slatterysec.com/reports/2026/04/2026-04-26_2026-04-30-ssh-web-honeypot-report.html
sensors 8 up last session 4m ago 24h captures 312 unique src 87

slattery@sec:~/reports$ cat 2026-04-26_2026-04-30-ssh-web-honeypot-report.md

HONEYPOT REPORT // SSH + WEB // 2026-04-26 – 2026-04-30

2026-04-26 – 2026-04-30 — SSH + Web Honeypot Report

Period: 2026-04-26 – 2026-04-30  |  Sensor: Cowrie v2.x (SSH + HTTP)  |  Host: VPS / RackNerd
SSH WEB ALERT SSH KEY IMPLANT APR 30 SPIKE
SSH EVENTS
117,570
across 5 days
AUTH ATTEMPTS
12,610
4,274 succeeded (33.9%)
UNIQUE SSH IPs
1,890
across all 5 days
KEY IMPLANTS
1,321
mdrfckr RSA key
WEB REQUESTS
4,720
819 unique IPs
.ENV PROBES
1,059
incl. encoded variants
PHPUNIT RCE HITS
796
libredtail-http — 18+ IPs
FILE DOWNLOADS
1,608
recorded by Cowrie

Executive summary

The April 26–30 period recorded 117,570 SSH events across 31,178 sessions — lower total session count than the preceding P5 window but with a sharply elevated success rate (33.9% vs typical sub-20%) and a significant Apr 30 single-day spike: 32,946 events and 546 unique source IPs, the highest daily figures of the month. The dominant SSH threat pattern is a coordinated two-step post-auth playbook — clearing .ssh directory attributes via chattr -ia then implanting the persistent mdrfckr RSA key — executed across 1,321 sessions. Secondary post-auth activity includes CPU/memory enumeration consistent with cryptominer pre-deployment, competing malware removal, and Cisco IOS command sequences targeting SSH-enabled network devices.

On the web sensor, two parallel campaigns dominated. The Redtail botnet continued its PHPUnit CVE-2017-9841 sweep via the libredtail-http UA — 796 requests across 18+ distinct IPs each sending a uniform 44-request block, confirming botnet coordination. A separate .env credential harvesting operation driven by 213.209.159.175 and 192.253.248.169 accounted for nearly 20% of all web traffic, with both IPs rotating spoofed User-Agent strings per request and using HEAD-before-GET to confirm file existence before downloading. A notable evasion technique emerged from 195.178.110.133: percent-encoding of the /admin/.env path as /%61%64%6D%69%6E/.%65%6Ev to bypass plaintext-string detection.

Cross-sensor: libredtail-http links the web PHPUnit campaign directly to the SSH key-implant operation — same Redtail infrastructure, concurrent multi-vector activity. Web RCE → SSH persistence → miner deployment is the inferred kill chain.

Daily SSH event trend

Apr 26
1,000
Apr 27
10,523
Apr 28
17,855
Apr 29
19,021
Apr 30 ▲
32,946

Apr 26 data is partial — consistent with log rotation at period open. The Apr 30 spike represents a ~73% single-day increase over Apr 29, with 546 unique source IPs — the highest daily unique-IP count of the month. Login successes also peaked at 1,049 that day.

SSH — notable sessions

2026-04-26 – 2026-04-30 (recurring — 1,321 sessions) ALERT multiple IPs
SSH key persistence implant — mdrfckr RSA key
step 1: cd ~; chattr -ia .ssh; lockr -ia .ssh
step 2: cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~
effect: removes immutable flags, wipes .ssh dir, injects attacker RSA key, locks permissions — persistent keyless backdoor access
2026-04-26 – 2026-04-30 (recurring — 39 sessions each cmd) ALERT multiple IPs
Cryptominer pre-deployment recon — CPU + memory enumeration
cmd: cat /proc/cpuinfo | grep name | wc -l
cmd: free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'
cmd: uname -m
cmd: w  |  crontab -l  |  ls -lh $(which ls)  |  which ls
context: standard Redtail pre-deployment host profiling — evaluates compute resources before miner drop
2026-04-26 – 2026-04-30 (recurring — 39 sessions) multiple IPs
Competing malware removal + hosts.deny wipe
cmd: rm -rf /tmp/secure.sh; rm -rf /tmp/auth.sh; pkill -9 secure.sh; pkill -9 auth.sh; echo > /etc/hosts.deny; pkill -9 sleep;
context: territorial botnet behavior — removes competing malware from /tmp, clears access deny list to ensure own access is not blocked
2026-04-26 – 2026-04-30 (recurring — 49 sessions) multiple IPs
Network device targeting — Cisco IOS-style command sequence
cmds: start  →  enable  →  config terminal  →  system
context: automated botnet module probing SSH-enabled routers and switches — consistent with botnet infrastructure expansion beyond Linux hosts

