Interesting Message Stored in Cowrie Logs, (Wed, Mar 18th)

2026-03-19T01:23:47Zd4c71bd430c2ea55d0f0a6e14879aa7069f73743910a1e2c47fa1e6a749f285a
RATadminercowriecredential-theftdshieldhoneypotipv4-mapped-ipv6malware-distributionphishingphpmyadminportscanproxy-scanreconnaissanceremcostelnetweb-honeypot

What happened

SANS ISC diary entries (Mar 13–19, 2026) describe multiple opportunistic reconnaissance and intrusion activities observed in honeypots. Cowrie/DShield sensors logged portscans, a successful Telnet login and web access from IP 64.89.161.198 (activity observed 30 Jan–22 Feb), including an echoed marker string "MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here" (likely actor/bot fingerprint). Other reports document broad scanning for adminer/phpmyadmin, /proxy/ URL abuse (including use of IPv4-mapped IPv6 notation to obfuscate source addresses), a SmartApeSG campaign using ClickFix pages

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
d4c71bd430c2ea55d0f0a6e14879aa7069f73743910a1e2c47fa1e6a749f285a
Enrichment time
2026-03-19T01:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.