Skip to content

Commit 423aaae

Browse files
authored
Merge branch 'NCSC-NL:main' into main
2 parents 355a500 + 7026761 commit 423aaae

2 files changed

Lines changed: 40 additions & 3 deletions

File tree

iocs/README.md

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -18,9 +18,13 @@ However NCSC-NL strives to provide IoCs from reliable sources.**
1818
| GovCert.ch | https://www.govcert.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/|
1919
| isc.sans.edu | https://isc.sans.edu/diary/Log4Shell+exploited+to+implant+coin+miners/28124 |
2020
| cert-agid.gov.it | https://cert-agid.gov.it/download/log4shell-iocs.txt |
21-
| NLD verified source | https://thanksforallthefish.nl/log4j_hashes.txt (Thor format) |
22-
| NLD verified source| https://thanksforallthefish.nl/log4j_hashes_sha256.txt (line-by-line) |
23-
| NLD verified source | https://thanksforallthefish.nl/log4j_hashes_sha1md5.txt (line-by-line) |
21+
| NLD Police | https://thanksforallthefish.nl/log4j_hashes.txt (Thor format) Auto Updated every 15min |
22+
| NLD Police | https://thanksforallthefish.nl/log4j_hashes_sha256.txt (line-by-line) Auto Updated every 15min |
23+
| NLD Police | https://thanksforallthefish.nl/log4j_hashes_sha1md5.txt (line-by-line) Auto Updated every 15min |
24+
| NLD Police | https://thanksforallthefish.nl/log4j_domains.txt (Thor format) Auto Updated every 15min |
25+
| NLD Police | https://thanksforallthefish.nl/log4j_urls.txt (line-by-line) Auto Updated every 15min |
26+
| NLD Police | https://thanksforallthefish.nl/log4j_blocklist.txt (line-by-line) Not Verified |
27+
2428

2529
## List of IoC's from security vendors
2630

software/README.md

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1825,6 +1825,39 @@ _Note: daily releases of this software list are listed, including CSV and JSON f
18251825
| PowerDNS | PowerDNS Recursor | | Not vuln | | [source](https://blog.powerdns.com/2021/12/16/powerdns-and-log4j-log4shell/) |
18261826
| Progress | DataDirect Hybrid Data Pipeline | | Workaround | | [source](https://www.progress.com/security), [mitigations](https://knowledgebase.progress.com/articles/Knowledge/Is-Hybrid-Data-Pipeline-vulnerable-CVE-2021-44228-Log4j) |
18271827
| Progress | OpenEdge | | Workaround | | [source](https://www.progress.com/security), [mitigations](https://knowledgebase.progress.com/articles/Knowledge/Is-OpenEdge-vulnerable-to-CVE-2021-44228-Log4j) |
1828+
| Proofpoint | Archiving Appliance | | Vulnerable | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1829+
| Proofpoint | Archiving Backend | | Fix | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1830+
| Proofpoint | Cloud App Security Broker | | Vulnerable | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1831+
| Proofpoint | Cloudmark Cloud/Cloudmark Hybrid | | Fix | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1832+
| Proofpoint | Cloudmark on Premise | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1833+
| Proofpoint | Content Patrol | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1834+
| Proofpoint | Data Discover | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1835+
| Proofpoint | DLP Core Engine | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1836+
| Proofpoint | Email Continuity | | Fix | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1837+
| Proofpoint | Email Fraud Defense (EFD) | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1838+
| Proofpoint | Email Protection on Demand (PoD), including Email DLP and Email Encryption | | Fix | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1839+
| Proofpoint | mail Protection On-Premises (PPS), including Email DLP and Email Encryption | | Fix | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1840+
| Proofpoint | Email Security Relay | | Fix | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1841+
| Proofpoint | Endpoint DLP | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1842+
| Proofpoint | Essentials Archive | | Fix | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1843+
| Proofpoint | Essentials Email | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1844+
| Proofpoint | Insider Threat Management On-prem | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1845+
| Proofpoint | Insider Threat Management SaaS | | Fix | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1846+
| Proofpoint | Isolation | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1847+
| Proofpoint | ITM SaaS Endpoint Agents | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1848+
| Proofpoint | Meta/ZTNA | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1849+
| Proofpoint | Nexus People Risk Explorer | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1850+
| Proofpoint | Proofpoint Compliance Gateway | | Fix | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1851+
| Proofpoint | Secure Email Relay | | Fix | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1852+
| Proofpoint | Secure Share | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1853+
| Proofpoint | Security Awareness Training | | Fix | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1854+
| Proofpoint | Sentrion | | Fix | Version 4.4 and earlier are not vulnerable. For version 4.5 patches have been made available to remediate the vulnerability. | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1855+
| Proofpoint | Social Discover | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1856+
| Proofpoint | SocialPatrol | | Fix | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1857+
| Proofpoint | Targeted Attack Protection (TAP) | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1858+
| Proofpoint | Threat Response (TRAP) | | Not vuln | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1859+
| Proofpoint | Web Gateway | | Fix | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
1860+
| Proofpoint | Web Security | | Vulnerable | | [source](https://www.proofpoint.com/us/blog/corporate-news/proofpoints-response-log4j-vulnerability) |
18281861
| Proxmox | Backup Server | | Not vuln | | [source](https://forum.proxmox.com/threads/log4j-exploit-what-to-do.101254/#post-436880) |
18291862
| Proxmox | Mail Gateway | | Not vuln | | [source](https://forum.proxmox.com/threads/log4j-exploit-what-to-do.101254/#post-436880) |
18301863
| Proxmox | VE | | Not vuln | | [source](https://forum.proxmox.com/threads/log4j-exploit-what-to-do.101254/#post-436880) |

0 commit comments

Comments
 (0)