logo

Honeypots: Tracking Attacks Against Misconfigured or Exposed Services

ID: ee490878-9b31-5e58-9e05-0d288c8034e5

STIX ID: report--ee490878-9b31-5e58-9e05-0d288c8034e5

Feed Name: ReliaQuest Blog

Threat Score
70/100

Date Published: 2019-10-17

Date Updated: 2026-04-29

...
...

This honeypot analysis summarizes telemetry collected from internet-facing rsync, FTP, SMB, and RDP honeypots over August–September 2019, showing high-volume automated scanning and exploitation attempts—most notably 1,287,747 DoublePulsar backdoor C2 communication attempts and thousands of SMB/RDP alerts. The report lists frequently targeted CVEs (including CVE-2017-0143 EternalBlue and CVE-2019-0708 BlueKeep), top source IPs, MD5 hashes of files uploaded to the SMB honeypot, and recommends patching, reducing exposed services, and improved asset visibility to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.