HONEYPOT REPORT // SSH + WEB // 2026-04-11 – 2026-04-15
2026-04-11 – 2026-04-15 — SSH + Web Honeypot Report
SSH connection volume by day
*Apr 16 connections captured in Apr 15 log files (UTC rollover). Apr 12 was peak day at 4,853 connections.
Executive summary
The Apr 11–15 window continues established campaign patterns while introducing two new developments worth tracking. The mdrfckr SSH key injection campaign reached 3,418 sessions — its third consecutive weekly increase — with 130.12.180.51 returning on Apr 14 for another multi-session Redtail binary upload, now with a new clean.sh hash (94db7ecd...) suggesting the operator updated the deployment script while keeping the same miner binaries. The operator has now appeared in all three reporting periods, making this the most persistent single actor observed across the sensor.
The most significant new finding is the emergence of the Kurayami botnet. Five distinct download URLs were observed pointing to 142.248.80.144, serving lol.sh and architecture-specific binaries: kurayami.x86, kurayami.mips, kurayami.arc, and kurayami.i468. Kurayami is a known DDoS botnet family targeting Linux embedded devices. Its appearance alongside the existing Redtail and mdrfckr campaigns suggests the honeypot is being discovered by multiple independent scanning operations simultaneously.
On the web side, the period's most notable actor was 185.177.72.11, which launched 31 curl-based requests on Apr 16 against the router-admin.uk vhost. Unlike prior web actors, this one attempted a command injection probe — /admin/config?cmd=cat%20/root/.aws/credentials — making it the first observed RCE attempt across all three reporting periods. The same session also enumerated database-related paths (db.php, db.conf, sql.conf, sqladmin.php) and targeted the adminer database management tool specifically. 130.12.180.111 (the same /24 as the Redtail SSH uploader) returned again on Apr 14 with a full .env enumeration sweep across 13 path variants.
lol.sh dropper serving x86, MIPS, ARC, and i486 variants from 142.248.80.144. Distinct from the Redtail campaign; DDoS-focused rather than cryptomining.
185.177.72.11 probed /admin/config?cmd=cat%20/root/.aws/credentials on Apr 16. All prior web activity was passive enumeration — this is the first active exploitation attempt logged.
Notable sessions — SSH
clean.sh hash: 94db7ecdcb422930... (changed from d46555af... in prior periods)
miner hashes: unchanged — same arm7/arm8/i686/x86_64 binaries as Apr 1 and Apr 7
note: Updated dropper script with same payload suggests operator is refining deployment logic — possible detection evasion or new persistence mechanism in clean.sh
week-over-week: Apr 1–5: 2,431 → Apr 6–10: 3,159 → Apr 11–15: 3,418 (+8.2%)
note: Consistent growth trajectory suggests the botnet is expanding its node pool and tasking more bots against this sensor
binaries: kurayami.x86, kurayami.mips, kurayami.arc, kurayami.i468
hashes: 5 distinct new hashes — 9ca881ab, ea61e090, a65211cd, 1c912c5f, 0bfae0d5
note: Kurayami is a known Linux DDoS botnet distinct from Redtail's cryptomining focus. Architecture coverage (x86/MIPS/ARC/i486) targets broad embedded device range including routers and IoT.
