/blob/main/log4j_IoCs/Dridex_log4j
Cluster25Dridexhttps://github.com/Cluster25/feed/blob/main/log4shell/dridex/ioc
FortiGuardMirai-based "Worm"https://www.fortiguard.com/threat-signal-report/4346/mirai-malware-that-allegedly-propagates-using-log4shell-spotted-in-the-wild
CyStackKworker backdoorhttps://cystack.net/research/the-attack-on-onus-a-real-life-case-of-the-log4shell-vulnerability
MSTIC (4)DEV-0401https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/#ransomware-update
DarkFeedAvosLockerhttps://twitter.com/ido_cohen2/status/1478418331434639363
Centre for Cyber security BelgiumFarfli (Gh0st RAT), CobaltStrikehttps://twitter.com/FancyCyber/status/1482454456071598082?s=20

Payload Examples

SourceURL
GreyNoise (2)https://gist.github.com/nathanqthai/01808c569903f41a52e7e7b575caa890
Cloudflarehttps://blog.cloudflare.com/actual-cve-2021-44228-payloads-captured-in-the-wild/
yt0nghttps://gist.github.com/yt0ng/8a87f4328c8c6cde327406ef11e68726
eromanghttps://github.com/eromang/researches/tree/main/CVE-2021-44228
VX-Undergroundhttps://samples.vx-underground.org/samples/Families/Log4J%20Malware/
Malware-Traffic-Analysis (PCAP)https://www.malware-traffic-analysis.net/2021/12/14/index.html
rwinceyhttps://github.com/rwincey/CVE-2021-44228-Log4j-Payloads

Threat Profiling

ThreatTypeProfile: MalpediaProfile: MITRE ATT&CKActivity
DridexBanking TrojanDridex (Malware Family) (fraunhofer.de)Didex, Software S0384Command and Control, Tactic TA0011
Cobalt StrikeAttack tool usageCobalt Strike (Malware Family) (fraunhofer.de)Cobalt Strike, Software S0154Command and Control, Tactic TA0011
MeterpreterAttack tool usageMeterpreter (Malware Family) (fraunhofer.de)N/ACommand and Control, Tactic TA0011
Orcus RATAttack tool usageOrcus RAT (Malware Family) (fraunhofer.de)N/ARemote Access Software, Technique T1219
NanoCore RATAttack tool usageNanoCore RAT (Malware Family) (fraunhofer.de)NanoCore, Software S0336Remote Access Software, Technique T1219
njRAT / BladabindiAttack tool usagenjRAT (Malware Family) (fraunhofer.de)njRAT, Software S0385Remote Access Software, Technique T1219
HabitsRATAttack tool usageHabitsRAT (Malware Family) (fraunhofer.de)N/ARemote Access Software, Technique T1219
Gh0st RATAttack tool usageGh0st RAT (Malware Family) (fraunhofer.de)Gh0st RAT, Software S0032Remote Access Software, Technique T1219
BillGates / ElknotBotnet expansion (DDoS)BillGates (Malware Family) (fraunhofer.de)N/AAcquire Infrastructure: Botnet, Sub-technique T1583.005
Bashlite (aka Gafgyt)Botnet expansion (DDoS)Bashlite (Malware Family) (fraunhofer.de)N/AAcquire Infrastructure: Botnet, Sub-technique T1583.005
Mirai (AKA Katana)Botnet expansion (DDoS, miner)Mirai (Malware Family) (fraunhofer.de)N/AAcquire Infrastructure: Botnet, Sub-technique T1583.005
Muhstik (AKA Tsunami)Botnet expansion (DDoS, miner)Tsunami (Malware Family) (fraunhofer.de)N/AResource Hijacking, Technique T1496
KinsingBotnet expansion (miner)Kinsing (Malware Family) (fraunhofer.de)Kinsing, Software S0599Resource Hijacking, Technique T1496
m8220Botnet expansion (miner)N/AN/AResource Hijacking, Technique T1496
SwrortDownloader usage (stager)Swrort Stager (Malware Family) (fraunhofer.de)N/AIngress Tool Transfer, Technique T1105
SitesLoaderDownloader usage (stager)N/AN/AIngress Tool Transfer, Technique T1105
KirabashInfostealer usageN/AN/AOS Credential Dumping: /etc/passwd and /etc/shadow, Sub-technique T1003.008
XMRigMining tool usageN/AN/AResource Hijacking, Technique T1496
ZgrabNetwork scanner tool usageN/AN/ANetwork Service Scanning, Technique T1046
TellYouThePass RansomwareRansomware usageN/AN/AData Encrypted for Impact, Technique T1486
Khonsari RansomwareRansomware usageN/AN/AData Encrypted for Impact, Technique T1486
Conti RansomwareRansomware usageConti (Malware Family) (fraunhofer.de)Conti, Software S0575Data Encrypted for Impact, Technique T1486
NightSky RansomwareRansomware usageN/AN/AData Encrypted for Impact, Technique T1486
AvosLocker RansomwareRansomware usageN/AN/AData Encrypted for Impact, Technique T1486

