markcardiff.tech:/honeypot-reviews/cowrie-ssh-honeypot-weekly-2026-08-31-to-2026-09-06.html
root@markcardiff:~/honeypot-reviews$ ./render weekly --public-safe

Weekly Cowrie SSH Honeypot Report

Public-safe weekly SSH honeypot telemetry summary. Coverage is 31 Aug 2026 – 6 Sep 2026 UTC. Raw transcripts, payload code, attacker key material, credentials, and sensitive operational details are intentionally omitted.

Coverage 31 Aug 2026 – 6 Sep 2026 UTC
Posture public-safe
Timezone UTC
21,449Sessions
1,186Unique source IPs
10,271Failed logins
9,358Accepted logins

Summary

  • Observed 21,449 connection sessions from 1,186 unique source IPs across 141,484 Cowrie JSON events.
  • Authentication automation produced 10,271 failed attempts and 9,358 accepted honeypot logins.
  • Post-login activity generated 10,647 command events; median observed closed-session duration was 1.29 seconds.
  • Captured artifact activity included 2,304 successful download events, 0 failed download events, and 72 upload events.

Key observations

  • Commodity SSH automation remains constant: high-volume credential attempts rapidly transition into system reconnaissance after an accepted honeypot login.
  • Observed command themes were dominated by Linux reconnaissance, SSH access manipulation/persistence attempts, and cleanup/evasion behaviour.
  • Source IPs are published only as defensive indicators; they may represent compromised hosts, scanners, VPN/proxy nodes, or short-lived cloud infrastructure rather than actor-owned systems.

Activity metrics

MetricValue
Sessions21,449
Unique source IPs1,186
Failed login attempts10,271
Accepted honeypot logins9,358
Command events10,647
Successful file download events2,304
Failed file download events0
File upload events72

Common behavior themes

ThemeMatching command events
destructive or evasion4,514
recon3,635
persistence2,271
mikrotik probe14

Selected public-safe indicators

These indicators are provided for defensive awareness only and should not be treated as attribution.

IndicatorContext
94.154.35.2151,472 sessions
45.156.87.13785 sessions
45.156.87.166785 sessions
91.92.42.227785 sessions
155.117.234.176745 sessions

Defensive takeaways

  • Monitor internet-facing SSH for short-lived login bursts followed by system reconnaissance and downloader or staging behaviour.
  • Alert on post-auth writes to .ssh/authorized_keys, repeated process-kill cleanup, suspicious downloaders, and unusual client-version/HASSH clusters.
  • Use honeypot-derived indicators as weak signals and correlate with production telemetry before taking blocking action.

Limitations

  • This report summarizes honeypot telemetry only; it does not imply compromise of production systems.
  • No attribution is asserted from this data.
  • Public output omits raw payload code, full attacker keys, detailed transcripts, credentials, and sensitive operational details.