Scanning for Apache Struts Vulnerability CVE-2017-5638, (Sun, Mar 25th)

Over the past two weeks, I have noticed several attempts against my honeypot looking to exploit CVE-2017-5638 Apache Struts2 vulnerability that look very similar to this python script[2]. Today alone I recorded 57 attempts against port 80, 8080 and 443. T format of the queries I have observed over the past two weeks contain one of these two requests:

Article Link: https://isc.sans.edu/diary/rss/23479