SSH — top attempted credentials

usernamepasswordattemptsnotes
root(various)4,474dominant target account
admin(various)1,519
345gs5662d34345gs5662d341,280Mirai IoT botnet credential pair
345gs5662d343245gs5662d341,280Mirai variant — same campaign
support(various)1,001
ubuntu(various)943cloud image default targeting
(any)admin718
(any)password401
(any)toor334root reversed — trivial change detection
(any)123456258

SSH — top source IPs

IPeventsnotes
87.251.64.1763,787top single source — RU netblock
2.228.129.2302,616
136.243.10.1982,492Hetzner DE
51.75.144.211,668OVH FR
67.207.94.2231,666
85.14.245.1221,460
62.210.127.481,206Online SAS FR
46.4.64.1041,134Hetzner DE
87.251.64.1471,090same /24 as top source
87.251.64.1441,090same /24 as top source

Three IPs in the 87.251.64.0/24 netblock account for 5,967 combined events. This coordinated cluster — likely shared botnet C2 or VPS abuse infrastructure — is consistent with the multi-IP subnet patterns observed in the 185.177.72.x cluster from P5.

SSH — client fingerprints

client versionsessionsnotes
SSH-2.0-libssh_0.12.06,650dominant automated scanner lib
SSH-2.0-libssh_0.11.13,226
SSH-2.0-Go1,983custom Go-based attack tooling
SSH-2.0-libssh-0.21,162
SSH-2.0-sshcustom_0.1410non-standard — purpose-built binary, evasion identifier
SSH-2.0-libssh_0.9.6110
SSH-2.0-OpenSSH_10.0101
SSH-2.0-libssh2_1.11.157

web — notable sessions

2026-04-26 – 2026-04-30 (recurring — 796 requests) ALERT 18+ IPs — libredtail-http
Redtail PHPUnit RCE sweep — CVE-2017-9841
uri: /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
uri: /admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
ua: libredtail-http
pattern: each participating IP sent exactly 44 requests — botnet-coordinated sweep, not single-source scanning
cve: CVE-2017-9841 — unauthenticated PHP RCE when vendor dir is web-accessible (PHPUnit < 4.8.28 / 5.6.3)
2026-04-27 – 2026-04-30 (recurring — 508 requests) ALERT 213.209.159.175
.env harvesting — HEAD+GET pattern, rotating spoofed User-Agent strings
uris: /admin/.env, /admin/phpinfo, /admin/phpinfo
method: HEAD (confirm existence) → GET (download) per target
ua rotation: Android 2.3.3 LG-LU3000, IE11/MALNJS, Chrome/31 MetaSr, Chrome/59, Firefox/52, Samsung GT-P5110 — new UA per request pair
context: systematic evasion of UA-based detection; same IP active all five days
2026-04-30T03:28:28 UTC ALERT 195.178.110.133
URL-encoded .env path — WAF / detection evasion
request 1: GET /admin/.env HTTP/1.1
request 2: GET /%61%64%6D%69%6E/.%65%6Ev HTTP/1.1
decoded: /admin/.env — identical target, percent-encoded to bypass plaintext-match detection
ua: Mozilla/5.0 (compatible; SecurityScanner/1.0)
2026-04-29T23:53:44 – 23:54:13 UTC 157.245.58.198
Multi-path .env + phpinfo sweep — DigitalOcean host, router-admin.uk vhost
uri 1: GET /admin/.env (host: router-admin.uk)
uri 2: GET /administrator/.env (host: router-admin.uk)
uri 3: GET /admin/phpinfo.php (host: router-admin.uk)
ua: Mozilla/5.0 (X11; Linux x86_64) Chrome/131

