Advanced: fingerprinting & relay abuse tap to expand
🔐 Client Fingerprints
i
Every SSH connection announces a client "fingerprint" (its software version and cryptography preferences). When the exact same fingerprint shows up from different IP addresses, it's a strong sign they're all running the same tool or botnet — even if the IPs look unrelated.
📡 Proxy / Relay Abuse Attempts
i
Some attackers who get a fake login immediately try to use this server as a relay to reach somewhere else — usually to check what IP address their traffic would appear to come from, sometimes to test if it could be used to send spam. Cowrie logs the attempt and safely discards it; nothing is ever actually relayed.
Geographic Distribution
✉ SMTP Honeypot (Mailoney)
i
Mailoney answers on the SMTP ports, both directly and via anything relayed through Cowrie's own SSH tunnel abuse. It always fakes acceptance and never actually delivers mail — this tab covers only SMTP activity, separate from the SSH data on the other tabs.
SMTP hits per hour (last 24h)
Top SMTP Source IPs
SMTP Outcome Breakdown
🔑 Relay / Auth Credentials Tried
Claimed Senders & Recipients
Recent SMTP Hits
Indicators of Compromise
i
A structured feed derived from everything Cowrie and Mailoney have observed — attacker IPs, captured malware hashes, relay/tunnel targets, shared client fingerprints, and credentials tried. Export buttons produce CSV/JSON for feeding into a SIEM, firewall block-list, or other tooling.
Tracked Campaigns
i
Named, persistent threat actors/operations tracked by shared SSH client fingerprint (or explicit IPs when no reliable fingerprint cluster exists). Membership and session counts recompute live from current data every time this loads - only the identity and analysis are hand-maintained.
Analyst-Curated IOCs
i
Findings from manual static analysis (malware reverse-engineering, C2 infrastructure pulled from disassembly) that automated log capture has no way to derive on its own - hand-maintained, separate from everything else on this page.