Honeypots: Tracking Attacks Against Misconfigured or Exposed Services
ID: ee490878-9b31-5e58-9e05-0d288c8034e5
STIX ID: report--ee490878-9b31-5e58-9e05-0d288c8034e5
Feed Name: ReliaQuest Blog
This honeypot analysis summarizes telemetry collected from internet-facing rsync, FTP, SMB, and RDP honeypots over August–September 2019, showing high-volume automated scanning and exploitation attempts—most notably 1,287,747 DoublePulsar backdoor C2 communication attempts and thousands of SMB/RDP alerts. The report lists frequently targeted CVEs (including CVE-2017-0143 EternalBlue and CVE-2019-0708 BlueKeep), top source IPs, MD5 hashes of files uploaded to the SMB honeypot, and recommends patching, reducing exposed services, and improved asset visibility to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