web — top source IPs

IPrequests% trafficprimary activity
213.209.159.17550810.8%.env harvesting — rotating UA, HEAD+GET pattern
192.253.248.1693988.4%.env + info.php harvesting — rotating UA
195.178.110.1331974.2%.env + URL-encoded evasion; SecurityScanner/1.0
157.245.58.1981703.6%.env, /administrator/.env, phpinfo — DigitalOcean
104.243.35.941463.1%root path scanning
179.43.146.2261262.7%root path scanning
185.2.101.118481.0%libredtail-http PHPUnit RCE
167.86.120.35461.0%libredtail-http PHPUnit RCE
35.194.141.75461.0%libredtail-http PHPUnit RCE — GCP
103.85.72.144461.0%libredtail-http PHPUnit RCE

web — top user agents

user agentrequestsclassification
libredtail-http796Redtail botnet — malicious
(empty)546automated scanner — UA not set
Umai-Scanner/2.0 (+https://umai.entelijan.com/methodology)177security research scanner
Mozilla/5.0 ... Chrome/131 ... Linux x86_64172157.245.58.198 .env sweep
Mozilla/5.0 ... Chrome/144127general scanner
Mozilla/5.0 zgrab/0.x120ZMap/ZGrab internet-wide scan
Mozilla/5.0 (compatible; CensysInspect/1.1 ...)114Censys internet scan infrastructure
Go-http-client/1.1113custom Go tooling — automated

web — additional probe categories

target / patternhitspurpose
/.git/config31git repository exposure — secret / credential harvesting
/squid-internal-mgr/cachemgr.cgi27Squid proxy management interface exploitation
/SDK/webLanguage23Hikvision camera RCE — CVE-2021-36260
PHP RFI via ?%ADd+allow_url_include%3d1...38PHP Remote File Inclusion via allow_url_include
wp- paths29WordPress core / plugin enumeration
/admin/config.php5admin config file exposure

Raw log excerpts

mdrfckr SSH key implant — two-step session pattern (recurring across 1,321 sessions):

cowrie.command.input  input="cd ~; chattr -ia .ssh; lockr -ia .ssh"
cowrie.command.input  input="cd ~ && rm -rf .ssh && mkdir .ssh && echo \"ssh-rsa AAAAB3NzaC1yc2EAAAAB...mdrfckr\" >>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~"

195.178.110.133 — URL-encoded .env evasion (2026-04-30):

2026-04-30T03:28:28+00:00 195.178.110.133 "GET /admin/.env HTTP/1.1"               198.12.67.153  ua: Mozilla/5.0 (compatible; SecurityScanner/1.0)
2026-04-30T03:28:28+00:00 195.178.110.133 "GET /%61%64%6D%69%6E/.%65%6Ev HTTP/1.1" 198.12.67.153  ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Firefox/121.0
# decoded: /admin/.env — same target, percent-encoded path to bypass detection

213.209.159.175 — HEAD+GET .env pattern with UA rotation (2026-04-30):

2026-04-30T06:53:02+00:00 213.209.159.175 HEAD /admin/.env  ua: Mozilla/5.0 (Linux; U; Android 2.3.3; ko-kr; LG-LU3000 ...)
2026-04-30T06:53:02+00:00 213.209.159.175 GET  /admin/.env  ua: Mozilla/5.0 (Linux; U; Android 2.3.3; ko-kr; LG-LU3000 ...)
2026-04-30T13:15:16+00:00 213.209.159.175 HEAD /admin/.env  ua: Mozilla/5.0 (Windows NT 6.1; Win64; x64) Chrome/59.0.3071.104
2026-04-30T13:15:16+00:00 213.209.159.175 GET  /admin/.env  ua: Mozilla/5.0 (Windows NT 6.1; Win64; x64) Chrome/59.0.3071.104
2026-04-30T15:01:46+00:00 213.209.159.175 HEAD /admin/.env  ua: Mozilla/5.0 (Windows NT 6.1; WOW64) ... SE 2.X MetaSr 1.0
2026-04-30T15:01:46+00:00 213.209.159.175 GET  /admin/.env  ua: Mozilla/5.0 (Windows NT 6.1; WOW64) ... SE 2.X MetaSr 1.0

