Scanning Webserver with /$(pwd)/ as a Starting Path, (Sun, Jan 25th)
ID: 0ddf1adf-99dc-5541-98b9-210536236847
STIX ID: report--0ddf1adf-99dc-5541-98b9-210536236847
Feed Name: SANS ISC Diary
ISC sensors observed a small campaign of reconnaissance scans in mid-January 2026 from IPs 185.177.72.52 and 185.177.72.23 probing for URLs containing the literal $(pwd) string and exposed configuration files (.env*, terraform.tfstate, docker-compose.yml, netlify.toml). The report includes a Kibana ES|QL query to identify matching events and notes limited probe volumes, along with references to visualized relationships among probed URLs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
