The Behavior of Coordinated SSH Brute Force Attacks over the last three months [Guest Diary], (Wed, Jun 17th)
ID: 3fc16edb-8ee8-56c6-81f9-039daa567b3d
STIX ID: report--3fc16edb-8ee8-56c6-81f9-039daa567b3d
Feed Name: SANS ISC Diary
This guest-diary style report analyzes nearly 100 days of Cowrie/DShield honeypot logs that recorded over 20 million SSH brute-force attempts, highlighting coordinated botnet behavior (shared HASSH fingerprint, synchronized scans, and quota-assigned rates), correlating activity spikes with geopolitical events and public vulnerability disclosures, listing top probing IPs and ASNs, and providing practical mitigation and detection guidance such as disabling root login, enforcing MFA, using SSH keys, and centralized SIEM monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
