# T-Pot Honeypot Weekly Threat Intelligence Summary: 2026-09-21 to 2026-09-28

**Reporting Window:** 2026-09-21 to 2026-09-28  
**Deployment:** T-Pot Distributed Sensor Network  
**Target Focus:** RDP (3389), SSH/Telnet (22/23), Ingress Malware Droppers  
**Generated At:** 2026-09-28 00:00:02 UTC  

---

## 1. Weekly Executive Summary

Over the 7-day monitoring window from **2026-09-21 to 2026-09-28**, the sensor array recorded substantial automated reconnaissance and intrusion traffic.

* **RDP Attack Volume**: Over **137,815** connection attempts detected across **309** unique source IPs.
* **SSH & Telnet Probes**: **151,717** events processed across **1,023** distinct attacking hosts.
* **Captured Payloads**: **359** automated ingress tool transfer(s) captured by honeypot emulators.

---

## 2. Top Remote Desktop (RDP) Threat Actors

Automated scanners continue aggressive password spraying against exposed RDP endpoints. The top attacking hosts identified during this period:

| Source IP | Country | Autonomous System (ASN) | Attempt Count | Target Profile |
| :--- | :--- | :--- | :--- | :--- |
| `149.50.115.15` | PL | AS201814 MEVSPACE sp. z o.o. | **25,656** | Automated RDP NLA Spray |
| `79.124.8.107` | NL | AS213438 ColocaTel Inc. | **23,185** | Automated RDP NLA Spray |
| `185.136.15.36` | NL | AS210328 AO ALMAZ | **21,461** | Automated RDP NLA Spray |
| `5.189.128.62` | FR | AS51167 Contabo GmbH | **15,423** | Automated RDP NLA Spray |
| `213.136.71.23` | FR | AS51167 Contabo GmbH | **11,165** | Automated RDP NLA Spray |

### Targeted RDP Accounts
The most frequently targeted account names across incoming RDP sessions:
* **`Administrator`**: 17,506 attempts
* **`administrator`**: 6,995 attempts
* **`buh`**: 159 attempts
* **`бух`**: 155 attempts
* **`администратор`**: 153 attempts
* **`DefaultAccount`**: 19 attempts

---

## 3. SSH & Telnet Exploitation Telemetry

### Top Attacking IPs
| Source IP | Country | Autonomous System (ASN) | Attempt Count |
| :--- | :--- | :--- | :--- |
| `109.160.32.73` | NL | AS197170 TechTies Inc. | **11,009** |
| `109.160.32.97` | NL | AS197170 TechTies Inc. | **5,506** |
| `109.160.32.108` | NL | AS197170 TechTies Inc. | **5,506** |
| `109.160.32.84` | NL | AS197170 TechTies Inc. | **5,506** |
| `109.160.32.68` | NL | AS197170 TechTies Inc. | **5,506** |

### Targeted SSH/Telnet Credentials
Common authentication pairs observed:
* **`root`**: 9,253 login attempts
* **`admin`**: 1,523 login attempts
* **`ubuntu`**: 879 login attempts
* **`user`**: 624 login attempts
* **`deploy`**: 433 login attempts
* **`test`**: 352 login attempts

---

## 4. Captured Ingress Malware & Payloads

The honeypot captured 359 malicious staging script(s) dropped via shell access during this window:

* **SHA-256**: `39be6853a8204ce6455a373a6ffb4cb4672d4a62d90be69f7d6eeb66cda10b96`
  * **Source IP**: `160.119.66.206`
  * **Download URL**: `http://160.119.66.206/bins/kla.sh`
  * **Timestamp**: `2026-09-21T00:00:59.671009+00:00`

* **SHA-256**: `39be6853a8204ce6455a373a6ffb4cb4672d4a62d90be69f7d6eeb66cda10b96`
  * **Source IP**: `160.119.66.206`
  * **Download URL**: `http://160.119.66.206/bins/kla.sh`
  * **Timestamp**: `2026-09-21T00:01:00.157122+00:00`

* **SHA-256**: `39be6853a8204ce6455a373a6ffb4cb4672d4a62d90be69f7d6eeb66cda10b96`
  * **Source IP**: `160.119.66.206`
  * **Download URL**: `http://160.119.66.206/bins/kla.sh`
  * **Timestamp**: `2026-09-21T00:01:00.359991+00:00`


---

## 5. Defensive Mitigations & IoCs

1. **Firewall Blocking**: Block all incoming traffic from the top offending autonomous systems and subnets identified above.
2. **Eliminate Public RDP Exposure**: Place RDP access strictly behind an authenticated VPN or Cloudflare Zero Trust / WireGuard gateway.
3. **Disable Telnet & Default Accounts**: Ensure port 23 is closed at perimeter firewalls and disable default accounts (`root`, `admin`, `guest`).
