Skip to main content
Skip to main content
Microsoft Security Intelligence
66 entries found. Displaying page 3 of 4.
Updated on May 05, 2018
Alert level: severe
Updated on Aug 03, 2018
Alert level: severe
Updated on Jan 26, 2019
Alert level: severe
Updated on Nov 12, 2020
Alert level: severe
Updated on Sep 23, 2015
Alert level: severe
Updated on Dec 22, 2016
Alert level: severe
Updated on Feb 10, 2018
Alert level: severe
Updated on Feb 10, 2018
Alert level: severe
Updated on Jul 24, 2017
Alert level: severe
Updated on Nov 02, 2017
Alert level: severe
Updated on May 29, 2018
Alert level: severe
Updated on Jul 03, 2018
Alert level: severe
Updated on Feb 10, 2018
Alert level: severe
Updated on May 09, 2016
Alert level: severe
Updated on Jan 16, 2018
Alert level: severe
Updated on Apr 13, 2018
Alert level: severe
Updated on May 20, 2015
Alert level: severe
Updated on Nov 23, 2021
Alert level: severe
Updated on May 17, 2022
Alert level: severe
Updated on Mar 12, 2016

Microsoft Defender Antivirus detects and removes this threat.

This threat represents a cryptocurrency mining payload associated with post exploitation of the remote code execution vulnerability, CVE-2021-44228 (also referred to as “Log4Shell”), in the Log4j component of Apache. This vulnerability affects Java-based applications that use Log4j 2.

Attackers gain access to the target device and launch arbitrary remote code loaded from LDAP servers, which are logged and launched by the Log4j component. This can allow attackers to install cryptocurrency miners on a target device. 

Read the following blogs for more information: 

 

Alert level: severe