slatterysec.com/reports/2026/04/2026-04-11_2026-04-15-ssh-web-honeypot-report.html
sensors 8 up last session 4m ago 24h captures 312 unique src 87

slattery@sec:~/reports$ cat 2026-04-11_2026-04-15-ssh-web-honeypot-report.md

HONEYPOT REPORT // SSH + WEB // 2026-04-11 – 2026-04-15

2026-04-11 – 2026-04-15 — SSH + Web Honeypot Report

Period: 2026-04-11 – 2026-04-15  |  Sensor: Cowrie v2.x (SSH + HTTP)  |  Host: VPS / RackNerd
SSH WEB ALERT REDTAIL KURAYAMI
SSH CONNECTIONS
20,823
across 5 days
AUTH ATTEMPTS
16,071
7,706 succeeded
UNIQUE SSH IPs
1,273
top: 80.66.66.10
PAYLOAD DROPS
3,620
8 unique hashes
FILE UPLOADS
36
Redtail — 130.12.180.51
WEB REQUESTS
126
48 unique IPs

SSH connection volume by day

Apr 11
634
Apr 12
4,853
Apr 13
3,348
Apr 14
4,714
Apr 15
3,473
Apr 16*
3,801

*Apr 16 connections captured in Apr 15 log files (UTC rollover). Apr 12 was peak day at 4,853 connections.

Executive summary

The Apr 11–15 window continues established campaign patterns while introducing two new developments worth tracking. The mdrfckr SSH key injection campaign reached 3,418 sessions — its third consecutive weekly increase — with 130.12.180.51 returning on Apr 14 for another multi-session Redtail binary upload, now with a new clean.sh hash (94db7ecd...) suggesting the operator updated the deployment script while keeping the same miner binaries. The operator has now appeared in all three reporting periods, making this the most persistent single actor observed across the sensor.

The most significant new finding is the emergence of the Kurayami botnet. Five distinct download URLs were observed pointing to 142.248.80.144, serving lol.sh and architecture-specific binaries: kurayami.x86, kurayami.mips, kurayami.arc, and kurayami.i468. Kurayami is a known DDoS botnet family targeting Linux embedded devices. Its appearance alongside the existing Redtail and mdrfckr campaigns suggests the honeypot is being discovered by multiple independent scanning operations simultaneously.

On the web side, the period's most notable actor was 185.177.72.11, which launched 31 curl-based requests on Apr 16 against the router-admin.uk vhost. Unlike prior web actors, this one attempted a command injection probe — /admin/config?cmd=cat%20/root/.aws/credentials — making it the first observed RCE attempt across all three reporting periods. The same session also enumerated database-related paths (db.php, db.conf, sql.conf, sqladmin.php) and targeted the adminer database management tool specifically. 130.12.180.111 (the same /24 as the Redtail SSH uploader) returned again on Apr 14 with a full .env enumeration sweep across 13 path variants.

New botnet: Kurayami binaries observed for the first time — lol.sh dropper serving x86, MIPS, ARC, and i486 variants from 142.248.80.144. Distinct from the Redtail campaign; DDoS-focused rather than cryptomining.
First RCE attempt observed across all reporting periods: 185.177.72.11 probed /admin/config?cmd=cat%20/root/.aws/credentials on Apr 16. All prior web activity was passive enumeration — this is the first active exploitation attempt logged.

