slatterysec.com/reports/2026/04/2026-04-16_2026-04-20-ssh-web-honeypot-report.html
sensors 8 up last session 4m ago 24h captures 312 unique src 87

slattery@sec:~/reports$ cat 2026-04-16_2026-04-20-ssh-web-honeypot-report.md

HONEYPOT REPORT // SSH + WEB // 2026-04-16 – 2026-04-20

2026-04-16 – 2026-04-20 — SSH + Web Honeypot Report

Period: 2026-04-16 – 2026-04-20  |  Sensor: Cowrie v2.x (SSH + HTTP)  |  Host: VPS / RackNerd
SSH WEB ALERT MASS SCAN SPIKE DEMON
SSH CONNECTIONS
59,761
largest period yet
AUTH ATTEMPTS
54,901
44,518 succeeded (81%)
UNIQUE SSH IPs
1,362
top: 134.122.95.87
PAYLOAD DROPS
4,178
9 unique hashes
FILE UPLOADS
84
Redtail — 5 days active
WEB REQUESTS
273
50 unique IPs

SSH connection volume by day

Apr 16
433
Apr 17
4,066
Apr 18
8,391
Apr 19
4,680
Apr 20
5,574
Apr 21*
36,617

*Apr 21 connections captured in Apr 20 log files (UTC rollover). Bar shown in red — single-day record across all reporting periods. 134.122.95.87 alone accounts for 31,772 of these connections.

Executive summary

This period is defined by two headline events: a mass-scan spike on Apr 21 that set a single-day connection record across the entire observation window, and the first appearance of the Demon botnet. Apr 21 saw 36,617 SSH connections — more than any prior full five-day period — driven almost entirely by 134.122.95.87, which made 31,772 successful logins and ran a single command on each: echo -e "\x6F\x6B", which decodes to ok. This is a canary check — the actor is testing whether command execution succeeds, not deploying anything. The pattern is consistent with a botnet operator scanning a large IP range to identify viable nodes before returning for payload delivery. A second IP, 8.217.18.158, ran the identical canary check across 3,317 sessions simultaneously, suggesting coordinated infrastructure.

The Demon botnet appeared on Apr 18 via 143.137.204.138, downloading bins.sh plus MIPS, MPSL, SH4, and x86 binaries from 89.190.156.34. Demon is a known DDoS botnet family targeting embedded Linux devices — its architecture coverage (SH4 in particular) suggests targeting of older MIPS-based routers and Renesas SH-series embedded systems not typically targeted by Redtail or Kurayami. This marks the third distinct DDoS/botnet family observed across the full reporting window alongside Redtail and Kurayami.

The Redtail operator at 130.12.180.51 was active across five consecutive days this period — the most sustained presence observed so far — completing 14 upload sessions with the original clean.sh hash returning (reverted from the updated version seen in Apr 11–15). On the web side, 195.178.110.101 became the dominant source with 185 requests on Apr 21 alone, using five rotating user agents alongside the self-identified SecurityScanner/1.0 UA — probing for backup archives, credential files, and phpinfo endpoints across a broad path list. The Scaleway IP cluster (51.15.x.x, 51.159.x.x) sent 13 Go-http-client requests all targeting /login, consistent with a distributed credential brute tool.

Single-day record: Apr 21 logged 36,617 SSH connections — more than the entire Apr 1–5 reporting period combined. The dominant source ran only an execution canary check (echo ok), not a payload. This pattern is consistent with pre-exploitation reconnaissance ahead of a follow-on deployment campaign.
Third DDoS botnet family: Demon joins Redtail and Kurayami as a distinct botnet observed on this sensor. SH4 architecture targeting is unusual and suggests broader embedded device scope than prior campaigns.

