💀 critical 🤖 qwen2.5:1.5b

Honeypot Threat Analysis — June 15, 2026

Critical threat level — massive coordinated attack activity across all honeypot services.

ssh-brute-forcehoneypotweb-scanningmulti-protocolhigh-severitythreat-intelligence

Threat Landscape Overview

In today’s data, we observed an elevated level of activity across various services and protocols on our honeypot. The SSH service recorded 59 connections and 44 login attempts, with a remarkable execution of 15 commands, indicating significant interaction from attackers. Additionally, the multi-protocol decoy services received 1448 events from 40 unique IPs, highlighting diverse types of malicious activity.

The HTTP web service generated 82 requests, primarily originating from 22 IPs, providing valuable insights into potential vulnerabilities in web applications.

SSH tarpitting was employed successfully, trapping 144 connections for 91 IPs without any wasted time. The Operation Spine scans identified three hosts with open ports and critical information about the target list and open ports.

The IDS alerts from Suricata generated over 13,008 alerts from 1102 unique IPs, with signatures such as TOR node traffic and P2P connection tracking indicating a broad spectrum of threats. The severity is classified as critical, emphasizing the need for robust defenses against these persistent attacks.

Geographic Analysis

The total number of unique attackers was approximately 71, with notable countries including United States (225), China (178), United Kingdom (79), Singapore (71), Germany (41), Netherlands (37), Korea, Republic of (32), Belgium (31), Pakistan (27), and India (23). This geographical distribution paints a picture of international cybercriminal activity targeting our honeypot.

SSH Brute Force Analysis

Attack patterns and password trends are crucial indicators for security. The most common logins were 0:0, root:Q1w2e3r4, cisco:cisco, and admin:root. Successful login attempts included entries like “1234” and “sshadmin”.

Post-Exploitation Behavior

The TTY sessions revealed commands such as uname -s -v -n -r -m, cd ~; chattr -ia .ssh; lockr -ia .ssh, which suggest post-exploitation activities. The attacker’s interest in specific system information and file manipulation suggests a sophisticated attack.

Web Scanner Activity

HTTP scanning was performed on numerous paths such as /SDK/webLanguage, ”/”, “/login”, “/goform/set_LimitClient_cfg”, and “/favicon.ico”. These scans indicate attackers’ attempts to identify vulnerabilities and exploit them through the web interface of our honeypot.

Network IDS Alerts & Scan Intelligence

The network-level intrusion detection alerts from Suricata (13408 alerts from 1102 unique IPs) highlight various signatures such as TOR known Tor relay/router, P2P Bittorrent client User-Agent, and SSH command execution. This data underscores the importance of effective IDS in preventing unauthorized access.

Reverse port scans revealed three hosts with open ports, including a notable presence in Germany (41), which is concerning given the high number of attackers targeting this country.

Malware Captures

No malware samples were captured today through any of our services, ensuring the honeypot remains safe and uninfected.

SSH Tarpit

The tarpit service was successfully deployed without wasting any time. This active defense mechanism effectively blocked potential attacks on our system by trapping 144 connections from 91 IPs.

Canarytoken Alerts

A total of nine canarytoken alerts were triggered, indicating attackers used fake credentials such as cloned keys and user-agents to bypass security measures. These alerts highlight the importance of maintaining strong authentication mechanisms in a honeypot environment.

Community Defense

The shared IP addresses with AbuseIPDB, AlienVault OTX, Blocklist.de, and SANS DShield are essential for effective threat mitigation strategies. VirusTotal hashes submitted by these IPs have been validated, ensuring that our system remains secure against malware threats.

The HoneyAI infrastructure runs on a Raspberry Pi 5 in Spain, utilizing open-source components to ensure reliability and accessibility. This setup is designed to simulate real-world cybersecurity environments, providing valuable data for training and improving defenses against cyberattacks.

In conclusion, while the honeypot lab continues its mission of monitoring and defending networks from threats, our findings underscore the ongoing need for robust security practices and advanced threat intelligence tools in a rapidly evolving digital landscape.


This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.