{"id":30311,"date":"2019-10-31T21:34:49","date_gmt":"2019-10-31T18:34:49","guid":{"rendered":"https:\/\/prohoster.info\/blog\/analiz-atak-na-hanipot-cowrie\/"},"modified":"2019-10-31T21:34:49","modified_gmt":"2019-10-31T18:34:49","slug":"analiz-atak-na-hanipot-cowrie","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/analiz-atak-na-hanipot-cowrie","title":{"rendered":"Analysis of attacks on the Cowrie honeypot","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><b>Statistics for 24 hours after the honeypot was installed on a Digital Ocean node in Singapore<\/b> <\/p>\n<h1>Pew pew! Let\u2019s start right away with the attack map<\/h1>\n<p>\nOur super cool map shows unique ASNs that connected to our Cowrie honeypot in the last 24 hours. Yellow corresponds to SSH connections, while red indicates Telnet. Such animations often impress the company's board of directors, allowing for more funding for security and resources. However, the map has some value, clearly demonstrating the geographical and organizational distribution of attack sources on our host over just 24 hours. The animation does not reflect the volume of traffic from each source.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h3>What is the Pew Pew map?<\/h3>\n<p>\n<i>Pew Pew Map<\/i> \u2014 this is <noindex><a rel=\"nofollow\" href=\"https:\/\/krebsonsecurity.com\/2015\/01\/whos-attacking-whom-realtime-attack-trackers\/\">visualization of cyber attacks<\/a><\/noindex>, typically animated and very beautiful. It\u2019s a trendy way to sell your product, famously used by Norse Corp. The company ended poorly: it turned out that the pretty animations were their only merit, and they used fragmentary data for analysis.<\/p>\n<h3>Made with Leafletjs<\/h3>\n<p>\nFor those who want to develop an attack map for a large screen in the operations center (your boss will love it), there is a library <noindex><a rel=\"nofollow\" href=\"https:\/\/leafletjs.com\/\">leafletjs<\/a><\/noindex>. We combine it with the <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/lit-forest\/leaflet.migrationLayer\">leaflet migration layer<\/a><\/noindex>, Maxmind GeoIP service \u2014 <noindex><a rel=\"nofollow\" href=\"https:\/\/hackertarget.com\/pewpew\/map.html\">and it's ready<\/a><\/noindex>.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/hackertarget.com\/pewpew\/map.html\"><img decoding=\"async\" alt=\"Analysis of attacks on the Cowrie honeypot\" src=\"\/wp-content\/uploads\/2019\/03\/c4765ba5f2c89e502e5d8791dcfcfc62.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<h1>WTF: what is the Cowrie honeypot?<\/h1>\n<p>\nA honeypot is a system that is placed on the network specifically to attract attackers. Connections to the system are usually illegal and allow the detection of the attacker through detailed logs. The logs not only store regular connection information but also session information that reveals <b>the attacker\u2019s tactics, techniques, and procedures (TTP)<\/b> .<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/micheloosterhof\/cowrie\">The Cowrie honeypot<\/a><\/noindex> is designed for <b>recording SSH and Telnet connections<\/b>. Such honeypots are often exposed to the internet to track the tools, scripts, and hosts of attackers.<\/p>\n<blockquote><p>My message for companies that think they aren't being attacked: 'You are not looking hard enough.'<br \/>\n<i>\u2014 James Snook<\/i><\/p><\/blockquote>\n<p>\n<img decoding=\"async\" alt=\"Analysis of attacks on the Cowrie honeypot\" src=\"\/wp-content\/uploads\/2019\/03\/40feddaacc42add563f98a0f64c1c3b0.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h1>What\u2019s in the logs?<\/h1>\n<p><\/p>\n<h3>Total number of connections<\/h3>\n<p>\nConnections from numerous hosts made repeated connection attempts. This is normal since attacking scripts contain a list of credentials and try several combinations. The Cowrie honeypot is configured to accept certain combinations of username and password. This is set in <b>the user.db file<\/b>.<\/p>\n<p><img decoding=\"async\" alt=\"Analysis of attacks on the Cowrie honeypot\" src=\"\/wp-content\/uploads\/2019\/03\/d7da6ec208e821453607fb6c29c7e347.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>Geography of attacks<\/h3>\n<p>\nAccording to Maxmind's geolocation data, I calculated the number of connections from each country. Brazil and China lead by a large margin, frequently generating significant noise from scanners.<\/p>\n<p><img decoding=\"async\" alt=\"Analysis of attacks on the Cowrie honeypot\" src=\"\/wp-content\/uploads\/2019\/03\/0dd7a52da1c12db2f317f2195e92bccf.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>Network Block Owner<\/h3>\n<p>\nStudying the owners of network blocks (ASN) can reveal organizations with a high number of attacking hosts. Of course, in such cases, it is always essential to remember that many attacks originate from compromised hosts. It is reasonable to assume that most attackers are not foolish enough to scan the network from a home computer.