logo

Who's Knocking on Your Door? An Analysis of Exposed Services and Their Risks

ID: badb8397-556b-54e7-9393-336d38185523

STIX ID: report--badb8397-556b-54e7-9393-336d38185523

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2025-11-07

Date Updated: 2026-04-27

Author: Jean Pierre Ruiz Ocampo; Jonas Gyllenhammar

...
...

This report analyzes automated internet scanning and exploitation of exposed services, showing concrete examples: SSH brute-force intrusions that install persistent keys and attempt environment fingerprinting, HTTP/HTTPS command-injection and remote code execution probes that stage Mirai-style ELF droppers, and out‑of‑band (OAST) blind-RCE tests via Java expression injection. The document includes observed IoCs (source and infrastructure IPs, malicious request patterns and payload URLs), measurements of time-to-first-probe, and a prioritized incident response and long-term mitigation plan (blocklists, hardening SSH/web apps, WAF tuning, egress restrictions, and continuous ASM).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.