logo

Nation-State Attack or Compromised Government? [Guest Diary], (Thu, Dec 4th)

ID: c58727e3-0018-5fc1-9c64-84103b764cd3

STIX ID: report--c58727e3-0018-5fc1-9c64-84103b764cd3

Feed Name: SANS ISC Diary

Threat Score
50/100

Date Published: 2025-12-04

Date Updated: 2026-04-19

...
...

On 2025-11-10 a honeypot observed IP 103.148.195.161 successfully brute-force SSH (root:linux) and upload an ELF trojan named "sshd" (SHA256: 7a9da7d10aa80b0f9e2e3f9e518030c86026a636e0b6de35905e15dd4c8e3e2d) that was detected as malicious by VirusTotal and Hybrid-Analysis; the report provides MITRE ATT&CK mappings, IOCs, screenshots of cowrie output, and mitigation recommendations (disable password auth, IP allowlisting, EDR/IDS, threat hunting, MFA).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.