Let's Look for Bad Stuff Using Censys' "Suspicious-Open-Directory" Label!
ID: bede5142-a2b9-500e-90c8-5a10cb3c1396
STIX ID: report--bede5142-a2b9-500e-90c8-5a10cb3c1396
Feed Name: Censys Blog
Date Published: 2024-11-08
Date Updated: 2026-04-27
Author: Ivonne Francia; Jeremy Fernandez; Guest Author; Security Researcher
This report explains Censys's new "suspicious-open-dir" label that filters open directories to a smaller, more likely-malicious set and demonstrates its utility through examples: directories hosting exploit toolkits (including Adobe ColdFusion attack scripts and RDWeb brute-force logs), phishing pages capturing credentials, and a botnet/cryptominer framework with a C2 web UI and payloads. The author shows how the label reduces noise from ~393k open directories to roughly 4.5k flagged as suspicious and discusses potential enhancements to better identify truly malicious hosting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
