Captured Attack Investigations
Technical analysis of malware, automated attacks, credential activity, reconnaissance, and SSH abuse observed by the live AWS honeypot.
SSH Credential Validation
Recurring Go-based SSH activity using unique credentials to authenticate as root before disconnecting with little or no interaction.
SSH / CREDENTIALSRaspberry Pi SSH Worm
Self-propagating Bash payload targeting Raspberry Pi-style SSH credentials with persistence and IRC command-and-control behavior.
MALWARE / WORMSSH Propagation Payload
Repeated deployment of the same large ELF payload across multiple source addresses using automated SSH infrastructure.
MALWARE / SSHPIMINE Activity
Observed activity associated with automated Linux targeting and cryptocurrency-mining behavior.
MALWAREPANCHAN Investigation
Analysis of suspicious Linux activity and artifacts investigated for possible PANCHAN-related behavior.
MALWARE ANALYSISRecurring PANCHAN Activity
Follow-up analysis documenting recurring activity and behavioral similarities observed after the initial investigation.
CAMPAIGN TRACKINGSSH Tunneling
Sessions attempting to use the honeypot as an SSH forwarding point to reach external services.
SSH ABUSEAutomated Reconnaissance
Automated post-authentication commands used to fingerprint the operating system, hardware, and host environment.
RECONNAISSANCECredential Scanning
Analysis of automated username and password attempts recorded against the public SSH honeypot.
CREDENTIALS