Skip to content

Instantly share code, notes, and snippets.

@yt0ng
Last active January 7, 2022 12:21
Show Gist options
  • Select an option

  • Save yt0ng/b933d0c8ce1076fa74bd31cbecedb884 to your computer and use it in GitHub Desktop.

Select an option

Save yt0ng/b933d0c8ce1076fa74bd31cbecedb884 to your computer and use it in GitHub Desktop.
RPZ for Log4j
############################################################################
# RPZ to detect internal exploitation of Log4j
############################################################################
# Joint work @craiu https://twitter.com/craiu
# https://github.com/craiu/iocs/blob/main/log4shell/log4j_blocklist.txt
############################################################################
dnspod.cn
bingsearchlib.com
interactsh.com
dnslog.cn
interact.sh
burpcollaborator.net
requestbin.net
rce.ee
requestcatcher.com
y.psc4fuel.com
htbiw.com
log4shell.huntress.com
x00.fi
d9.wf
knary.xyz
test2.ggdd.co.uk
synprobe001.leakix.net
md-l4j.s2.inty.io
do-01.redteam.tf
w.nessus.org
w0.cx
oob.li
scanworld.net
binaryedge.io
1ma.xyz
ghhui.tk
kryptoslogic-cve-2021-44228.com
dns.cyberwar.nl
1433.eu.org
log4j.leakix.net
5ed.xyz
# domains which could have impact when blocking
members.linode.com
ngrok.io
econ-jobs.com
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment