HONEYPOT REPORT // SSH + WEB // 2026-04-16 – 2026-04-20
2026-04-16 – 2026-04-20 — SSH + Web Honeypot Report
SSH connection volume by day
*Apr 21 connections captured in Apr 20 log files (UTC rollover). Bar shown in red — single-day record across all reporting periods. 134.122.95.87 alone accounts for 31,772 of these connections.
Executive summary
This period is defined by two headline events: a mass-scan spike on Apr 21 that set a single-day connection record across the entire observation window, and the first appearance of the Demon botnet. Apr 21 saw 36,617 SSH connections — more than any prior full five-day period — driven almost entirely by 134.122.95.87, which made 31,772 successful logins and ran a single command on each: echo -e "\x6F\x6B", which decodes to ok. This is a canary check — the actor is testing whether command execution succeeds, not deploying anything. The pattern is consistent with a botnet operator scanning a large IP range to identify viable nodes before returning for payload delivery. A second IP, 8.217.18.158, ran the identical canary check across 3,317 sessions simultaneously, suggesting coordinated infrastructure.
The Demon botnet appeared on Apr 18 via 143.137.204.138, downloading bins.sh plus MIPS, MPSL, SH4, and x86 binaries from 89.190.156.34. Demon is a known DDoS botnet family targeting embedded Linux devices — its architecture coverage (SH4 in particular) suggests targeting of older MIPS-based routers and Renesas SH-series embedded systems not typically targeted by Redtail or Kurayami. This marks the third distinct DDoS/botnet family observed across the full reporting window alongside Redtail and Kurayami.
The Redtail operator at 130.12.180.51 was active across five consecutive days this period — the most sustained presence observed so far — completing 14 upload sessions with the original clean.sh hash returning (reverted from the updated version seen in Apr 11–15). On the web side, 195.178.110.101 became the dominant source with 185 requests on Apr 21 alone, using five rotating user agents alongside the self-identified SecurityScanner/1.0 UA — probing for backup archives, credential files, and phpinfo endpoints across a broad path list. The Scaleway IP cluster (51.15.x.x, 51.159.x.x) sent 13 Go-http-client requests all targeting /login, consistent with a distributed credential brute tool.
echo ok), not a payload. This pattern is consistent with pre-exploitation reconnaissance ahead of a follow-on deployment campaign.
Notable sessions — SSH
credentials used: root:jetaime, root:lamour, root:123456, root:zitian2008 (rotating)
success rate: ~100% — nearly every connection resulted in a successful login
note: Execution canary pattern — verifying shell access works before returning with payload. Coordinated with 8.217.18.158 running identical behavior simultaneously. DigitalOcean-hosted infrastructure.
binaries: Demon.mips, Demon.mpsl, Demon.sh4, Demon.x86
notable arch: SH4 (Renesas SuperH) — targets older embedded routers not covered by Redtail/Kurayami
note: Third distinct DDoS/botnet family observed across the full window. All three (Redtail, Kurayami, Demon) now active within a 3-week span on this sensor.
miner binaries: unchanged across all periods — arm7/arm8/i686/x86_64 hashes identical since Apr 1
cadence: Apr 1 → Apr 7 → Apr 14 → Apr 17–21 (daily). Operator shifting from weekly to daily deployment runs.
note: Reversion to original clean.sh may indicate the Apr 11–15 updated script caused issues and was rolled back.
note: Largest single-period jump yet. Campaign shows no signs of slowing.
Notable sessions — web
targets: /.pgpass, /.aws/config, /.aws/credentials, /.netrc, /backup*.zip/tar/tar.gz, /.env*, /debug.php, /info.php, /test.php
note: Self-identifying as SecurityScanner/1.0 while simultaneously spoofing browser UAs — the scanner UA likely leaks from a misconfigured rotation. Backup archive targeting (.zip/.tar/.tar.gz variants) not seen from prior actors.
new: All requests now hitting port 443 — prior periods used port 80/direct IP. Possible TLS scanning added to toolset.
note: Four consecutive reporting periods. Same /24 as Redtail SSH uploader (130.12.180.51). Duplicate requests per path suggest retry logic or parallel thread execution.
note: One request per IP, all identical target — distributed credential bruteforce pattern using Scaleway VPS infrastructure to evade per-IP rate limiting.
note: GeoServer (CVE-2024-36401 RCE) and Synology DSM probing indicate broader NAS/geospatial server targeting — not seen in prior periods.
path: /admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
note: Same CVE-2017-9841 target as libredtail-http but different tooling. Suggests multiple independent scanner implementations targeting the same vulnerability.
