Uploaded December 2021 | Updated September 2026, 9 hours ago
The Log4j is quite the buzz these days - as it should be! There are lots of videos showing the code of how it works, but let's analyze how CVE-2021-44228 looks on the wire. You can download the pcap with the attack traffic and follow along with me here:
bit.ly/Log4jAttack
(Thanks Brad Duncan from malware-traffic-analysis.net!)
As a side point - there is a possibility that the filter shown will show some false positives if the target server connects to other internal servers. Take that into account when analyzing the filter results!
Link to video on how to configure Wireshark GeoIP: youtu.be/IlVppluWTHw
Other links:
E-mail: packetpioneer@gmail.com
Twitter: twitter.com/packetpioneer
Full Wireshark Cybersecurity Course - bit.ly/wiresharkhunt
TCP Analysis Course - bit.ly/wiresharktcp
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Timestamps:
0:00 Intro
0:58 PCAP Overview
1:32 Mapping the source IP's
2:51 Analyzing the Log4j Post
4:29 Decoding the Base64 with CyberChef
5:35 Researching the remote server - Virus Total
6:46 Filtering for Log4j
9:40 Wrap-Up
The Log4j is quite the buzz these days - as it should be! There are lots of videos showing the code of how it works, but let's analyze how CVE-2021-44228 looks on the wire. You can download the pcap with the attack traffic and follow along with me here:
bit.ly/Log4jAttack
(Thanks Brad Duncan from malware-traffic-analysis.net!)
As a side point - there is a possibility that the filter shown will show some false positives if the target server connects to other internal servers. Take that into account when analyzing the filter results!
Link to video on how to configure Wireshark GeoIP: youtu.be/IlVppluWTHw
Other links:
E-mail: packetpioneer@gmail.com
Twitter: twitter.com/packetpioneer
Full Wireshark Cybersecurity Course - bit.ly/wiresharkhunt
TCP Analysis Course - bit.ly/wiresharktcp
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Timestamps:
0:00 Intro
0:58 PCAP Overview
1:32 Mapping the source IP's
2:51 Analyzing the Log4j Post
4:29 Decoding the Base64 with CyberChef
5:35 Researching the remote server - Virus Total
6:46 Filtering for Log4j
9:40 Wrap-Up










