logo

More Honeypot Fingerprinting Scans, (Wed, Apr 8th)

ID: a7d96872-e197-5ca8-b3ac-ecde01a983ea

STIX ID: report--a7d96872-e197-5ca8-b3ac-ecde01a983ea

Feed Name: SANS ISC Diary

Date Published: 2026-04-08

Date Updated: 2026-04-19

...
...

The author describes how attackers can detect medium-interaction honeypots (Cowrie) by observing simulated package installs, SSH artifacts, and by attempting unlikely username/password combinations; the post provides an example IP (45.135.194.48) and a table of credentials the attacker tried, and concludes that the operator is unlikely to hide honeypots since they focus on broad internet-wide scans rather than targeted attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.