Java Payload Strings

 Original Source: [Sigma source]
Title: Java Payload Strings
Status: test
Description:Detects possible Java payloads in web access logs
References:
  -https://www.rapid7.com/blog/post/2022/06/02/active-exploitation-of-confluence-cve-2022-26134/
  -https://www.rapid7.com/blog/post/2021/09/02/active-exploitation-of-confluence-server-cve-2021-26084/
  -https://github.com/httpvoid/writeups/blob/62d3751945289d088ccfdf4d0ffbf61598a2cd7d/Confluence-RCE.md
  -https://twitter.com/httpvoid0x2f/status/1532924261035384832
  -https://medium.com/geekculture/text4shell-exploit-walkthrough-ebc02a01f035
Author: frack113, Harjot Singh, "@cyb3rjy0t" (update)
Date: 2022-06-04
modified:2023-01-19
Tags:
  • -'cve.2022-26134'
  • -'cve.2021-26084'
  • -'attack.initial-access'
  • -'attack.t1190'
Logsource:
  • category: webserver
Detection:
  keywords:
    - '%24%7B%28%23a%3D%40'
    - '${(#a=@'
    - '%24%7B%40java'
    - '${@java'
    - 'u0022java'
    - '%2F%24%7B%23'
    - '/${#'
    - 'new+java.'
    - 'getRuntime().exec('
    - 'getRuntime%28%29.exec%28'
  condition:keywords
Falsepositives:
  -Legitimate apps
Level: high