What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)
This SANS Internet Storm Center guest diary details an analysis of automated cybercrime activity observed through a honeypot, focusing on the Terrabot IoT botnet. The author, a BACS student, highlights the prevalence of low-level scanning and exploitation attempts by automated scripts, primarily targeting vulnerable IoT devices like D-Link routers and MVPower DVRs. The analysis reveals Terrabot's operational patterns, including its reliance on outdated vulnerabilities and its tendency to ‘shoot blanks’ due to flawed automation, illustrating the challenges of detecting and mitigating automated attacks.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
