Interesting Message Stored in Cowrie Logs, (Wed, Mar 18th)
2026-03-19T01:23:47Z•d4c71bd430c2ea55d0f0a6e14879aa7069f73743910a1e2c47fa1e6a749f285a
RATadminercowriecredential-theftdshieldhoneypotipv4-mapped-ipv6malware-distributionphishingphpmyadminportscanproxy-scanreconnaissanceremcostelnetweb-honeypot
What happened
SANS ISC diary entries (Mar 13–19, 2026) describe multiple opportunistic reconnaissance and intrusion activities observed in honeypots. Cowrie/DShield sensors logged portscans, a successful Telnet login and web access from IP 64.89.161.198 (activity observed 30 Jan–22 Feb), including an echoed marker string "MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here" (likely actor/bot fingerprint). Other reports document broad scanning for adminer/phpmyadmin, /proxy/ URL abuse (including use of IPv4-mapped IPv6 notation to obfuscate source addresses), a SmartApeSG campaign using ClickFix pages
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- d4c71bd430c2ea55d0f0a6e14879aa7069f73743910a1e2c47fa1e6a749f285a
- Enrichment time
- 2026-03-19T01:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.