As with many other applications, the Unifi application from Ubiquiti was vulnerable to the Log4J attacks. Morphisec has observed these attacks in the wild utilizing a Command-and-Control (C2) system that appears to be related to TA505 (aka Graceful Spider), and the C2 is correlated to some previous SolarWinds attacks.
These attacks are utilizing a Cobalt Strike beacon with a reverse TCP PowerShell script.
Morphisec Report: https://blog.morphisec.com/log4j-exploit-targets-vulnerable-unifi-network-applications
Indicators of Compromise
Indicator Type | Indicator |
File Hash SHA256 | 079089176ad528393c0641a630d90ca90a353a3c1765fb052e8c43ed45a29506 |
File Hash SHA256 | 5e53ee9c3299a60b313bdfa3d8b8aaafae67d70eb565a7999e42139d51614462 |
CVE | CVE-2021-44228 |
File Hash SHA256 | 2275247244f03091373f51d613939f5a96c48481c60832d443c112611142ceba |
File Hash SHA256 | cccd16f0c8e1f490f9cf8b0a42d61b52185f0e44e66e098c4f116b3e19f75b1c |
IPv4 | 179.60.150.32 |
IPv4 | 179.60.150.25 |
IPv4 | 179.60.150.26 |
IPv4 | 179.60.150.27 |
IPv4 | 179.60.150.29 |
IPv4 | 179.60.150.30 |
