Skip to main content
Question

SCC threat finding - Initial access: log4j compromise attempt

  • July 8, 2026
  • 1 reply
  • 32 views

arv261095
Forum|alt.badge.img+7

Hi Team anyone has any idea on what this low sev SCC findings are actually i am very much confused as most of them are having source IPs as AWS and Google and generating lot of noise also the url contains nessus so not sure why a google / AWS source IP would trigger this :

E.g : 

Source IP

100.27.42.240 


      "refererUrl": "${jndi:ldap://log4shell-generic-lQr0LA9voF9PHEyop2C6${lower:ten}.w.nessus.org/nessus}"


and these are generated daily via multiple different AWS and Google IPs as source 
 

 

1 reply

a_aleinikov
Forum|alt.badge.img+8
  • Bronze 2
  • July 14, 2026

This appears to be a Nessus Log4Shell validation scan, not proof of compromise. Confirm the scanner is authorized, check for any successful callback or follow-on activity, and tune the finding by scanner identity or specific IPs rather than allowlisting AWS or Google ranges.