SSH Honeypot Logged 3,888 Attack Attempts from 666 IPs in Just 22 Hours

A security researcher exposed a decoy SSH server to the public internet for 22 hours and recorded nearly 3,900 intrusion attempts from 666 distinct IP addresses, averaging 176 attempts per hour. The honeypot also simulated Telnet, PostgreSQL, and FTP services to broaden the attack surface and capture a wider range of scanning activity. Most traffic originated from cheap hosting infrastructure, with the Netherlands alone accounting for over 1,200 attempts, and a single IP was responsible for more than 20% of all traffic. Common credentials like 'root' and '123456' dominated login attempts, while the presence of 'crypto' as a targeted username indicated bots hunting for cryptocurrency wallets and miners. Post-login behavior was fully automated, with captured payloads revealing known malware families including Mirai and Gafgyt, which systematically probed for compatible CPU architectures to deploy malicious binaries.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in