This page contains an overview of any Indicators of Compromise regarding the Log4j vulnerability. On this page NCSC-NL will maintain a list of all known IOCs which can be used to detect and block. Furthermore any references will contain specific information regarding indicator reports.
NCSC-NL has not verified the IoCs listed below and therefore cannot guarantee the validity of said rules. However NCSC-NL strives to provide IoCs from reliable sources.
Note | Links |
---|---|
The list of callback servers, updated by Greynoise | https://gist.github.com/superducktoes/9b742f7b44c71b4a0d19790228ce85d8 |
The list of scanning IP's, updated by Greynoise | https://gist.github.com/gnremy/c546c7911d5f876f263309d7161a7217 |
Threatfox | https://threatfox.abuse.ch/browse/tag/log4j/ |
UrlHaus | https://urlhaus.abuse.ch/browse/tag/log4j/ |
Malware Bazaar | https://bazaar.abuse.ch/browse/tag/log4j/ |
CTCI | https://docs.google.com/spreadsheets/d/e/2PACX-1vT1hFu_VlZazvc_xsNvXK2GJbPBCDvhgjfCTbNHJoP6ySFu05sIN09neV73tr-oYm8lo42qI_Y0whNB/pubhtml# |
Malwar3Ninja | https://twitter.com/bad_packets/status/1469225135504650240 |
GovCert.ch | https://www.govcert.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/ |
isc.sans.edu | https://isc.sans.edu/diary/Log4Shell+exploited+to+implant+coin+miners/28124 |
cert-agid.gov.it | https://cert-agid.gov.it/download/log4shell-iocs.txt |
Note | Links |
---|---|
TweetFeed | https://twitter.com/0xdaniellopez/status/1470029308152487940?s=21 |