HONEYPOT REPORT // MONTHLY SUMMARY // APRIL 2026
April 2026 — Monthly Honeypot Summary
Executive summary
April 2026 was the most active month recorded on these sensors since deployment. Six five-day reporting periods captured a sustained escalation in both SSH and web attack volume, with total SSH events reaching an estimated 264,841 — more than ten times the baseline observed in early 2025. The month was defined by three concurrent threat tracks running in parallel across all six periods: the mdrfckr SSH key persistence campaign (17,537 confirmed implants), the Redtail cryptominer operation (persistent SCP payload delivery from 130.12.180.51, PHPUnit RCE sweeps via libredtail-http across both sensors), and a sustained .env credential harvesting operation from a small cluster of IPs rotating spoofed User-Agents.
Three new botnet families made first appearances during the month: Kurayami (P3, Apr 11–15), Demon DDoS (P4, Apr 16–20), and a Canary C2 operation (P5, Apr 21–25) that progressed from a mass reachability scan — 5,175 sessions from 113.87.226.234 echoing ok to confirm shell access — to confirmed payload delivery of ARM and Motorola 68k binaries from 87.121.79.73. The Apr 21 single-day record of 36,617 events was driven by this canary scan. The final period (P6, Apr 26–30) saw the highest total event count of any period (117,570) with Apr 30 producing the highest single-day unique-IP count (546), suggesting continued botnet ramp-up as the month closed.
libredtail-http user agent appeared on both the SSH and web sensors every single period of the month — the clearest cross-sensor indicator of persistent, multi-vector Redtail infrastructure targeting this honeypot throughout April.
SSH events by period
Apr 1–5
Apr 6–10
Apr 11–15
Apr 16–20
Apr 21–25
Apr 26–30
P4 spike driven by a single-day mass canary scan (Apr 21: 36,617 events). P6 total is the highest period of the month despite no single-day anomaly — sustained elevated volume across all five days, with Apr 30 alone producing 32,946 events.
Period-by-period breakdown
| period | dates | ssh events | mdrfckr injections | key findings | report |
|---|---|---|---|---|---|
| P1 | Apr 1–5 | 16,491 | 2,431 | Redtail multi-arch SCP upload; phpunit CVE-2017-9841 web probes; 458-req admin brute force burst | view >> |
| P2 | Apr 6–10 | 23,470 | 3,159 | Redtail operator returns with identical binary set; new Hammz.sh dropper; 80.66.66.10 dominant SSH source (20k+ events) | view >> |
| P3 | Apr 11–15 | 20,823 | 3,418 | Kurayami DDoS botnet first observed; Redtail operator returns for third week with updated dropper; first RCE attempt via curl targeting AWS credentials | view >> |
| P4 ▲ | Apr 16–20 | 59,761 | 3,956 | Single-day record (36,617 on Apr 21) driven by mass canary scan; Demon DDoS botnet first observed; Redtail shifts to daily deployment cadence; mdrfckr injections up 63% since P1 | view >> |
| P5 | Apr 21–25 | 26,726 | 3,252 | Canary follow-on payload confirmed (87.121.79.73 — ARM + m68k binaries); 185.177.72.x subnet curl RCE expanding; 130.12.180.51 Redtail uploads peak at 126 sessions; new breach-list credential root:nPSpP4PBW0 | view >> |
| P6 ▲ | Apr 26–30 | 117,570 | 1,321 | Highest period event total; Apr 30 spike (32,946 events / 546 unique IPs); 87.251.64.0/24 coordinated cluster emerges; Mirai 345gs5662d34 pair first appearance; libredtail-http PHPUnit surge (796 hits) | view >> |
Botnet family timeline
-
2026-04-01 — present (all six periods)
Redtail cryptominer — persistent multi-vector operation. SSH: SCP payload delivery (clean.sh, setup.sh, redtail.arm7/arm8/i686/x86_64) from
130.12.180.51; mdrfckr key implant campaign running every period. Web: PHPUnit CVE-2017-9841 RCE sweeps vialibredtail-httpUA, 47–796 hits per period. CPU/memory pre-deployment recon consistent across all post-auth sessions. - 2026-04-11 — first observed P3 Kurayami DDoS botnet — first observed in P3 (Apr 11–15). Post-auth DDoS module deployment alongside credential stuffing. Distinct from Redtail — separate C2 infrastructure.
- 2026-04-16 — first observed P4 Demon DDoS botnet — first observed in P4 (Apr 16–20), coinciding with the single-day connection record. DDoS payload family, separate from Kurayami. P4 marks the first period with two distinct DDoS botnet families active simultaneously.
-
2026-04-21 — P4 scan, P5 payload delivery
Canary C2 operation — mass reachability scan from
113.87.226.234(5,175 sessions, echo-ok shell confirmation) in P4. Payload delivery confirmed in P5 from87.121.79.73: ARM5/6/7 and Motorola 68k binaries. The m68k target architecture is unusual and suggests broad automated sweeping across embedded/legacy hardware. -
2026-04-26 — first observed P6
Mirai IoT credential sweep —
345gs5662d34/3245gs5662d34credential pair appearing for the first time in P6 with 1,280 attempts each. Classic Mirai IoT botnet signature — separate campaign track from Redtail key-implant operation.
