💀 critical 🤖 qwen2.5:1.5b

Honeypot Threat Analysis — June 12, 2026

Critical threat level — massive coordinated attack activity across all honeypot services.

ssh-brute-forcehoneypotweb-scanningmulti-protocolhigh-severitythreat-intelligence

Threat Landscape Overview

In today’s data, we observe a high activity level in our honeypot environment. The SSH service has seen over 412 connections and 345 login attempts with 72 unique IPs executing 589 commands. This includes 980 events across multi-protocol decoy services (FTP/Telnet/SMTP/MySQL/Redis/Git/VNC/RDP), highlighting a sophisticated threat landscape.

Geographic Analysis

The attack activity is predominantly originating from several countries, with the United States contributing the highest percentage at around 20%. Other notable contributors include China, Singapore, the UK, Netherlands, Germany, South Korea, India, France, and Hong Kong. This geographical distribution underscores the international nature of cyber threats.

SSH Brute Force Analysis

The data reveals a mix of brute force attacks with various password combinations including ‘root’, ‘admin’, ‘password’, and ‘123456’. The post-authentication commands show typical reconnaissance activities like changing permissions on directories, attempting to root the system, and scanning for available CPU information. These types of actions indicate an attacker’s desire to gather basic information about the target environment.

Post-Exploitation Behavior

In TTY sessions, attackers are executing various commands such as ‘uname -s’, ‘chattr -ia .ssh’, and ‘ls -lh $(which ls)’. The successful login attempts (‘1234:1234’ and ‘0:0’) further highlight that the attacker has successfully gained access. This pattern suggests an ongoing examination of system configurations and user accounts.

Web Scanner Activity

The HTTP web service activity includes scanning for open ports via GET requests to paths like “/SDK/webLanguage”, “/login”, and “/.env”. These actions indicate a preliminary reconnaissance phase aimed at identifying vulnerabilities in the target environment, possibly leading towards exploitation phases.

Network IDS Alerts & Scan Intelligence

In today’s network monitoring, we see over 15273 alerts from 1245 unique IPs, primarily related to generic protocol command decode and potential corporate privacy violation. The signatures ‘ET INFO Session Traversal Utilities for NAT (STUN Binding Request)’ and ‘SURICATA STREAM 3way handshake wrong seq wrong ack’ are noteworthy as they represent known vulnerabilities exploited by attackers.

Malware Captures

No malware samples were captured today, indicating that the honeypot remained resilient in preventing actual malware infections. The analysis of these alerts suggests ongoing attempts to detect and respond to potential threats within the environment.

SSH Tarpit

There was no data available on tarpits, so no attackers were caught being trapped or experiencing resource wastage due to this mechanism.

Canarytoken Alerts

No canarytokens were triggered today, suggesting that the attacker did not use any fake credentials. This absence could be a positive signal of effective cybersecurity measures in place within the honeypot setup.

Community Defense

The top IPs reported to AbuseIPDB include ‘93.123.72.183’, ‘172.235.240.148’, and others, indicating a broad range of potential threat actors originating from various locations worldwide.

In conclusion, the honeypot continues to provide valuable insights into evolving cyber threats while also demonstrating effective cybersecurity practices in place. The infrastructure remains robust against sophisticated attacks, focusing on maintaining a live environment that can detect and respond to real-world threats.

The honeypot is deployed using Raspberry Pi 5 as its primary hardware platform, with operations conducted from Spain, showcasing the effectiveness of open-source solutions in providing secure testing environments for cybersecurity research and defense.


This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.