logo

A Beginner's Guide to Hunting Malicious Open Directories

ID: 81b0bb9c-b0a4-5b5a-8824-844eee02573c

STIX ID: report--81b0bb9c-b0a4-5b5a-8824-844eee02573c

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2024-07-22

Date Updated: 2026-04-27

Author: Ivonne Francia; Embee Research

...
...

This blog explains practical hunting techniques for identifying malicious open directories on the Internet using Censys, demonstrating pivots on static filenames, hosting providers/ASNs, regular-expression file patterns, and combined file-extension queries; it includes concrete IOCs (example IPs, filenames like a.exe, yaml-payload.jar, artifact_x86.exe, references to CS4.9), mentions observed malware families (Cobalt Strike, Sliver, Vidar, Lumma, ransomware), and provides reusable queries for defenders to find and investigate similar infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.