#opendir

Open directories - publicly listable web roots hosting attacker payloads, kits and tools

Subscribe (RSS)


#opendir

Open directories hosting attacker payloads

Subscribe (RSS)


IOCs by window

Today

0

IOCs tagged #opendir

Week

33

IOCs tagged #opendir

Month

153

IOCs tagged #opendir

Year

715

IOCs tagged #opendir

Counts as of 2026-08-09. Regenerated daily.

About #opendir

  • Definition: an HTTP server (often nginx / Apache / IIS) configured with directory autoindex enabled, exposing the contents of a folder. When the folder belongs to an attacker (staging server, kit drop, panel root) the listing reveals payloads, scripts and operator artefacts.
  • Why researchers track them: open directories are a high-yield source of fresh IOCs. A single opendir often hosts multiple loaders, second-stage payloads, exfiltrated-data archives and YARA-friendly scripts; researchers download, hash and tag each artefact in bulk.
  • Detection: for defenders, periodic scans of organisation egress for `Index of /` patterns; for hunters, services like ODIN by The DFIR Report, URLscan tag filters, and certificate-transparency-driven sweeps.
  • References: MITRE ATT&CK T1190 · The DFIR Report.

Recent IOCs tagged #opendir

Latest 10 IOCs from the past 30 days. Live JSON: api.tweetfeed.live/v1/month/opendir.

Date Type Value Source
Aug 07, 20:53 url http://192.252.178.228 @skocherhan
Aug 07, 20:53 ip 192.252.178.228 @skocherhan
Aug 07, 20:53 md5 424276f503040bf22b9d98f61fbe49c0 @skocherhan
Aug 07, 20:53 md5 1ac13ebb0f5f90bae4692a4c7fe8b6c2 @skocherhan
Aug 07, 13:03 ip 120.26.146.96 @teamcymru_S2
Aug 07, 13:03 ip 209.177.145.97 @teamcymru_S2
Aug 07, 13:03 ip 118.25.25.199 @teamcymru_S2
Aug 07, 13:03 ip 154.201.70.25 @teamcymru_S2
Aug 07, 13:03 ip 46.224.67.169 @teamcymru_S2
Aug 07, 13:03 ip 154.217.241.175 @teamcymru_S2

Related tags

Tags that frequently co-occur with #opendir.

See all tags on the Dashboard or browse the full IOC feed.

Frequently asked questions

What is an opendir?

An opendir (open directory) is a web folder where directory autoindexing is enabled, exposing all files inside as a clickable listing. When attackers misconfigure their staging servers this way - which happens often - researchers can browse the listing, download every artefact and reverse-engineer the kit or payload set.

How do opendirs end up in this feed?

Public researchers post URLs to attacker opendirs they discover, tagged #opendir. The TweetFeed pipeline picks up these URLs (and the IPs/domains hosting them) and republishes them in CSV, JSON and RSS within 15 minutes. Many opendirs are short-lived: the operator notices the leak and locks down the directory or rotates infrastructure.

How is this list updated?

Every 15 minutes. The TweetFeed pipeline scrapes RSS feeds from public Twitter/X security researcher accounts and lists, extracts IOCs, tags them with the relevant malware family or threat actor, and republishes the result in CSV, JSON and RSS. Opendir-tagged IOCs are surfaced on this page within the next 15-minute tick. The page itself is regenerated daily by a GitHub Action.

What is the license? Can I use this commercially?

All TweetFeed IOC data, including this Opendir subset, is released under CC0 1.0 Universal (Public Domain Dedication). No attribution required, no warranty. Commercial use is allowed. The TweetFeed website code and branding are not covered by CC0.

License

Opendir IOC data: CC0 1.0 Public Domain. No attribution required, no warranty. Source code for the pipeline: github.com/0xDanielLopez/TweetFeed (MIT).