TTY Logs and the Data it Captures, (Sun, Oct 4th)
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of each day to the DShield SIEM [2] to be correlated with all the data.
The following ES|QL query provides a summary of all contab commands matching a TTYLog hash performed by different actors while logged in the sensor over a 90 day period.
TTYLogs Correlation
FROM cowrie*
| WHERE transaction.id == "f904275333aeac48d7df6cf53fe5fb9212c7d132a7d37253d2ab9321ba2690d8"
| WHERE event.hash IS NOT NULL
| KEEP transaction.id, event.hash
| STATS Total=COUNT(event.hash) BY event.hash, transaction.id
| SORT Total DESC
This transaction ID captured 5 similar crontab commands that are translated from its hash equivalent into this list executed by more than 3130 different actors (IPs):
TTYLogs Sources
transaction.id: f904275333aeac48d7df6cf53fe5fb9212c7d132a7d37253d2ab9321ba2690d8 over a 90 day period
Other example of Event Hash decoded and sent to DShield SIEM for analysis
Top 10 Indicators
IP ASN
102.88.137.80 29465
42.96.20.16 131423
182.253.221.210 38482
46.188.119.26 8334
159.223.97.218 14061
185.158.22.150 210022
193.233.48.169 207713
209.99.190.200 402253
45.64.74.51 55933
202.152.148.27 23951
[1] https://github.com/bruneaug/DShield-Sensor/blob/main/sensor_scripts/daily_tty.sh
[2] https://github.com/bruneaug/DShield-SIEM
[3] https://www.elastic.co/docs/reference/query-languages/esql
-----------
Guy Bruneau IPSS Inc.
My GitHub Page
Twitter: GuyBruneau
gbruneau at isc dot sans dot edu
Originally published by SANS Internet Storm Center. © SANS Internet Storm Center.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-10-05 00:15 UTC
Related stories
- ISC Stormcast For Monday, October 5th, 2026 https://isc.sans.edu/podcastdetail/10122, (Mon, Oct 5th)
SANS Internet Storm Center · 2026-10-05
- User Agent Strings Curiosities, (Sun, Oct 4th)
SANS Internet Storm Center · 2026-10-04
- China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
The Hacker News · 2026-10-04
- YARA-X 1.21.0 Release, (Sat, Oct 3rd)
SANS Internet Storm Center · 2026-10-03
- MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
The Hacker News · 2026-10-03