markcardiff.tech:/honeypot-reviews/cowrie-ssh-honeypot-weekly-2026-08-24-to-2026-08-30.html
root@markcardiff:~/honeypot-reviews$ ./render weekly --public-safe

Weekly Cowrie SSH Honeypot Report

Public-safe weekly SSH honeypot telemetry summary. Coverage is 24 Aug 2026 – 30 Aug 2026 UTC. Raw transcripts, payload code, attacker key material, credentials, and sensitive operational details are intentionally omitted.

Coverage 24 Aug 2026 – 30 Aug 2026 UTC
Posture public-safe
Timezone UTC
24,306Sessions
1,104Unique source IPs
12,918Failed logins
9,950Accepted logins

Summary

  • Observed 24,306 connection sessions from 1,104 unique source IPs across 157,464 Cowrie JSON events.
  • Authentication automation produced 12,918 failed attempts and 9,950 accepted honeypot logins.
  • Post-login activity generated 11,048 command events; median observed closed-session duration was 1.27 seconds.
  • Captured artifact activity included 1,995 successful download events, 0 failed download events, and 62 upload events.

Key observations

  • Commodity SSH automation remains constant: high-volume credential attempts rapidly transition into system reconnaissance after an accepted honeypot login.
  • Observed command themes were dominated by Linux reconnaissance, SSH access manipulation/persistence attempts, and cleanup/evasion behaviour.
  • Source IPs are published only as defensive indicators; they may represent compromised hosts, scanners, VPN/proxy nodes, or short-lived cloud infrastructure rather than actor-owned systems.

Activity metrics

MetricValue
Sessions24,306
Unique source IPs1,104
Failed login attempts12,918
Accepted honeypot logins9,950
Command events11,048
Successful file download events1,995
Failed file download events0
File upload events62

Common behavior themes

ThemeMatching command events
recon4,865
destructive or evasion3,988
persistence1,998
mikrotik probe6

Selected public-safe indicators

These indicators are provided for defensive awareness only and should not be treated as attribution.

IndicatorContext
91.92.40.1531,570 sessions
94.154.35.2151,441 sessions
77.239.124.252785 sessions
91.92.40.202785 sessions
77.239.124.246785 sessions

Defensive takeaways

  • Monitor internet-facing SSH for short-lived login bursts followed by system reconnaissance and downloader or staging behaviour.
  • Alert on post-auth writes to .ssh/authorized_keys, repeated process-kill cleanup, suspicious downloaders, and unusual client-version/HASSH clusters.
  • Use honeypot-derived indicators as weak signals and correlate with production telemetry before taking blocking action.

Limitations

  • This report summarizes honeypot telemetry only; it does not imply compromise of production systems.
  • No attribution is asserted from this data.
  • Public output omits raw payload code, full attacker keys, detailed transcripts, credentials, and sensitive operational details.