<\/p>\n<p><img decoding=\"async\" alt=\"Analysis of attacks on the Cowrie honeypot\" src=\"\/wp-content\/uploads\/2019\/03\/0f60be7772ea993e2c0a5d0ab6c08cd8.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>Open Ports on Attacking Systems (data from Shodan.io)<\/h3>\n<p>\nRunning an IP list through the excellent <noindex><a rel=\"nofollow\" href=\"https:\/\/developer.shodan.io\/\">Shodan API<\/a><\/noindex> quickly identifies <b>systems with open ports<\/b> and what those ports are. The figure below shows the concentration of open ports by country and organization. It could reveal blocks of compromised systems, but within the <b>small sample<\/b> nothing remarkable is visible except for a large number of <b>open ports 500 in China.<\/b>.<\/p>\n<p>An interesting finding is the significant number of systems in Brazil that have <b>ports 22, 23 closed.<\/b> or <b>Other ports<\/b>, according to Censys and Shodan. Apparently, these are connections from end-user computers.<\/p>\n<p><img decoding=\"async\" alt=\"Analysis of attacks on the Cowrie honeypot\" src=\"\/wp-content\/uploads\/2019\/03\/6138379c7d069807f01b57a8d97784fb.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n <\/p>\n<h3>Bots? Not necessarily.<\/h3>\n<p>\nData <noindex><a rel=\"nofollow\" href=\"https:\/\/censys.io\/\">Censys<\/a><\/noindex> For ports 22 and 23 that day showed strange behavior. I assumed that most scans and password attacks come from bots. The script spreads through open ports, guessing passwords, and from a new system copies itself and continues spreading using the same method.<\/p>\n<p>However, here we see that only a small number of hosts scanning telnet have port 23 exposed. This indicates that the systems are either compromised in another way or the attackers are executing scripts manually.<\/p>\n<p><img decoding=\"async\" alt=\"Analysis of attacks on the Cowrie honeypot\" src=\"\/wp-content\/uploads\/2019\/03\/4c3ccbc609a46365473f582315ca90bd.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>Home Connections<\/h3>\n<p>\nAnother interesting finding was the significant number of home users in the sample. Using <b>reverse lookup, <\/b> I identified 105 connections from specific home computers. For many home connections, the DNS reverse lookup displays host names with words like dsl, home, cable, fiber, and so on.<\/p>\n<p><img decoding=\"async\" alt=\"Analysis of attacks on the Cowrie honeypot\" src=\"\/wp-content\/uploads\/2019\/03\/a665a90dfdbbfb5e9971fb2885ccd669.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h1>Learn and Explore: Set Up Your Own Honeypot<\/h1>\n<p>\nRecently, I wrote a brief manual on how to <noindex><a rel=\"nofollow\" href=\"https:\/\/hackertarget.com\/cowrie-honeypot-ubuntu\/\">install the Cowrie honeypot on your system.<\/a><\/noindex>As mentioned, in our case we used a Digital Ocean VPS located in Singapore. The analysis over 24 hours cost literally a few cents, and the system setup took 30 minutes.<\/p>\n<p>Instead of running Cowrie on the internet and catching all the noise, you can benefit from a honeypot in a local network. Just set up notifications if requests come to certain ports. This could be either an attacker within the network, a curious employee, or a vulnerability scan.<\/p>\n<h1>Conclusions<\/h1>\n<p>\nAfter observing the actions of attackers over a day, it becomes clear that it is impossible to pinpoint a clear source of attacks to a specific organization, country, or even operating system.<\/p>\n<p>The wide distribution of sources shows that the scanning noise is constant and not associated with a specific source. Anyone working on the internet must ensure that their system <b>has several layers of security.<\/b>A common and effective solution for <b>SSH<\/b> is to move the service to a random high port. This does not eliminate the need for strict password protection and monitoring, but it at least ensures that logs are not constantly filled with scanning activity. Connections to a high port are more likely to be targeted attacks that may interest you.<\/p>\n<p>Often, open telnet ports are found on routers or other devices, making them hard to easily move to a high port. <noindex><a rel=\"nofollow\" href=\"https:\/\/hackertarget.com\/nmap-online-port-scanner\/\">Information about all open ports<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/hackertarget.com\/domain-profiler\/\">attack surface<\/a><\/noindex> is the only way to ensure these services are protected by a firewall or disabled. Whenever possible, avoid using Telnet altogether, as this protocol is not encrypted. If it is absolutely necessary, monitor it closely and use strong passwords.