This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Java Payload Strings
Original Source:
[Sigma source]
Title:
Java Payload Strings
Status:
test
Description:
Detects possible Java payloads in web access logs
References:
-https://www.rapid7.com/blog/post/2022/06/02/active-exploitation-of-confluence-cve-2022-26134/
-https://www.rapid7.com/blog/post/2021/09/02/active-exploitation-of-confluence-server-cve-2021-26084/
-https://github.com/httpvoid/writeups/blob/62d3751945289d088ccfdf4d0ffbf61598a2cd7d/Confluence-RCE.md
-https://twitter.com/httpvoid0x2f/status/1532924261035384832
-https://medium.com/geekculture/text4shell-exploit-walkthrough-ebc02a01f035
Author:
frack113, Harjot Singh, "@cyb3rjy0t" (update)
Date:
2022-06-04
modified:
2023-01-19
Tags:
-'cve.2022-26134'
-'cve.2021-26084'
-'attack.initial-access'
-'attack.t1190'
Logsource:
category: webserver
Detection:
keywords:
- '%24%7B%28%23a%3D%40'
- '${(#a=@'
- '%24%7B%40java'
- '${@java'
- 'u0022java'
- '%2F%24%7B%23'
- '/${#'
- 'new+java.'
- 'getRuntime().exec('
- 'getRuntime%28%29.exec%28'
condition
:
keywords
Falsepositives:
-Legitimate apps
Level:
high