More Honeypot Fingerprinting Scans, (Wed, Apr 8th)
ID: a7d96872-e197-5ca8-b3ac-ecde01a983ea
STIX ID: report--a7d96872-e197-5ca8-b3ac-ecde01a983ea
Feed Name: SANS ISC Diary
The author describes how attackers can detect medium-interaction honeypots (Cowrie) by observing simulated package installs, SSH artifacts, and by attempting unlikely username/password combinations; the post provides an example IP (45.135.194.48) and a table of credentials the attacker tried, and concludes that the operator is unlikely to hide honeypots since they focus on broad internet-wide scans rather than targeted attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