Notable sessions — SSH

2026-04-14T12:21:51Z (and recurring) REDTAIL DROP 130.12.180.51
Third consecutive appearance — Redtail operator returns with updated clean.sh, same miner binaries
uploaded: clean.sh (new hash), setup.sh, redtail.arm7, redtail.arm8, redtail.i686, redtail.x86_64
clean.sh hash: 94db7ecdcb422930... (changed from d46555af... in prior periods)
miner hashes: unchanged — same arm7/arm8/i686/x86_64 binaries as Apr 1 and Apr 7
note: Updated dropper script with same payload suggests operator is refining deployment logic — possible detection evasion or new persistence mechanism in clean.sh
2026-04-11–15 (sustained) SSH BACKDOOR multiple
mdrfckr key injection — 3,418 sessions, third consecutive weekly increase
credential: root:3245gs5662d34 (3,230) / 345gs5662d34:345gs5662d34 (3,234)
week-over-week: Apr 1–5: 2,431 → Apr 6–10: 3,159 → Apr 11–15: 3,418 (+8.2%)
note: Consistent growth trajectory suggests the botnet is expanding its node pool and tasking more bots against this sensor
2026-04-11–15 (new) KURAYAMI multiple
Kurayami DDoS botnet binaries dropped for first time — lol.sh dropper serving multi-arch payload set
dropper: http://142.248.80.144/lol.sh
binaries: kurayami.x86, kurayami.mips, kurayami.arc, kurayami.i468
hashes: 5 distinct new hashes — 9ca881ab, ea61e090, a65211cd, 1c912c5f, 0bfae0d5
note: Kurayami is a known Linux DDoS botnet distinct from Redtail's cryptomining focus. Architecture coverage (x86/MIPS/ARC/i486) targets broad embedded device range including routers and IoT.
2026-04-11–15 (sustained) HIGH VOLUME 80.66.66.10 / 46.151.182.220
80.66.66.10 continues as top SSH source (5,901 events); 46.151.182.220 emerges as new second-highest (1,180)
80.66.66.10: Down from 20,213 in prior period — still top source, reduced volume
46.151.182.220: New entrant — 1,180 events, not seen in prior periods
note: HTTP/Solr/InfluxDB probe strings appearing as username:password pairs suggest this source is also probing non-SSH services on port 23 (Telnet forwarding)

Notable sessions — web

2026-04-16T11:50:47–11:54:52Z RCE ATTEMPT 185.177.72.11
First RCE probe observed — curl-based actor attempts command injection targeting AWS credentials, then pivots to database tool enumeration
rce probe: GET /admin/config?cmd=cat%20/root/.aws/credentials
db enumeration: /admin/db.php, /admin/db.conf, /admin/sql.conf, /admin/sqladmin.php, /admin/phpmyadmin.php, /admin/adminer.php
ua: curl/8.7.1   vhost: router-admin.uk
total requests: 31 across multiple path categories
note: Notably in the same /24 as l9explore actor 185.177.72.61 — possible same operator running different tooling, or same infrastructure hosting multiple scanning tools
2026-04-14T16:11:28–16:11:33Z ENV HARVEST 130.12.180.111
130.12.180.111 returns — 13-request .env sweep covering backup files, alternate extensions, and path variants
paths: /admin/.env, /admin/.aws/credentials, /admin/public/.env, /admin-app/.env, /adminapp/.env, /admin/config/.env, /admin/config/env.bak, //admin/.env, /admin/.env.bak, /admin/env.bak, /admin/.env.dist, /adminer/.env, /admin/public/.env.bak
note: Now seen in all three reporting periods. Same /24 as Redtail SSH uploader (130.12.180.51) — cross-sensor actor linkage consistent across the full observation window
2026-04-15T09:22–09:24Z GO SCANNER 149.50.97.236
New Go-http-client scanner — Django admin login probe followed by phpinfo and .env enumeration
login probe: GET /admin/login/?next=/admin/ (mobile Chrome UA) — then switched to Go-http-client
paths: /administrator/config/.env, /admin/php.php, /admin/php-info.php, /admin/console/.env, /administrator/phpinfo.php, /admin/info.php, /admin/phpinfo.php, /admin/.env, /admin/config/.env, /administrator/.env, /admin/php_info.php
note: UA switch mid-session (mobile Chrome → Go-http-client) suggests tooling that spoof-checks for WAF/bot detection before switching to scanner mode
2026-04-16T08:59–09:12Z SECRETS HARVEST 64.89.163.32
python-requests actor probing /admin/.env and /administrator/.env — repeated twice within 14 minutes
ua: python-requests/2.32.5
note: Simple two-path probe repeated after a delay — consistent with a script retrying on timeout or checking for deployment changes
2026-04-11–15 (sustained) GIT RECON 185.177.72.61
l9explore/1.2.2 continues daily .git/config probing — 11 hits this period, all from same IP
note: Now confirmed across all three reporting periods without interruption. Likely scheduled scan job running on a fixed interval against this sensor specifically.