46.151.182.220: New entrant — 1,180 events, not seen in prior periods
note: HTTP/Solr/InfluxDB probe strings appearing as username:password pairs suggest this source is also probing non-SSH services on port 23 (Telnet forwarding)
Notable sessions — web
db enumeration: /admin/db.php, /admin/db.conf, /admin/sql.conf, /admin/sqladmin.php, /admin/phpmyadmin.php, /admin/adminer.php
ua: curl/8.7.1 vhost: router-admin.uk
total requests: 31 across multiple path categories
note: Notably in the same /24 as l9explore actor 185.177.72.61 — possible same operator running different tooling, or same infrastructure hosting multiple scanning tools
note: Now seen in all three reporting periods. Same /24 as Redtail SSH uploader (130.12.180.51) — cross-sensor actor linkage consistent across the full observation window
paths: /administrator/config/.env, /admin/php.php, /admin/php-info.php, /admin/console/.env, /administrator/phpinfo.php, /admin/info.php, /admin/phpinfo.php, /admin/.env, /admin/config/.env, /administrator/.env, /admin/php_info.php
note: UA switch mid-session (mobile Chrome → Go-http-client) suggests tooling that spoof-checks for WAF/bot detection before switching to scanner mode
note: Simple two-path probe repeated after a delay — consistent with a script retrying on timeout or checking for deployment changes
Top attempted SSH credentials
| username | password | attempts | notes |
|---|---|---|---|
| 345gs5662d34 | 345gs5662d34 | 3,234 | mdrfckr campaign — continued growth |
| root | 3245gs5662d34 | 3,230 | mdrfckr campaign — continued growth |
| root | admin | 869 | Generic — lower than prior period (2,918) |
| admin | admin | 50 | Generic default |
| root | P | 18 | Single-char probe |
| AdminGPON | ALC#FGU | 17 | GPON router default — Mirai variant |
| orangepi | orangepi | 12 | Orange Pi SBC default |
| root | Aa102026 | 7 | Date-patterned weak password |
| root | Server@123 | 7 | Common server default |
Observed payload hashes (ssh downloads)
| sha256 (truncated) | count | context |
|---|---|---|
| a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2 | 3,418 | Primary mdrfckr payload — all three periods, unchanged |
| 01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b | 189 | Null placeholder — consistent across all periods |
| 8a68d1c08ea31250063f70b1ccb5051db1f7ab6e17d46e9dd3cc292b9849878b | 3 | Redtail-linked — declining frequency |
| 9ca881abd3c11368e381b8a9f6d32ef14e022058ce936922afb82164c17f3310 | 2 | Kurayami — new this period |
| ea61e090f64b28c641b4d7c1fd771082eaf91bec933242589e48f525cebb3da6 | 2 | Kurayami — new this period |
| a65211cd909a1bf9ad9c528f9e49915dda62eb23d104d5f56772cedfefc9656e | 2 | Kurayami — new this period |
| 1c912c5fb80edc312de11238b21d63f75fdf8e8221926a53dbe99d02a454815a | 2 | Kurayami — new this period |
| 0bfae0d5a6be574998ffb5f15b2060f56b84afdd480ee07ce2fdb3685a3f81a5 | 2 | Kurayami — new this period |
Indicators of compromise
| type | value | context |
|---|---|---|
| IP | 130.12.180.51 | Redtail SCP uploader — returned Apr 14, updated clean.sh hash |
| IP | 80.66.66.10 | Top SSH source — 5,901 events, root:admin credential |
| IP | 185.177.72.11 | curl RCE attempt + DB enumeration — router-admin.uk vhost, Apr 16 |
| IP | 130.12.180.111 | .env sweep — 13 paths, third consecutive period. Same /24 as Redtail uploader |
| IP | 185.177.72.61 | l9explore/1.2.2 — .git/config recon, all three periods |
| IP | 149.50.97.236 | Go-http-client scanner — UA switching behavior, Django + phpinfo probe |
| IP | 64.89.163.32 | python-requests .env probe — repeated twice |
| IP | 142.248.80.144 | Kurayami C2/hosting — lol.sh dropper + multi-arch binaries |
| hash | a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2 | mdrfckr primary payload — persistent all periods |
| hash | 94db7ecdcb422930... | Updated Redtail clean.sh — new hash vs prior periods |
| hash | 9ca881abd3c11368e381b8a9f6d32ef14e022058ce936922afb82164c17f3310 | Kurayami binary — new this period |
| UA | libredtail-http | Redtail scanner — all three periods, 16 hits this window |
| UA | l9explore/1.2.2 | Git config recon — all three periods |
| UA | curl/8.7.1 | 185.177.72.11 — RCE and DB enumeration tool |
