[Honeypot Report] Malware dropped following HTTP, SSH and Telnet intrusion
An automated malware loa ...
show more[Honeypot Report] Malware dropped following HTTP, SSH and Telnet intrusion
An automated malware loader attempted to exploit CVE-2012-1823, then attempted multiple logins against our emulated HTTP, SSH and Telnet services, then obtained shell access and executed commands, and finally delivered an executable payload. Credentials and request paths match Apache HTTP Server (CGI), PHP-CGI.
Observed: 2026-09-04 01:56 to 2026-09-18 02:45 UTC | 4 sessions | 60 events | HTTP/SSH/Telnet (port 22, 23, 80)
Attack chain:
1. Exploit attempt: CVE-2012-1823 - PHP-CGI argument injection RCE [CISA KEV]
2. Exploit attempt: CVE-2021-41773 - Apache HTTP Server path traversal to RCE [CISA KEV]
3. 2 credential attempts: admin/admin
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/156.227.234.198.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via SMB
A remote host obtained sh ...
show more[Honeypot Report] Unauthorised shell access and command execution via SMB
A remote host obtained shell access and executed commands.
Observed: 2026-09-20 09:33 UTC | 1 session | 3 events | SMB (port 445)
Attack chain:
1. Shell access obtained; 1 distinct command executed: SMB2 NEGOTIATE (1 dialects)
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/34.156.57.140.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via REDIS
A remote host obtained ...
show more[Honeypot Report] Unauthorised shell access and command execution via REDIS
A remote host obtained shell access and executed commands.
Observed: 2026-09-20 09:25 UTC | 1 session | 3 events | REDIS (port 6379)
Attack chain:
1. Shell access obtained; 1 distinct command executed: MGLNDD_[sensor]_6379
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/20.169.49.49.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via REDIS
A remote host obtained ...
show more[Honeypot Report] Unauthorised shell access and command execution via REDIS
A remote host obtained shell access and executed commands.
Observed: 2026-09-20 07:09 UTC | 1 session | 3 events | REDIS (port 6379)
Attack chain:
1. Shell access obtained; 1 distinct command executed: PING
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/61.153.10.38.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via FTP
A remote host obtained sh ...
show more[Honeypot Report] Unauthorised shell access and command execution via FTP
A remote host obtained shell access and executed commands.
Observed: 2026-09-20 10:32 UTC | 1 session | 4 events | FTP (port 21)
Attack chain:
1. Shell access obtained; 2 distinct commands executed: AUTH TLS ; AUTH SSL
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/31.14.254.85.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via REDIS
A remote host obtained ...
show more[Honeypot Report] Unauthorised shell access and command execution via REDIS
A remote host obtained shell access and executed commands.
Observed: 2026-09-20 06:37 UTC | 1 session | 6 events | REDIS (port 6379)
Attack chain:
1. Shell access obtained; 4 distinct commands executed: PING ; INFO ; NONEXISTENT
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/66.132.224.229.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via HTTP and SMB
A remote host pr ...
show more[Honeypot Report] Unauthorised shell access and command execution via HTTP and SMB
A remote host probed for vulnerable web applications, then obtained shell access and executed commands.
Observed: 2026-09-13 12:52 to 2026-09-20 07:59 UTC | 2 sessions | 6 events | HTTP/SMB (port 80, 445)
Attack chain:
1. Requested 1 distinct path, including: /mcp
2. Shell access obtained; 1 distinct command executed: SMB2 NEGOTIATE (5 dialects)
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/5.226.140.95.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via HTTP and SMB
A remote host pr ...
show more[Honeypot Report] Unauthorised shell access and command execution via HTTP and SMB
A remote host probed for vulnerable web applications, then obtained shell access and executed commands.
Observed: 2026-09-19 17:46 to 2026-09-20 07:57 UTC | 3 sessions | 9 events | HTTP/SMB (port 80, 445, 8443)
Attack chain:
1. Requested 2 distinct paths, including: /mcp/ | /sse
2. Shell access obtained; 1 distinct command executed: SMB2 NEGOTIATE (5 dialects)
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/185.216.145.181.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via FTP and HTTP
A remote host pr ...
show more[Honeypot Report] Unauthorised shell access and command execution via FTP and HTTP
A remote host probed for vulnerable web applications, then obtained shell access and executed commands.
Observed: 2026-09-16 20:05 to 2026-09-20 06:51 UTC | 2 sessions | 7 events | FTP/HTTP (port 21, 7547)
Attack chain:
1. Requested 1 distinct path, including: /
2. Shell access obtained; 2 distinct commands executed: AUTH TLS ; AUTH SSL
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/205.210.31.216.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via SSH
A remote host attempted t ...
show more[Honeypot Report] Unauthorised shell access and command execution via SSH
A remote host attempted to log in to our emulated SSH service, then obtained shell access and executed commands.
Observed: 2026-09-20 06:23 to 2026-09-20 06:25 UTC | 1 session | 13 events | SSH (port 22)
Attack chain:
1. 1 credential attempt: root/root
2. Shell access obtained; 9 distinct commands executed: /ip cloud print ; ifconfig ; uname -a
Signatures: Host Reconnaissance Commands
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/202.131.250.10.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less