Notable sessions — SSH

2026-04-21 (all day) MASS SCAN 134.122.95.87 + 8.217.18.158
31,772 + 3,317 successful logins — single execution canary check per session, no payload
cmd: echo -e "\x6F\x6B" → prints "ok"
credentials used: root:jetaime, root:lamour, root:123456, root:zitian2008 (rotating)
success rate: ~100% — nearly every connection resulted in a successful login
note: Execution canary pattern — verifying shell access works before returning with payload. Coordinated with 8.217.18.158 running identical behavior simultaneously. DigitalOcean-hosted infrastructure.
2026-04-18T00:37:41Z DEMON DROP 143.137.204.138
Demon DDoS botnet — bins.sh dropper fetching MIPS, MPSL, SH4, and x86 binaries from 89.190.156.34
dropper: http://89.190.156.34/bins.sh
binaries: Demon.mips, Demon.mpsl, Demon.sh4, Demon.x86
notable arch: SH4 (Renesas SuperH) — targets older embedded routers not covered by Redtail/Kurayami
note: Third distinct DDoS/botnet family observed across the full window. All three (Redtail, Kurayami, Demon) now active within a 3-week span on this sensor.
2026-04-17–21 (5 consecutive days) REDTAIL DROP 130.12.180.51
Redtail operator most active stretch yet — 14 upload sessions across 5 days, clean.sh hash reverted to original
clean.sh hash: d46555af... (reverted from 94db7ecd... seen in Apr 11–15)
miner binaries: unchanged across all periods — arm7/arm8/i686/x86_64 hashes identical since Apr 1
cadence: Apr 1 → Apr 7 → Apr 14 → Apr 17–21 (daily). Operator shifting from weekly to daily deployment runs.
note: Reversion to original clean.sh may indicate the Apr 11–15 updated script caused issues and was rolled back.
2026-04-16–20 (sustained) SSH BACKDOOR multiple
mdrfckr key injection — 3,956 sessions, continued week-over-week growth
week-over-week: Apr 1–5: 2,431 → Apr 6–10: 3,159 → Apr 11–15: 3,418 → Apr 16–20: 3,956 (+16%)
note: Largest single-period jump yet. Campaign shows no signs of slowing.

Notable sessions — web

2026-04-21T00:03:50Z (burst) BROAD SCAN 195.178.110.101
185 requests in a single burst — backup archive hunting, credential file enumeration, and phpinfo probing with 5 rotating UAs
uas: Mozilla/5.0 (compatible; SecurityScanner/1.0) + 4 spoofed desktop browser UAs
targets: /.pgpass, /.aws/config, /.aws/credentials, /.netrc, /backup*.zip/tar/tar.gz, /.env*, /debug.php, /info.php, /test.php
note: Self-identifying as SecurityScanner/1.0 while simultaneously spoofing browser UAs — the scanner UA likely leaks from a misconfigured rotation. Backup archive targeting (.zip/.tar/.tar.gz variants) not seen from prior actors.
2026-04-21T09:54:26Z ENV HARVEST 130.12.180.111
130.12.180.111 returns for the fourth consecutive period — 26 requests, now probing over HTTPS (port 443)
paths: /admin/.env, /admin/.aws/credentials, /admin/public/.env, /admin-app/.env, /adminapp/.env, /admin/config/.env, /admin/config/env.bak, //admin/.env, /admin/.env.bak, /admin/env.bak, /admin/.env.dist, /adminer/.env, /admin/public/.env.bak (all duplicated)
new: All requests now hitting port 443 — prior periods used port 80/direct IP. Possible TLS scanning added to toolset.
note: Four consecutive reporting periods. Same /24 as Redtail SSH uploader (130.12.180.51). Duplicate requests per path suggest retry logic or parallel thread execution.
2026-04-21 (distributed) LOGIN PROBE Scaleway cluster — 51.15.x.x / 51.159.x.x
13 Go-http-client requests from 13 distinct Scaleway IPs, all targeting /login
IPs: 51.15.252.88, 51.15.109.50, 51.15.132.162, 51.15.45.207, 51.15.48.77, 51.15.142.215, 51.15.111.179, 51.15.75.156, 51.15.123.54, 51.159.190.160, 51.159.154.249, 51.159.164.35, 163.172.180.130 + others
note: One request per IP, all identical target — distributed credential bruteforce pattern using Scaleway VPS infrastructure to evade per-IP rate limiting.
2026-04-19T00:02–00:07Z SERVICE PROBE 65.49.1.142
New actor probing GeoServer, DSM (Synology), and webUI endpoints — service fingerprinting beyond standard admin paths
paths: /geoserver/web/, /ssdp/desc-DSM-eth0.xml, /ssdp/desc-DSM-eth1.xml, /webui/
note: GeoServer (CVE-2024-36401 RCE) and Synology DSM probing indicate broader NAS/geospatial server targeting — not seen in prior periods.
2026-04-17T13:04Z NEW UA 59.44.42.9
Custom-AsyncHttpClient UA probing phpunit eval-stdin.php — first appearance of this tool signature
ua: Custom-AsyncHttpClient
path: /admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
note: Same CVE-2017-9841 target as libredtail-http but different tooling. Suggests multiple independent scanner implementations targeting the same vulnerability.