Top attempted SSH credentials
| username | password | attempts | notes |
|---|---|---|---|
| 345gs5662d34 | 345gs5662d34 | 3,763 | mdrfckr campaign — continued growth |
| root | 3245gs5662d34 | 3,747 | mdrfckr campaign — continued growth |
| root | admin | 550 | Generic — lower than prior periods |
| admin | admin | 71 | Generic default |
| root | P | 30 | Single-char probe |
| orangepi | orangepi | 21 | Orange Pi SBC default |
| AdminGPON | ALC#FGU | 20 | GPON router default — Mirai variant |
| admin1234 | admin1234 | 16 | New entrant — common weak credential |
| socks | socks | 12 | SOCKS proxy default — proxy server targeting |
| root | 3.14159265 | 9 | Pi-based password — targeted list artifact |
Observed payload hashes (ssh downloads)
| sha256 (truncated) | count | context |
|---|---|---|
| a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2 | 3,956 | Primary mdrfckr payload — all five periods, unchanged |
| 01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b | 203 | Null placeholder — consistent across all periods |
| 8a68d1c08ea31250063f70b1ccb5051db1f7ab6e17d46e9dd3cc292b9849878b | 14 | Redtail-linked — low frequency, persistent |
| 739135066c762d50a9542ff91c094e7a53df452ad188821a34dc05b5c9c35f40 | 1 | Demon bins.sh dropper |
| e9564236bdaac13cb38601b461a76c1b497ae21c85f524cd6f623587101b20e9 | 1 | Demon.mips binary |
| 2f261e21db56fb984baeec70a48b820c3d8006bb6611888adabe9bbb7a4a3dbf | 1 | Demon.mpsl binary |
| 343f666d548720d23ba6ca4c08e3ab10aced5cc9ea155c454f31bed5a939c89a | 1 | Demon.sh4 binary |
| b040e1a6476b048f7521c9d194933341bdbb9a5dc71697820fa3df9dde6e6da9 | 1 | Demon.x86 binary |
Indicators of compromise
| type | value | context |
|---|---|---|
| IP | 134.122.95.87 | Mass scan — 31,772 connections Apr 21, execution canary only |
| IP | 8.217.18.158 | Coordinated canary scan — 3,317 sessions, same pattern as 134.122.95.87 |
| IP | 130.12.180.51 | Redtail SCP uploader — 14 sessions across 5 days, Apr 17–21 |
| IP | 143.137.204.138 | Demon botnet dropper session — bins.sh + multi-arch binaries |
| IP | 89.190.156.34 | Demon C2/hosting — bins.sh and Demon binary host |
| IP | 195.178.110.101 | SecurityScanner/1.0 — 185 web requests, backup + credential enumeration |
| IP | 130.12.180.111 | .env sweep — 26 requests over HTTPS, fourth consecutive period |
| IP | 65.49.1.142 | GeoServer + Synology DSM probe — new service targeting |
| IP | 185.177.72.61 | l9explore/1.2.2 — .git/config, all five periods |
| hash | a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2 | mdrfckr primary payload — persistent all five periods |
| hash | 739135066c762d50a9542ff91c094e7a53df452ad188821a34dc05b5c9c35f40 | Demon bins.sh dropper |
| hash | 343f666d548720d23ba6ca4c08e3ab10aced5cc9ea155c454f31bed5a939c89a | Demon.sh4 — SH4 architecture binary |
| UA | libredtail-http | Redtail scanner — all five periods |
| UA | l9explore/1.2.2 | .git/config recon — all five periods |
| UA | Mozilla/5.0 (compatible; SecurityScanner/1.0) | 195.178.110.101 — broad credential/backup scan |
| UA | Custom-AsyncHttpClient | 59.44.42.9 — CVE-2017-9841 phpunit probe |
| URL | http://89.190.156.34/bins.sh | Demon dropper URL |
| URL | http://89.190.156.34/Demon.mips | Demon MIPS binary |
| URL | http://89.190.156.34/Demon.sh4 | Demon SH4 binary — unusual architecture |
| credential | root:3245gs5662d34 | mdrfckr — 3,747 attempts this period |
Cross-period actor tracking
| actor / indicator | Apr 1–5 | Apr 6–10 | Apr 11–15 | Apr 16–20 | trend |
|---|---|---|---|---|---|