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/436076\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u0442\u0430\u0442\u0438\u0441\u0442\u0438\u043a\u0430 \u0437\u0430 24 \u0447\u0430\u0441\u0430 \u043f\u043e\u0441\u043b\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0445\u0430\u043d\u0438\u043f\u043e\u0442\u0430 \u043d\u0430 \u0443\u0437\u043b\u0435 Digital Ocean \u0432 \u0421\u0438\u043d\u0433\u0430\u043f\u0443\u0440\u0435 \u041f\u0438\u0443-\u043f\u0438\u0443! \u041d\u0430\u0447\u043d\u0451\u043c \u0441\u0440\u0430\u0437\u0443 \u0441 \u043a\u0430\u0440\u0442\u044b \u0430\u0442\u0430\u043a \u041d\u0430\u0448\u0430 \u0441\u0443\u043f\u0435\u0440\u043a\u043b\u0430\u0441\u0441\u043d\u0430\u044f \u043a\u0430\u0440\u0442\u0430 \u043f\u043e\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442 \u0443\u043d\u0438\u043a\u0430\u043b\u044c\u043d\u044b\u0435 ASN, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0430\u043b\u0438\u0441\u044c \u043a \u043d\u0430\u0448\u0435\u043c\u0443 \u0445\u0430\u043d\u0438\u043f\u043e\u0442\u0443 Cowrie \u0437\u0430 24 \u0447\u0430\u0441\u0430. \u0416\u0451\u043b\u0442\u044b\u0439 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u0435\u0442 SSH-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f\u043c, \u0430 \u043a\u0440\u0430\u0441\u043d\u044b\u0439\u00a0\u2014 Telnet. \u0422\u0430\u043a\u0438\u0435 \u0430\u043d\u0438\u043c\u0430\u0446\u0438\u0438 \u0447\u0430\u0441\u0442\u043e \u0432\u043f\u0435\u0447\u0430\u0442\u043b\u044f\u044e\u0442 \u0441\u043e\u0432\u0435\u0442 \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u043e\u0432 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438, \u0447\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0432\u044b\u0431\u0438\u0442\u044c \u0431\u043e\u043b\u044c\u0448\u0435 \u0444\u0438\u043d\u0430\u043d\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043d\u0430 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c \u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-30311","post","type-post","status-publish","format-standard","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u0442\u0430\u0442\u0438\u0441\u0442\u0438\u043a\u0430 \u0437\u0430 24 \u0447\u0430\u0441\u0430 \u043f\u043e\u0441\u043b\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0445\u0430\u043d\u0438\u043f\u043e\u0442\u0430 \u043d\u0430 \u0443\u0437\u043b\u0435 Digital Ocean \u0432 \u0421\u0438\u043d\u0433\u0430\u043f\u0443\u0440\u0435 \u041f\u0438\u0443-\u043f\u0438\u0443!\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/analiz-atak-na-hanipot-cowrie\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u043d\u0430\u043b\u0438\u0437 \u0430\u0442\u0430\u043a \u043d\u0430 \u0445\u0430\u043d\u0438\u043f\u043e\u0442 Cowrie | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u0442\u0430\u0442\u0438\u0441\u0442\u0438\u043a\u0430 \u0437\u0430 24 \u0447\u0430\u0441\u0430 \u043f\u043e\u0441\u043b\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0445\u0430\u043d\u0438\u043f\u043e\u0442\u0430 \u043d\u0430 \u0443\u0437\u043b\u0435 Digital Ocean \u0432 \u0421\u0438\u043d\u0433\u0430\u043f\u0443\u0440\u0435 \u041f\u0438\u0443-\u043f\u0438\u0443!\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/analiz-atak-na-hanipot-cowrie\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:34:49+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:34:49+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Analysis of attacks on the Cowrie honeypot | ProHoster","description":"Statistics from 24 hours after installing the honeypot on a Digital Ocean node in Singapore Piu-piu!","canonical_url":"https:\/\/prohoster.info\/en\/blog\/analiz-atak-na-hanipot-cowrie","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u043d\u0430\u043b\u0438\u0437 \u0430\u0442\u0430\u043a \u043d\u0430 \u0445\u0430\u043d\u0438\u043f\u043e\u0442 Cowrie | ProHoster","og:description":"\u0421\u0442\u0430\u0442\u0438\u0441\u0442\u0438\u043a\u0430 \u0437\u0430 24 \u0447\u0430\u0441\u0430 \u043f\u043e\u0441\u043b\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0445\u0430\u043d\u0438\u043f\u043e\u0442\u0430 \u043d\u0430 \u0443\u0437\u043b\u0435 Digital Ocean \u0432 \u0421\u0438\u043d\u0433\u0430\u043f\u0443\u0440\u0435 \u041f\u0438\u0443-\u043f\u0438\u0443!","og:url":"https:\/\/prohoster.info\/en\/blog\/analiz-atak-na-hanipot-cowrie","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:34:49+00:00","article:modified_time":"2019-10-31T18:34:49+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"30311","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 00:36:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:37:27","updated":"2026-01-21 00:36:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/30311","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=30311"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/30311\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=30311"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=30311"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=30311"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}