
Example 2: hXXp://43.167.163[.]197:2080/ - File logback.xml contains POC for JDNI vulnerability in logback - Potentially linked to CVE-2021-42550 This one doesn't contain the vshell installation directory, but we can see the IP has been tagged as VShell C2 (4/8) https://t.co/T2kvu67G8x
Post summary
The message reports a POc for a JDNI logback vulnerability (CVE-2021-42550) and notes an IP recognized as a VShell C2, but it does not describe active exploitation, patches, or false positives.
