I continue to get this IDS firewall log entry:
vulnscan10.cyhy.ncats.cyber.dhs.gov
IP/port:100.27.42.250:48534
With event: Apache Log4j logging remote code execution attempt
The event is blocked.
It is directed to a SINGLE internal server NOT open to the internet. It appears to be a valid website. My concerns are,
1) How does this website even know about this particular server? ........it's rhetorical.
2) Why is it trying to run code on it? again rhetorical.
I am just at a loss to this. Server scanned, all clean. It is a new server that was added in the last year, new OS.
I cannot find anything in event log on this server that coincides with this, would give any hint as to why something on the outside is trying to get to it.
Thank you all in advanced!
Anyone else seeing this?