SSH Tunneling and Proxy Abuse
While monitoring my Cowrie honeypot, I observed several attackers attempting to use SSH port forwarding after successfully authenticating.
Instead of executing commands on the system, these sessions used SSH direct-tcpip requests to attempt connections to external destinations.
Observed Activity
Between September 19 and September 27, the honeypot recorded 9 direct TCP forwarding requests across 5 SSH sessions.
The activity came from four source IP addresses:
185.220.101.4814.255.187.76192.42.116.115192.42.116.101
The requested destinations included:
google.com:443159.65.2.87:80172.67.133.8:443104.21.5.61:443
Cowrie recorded the forwarding attempts but discarded the forwarded traffic.
Repeated google.com Forwarding Pattern
One pattern appeared multiple times from different source IP addresses.
On September 19, a connection from 185.220.101.48 authenticated as:
root/admin
The SSH client identified itself as:
SSH-2.0-OpenSSH_10.5
with the HASSH fingerprint:
d00d43d15d59705b090cf74488cc2218
Before attempting the password login, the client also attempted authentication using an RSA public key.
The public key fingerprint was:
d4:98:c4:f3:12:ef:3e:29:38:34:62:21:fd:99:ec:ef
After successfully authenticating, the session requested an SSH direct TCP connection to:
google.com:443
The same behavior appeared again on September 20 from 192.42.116.115.
The second session used the same:
- OpenSSH client version
- HASSH fingerprint
- RSA public-key fingerprint
root/admincredentialsgoogle.com:443forwarding destination
Another google.com:443 forwarding attempt was observed from 192.42.116.101 on September 27.
The repeated fingerprints and behavior across different source addresses strongly suggest the sessions were generated by the same or closely related automated tooling.
Separate Forwarding Activity
A different pattern was observed on September 20 from:
14.255.187.76
This source created multiple SSH sessions and attempted forwarding to:
```text 159.65.2.87:80 172.67.133.8:443 104.21.5.61:443