>_
AWS Cowrie Honeypot
Internet-facing SSH threat telemetry and analysis
← All Investigations

SSH Tunneling and Proxy Abuse

While monitoring my Cowrie honeypot, I observed several attackers attempting to use SSH port forwarding after successfully authenticating.

Instead of executing commands on the system, these sessions used SSH direct-tcpip requests to attempt connections to external destinations.

Observed Activity

Between September 19 and September 27, the honeypot recorded 9 direct TCP forwarding requests across 5 SSH sessions.

The activity came from four source IP addresses:

The requested destinations included:

Cowrie recorded the forwarding attempts but discarded the forwarded traffic.

Repeated google.com Forwarding Pattern

One pattern appeared multiple times from different source IP addresses.

On September 19, a connection from 185.220.101.48 authenticated as:

root/admin

The SSH client identified itself as:

SSH-2.0-OpenSSH_10.5

with the HASSH fingerprint:

d00d43d15d59705b090cf74488cc2218

Before attempting the password login, the client also attempted authentication using an RSA public key.

The public key fingerprint was:

d4:98:c4:f3:12:ef:3e:29:38:34:62:21:fd:99:ec:ef

After successfully authenticating, the session requested an SSH direct TCP connection to:

google.com:443

The same behavior appeared again on September 20 from 192.42.116.115.

The second session used the same:

Another google.com:443 forwarding attempt was observed from 192.42.116.101 on September 27.

The repeated fingerprints and behavior across different source addresses strongly suggest the sessions were generated by the same or closely related automated tooling.

Separate Forwarding Activity

A different pattern was observed on September 20 from:

14.255.187.76

This source created multiple SSH sessions and attempted forwarding to:

```text 159.65.2.87:80 172.67.133.8:443 104.21.5.61:443