Persistent actors — full month
| actor / indicator | P1 | P2 | P3 | P4 | P5 | P6 |
|---|---|---|---|---|---|---|
| mdrfckr SSH key implant | 2,431 | 3,159 | 3,418 | 3,956 | 3,252 | 1,321 |
| libredtail-http (web) | 47 | 58 | 16 | 17 | 17 | 796 ↑ |
| 130.12.180.51 Redtail SCP | ~100 | 72 | 36 | 84 | 126 ↑ | — |
| 213.209.159.175 .env harvest | ✓ | ✓ | ✓ | ✓ | ✓ | 508 ↑ peak |
| 185.177.72.x curl RCE | — | — | .11 | — | .52 + .30 | — |
| 185.177.72.61 l9explore/.git | ✓ | ✓ | ✓ | ✓ | — | — |
| 87.251.64.0/24 SSH cluster | — | — | — | — | — | 5,967 ↑ new |
| SSH events (period total) | 16,491 | 23,470 | 20,823 | 59,761 | 26,726 | 117,570 |
Top indicators of compromise — full month
| type | value | context |
|---|---|---|
| SSH pub key | ...mdrfckr (RSA) | 17,537 implants across all 6 periods — most persistent SSH IOC of the month |
| IP | 130.12.180.51 | Redtail SCP payload delivery — active P1–P5, 418+ upload sessions |
| IP | 113.87.226.234 | Canary C2 — 5,175 sessions Apr 21, echo-ok shell confirmation sweep |
| IP | 87.121.79.73 | Canary C2 payload server — ok, 00okarm5/6/7, 00okm68k binary delivery |
| IP | 213.209.159.175 | Top .env harvester — present all 6 periods, 508 requests in P6 alone |
| IP | 185.177.72.52 | curl RCE — URL-encoded dot obfuscation, JS config harvest, AWS cred probe |
| IP | 80.66.66.10 | Dominant SSH source P2 — 20k+ events |
| IP | 87.251.64.0/24 | Coordinated SSH cluster — 5,967 events, first appearance P6 |
| UA | libredtail-http | Redtail botnet — present on web sensor every period, 951+ total hits |
| UA | curl/8.7.1 | 185.177.72.52 + .30 — coordinated web RCE and admin enumeration |
| credential | root:3245gs5662d34 | mdrfckr campaign — 3,141+ attempts across month |
| credential | root:nPSpP4PBW0 | New breach-list credential — first appearance P5 |
| credential | 345gs5662d34 / 345gs5662d34 | Mirai IoT pair — first appearance P6, 1,280 attempts |
| CVE | CVE-2017-9841 | PHPUnit eval-stdin RCE — web sensor, all periods |
| CVE | CVE-2021-36260 | Hikvision camera RCE — /SDK/webLanguage probing |
| path | /%61%64%6D%69%6E/.%65%6Ev | URL-encoded /admin/.env — WAF evasion — first observed P6 |
MITRE ATT&CK mapping — full month
| technique id | name | observed |
|---|---|---|
| T1110.001 / T1110.003 | Brute Force | Sustained all month — default credentials, breach lists, IoT pairs, password spraying |
| T1078 | Valid Accounts | IoT defaults (345gs5662d34), cloud image defaults (ubuntu/ubuntu), toor |
| T1098.004 | SSH Authorized Keys | mdrfckr key — 17,537 implants across all 6 periods |
| T1222 | File/Dir Permissions Modification | chattr -ia .ssh; chmod -R go= ~/.ssh — every mdrfckr session |
| T1018 | Remote System Discovery | Canary scan — 5,175 sessions confirming shell execution (echo-ok) |
| T1059.004 | Unix Shell | ok dropper; clean.sh / setup.sh Redtail chains; curl pipe-to-bash |
| T1105 | Ingress Tool Transfer | Redtail SCP (130.12.180.51, 418+ sessions); 87.121.79.73 ARM/m68k delivery |
| T1496 | Resource Hijacking | Redtail cryptominer — persistent all month; CPU/mem recon pre-deployment |
| T1190 | Exploit Public-Facing Application | CVE-2017-9841 PHPUnit RCE (951+ hits); CVE-2021-36260 Hikvision |
| T1552.001 | Credentials In Files | .env harvesting all month; .aws/credentials; database.js; constants.js |
| T1595.002 | Vulnerability Scanning | Systematic CVE/misconfiguration probing — all periods |
| T1027 / T1027.001 | Obfuscation | Percent-encoding (/admin/.env, phpinfo%2ephp); UA string rotation |
| T1036 | Masquerading | Spoofed browser UAs — rotating per-request on .env harvesters |
| T1572 | Protocol Tunneling | 523 direct-tcpip requests observed P5 |
| T1583 / T1584 | Acquire / Compromise Infrastructure | Hetzner DE, OVH FR, GCP, DigitalOcean infrastructure used by multiple actors |
Analyst observations
Three trends stand out from April 2026. First, the mdrfckr campaign is not opportunistic — 17,537 implants across a single month, consistently executing the same two-step chattr + key-inject playbook, indicates an organized operation maintaining a credential database and re-exploiting previously accessed systems. Second, Redtail is operating across both sensors simultaneously — the libredtail-http UA on the web sensor and the SCP payload delivery on the SSH sensor are not coincidentally timed; they are the same infrastructure running parallel access vectors. Third, the Canary C2 operation is notable for its architecture breadth — dropping Motorola 68k binaries alongside standard ARM variants suggests automated tooling that shotguns payload types rather than targeting a specific device category.
The P6 volume surge (117,570 events, Apr 26–30) with no corresponding payload or novel TTP observed — just raw connection volume — is consistent with a botnet expanding its scan pool rather than executing a targeted campaign. Whether that translates to a significant May event remains to be seen.