Honeypot Threat Analysis — June 14, 2026
Critical threat level — massive coordinated attack activity across all honeypot services.
Threat Landscape Overview
Today’s threat intelligence snapshot reveals a diverse but largely benign landscape. The primary focus is on SSH tarpits and HTTP web services, which indicate low-level reconnaissance efforts without significant penetration activities.
The most notable events include:
- 2067 multi-protocol decoy service alerts.
- 84 HTTP requests to the HoneyAI web service.
- Multiple reverse port scans targeting specific IP addresses within Spain. The latest scan targeted an IP with open SSH ports, highlighting ongoing interest in these services.
- A single successful login attempt for a root user.
The total unique attackers identified today are approximately 74, including IPs from several countries such as the United States (200), China (181), and Singapore (71).
Geographic Analysis
Geographically, the primary threat sources come from:
- The United States: 200 attacks (21%)
- China: 181 attacks (19%)
- Singapore: 71 attacks (7%)
This pattern suggests a continuous presence of Chinese and US-based attackers targeting both high-value targets like SSH services and common HTTP endpoints.
SSH Brute Force Analysis
Today’s brute force attempts involved multiple successful login attempts, including:
- “root” with the hash “Q1w2e3r4”
- “cisco” with the hash “cisco”
Successful logins from users such as “ubuntu:123.com,” “sshadmin,” and “adm:123456.”
Post-Exploitation Behavior
During TTY sessions, attackers executed several commands:
- 796x ran
uname -s -v -n -r -m - Multiple attempts to change file attributes, such as
/usr/local/share/dirservers/passwdand other common system files. - Commands like
cd ~; chattr -ia .ssh; lockr -ia .ssh, indicating a preference for SSH configuration manipulation.
Web Scanner Activity
The HTTP web service received 84 requests from various IPs, including the known “HoneyAI” endpoint. This suggests ongoing reconnaissance through standard protocol methods.
Network IDS Alerts & Scan Intelligence
Suricata detected 11849 alerts across 895 unique IPs, covering a wide range of threat categories such as:
- Misc Attack (3220)
- Potential Corporate Privacy Violation (2946)
- Generic Protocol Command Decode (2519)
- Potentially Bad Traffic (2405)
- Misc activity (662)
The most notable threat was an alert triggered by a generic protocol command decode, indicating potential vulnerabilities in the services.
Reverse Port Scans
A single reverse port scan back to attackers revealed 1 successful host with open SSH ports. This indicates ongoing engagement and persistence from malicious actors targeting these specific IP addresses.
Malware Captures
No malware samples were detected during today’s operations.
SSH Tarpit
There was no evidence of an active tarpit service, hence the absence of any trapped attackers or wasted resources due to this type of attack.
Canarytoken Alerts
A total of 23 canary token triggers were identified. These alerts indicated attackers using fake AWS keys and other credentials in the honeypot for testing purposes.
Community Defense
All IPs shared with AbuseIPDB, AlienVault OTX, Blocklist.de, and SANS DShield. The malware hashes have been submitted to VirusTotal and OTX.
This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.