Top attempted SSH credentials

usernamepasswordattemptsnotes
345gs5662d34345gs5662d343,763mdrfckr campaign — continued growth
root3245gs5662d343,747mdrfckr campaign — continued growth
rootadmin550Generic — lower than prior periods
adminadmin71Generic default
rootP30Single-char probe
orangepiorangepi21Orange Pi SBC default
AdminGPONALC#FGU20GPON router default — Mirai variant
admin1234admin123416New entrant — common weak credential
sockssocks12SOCKS proxy default — proxy server targeting
root3.141592659Pi-based password — targeted list artifact

Observed payload hashes (ssh downloads)

sha256 (truncated)countcontext
a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f23,956Primary mdrfckr payload — all five periods, unchanged
01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b203Null placeholder — consistent across all periods
8a68d1c08ea31250063f70b1ccb5051db1f7ab6e17d46e9dd3cc292b9849878b14Redtail-linked — low frequency, persistent
739135066c762d50a9542ff91c094e7a53df452ad188821a34dc05b5c9c35f401Demon bins.sh dropper
e9564236bdaac13cb38601b461a76c1b497ae21c85f524cd6f623587101b20e91Demon.mips binary
2f261e21db56fb984baeec70a48b820c3d8006bb6611888adabe9bbb7a4a3dbf1Demon.mpsl binary
343f666d548720d23ba6ca4c08e3ab10aced5cc9ea155c454f31bed5a939c89a1Demon.sh4 binary
b040e1a6476b048f7521c9d194933341bdbb9a5dc71697820fa3df9dde6e6da91Demon.x86 binary

Indicators of compromise

typevaluecontext
IP134.122.95.87Mass scan — 31,772 connections Apr 21, execution canary only
IP8.217.18.158Coordinated canary scan — 3,317 sessions, same pattern as 134.122.95.87
IP130.12.180.51Redtail SCP uploader — 14 sessions across 5 days, Apr 17–21
IP143.137.204.138Demon botnet dropper session — bins.sh + multi-arch binaries
IP89.190.156.34Demon C2/hosting — bins.sh and Demon binary host
IP195.178.110.101SecurityScanner/1.0 — 185 web requests, backup + credential enumeration
IP130.12.180.111.env sweep — 26 requests over HTTPS, fourth consecutive period
IP65.49.1.142GeoServer + Synology DSM probe — new service targeting
IP185.177.72.61l9explore/1.2.2 — .git/config, all five periods
hasha8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2mdrfckr primary payload — persistent all five periods
hash739135066c762d50a9542ff91c094e7a53df452ad188821a34dc05b5c9c35f40Demon bins.sh dropper
hash343f666d548720d23ba6ca4c08e3ab10aced5cc9ea155c454f31bed5a939c89aDemon.sh4 — SH4 architecture binary
UAlibredtail-httpRedtail scanner — all five periods
UAl9explore/1.2.2.git/config recon — all five periods
UAMozilla/5.0 (compatible; SecurityScanner/1.0)195.178.110.101 — broad credential/backup scan
UACustom-AsyncHttpClient59.44.42.9 — CVE-2017-9841 phpunit probe
URLhttp://89.190.156.34/bins.shDemon dropper URL
URLhttp://89.190.156.34/Demon.mipsDemon MIPS binary
URLhttp://89.190.156.34/Demon.sh4Demon SH4 binary — unusual architecture
credentialroot:3245gs5662d34mdrfckr — 3,747 attempts this period

