Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
log4j-CVE-2021-44228-Public-IoCs — 关于 log4j CVE-2021-44228 的公开 IoCs | Kitploit
工具/GitHubGitHub/sh0ckfr/log4j-cve-2021-44228-public-iocs
危害指标 (IOC) 管理漏洞分析威胁情报学习与教育精选资源
GitHubsh0ckfr/log4j-cve-2021-44228-public-iocs

log4j-CVE-2021-44228-Public-IoCs

关于 log4j CVE-2021-44228 的公开 IoCs

查看仓库

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
91374年前尚未审核

log4j (log4shell) CVE-2021-44228 公开 IoCs 列表

关于 log4j CVE-2021-44228 (log4shell) 的公开 IoCs,基于 Twitter 和其他社交网络(接受 pull requests,我会自动去重)

IP 地址

  • https://github.com/Sh0ckFR/log4j-CVE-2021-44228-Public-IoCs/raw/main/ips.txt

回调域名

  • https://github.com/Sh0ckFR/log4j-CVE-2021-44228-Public-IoCs/raw/main/callbacks-domains.txt

哈希值(二进制文件)

  • https://github.com/Sh0ckFR/log4j-CVE-2021-44228-Public-IoCs/raw/main/hashes-binaries.txt

易受攻击的 log4j 版本的哈希值可在此获取

  • https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes

检测到的 Payload 列表可在此获取

  • https://gist.github.com/nathanqthai/01808c569903f41a52e7e7b575caa890

Yara 规则(持续更新中)

  • https://github.com/Sh0ckFR/log4j-CVE-2021-44228-Public-IoCs/blob/main/yara-rule.yar

IoCs 来源(用于生成上述列表的来源)

  • https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b
  • https://github.com/axelmorningstar/log4j
  • https://gist.github.com/gnremy/c546c7911d5f876f263309d7161a7217
  • https://github.com/CriticalPathSecurity/Zeek-Intelligence-Feeds/blob/master/log4j_ip.intel
  • https://gist.github.com/superducktoes/9b742f7b44c71b4a0d19790228ce85d8
  • https://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228/blob/main/Threatview.io-log4j2-IOC-list
  • https://github.com/eshlomo1/Azure-Sentinel-4-SecOps/blob/master/Hunting/CVE-2021-44228-Logshell/log4j-ioc-list.csv
  • https://raw.githubusercontent.com/guardicode/CVE-2021-44228_IoCs/main/iocs.csv
  • https://github.com/Orange-Cyberdefense/log4shell_iocs
  • 来自不同用户的推文

这里有一个用于检测攻击尝试的工具

  • https://github.com/Neo23x0/log4shell-detector

互联网社区关于 Log4j 对制造商和组件实际影响的总结

  • https://github.com/YfryTchsGD/Log4jAttackSurface
  • https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592
下载工具