[Honeypot Report] Unauthorised shell access and command execution via FTP
A remote host obtained sh ...
show more[Honeypot Report] Unauthorised shell access and command execution via FTP
A remote host obtained shell access and executed commands.
Observed: 2026-09-23 09:53 UTC | 1 session | 4 events | FTP (port 21)
Attack chain:
1. Shell access obtained; 2 distinct commands executed: AUTH TLS ; AUTH SSL
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/66.132.195.62.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via FTP
A remote host obtained sh ...
show more[Honeypot Report] Unauthorised shell access and command execution via FTP
A remote host obtained shell access and executed commands.
Observed: 2026-09-23 07:48 UTC | 2 sessions | 5 events | FTP (port 21)
Attack chain:
1. Shell access obtained; 1 distinct command executed: MGLNDD_[sensor]_21
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/20.14.94.94.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via FTP
A remote host obtained sh ...
show more[Honeypot Report] Unauthorised shell access and command execution via FTP
A remote host obtained shell access and executed commands.
Observed: 2026-09-23 04:49 UTC | 2 sessions | 5 events | FTP (port 21)
Attack chain:
1. Shell access obtained; 1 distinct command executed: MGLNDD_[sensor]_21
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/20.64.98.130.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via FTP
A remote host obtained sh ...
show more[Honeypot Report] Unauthorised shell access and command execution via FTP
A remote host obtained shell access and executed commands.
Observed: 2026-09-23 02:59 UTC | 1 session | 4 events | FTP (port 21)
Attack chain:
1. Shell access obtained; 2 distinct commands executed: AUTH TLS ; AUTH SSL
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/198.235.24.115.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via FTP
A remote host obtained sh ...
show more[Honeypot Report] Unauthorised shell access and command execution via FTP
A remote host obtained shell access and executed commands.
Observed: 2026-09-22 21:17 UTC | 1 session | 4 events | FTP (port 21)
Attack chain:
1. Shell access obtained; 2 distinct commands executed: AUTH TLS ; AUTH SSL
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/44.204.37.191.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via FTP
A remote host obtained sh ...
show more[Honeypot Report] Unauthorised shell access and command execution via FTP
A remote host obtained shell access and executed commands.
Observed: 2026-09-22 20:22 UTC | 1 session | 4 events | FTP (port 21)
Attack chain:
1. Shell access obtained; 2 distinct commands executed: AUTH TLS ; AUTH SSL
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/199.45.155.46.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via REDIS
A remote host obtained ...
show more[Honeypot Report] Unauthorised shell access and command execution via REDIS
A remote host obtained shell access and executed commands.
Observed: 2026-09-24 06:34 UTC | 1 session | 6 events | REDIS (port 6379)
Attack chain:
1. Shell access obtained; 4 distinct commands executed: PING ; INFO ; NONEXISTENT
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/66.132.195.68.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via REDIS
A remote host obtained ...
show more[Honeypot Report] Unauthorised shell access and command execution via REDIS
A remote host obtained shell access and executed commands.
Observed: 2026-09-24 06:47 UTC | 2 sessions | 10 events | REDIS (port 6379)
Attack chain:
1. Shell access obtained; 5 distinct commands executed: INFO ; CONFIG GET bind ; PUBSUB CHANNELS
Classification: scanner
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/104.155.126.205.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[Honeypot Report] Unauthorised shell access and command execution via Telnet
A remote host attempte ...
show more[Honeypot Report] Unauthorised shell access and command execution via Telnet
A remote host attempted to log in to our emulated Telnet service, then obtained shell access and executed commands.
Observed: 2026-09-24 09:25 to 2026-09-24 09:28 UTC | 1 session | 7 events | Telnet (port 23)
Attack chain:
1. 1 credential attempt: admin/admin
2. Shell access obtained; 3 distinct commands executed: id ; cat /etc/passwd ; echo -e "\x61\x75\x74\x68\x5F\x6F\x6B\x0A"
Signatures: Host Reconnaissance Commands
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/209.99.187.10.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less