Cross-period actor tracking

actor / indicatorApr 1–5Apr 6–10Apr 11–15Apr 16–20trend
mdrfckr injections2,4313,1593,4183,956↑ +63% since P1
130.12.180.51 Redtail uploads✓ Apr 1✓ Apr 7✓ Apr 14✓ Apr 17–21↑ daily cadence
130.12.180.111 .env sweep✓ (HTTPS)↑ all periods
185.177.72.61 l9explore↑ all periods
libredtail-http phpunit47581617→ stable low
172.94.9.253 admin brute✓ 458✓ 16↓ not seen P3–P4
Kurayami binaries✓ new→ single period
Demon binaries✓ new↑ new this period
SSH connections (total)16,49123,47020,82359,761↑ spike Apr 21
direct-tcpip tunneling3533,000863537↓ declining

MITRE ATT&CK mapping

technique idnameobserved
T1110.001Brute Force: Password Guessing54,901 SSH auth attempts; Scaleway /login cluster (13 IPs)
T1098.004Account Manipulation: SSH Authorized Keysmdrfckr key injection — 3,956 sessions
T1018Remote System Discovery134.122.95.87 canary scan — 31,772 sessions probing execution capability
T1059.004Command & Scripting: Unix Shellbins.sh / clean.sh / setup.sh execution chains
T1105Ingress Tool TransferRedtail SCP uploads (130.12.180.51); Demon wget from 89.190.156.34
T1496Resource HijackingRedtail cryptominer — daily deployment cadence Apr 17–21
T1498Network Denial of ServiceDemon DDoS botnet — MIPS/MPSL/SH4/x86 binaries
T1070.003Indicator Removal: Clear Command HistoryCompetitor cleanup — pkill competing bots, clear /tmp
T1082System Information DiscoveryScripted hardware recon; GeoServer/Synology DSM service fingerprinting
T1190Exploit Public-Facing ApplicationCVE-2017-9841 phpunit eval-stdin.php (libredtail-http + Custom-AsyncHttpClient)
T1083File and Directory DiscoveryBackup archive enumeration (.zip/.tar/.tar.gz); .env variant sweep; /.pgpass, /.netrc
T1552.001Credentials In Files/.aws/credentials, /.aws/config, /.pgpass, /.netrc, .env sweep — 130.12.180.111 + 195.178.110.101

Raw log excerpts

134.122.95.87 execution canary — repeated 31,770 times Apr 21:

2026-04-21 cowrie.session.connect    src=134.122.95.87
2026-04-21 cowrie.login.success      user=root pass=jetaime
2026-04-21 cowrie.command.input      CMD: echo -e "\x6F\x6B"   # → "ok"
2026-04-21 cowrie.session.closed
# Pattern repeats with rotating passwords: jetaime, lamour, 123456, zitian2008...

Demon botnet download chain — 143.137.204.138 (Apr 18):

2026-04-18T00:37:41Z cowrie.session.file_download url=http://89.190.156.34/bins.sh      sha256=739135066c762d50...
2026-04-18T00:37:42Z cowrie.session.file_download url=http://89.190.156.34/Demon.mips   sha256=e9564236bdaac13c...
2026-04-18T00:37:42Z cowrie.session.file_download url=http://89.190.156.34/Demon.mpsl   sha256=2f261e21db56fb98...
2026-04-18T00:37:42Z cowrie.session.file_download url=http://89.190.156.34/Demon.sh4    sha256=343f666d548720d2...
2026-04-18T00:37:43Z cowrie.session.file_download url=http://89.190.156.34/Demon.x86    sha256=b040e1a6476b048f...

195.178.110.101 — backup and credential sweep (Apr 21, SecurityScanner/1.0):

2026-04-21T00:03:50+00:00 195.178.110.101 "GET /.pgpass HTTP/1.1" 200
2026-04-21T00:03:51+00:00 195.178.110.101 "GET /.aws/config HTTP/1.1" 200
2026-04-21T00:03:51+00:00 195.178.110.101 "GET /.aws/credentials HTTP/1.1" 200
2026-04-21T00:03:51+00:00 195.178.110.101 "GET /backup2.zip HTTP/1.1" 200
2026-04-21T00:03:51+00:00 195.178.110.101 "GET /backup.tar.gz HTTP/1.1" 200
2026-04-21T00:03:51+00:00 195.178.110.101 "GET /.netrc HTTP/1.1" 200
Full session transcripts, raw JSON logs, and captured binaries available on request. Credential strings are presented as-observed. SHA256 hashes are undefanged; IP addresses are as logged.