Webserver log detection of Log4j CVE-2021-44228 JNDI strings in User-Agent, URI query, or Referer
Flags webserver requests with ${jndi:...} payloads in User-Agent, URI query, or Referer indicative of Log4Shell attempts.
FreeUnreviewedSigmahighv1
webserver-log-detection-of-log4j-cve-2021-44228-jndi-strings-in-user-agent-uri-q-9be472ed
title: Webserver log detection of Log4j CVE-2021-44228 JNDI strings in User-Agent, URI query, or Referer
id: e820f75d-6a43-4713-a8e9-a6a23159e668
status: test
description: This rule identifies HTTP requests in web server logs that contain Log4j-style ${jndi:...} payload fragments associated with the CVE-2021-44228 exploitation attempts, including multiple obfuscated variants. Attackers rely on these strings being processed by vulnerable logging components to trigger outbound lookups, enabling remote code execution or related impact. The detection relies on matching suspicious substrings in User-Agent, URI query parameters, and Referer fields (cs-user-agent, cs-uri-query, cs-referer) within webserver log telemetry.
references:
- https://web.archive.org/web/20231230220738/https://www.lunasec.io/docs/blog/log4j-zero-day/
- https://news.ycombinator.com/item?id=29504755
- https://github.com/tangxiaofeng7/apache-log4j-poc
- https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b
- https://github.com/YfryTchsGD/Log4jAttackSurface
- https://twitter.com/shutingrz/status/1469255861394866177?s=21
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Exploits/CVE-2021-44228/web_cve_2021_44228_log4j_fields.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-12-10
modified: 2023-01-02
tags:
- attack.initial-access
- attack.t1190
- cve.2021-44228
- detection.emerging-threats
logsource:
category: webserver
detection:
selection1:
cs-user-agent|contains:
- ${jndi:ldap:/
- ${jndi:rmi:/
- ${jndi:ldaps:/
- ${jndi:dns:/
- "/$%7bjndi:"
- "%24%7bjndi:"
- "$%7Bjndi:"
- "%2524%257Bjndi"
- "%2F%252524%25257Bjndi%3A"
- "${jndi:${lower:"
- ${::-j}${
- ${jndi:nis
- ${jndi:nds
- ${jndi:corba
- ${jndi:iiop
- "Reference Class Name: foo"
- ${${env:BARFOO:-j}
- ${::-l}${::-d}${::-a}${::-p}
- ${base64:JHtqbmRp
- ${${env:ENV_NAME:-j}ndi${env:ENV_NAME:-:}$
- "${${lower:j}ndi:"
- "${${upper:j}ndi:"
- "${${::-j}${::-n}${::-d}${::-i}:"
selection3:
cs-uri-query|contains:
- ${jndi:ldap:/
- ${jndi:rmi:/
- ${jndi:ldaps:/
- ${jndi:dns:/
- "/$%7bjndi:"
- "%24%7bjndi:"
- "$%7Bjndi:"
- "%2524%257Bjndi"
- "%2F%252524%25257Bjndi%3A"
- "${jndi:${lower:"
- ${::-j}${
- ${jndi:nis
- ${jndi:nds
- ${jndi:corba
- ${jndi:iiop
- "Reference Class Name: foo"
- ${${env:BARFOO:-j}
- ${::-l}${::-d}${::-a}${::-p}
- ${base64:JHtqbmRp
- ${${env:ENV_NAME:-j}ndi${env:ENV_NAME:-:}$
- "${${lower:j}ndi:"
- "${${upper:j}ndi:"
- "${${::-j}${::-n}${::-d}${::-i}:"
selection4:
cs-referer|contains:
- ${jndi:ldap:/
- ${jndi:rmi:/
- ${jndi:ldaps:/
- ${jndi:dns:/
- "/$%7bjndi:"
- "%24%7bjndi:"
- "$%7Bjndi:"
- "%2524%257Bjndi"
- "%2F%252524%25257Bjndi%3A"
- "${jndi:${lower:"
- ${::-j}${
- ${jndi:nis
- ${jndi:nds
- ${jndi:corba
- ${jndi:iiop
- "Reference Class Name: foo"
- ${${env:BARFOO:-j}
- ${::-l}${::-d}${::-a}${::-p}
- ${base64:JHtqbmRp
- ${${env:ENV_NAME:-j}ndi${env:ENV_NAME:-:}$
- "${${lower:j}ndi:"
- "${${upper:j}ndi:"
- "${${::-j}${::-n}${::-d}${::-i}:"
condition: 1 of selection*
falsepositives:
- Vulnerability scanning
level: high
license: DRL-1.1
related:
- id: 9be472ed-893c-4ec0-94da-312d2765f654
type: derived
What it detects
This rule identifies HTTP requests in web server logs that contain Log4j-style ${jndi:...} payload fragments associated with the CVE-2021-44228 exploitation attempts, including multiple obfuscated variants. Attackers rely on these strings being processed by vulnerable logging components to trigger outbound lookups, enabling remote code execution or related impact. The detection relies on matching suspicious substrings in User-Agent, URI query parameters, and Referer fields (cs-user-agent, cs-uri-query, cs-referer) within webserver log telemetry.
Known false positives
- Vulnerability scanning
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.