JNDIExploit Pattern

 Original Source: [Sigma source]
Title: JNDIExploit Pattern
Status: test
Description:Detects exploitation attempt using the JNDI-Exploit-Kit
References:
  -https://github.com/pimps/JNDI-Exploit-Kit
  -https://web.archive.org/web/20231015205935/https://githubmemory.com/repo/FunctFan/JNDIExploit
Author: Florian Roth (Nextron Systems)
Date: 2021-12-12
modified:2022-12-25
Tags:
  • -'attack.initial-access'
  • -'attack.t1190'
Logsource:
  • category: webserver
Detection:
  keywords:
    - '/Basic/Command/Base64/'
    - '/Basic/ReverseShell/'
    - '/Basic/TomcatMemshell'
    - '/Basic/JettyMemshell'
    - '/Basic/WeblogicMemshell'
    - '/Basic/JBossMemshell'
    - '/Basic/WebsphereMemshell'
    - '/Basic/SpringMemshell'
    - '/Deserialization/URLDNS/'
    - '/Deserialization/CommonsCollections1/Dnslog/'
    - '/Deserialization/CommonsCollections2/Command/Base64/'
    - '/Deserialization/CommonsBeanutils1/ReverseShell/'
    - '/Deserialization/Jre8u20/TomcatMemshell'
    - '/TomcatBypass/Dnslog/'
    - '/TomcatBypass/Command/'
    - '/TomcatBypass/ReverseShell/'
    - '/TomcatBypass/TomcatMemshell'
    - '/TomcatBypass/SpringMemshell'
    - '/GroovyBypass/Command/'
    - '/WebsphereBypass/Upload/'
  condition:keywords
Falsepositives:
  -Legitimate apps the use these paths
Level: high