Nathan reported today that he has been seeing a new trend of web scanning against his webservers looking for /info/whitelist.pac. The scanning he has observed is over SSL. He has been observing this activity since the 22 Aug.
[22/Aug/2014:18:55:32 -0500]Â Â Â xx.12.93.178Â Â Â GET /info/whitelist.pac HTTP/1.1Â Â Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
[...]
[14/Sep/2014:11:10:05 -0500]Â Â Â xx.216.137.7Â Â Â GET /info/whitelist.pac HTTP/1.1Â Â Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
[14/Sep/2014:13:16:19 -0500]Â Â Â xx.174.190.254 GET /info/whitelist.pac HTTP/1.1Â Â Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
[14/Sep/2014:14:03:48 -0500]Â Â Â xx.252.188.49Â Â GET /info/whitelist.pac HTTP/1.1Â Â Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
[14/Sep/2014:17:10:40 -0500]Â Â Â xx.17.199.47Â Â Â Â GET /info/whitelist.pac HTTP/1.1Â Â Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
[14/Sep/2014:21:10:26 -0500]Â Â Â xx.13.136.13Â Â Â GET /info/whitelist.pac HTTP/1.1Â Â Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
[16/Sep/2014:06:30:15 -0500]Â Â Â xx.10.51.74Â Â Â Â Â GET /info/whitelist.pac HTTP/1.1Â Â Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
[16/Sep/2014:14:03:54 -0500]Â Â Â xx.240.174.203Â GET /info/whitelist.pac HTTP/1.1Â Â Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
Is anyone else seeing similar activity against their webservers?
-----------
Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.