config.yaml
Detects obfuscation methods used to evade detection in log4j exploitation attempt of CVE-2021-44228Hacktool
SHA-256601ff80121e508118751f2e91dcdbefa68468ecb485b7c87cb5bd2fb41111f07
MaleculeTh
Evidence
67:45… y. The rule matches obfuscated Log4Shell lookup strings such as ${lower:j} or %24%7bjndi: anywhere in a file. Those strings are captured attack traffic, not executable code: they appear in web logs, WAF and scanner te …
553:61… ool banner strings, so a single string convicts. The $q string `objectif-securite` (a hacktool about-string) is also the domain of the objectif-securite.ch security blog, whose write-ups appear as Third Party …