| UA | python-requests/2.32.5 | 64.89.163.32 — .env harvest script |
| URL | http://142.248.80.144/lol.sh | Kurayami dropper — first observed this period |
| URL | http://142.248.80.144/lemperluvkurayami/kurayami.x86 | Kurayami x86 binary |
| path | /admin/config?cmd=cat%20/root/.aws/credentials | RCE probe — first observed across all periods |
| credential | root:3245gs5662d34 | mdrfckr campaign — 3,230 attempts this period |
Cross-period actor tracking
| actor / indicator | Apr 1–5 | Apr 6–10 | Apr 11–15 | trend |
|---|---|---|---|---|
| mdrfckr key injection (sessions) | 2,431 | 3,159 | 3,418 | ↑ growing |
| 130.12.180.51 Redtail uploads | ✓ Apr 1 | ✓ Apr 7 | ✓ Apr 14 | ↑ weekly cadence |
| 130.12.180.111 .env sweep | ✓ | ✓ | ✓ | ↑ all periods |
| 185.177.72.61 l9explore | ✓ | ✓ | ✓ | ↑ all periods |
| libredtail-http phpunit probe | 47 hits | 58 hits | 16 hits | ↓ lower this period |
| 172.94.9.253 admin brute force | ✓ 458 req | ✓ 16 req | — | → not seen |
| Kurayami binaries | — | — | ✓ new | ↑ new this period |
| direct-tcpip tunneling | 353 | 3,000 | 863 | ↓ reduced vs prior |
MITRE ATT&CK mapping
| technique id | name | observed |
|---|---|---|
| T1110.001 | Brute Force: Password Guessing | 16,071 SSH auth attempts; web admin login probes |
| T1098.004 | Account Manipulation: SSH Authorized Keys | mdrfckr key injection — 3,418 sessions |
| T1059.004 | Command & Scripting: Unix Shell | lol.sh / clean.sh / setup.sh execution chains |
| T1105 | Ingress Tool Transfer | Redtail SCP upload (130.12.180.51, Apr 14); Kurayami wget from 142.248.80.144 |
| T1496 | Resource Hijacking | Redtail cryptominer — consistent multi-arch deployment |
| T1498 | Network Denial of Service | Kurayami DDoS botnet binaries deployed for first time |
| T1070.003 | Indicator Removal: Clear Command History | Competitor cleanup — pkill competing bots, clear /tmp |
| T1082 | System Information Discovery | Scripted hardware recon: uname, cpuinfo, free, df, lscpu |
| T1572 | Protocol Tunneling | 863 direct-tcpip requests |
| T1190 | Exploit Public-Facing Application | CVE-2017-9841 phpunit eval-stdin.php (web); cmd injection probe (185.177.72.11) |
| T1083 | File and Directory Discovery | .env, .aws/credentials, db.conf, sql.conf, settings.ini enumeration |
| T1552.001 | Credentials In Files | RCE attempt targeting /root/.aws/credentials; .env sweep across 13 path variants |
Raw log excerpts
Redtail operator — Apr 14 return, updated clean.sh (130.12.180.51):
2026-04-14T12:21:51.789766Z cowrie.session.file_upload src=130.12.180.51 filename=clean.sh sha256=94db7ecdcb422930... (NEW) 2026-04-14T12:21:51.797298Z cowrie.session.file_upload src=130.12.180.51 filename=redtail.arm7 sha256=3625d068... (unchanged) 2026-04-14T12:21:51.806390Z cowrie.session.file_upload src=130.12.180.51 filename=redtail.arm8 sha256=dbb7ebb9... (unchanged) 2026-04-14T12:21:51.816195Z cowrie.session.file_upload src=130.12.180.51 filename=redtail.i686 sha256=048e374b... (unchanged) 2026-04-14T12:21:51.829741Z cowrie.session.file_upload src=130.12.180.51 filename=redtail.x86_64 sha256=59c29436... (unchanged)
Kurayami dropper downloads — first observed:
cowrie.session.file_download url=http://142.248.80.144/lol.sh (x2) cowrie.session.file_download url=http://142.248.80.144/lemperluvkurayami/kurayami.x86 (x2) cowrie.session.file_download url=http://142.248.80.144/lemperluvkurayami/kurayami.mips (x2) cowrie.session.file_download url=http://142.248.80.144/lemperluvkurayami/kurayami.arc (x2) cowrie.session.file_download url=http://142.248.80.144/lemperluvkurayami/kurayami.i468 (x2)
185.177.72.11 — RCE probe and DB enumeration (Apr 16, curl/8.7.1, router-admin.uk):
2026-04-16T11:50:55+00:00 185.177.72.11 "GET /admin/config?cmd=cat%20/root/.aws/credentials HTTP/1.1" 200 2026-04-16T11:50:56+00:00 185.177.72.11 "GET /admin/.env HTTP/1.1" 200 2026-04-16T11:53:33+00:00 185.177.72.11 "GET /adminer-4.2.5-mysql-en.php HTTP/1.1" 200 2026-04-16T11:53:40+00:00 185.177.72.11 "GET /admin/db.php HTTP/1.1" 200 2026-04-16T11:53:41+00:00 185.177.72.11 "GET /admin/db.conf HTTP/1.1" 200 2026-04-16T11:53:41+00:00 185.177.72.11 "GET /admin/sqladmin.php HTTP/1.1" 200 2026-04-16T11:53:41+00:00 185.177.72.11 "GET /admin/phpmyadmin.php HTTP/1.1" 200