Top attempted SSH credentials

usernamepasswordattemptsnotes
345gs5662d34345gs5662d343,234mdrfckr campaign — continued growth
root3245gs5662d343,230mdrfckr campaign — continued growth
rootadmin869Generic — lower than prior period (2,918)
adminadmin50Generic default
rootP18Single-char probe
AdminGPONALC#FGU17GPON router default — Mirai variant
orangepiorangepi12Orange Pi SBC default
rootAa1020267Date-patterned weak password
rootServer@1237Common server default

Observed payload hashes (ssh downloads)

sha256 (truncated)countcontext
a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f23,418Primary mdrfckr payload — all three periods, unchanged
01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b189Null placeholder — consistent across all periods
8a68d1c08ea31250063f70b1ccb5051db1f7ab6e17d46e9dd3cc292b9849878b3Redtail-linked — declining frequency
9ca881abd3c11368e381b8a9f6d32ef14e022058ce936922afb82164c17f33102Kurayami — new this period
ea61e090f64b28c641b4d7c1fd771082eaf91bec933242589e48f525cebb3da62Kurayami — new this period
a65211cd909a1bf9ad9c528f9e49915dda62eb23d104d5f56772cedfefc9656e2Kurayami — new this period
1c912c5fb80edc312de11238b21d63f75fdf8e8221926a53dbe99d02a454815a2Kurayami — new this period
0bfae0d5a6be574998ffb5f15b2060f56b84afdd480ee07ce2fdb3685a3f81a52Kurayami — new this period

Indicators of compromise

typevaluecontext
IP130.12.180.51Redtail SCP uploader — returned Apr 14, updated clean.sh hash
IP80.66.66.10Top SSH source — 5,901 events, root:admin credential
IP185.177.72.11curl RCE attempt + DB enumeration — router-admin.uk vhost, Apr 16
IP130.12.180.111.env sweep — 13 paths, third consecutive period. Same /24 as Redtail uploader
IP185.177.72.61l9explore/1.2.2 — .git/config recon, all three periods
IP149.50.97.236Go-http-client scanner — UA switching behavior, Django + phpinfo probe
IP64.89.163.32python-requests .env probe — repeated twice
IP142.248.80.144Kurayami C2/hosting — lol.sh dropper + multi-arch binaries
hasha8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2mdrfckr primary payload — persistent all periods
hash94db7ecdcb422930...Updated Redtail clean.sh — new hash vs prior periods
hash9ca881abd3c11368e381b8a9f6d32ef14e022058ce936922afb82164c17f3310Kurayami binary — new this period
UAlibredtail-httpRedtail scanner — all three periods, 16 hits this window
UAl9explore/1.2.2Git config recon — all three periods
UAcurl/8.7.1185.177.72.11 — RCE and DB enumeration tool
UApython-requests/2.32.564.89.163.32 — .env harvest script
URLhttp://142.248.80.144/lol.shKurayami dropper — first observed this period
URLhttp://142.248.80.144/lemperluvkurayami/kurayami.x86Kurayami x86 binary
path/admin/config?cmd=cat%20/root/.aws/credentialsRCE probe — first observed across all periods
credentialroot:3245gs5662d34mdrfckr campaign — 3,230 attempts this period

Cross-period actor tracking

actor / indicatorApr 1–5Apr 6–10Apr 11–15trend
mdrfckr key injection (sessions)2,4313,1593,418↑ growing
130.12.180.51 Redtail uploads✓ Apr 1✓ Apr 7✓ Apr 14↑ weekly cadence
130.12.180.111 .env sweep↑ all periods
185.177.72.61 l9explore↑ all periods
libredtail-http phpunit probe47 hits58 hits16 hits↓ lower this period
172.94.9.253 admin brute force✓ 458 req✓ 16 req→ not seen
Kurayami binaries✓ new↑ new this period
direct-tcpip tunneling3533,000863↓ reduced vs prior

