logo

Interesting Message Stored in Cowrie Logs, (Wed, Mar 18th)

ID: 699d9aa2-0b08-5c4e-9761-cd04c8fff90c

STIX ID: report--699d9aa2-0b08-5c4e-9761-cd04c8fff90c

Feed Name: SANS ISC Diary

Threat Score
50/100

Date Published: 2026-03-19

Date Updated: 2026-04-19

...
...

A DShield sensor owner observed a bot performing Telnet login(s) and uploading a shell script (SHA-256 provided) on 19 Feb 2026 that attempts to exploit IoT and 64-bit Linux devices. The report includes two source IP addresses (64.89.161.198, 188.214.30.5), a download URL (http://188.214.30.5/r.sh), cowrie/webhoneypot logs, and links to VirusTotal and additional context—indicating an active, limited-scale scanning/exploitation campaign targeting exposed devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.