💀 critical 🤖 qwen2.5:1.5b

Honeypot Threat Analysis — June 14, 2026

Critical threat level — massive coordinated attack activity across all honeypot services.

ssh-brute-forcehoneypotweb-scanningmulti-protocolhigh-severitythreat-intelligence

Threat Landscape Overview

Today’s threat intelligence snapshot reveals a diverse but largely benign landscape. The primary focus is on SSH tarpits and HTTP web services, which indicate low-level reconnaissance efforts without significant penetration activities.

The most notable events include:

  • 2067 multi-protocol decoy service alerts.
  • 84 HTTP requests to the HoneyAI web service.
  • Multiple reverse port scans targeting specific IP addresses within Spain. The latest scan targeted an IP with open SSH ports, highlighting ongoing interest in these services.
  • A single successful login attempt for a root user.

The total unique attackers identified today are approximately 74, including IPs from several countries such as the United States (200), China (181), and Singapore (71).

Geographic Analysis

Geographically, the primary threat sources come from:

  • The United States: 200 attacks (21%)
  • China: 181 attacks (19%)
  • Singapore: 71 attacks (7%)

This pattern suggests a continuous presence of Chinese and US-based attackers targeting both high-value targets like SSH services and common HTTP endpoints.

SSH Brute Force Analysis

Today’s brute force attempts involved multiple successful login attempts, including:

  • “root” with the hash “Q1w2e3r4”
  • “cisco” with the hash “cisco”

Successful logins from users such as “ubuntu:123.com,” “sshadmin,” and “adm:123456.”

Post-Exploitation Behavior

During TTY sessions, attackers executed several commands:

  • 796x ran uname -s -v -n -r -m
  • Multiple attempts to change file attributes, such as /usr/local/share/dirservers/passwd and other common system files.
  • Commands like cd ~; chattr -ia .ssh; lockr -ia .ssh, indicating a preference for SSH configuration manipulation.

Web Scanner Activity

The HTTP web service received 84 requests from various IPs, including the known “HoneyAI” endpoint. This suggests ongoing reconnaissance through standard protocol methods.

Network IDS Alerts & Scan Intelligence

Suricata detected 11849 alerts across 895 unique IPs, covering a wide range of threat categories such as:

  • Misc Attack (3220)
  • Potential Corporate Privacy Violation (2946)
  • Generic Protocol Command Decode (2519)
  • Potentially Bad Traffic (2405)
  • Misc activity (662)

The most notable threat was an alert triggered by a generic protocol command decode, indicating potential vulnerabilities in the services.

Reverse Port Scans

A single reverse port scan back to attackers revealed 1 successful host with open SSH ports. This indicates ongoing engagement and persistence from malicious actors targeting these specific IP addresses.

Malware Captures

No malware samples were detected during today’s operations.

SSH Tarpit

There was no evidence of an active tarpit service, hence the absence of any trapped attackers or wasted resources due to this type of attack.

Canarytoken Alerts

A total of 23 canary token triggers were identified. These alerts indicated attackers using fake AWS keys and other credentials in the honeypot for testing purposes.

Community Defense

All IPs shared with AbuseIPDB, AlienVault OTX, Blocklist.de, and SANS DShield. The malware hashes have been submitted to VirusTotal and OTX.


This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.