>_

AWS Cowrie Honeypot

Internet-facing SSH threat telemetry and analysis
THREAT RESEARCH

Captured Attack Investigations

Technical analysis of malware, automated attacks, credential activity, reconnaissance, and SSH abuse observed by the live AWS honeypot.

9 Investigations Live Internet Telemetry AWS Infrastructure

SSH Credential Validation

Recurring Go-based SSH activity using unique credentials to authenticate as root before disconnecting with little or no interaction.

SSH / CREDENTIALS

Raspberry Pi SSH Worm

Self-propagating Bash payload targeting Raspberry Pi-style SSH credentials with persistence and IRC command-and-control behavior.

MALWARE / WORM

SSH Propagation Payload

Repeated deployment of the same large ELF payload across multiple source addresses using automated SSH infrastructure.

MALWARE / SSH

PIMINE Activity

Observed activity associated with automated Linux targeting and cryptocurrency-mining behavior.

MALWARE

PANCHAN Investigation

Analysis of suspicious Linux activity and artifacts investigated for possible PANCHAN-related behavior.

MALWARE ANALYSIS

Recurring PANCHAN Activity

Follow-up analysis documenting recurring activity and behavioral similarities observed after the initial investigation.

CAMPAIGN TRACKING

SSH Tunneling

Sessions attempting to use the honeypot as an SSH forwarding point to reach external services.

SSH ABUSE

Automated Reconnaissance

Automated post-authentication commands used to fingerprint the operating system, hardware, and host environment.

RECONNAISSANCE

Credential Scanning

Analysis of automated username and password attempts recorded against the public SSH honeypot.

CREDENTIALS