markcardiff.tech:/honeypot-reviews/cowrie-ssh-honeypot-weekly-2026-09-07-to-2026-09-13.html
root@markcardiff:~/honeypot-reviews$ ./render weekly --public-safe

Weekly Cowrie SSH Honeypot Report

Public-safe weekly SSH honeypot telemetry summary. Coverage is 7 Sep 2026 – 13 Sep 2026 UTC. Raw transcripts, payload code, attacker key material, credentials, and sensitive operational details are intentionally omitted.

Coverage 7 Sep 2026 – 13 Sep 2026 UTC
Posture public-safe
Timezone UTC
41,289Sessions
1,213Unique source IPs
19,506Failed logins
19,686Accepted logins

Summary

  • Observed 41,289 connection sessions from 1,213 unique source IPs across 269,314 Cowrie JSON events.
  • Authentication automation produced 19,506 failed attempts and 19,686 accepted honeypot logins.
  • Post-login activity generated 21,498 command events; median observed closed-session duration was 1.48 seconds.
  • Captured artifact activity included 1,955 successful download events, 0 failed download events, and 61 upload events.

Key observations

  • Commodity SSH automation remains constant: high-volume credential attempts rapidly transition into system reconnaissance after an accepted honeypot login.
  • Observed command themes were dominated by Linux reconnaissance, SSH access manipulation/persistence attempts, and cleanup/evasion behaviour.
  • Source IPs are published only as defensive indicators; they may represent compromised hosts, scanners, VPN/proxy nodes, or short-lived cloud infrastructure rather than actor-owned systems.

Activity metrics

MetricValue
Sessions41,289
Unique source IPs1,213
Failed login attempts19,506
Accepted honeypot logins19,686
Command events21,498
Successful file download events1,955
Failed file download events0
File upload events61

Common behavior themes

ThemeMatching command events
recon8,636
destructive or evasion3,672
persistence1,844
mikrotik probe12
downloaders5

Selected public-safe indicators

These indicators are provided for defensive awareness only and should not be treated as attribution.

IndicatorContext
144.225.124.2437,219 sessions
109.160.32.182,222 sessions
109.160.32.141,437 sessions
109.160.32.1111,437 sessions
109.160.32.1171,435 sessions
http://213.232.114.14/handshakebins.sh15 URL observation(s)
http://213.232.114.14/handshakebins.sh;curl5 URL observation(s)
http://213.232.114.14/handshakebins.sh;busybox5 URL observation(s)

Defensive takeaways

  • Monitor internet-facing SSH for short-lived login bursts followed by system reconnaissance and downloader or staging behaviour.
  • Alert on post-auth writes to .ssh/authorized_keys, repeated process-kill cleanup, suspicious downloaders, and unusual client-version/HASSH clusters.
  • Use honeypot-derived indicators as weak signals and correlate with production telemetry before taking blocking action.

Limitations

  • This report summarizes honeypot telemetry only; it does not imply compromise of production systems.
  • No attribution is asserted from this data.
  • Public output omits raw payload code, full attacker keys, detailed transcripts, credentials, and sensitive operational details.