Threat Groups

GroupingActorMentioned AliasOther Alias EternalLibertyThreat ReportNote
State actorChinaHAFNIUMN/AMSTIC (2)Attacking infrastructure to extend their typical targeting. In these attacks, HAFNIUM-associated systems were observed using a DNS service typically associated with testing activity to fingerprint systems.
State actorIranPHOSPHORUSAPT35, TEMP.Beanie, TA 453, NewsBeef, CharmingKitten, G0003, CobaltIllusion, TG-2889, Timberworm, C-Major, Group 41, Tarh Andishan, Magic Hound, NewscasterMSTIC (2)Iranian actor that has been deploying ransomware, acquiring and making modifications of the Log4j exploit.
Organized CybercrimeRussiaWizard SpiderTrickbot Gang, FIN12, GOLD BLACKBURN, Grim SpiderAdvIntelWizard Spider is the developer of the Conti Ransomware-as-a-Service (RaaS) operation which has a high number of affiliates, and a Conti affiliate has leveraged Log4Shell in Log4j2 in the wild
Organized CybercrimeRussiaEvilCorpIndrik Spider, GOLD DRAKECryptolaemusEvilCorp are the developers of the Dridex Trojan, which began life as a banking malware but has since shifted to support the delivery of ransomware, which has included BitPaymer, DoppelPaymer, Grief, and WastedLocker, among others. Dridex is now being dropped following the exploitation of vulnerable Log4j instances
State actorChinaAquatic PandaN/ACrowdStrikeAQUATIC PANDA is a China-based targeted intrusion adversary with a dual mission of intelligence collection and industrial espionage. It has likely operated since at least May 2020. AQUATIC PANDA operations have primarily focused on entities in the telecommunications, technology and government sectors. AQUATIC PANDA relies heavily on Cobalt Strike, and its toolset includes the unique Cobalt Strike downloader tracked as FishMaster. AQUATIC PANDA has also been observed delivering njRAT payloads to targets.
To be determinedChinaDEV-0401N/AMSTIC (4)Attackers started exploiting the CVE-2021-44228 vulnerability in internet-facing systems running VMware Horizon. An investigation shows that successful intrusions in these campaigns led to the deployment of the NightSky ransomware. These attacks are performed by a China-based ransomware operator that MSTIC is tracking as DEV-0401. DEV-0401 has previously deployed multiple ransomware families including LockFile, AtomSilo, and Rook, and has similarly exploited Internet-facing systems running Confluence (CVE-2021-26084) and on-premises Exchange servers (CVE-2021-34473).
Organized CybercrimeRussiaMummy SpiderTA542, MealyBug, GoldCrestwoodSentinelOneNaturally, the Emotet crew has been taking advantage of Log4j as well. For example, vulnerable servers were quickly compromised and used for staging and payload hosting within the greater Emotet network.
Organized CybercrimeRussiaProphet SpiderUNC961BlackBerryThe Initial Access Broker (IAB) group Prophet Spider has been exploiting the Log4j vulnerability in the Apache Tomcat component of VMware Horizon