| mdrfckr injections | 2,431 | 3,159 | 3,418 | 3,956 | ↑ +63% since P1 |
| 130.12.180.51 Redtail uploads | ✓ Apr 1 | ✓ Apr 7 | ✓ Apr 14 | ✓ Apr 17–21 | ↑ daily cadence |
| 130.12.180.111 .env sweep | ✓ | ✓ | ✓ | ✓ (HTTPS) | ↑ all periods |
| 185.177.72.61 l9explore | ✓ | ✓ | ✓ | ✓ | ↑ all periods |
| libredtail-http phpunit | 47 | 58 | 16 | 17 | → stable low |
| 172.94.9.253 admin brute | ✓ 458 | ✓ 16 | — | — | ↓ not seen P3–P4 |
| Kurayami binaries | — | — | ✓ new | — | → single period |
| Demon binaries | — | — | — | ✓ new | ↑ new this period |
| SSH connections (total) | 16,491 | 23,470 | 20,823 | 59,761 | ↑ spike Apr 21 |
| direct-tcpip tunneling | 353 | 3,000 | 863 | 537 | ↓ declining |
MITRE ATT&CK mapping
| technique id | name | observed |
|---|---|---|
| T1110.001 | Brute Force: Password Guessing | 54,901 SSH auth attempts; Scaleway /login cluster (13 IPs) |
| T1098.004 | Account Manipulation: SSH Authorized Keys | mdrfckr key injection — 3,956 sessions |
| T1018 | Remote System Discovery | 134.122.95.87 canary scan — 31,772 sessions probing execution capability |
| T1059.004 | Command & Scripting: Unix Shell | bins.sh / clean.sh / setup.sh execution chains |
| T1105 | Ingress Tool Transfer | Redtail SCP uploads (130.12.180.51); Demon wget from 89.190.156.34 |
| T1496 | Resource Hijacking | Redtail cryptominer — daily deployment cadence Apr 17–21 |
| T1498 | Network Denial of Service | Demon DDoS botnet — MIPS/MPSL/SH4/x86 binaries |
| T1070.003 | Indicator Removal: Clear Command History | Competitor cleanup — pkill competing bots, clear /tmp |
| T1082 | System Information Discovery | Scripted hardware recon; GeoServer/Synology DSM service fingerprinting |
| T1190 | Exploit Public-Facing Application | CVE-2017-9841 phpunit eval-stdin.php (libredtail-http + Custom-AsyncHttpClient) |
| T1083 | File and Directory Discovery | Backup archive enumeration (.zip/.tar/.tar.gz); .env variant sweep; /.pgpass, /.netrc |
| T1552.001 | Credentials In Files | /.aws/credentials, /.aws/config, /.pgpass, /.netrc, .env sweep — 130.12.180.111 + 195.178.110.101 |
Raw log excerpts
134.122.95.87 execution canary — repeated 31,770 times Apr 21:
2026-04-21 cowrie.session.connect src=134.122.95.87 2026-04-21 cowrie.login.success user=root pass=jetaime 2026-04-21 cowrie.command.input CMD: echo -e "\x6F\x6B" # → "ok" 2026-04-21 cowrie.session.closed # Pattern repeats with rotating passwords: jetaime, lamour, 123456, zitian2008...
Demon botnet download chain — 143.137.204.138 (Apr 18):
2026-04-18T00:37:41Z cowrie.session.file_download url=http://89.190.156.34/bins.sh sha256=739135066c762d50... 2026-04-18T00:37:42Z cowrie.session.file_download url=http://89.190.156.34/Demon.mips sha256=e9564236bdaac13c... 2026-04-18T00:37:42Z cowrie.session.file_download url=http://89.190.156.34/Demon.mpsl sha256=2f261e21db56fb98... 2026-04-18T00:37:42Z cowrie.session.file_download url=http://89.190.156.34/Demon.sh4 sha256=343f666d548720d2... 2026-04-18T00:37:43Z cowrie.session.file_download url=http://89.190.156.34/Demon.x86 sha256=b040e1a6476b048f...
195.178.110.101 — backup and credential sweep (Apr 21, SecurityScanner/1.0):
2026-04-21T00:03:50+00:00 195.178.110.101 "GET /.pgpass HTTP/1.1" 200 2026-04-21T00:03:51+00:00 195.178.110.101 "GET /.aws/config HTTP/1.1" 200 2026-04-21T00:03:51+00:00 195.178.110.101 "GET /.aws/credentials HTTP/1.1" 200 2026-04-21T00:03:51+00:00 195.178.110.101 "GET /backup2.zip HTTP/1.1" 200 2026-04-21T00:03:51+00:00 195.178.110.101 "GET /backup.tar.gz HTTP/1.1" 200 2026-04-21T00:03:51+00:00 195.178.110.101 "GET /.netrc HTTP/1.1" 200