Indicators of compromise

typevaluecontext
IP87.251.64.176Top SSH source — 3,787 events — RU netblock /24 cluster
IP87.251.64.147Same /24 — 1,090 events — coordinated cluster
IP87.251.64.144Same /24 — 1,090 events — coordinated cluster
IP136.243.10.198Hetzner DE — 2,492 SSH events
IP213.209.159.175Top .env harvester — 508 web requests, rotating UA, HEAD+GET
IP192.253.248.169.env + info.php harvester — 398 web requests, rotating UA
IP195.178.110.133URL-encoded .env evasion — SecurityScanner/1.0
IP157.245.58.198.env + phpinfo sweep — DigitalOcean NYC
SSH pub keyAAAAB3NzaC1yc2EAAAABJQAAAQEArDp4...mdrfckrPersistent backdoor key — 1,321 implants this period
credential345gs5662d34 / 345gs5662d34Mirai IoT botnet pair — 1,280 attempts
credential345gs5662d34 / 3245gs5662d34Mirai variant — 1,280 attempts
UAlibredtail-httpRedtail botnet — 796 web requests, 18+ IPs, cross-sensor
client verSSH-2.0-sshcustom_0.1Non-standard SSH client — purpose-built attack binary
CVECVE-2017-9841PHPUnit eval-stdin RCE — 796 probe attempts
CVECVE-2021-36260Hikvision camera RCE — /SDK/webLanguage — 23 attempts
path/%61%64%6D%69%6E/.%65%6EvURL-encoded /admin/.env — WAF evasion — 195.178.110.133

Cross-period actor tracking

actor / indicatorP1 Apr1–5P2 Apr6–10P3 Apr11–15P4 Apr16–20P5 Apr21–25P6 Apr26–30trend
mdrfckr injections2,4313,1593,4183,9563,2521,321↓ lower period volume
87.251.64.0/24 cluster5,967 ↑ new↑ first appearance
libredtail-http phpunit4758161717796↑ surge
213.209.159.175 .env508 ↑ peak↑ most active period
185.177.72.x curl RCE.11.52 + .30→ absent P6
130.12.180.51 Redtail SCP~100723684126 peak→ absent P6
345gs5662d34 Mirai pair1,280 ↑ new↑ first appearance
SSH events (total)16,49123,47020,82359,76126,726117,570 ↑↑ highest period

MITRE ATT&CK mapping

technique idnameobserved
T1110.003Brute Force: Password Spraying12,610 SSH auth attempts across 1,890 unique IPs
T1078Valid Accounts345gs5662d34 Mirai IoT pair; ubuntu/ubuntu, toor, cloud defaults
T1098.004Account Manipulation: SSH Authorized Keysmdrfckr key implanted in 1,321 sessions
T1222File and Directory Permissions Modificationchattr -ia .ssh; chmod -R go= ~/.ssh
T1082System Information Discoverycpuinfo, uname -m, free -m — miner pre-deployment recon
T1070.004Indicator Removal: File Deletionrm -rf competing malware from /tmp; echo > /etc/hosts.deny
T1496Resource HijackingCPU/memory recon consistent with Redtail miner pre-deployment
T1190Exploit Public-Facing ApplicationCVE-2017-9841 PHPUnit RCE (796 hits); CVE-2021-36260 Hikvision (23 hits)
T1552.001Credentials In Files.env harvesting — 1,059 requests across plaintext and encoded paths
T1595.002Active Scanning: Vulnerability ScanningSystematic probing of CVEs, .git/config, Squid, WordPress
T1027Obfuscated Files or InformationPercent-encoding of /admin/.env; UA string rotation per request
T1036Masquerading213.209.159.175 / 192.253.248.169 rotating spoofed browser UAs
Full session transcripts, raw JSON logs available on request. Credential strings presented as observed. IP addresses undefanged. CVEs as documented — no exploitation confirmed on honeypot host (all responses Cowrie-emulated).