MITRE ATT&CK mapping

technique idnameobserved
T1110.001Brute Force: Password Guessing16,071 SSH auth attempts; web admin login probes
T1098.004Account Manipulation: SSH Authorized Keysmdrfckr key injection — 3,418 sessions
T1059.004Command & Scripting: Unix Shelllol.sh / clean.sh / setup.sh execution chains
T1105Ingress Tool TransferRedtail SCP upload (130.12.180.51, Apr 14); Kurayami wget from 142.248.80.144
T1496Resource HijackingRedtail cryptominer — consistent multi-arch deployment
T1498Network Denial of ServiceKurayami DDoS botnet binaries deployed for first time
T1070.003Indicator Removal: Clear Command HistoryCompetitor cleanup — pkill competing bots, clear /tmp
T1082System Information DiscoveryScripted hardware recon: uname, cpuinfo, free, df, lscpu
T1572Protocol Tunneling863 direct-tcpip requests
T1190Exploit Public-Facing ApplicationCVE-2017-9841 phpunit eval-stdin.php (web); cmd injection probe (185.177.72.11)
T1083File and Directory Discovery.env, .aws/credentials, db.conf, sql.conf, settings.ini enumeration
T1552.001Credentials In FilesRCE attempt targeting /root/.aws/credentials; .env sweep across 13 path variants

Raw log excerpts

Redtail operator — Apr 14 return, updated clean.sh (130.12.180.51):

2026-04-14T12:21:51.789766Z cowrie.session.file_upload src=130.12.180.51 filename=clean.sh    sha256=94db7ecdcb422930... (NEW)
2026-04-14T12:21:51.797298Z cowrie.session.file_upload src=130.12.180.51 filename=redtail.arm7  sha256=3625d068... (unchanged)
2026-04-14T12:21:51.806390Z cowrie.session.file_upload src=130.12.180.51 filename=redtail.arm8  sha256=dbb7ebb9... (unchanged)
2026-04-14T12:21:51.816195Z cowrie.session.file_upload src=130.12.180.51 filename=redtail.i686  sha256=048e374b... (unchanged)
2026-04-14T12:21:51.829741Z cowrie.session.file_upload src=130.12.180.51 filename=redtail.x86_64 sha256=59c29436... (unchanged)

Kurayami dropper downloads — first observed:

cowrie.session.file_download url=http://142.248.80.144/lol.sh                              (x2)
cowrie.session.file_download url=http://142.248.80.144/lemperluvkurayami/kurayami.x86      (x2)
cowrie.session.file_download url=http://142.248.80.144/lemperluvkurayami/kurayami.mips     (x2)
cowrie.session.file_download url=http://142.248.80.144/lemperluvkurayami/kurayami.arc      (x2)
cowrie.session.file_download url=http://142.248.80.144/lemperluvkurayami/kurayami.i468     (x2)

185.177.72.11 — RCE probe and DB enumeration (Apr 16, curl/8.7.1, router-admin.uk):

2026-04-16T11:50:55+00:00 185.177.72.11 "GET /admin/config?cmd=cat%20/root/.aws/credentials HTTP/1.1" 200
2026-04-16T11:50:56+00:00 185.177.72.11 "GET /admin/.env HTTP/1.1" 200
2026-04-16T11:53:33+00:00 185.177.72.11 "GET /adminer-4.2.5-mysql-en.php HTTP/1.1" 200
2026-04-16T11:53:40+00:00 185.177.72.11 "GET /admin/db.php HTTP/1.1" 200
2026-04-16T11:53:41+00:00 185.177.72.11 "GET /admin/db.conf HTTP/1.1" 200
2026-04-16T11:53:41+00:00 185.177.72.11 "GET /admin/sqladmin.php HTTP/1.1" 200
2026-04-16T11:53:41+00:00 185.177.72.11 "GET /admin/phpmyadmin.php HTTP/1.1" 200
Full session transcripts, raw JSON logs, and captured binaries available on request. Credential strings are presented as-observed. SHA256 hashes are undefanged; IP addresses are as logged.