Interesting Message Stored in Cowrie Logs, (Wed, Mar 18th)
ID: 699d9aa2-0b08-5c4e-9761-cd04c8fff90c
STIX ID: report--699d9aa2-0b08-5c4e-9761-cd04c8fff90c
Feed Name: SANS ISC Diary
Threat Score
A DShield sensor owner observed a bot performing Telnet login(s) and uploading a shell script (SHA-256 provided) on 19 Feb 2026 that attempts to exploit IoT and 64-bit Linux devices. The report includes two source IP addresses (64.89.161.198, 188.214.30.5), a download URL (http://188.214.30.5/r.sh), cowrie/webhoneypot logs, and links to VirusTotal and additional context—indicating an active, limited-scale scanning/exploitation campaign targeting exposed devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
