# T-Pot Honeypot Weekly Threat Intelligence Summary: 2026-09-28 to 2026-10-05

**Reporting Window:** 2026-09-28 to 2026-10-05  
**Deployment:** T-Pot Distributed Sensor Network  
**Target Focus:** RDP (3389), SSH/Telnet (22/23), Ingress Malware Droppers  
**Generated At:** 2026-10-05 00:00:02 UTC  

---

## 1. Weekly Executive Summary

Over the 7-day monitoring window from **2026-09-28 to 2026-10-05**, the sensor array recorded substantial automated reconnaissance and intrusion traffic.

* **RDP Attack Volume**: Over **207,715** connection attempts detected across **323** unique source IPs.
* **SSH & Telnet Probes**: **161,450** events processed across **1,008** distinct attacking hosts.
* **Captured Payloads**: **419** automated ingress tool transfer(s) captured by honeypot emulators.

---

## 2. Top Remote Desktop (RDP) Threat Actors

Automated scanners continue aggressive password spraying against exposed RDP endpoints. The top attacking hosts identified during this period:

| Source IP | Country | Autonomous System (ASN) | Attempt Count | Target Profile |
| :--- | :--- | :--- | :--- | :--- |
| `5.189.128.62` | FR | AS51167 Contabo GmbH | **59,512** | Automated RDP NLA Spray |
| `217.138.216.214` | DE | AS9009 M247 Europe SRL | **48,173** | Automated RDP NLA Spray |
| `94.26.88.34` | PL | AS201814 MEVSPACE sp. z o.o. | **16,932** | Automated RDP NLA Spray |
| `183.82.117.119` | IN | AS18209 Atria Convergence Technologies Ltd., | **10,364** | Automated RDP NLA Spray |
| `85.239.151.18` | US | AS19318 Interserver, Inc | **8,521** | Automated RDP NLA Spray |

### Targeted RDP Accounts
The most frequently targeted account names across incoming RDP sessions:
* **`Administrator`**: 27,773 attempts
* **`administrator`**: 4,568 attempts
* **`Admin`**: 2,749 attempts
* **`admin`**: 2,461 attempts
* **`vpn`**: 28 attempts
* **`system`**: 28 attempts

---

## 3. SSH & Telnet Exploitation Telemetry

### Top Attacking IPs
| Source IP | Country | Autonomous System (ASN) | Attempt Count |
| :--- | :--- | :--- | :--- |
| `160.119.66.206` | NL | AS49870 Alsycon B.V. | **8,954** |
| `109.160.32.154` | NL | AS198364 BANATSYNC SRL | **8,013** |
| `109.160.32.139` | DE | AS198364 BANATSYNC SRL | **5,509** |
| `109.160.32.168` | DE | AS198364 BANATSYNC SRL | **5,506** |
| `77.239.124.156` | NL | AS198364 BANATSYNC SRL | **5,506** |

### Targeted SSH/Telnet Credentials
Common authentication pairs observed:
* **`root`**: 8,177 login attempts
* **`admin`**: 1,227 login attempts
* **`system`**: 1,080 login attempts
* **`enable`**: 1,066 login attempts
* **`ubuntu`**: 705 login attempts
* **`user`**: 530 login attempts

---

## 4. Captured Ingress Malware & Payloads

The honeypot captured 419 malicious staging script(s) dropped via shell access during this window:

* **SHA-256**: `a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2`
  * **Source IP**: `130.49.213.197`
  * **Download URL**: `None`
  * **Timestamp**: `2026-09-28T00:11:12.331389+00:00`

* **SHA-256**: `01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b`
  * **Source IP**: `130.49.213.197`
  * **Download URL**: `None`
  * **Timestamp**: `2026-09-28T00:11:20.729187+00:00`

* **SHA-256**: `a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2`
  * **Source IP**: `130.49.213.197`
  * **Download URL**: `None`
  * **Timestamp**: `2026-09-28T00:46:04.773811+00:00`


---

## 5. Defensive Mitigations & IoCs

1. **Firewall Blocking**: Block all incoming traffic from the top offending autonomous systems and subnets identified above.
2. **Eliminate Public RDP Exposure**: Place RDP access strictly behind an authenticated VPN or Cloudflare Zero Trust / WireGuard gateway.
3. **Disable Telnet & Default Accounts**: Ensure port 23 is closed at perimeter firewalls and disable default accounts (`root`, `admin`, `guest`).
