💀 critical 🤖 qwen2.5:1.5b

Honeypot Threat Analysis — June 18, 2026

Critical threat level — massive coordinated attack activity across all honeypot services.

ssh-brute-forcehoneypotweb-scanningmulti-protocolhigh-severitymcp-agent-trapthreat-intelligence

Cybersecurity Analysis for June 18th, 2026

Threat Overview

In the past day, our Raspberry Pi honeypot in Spain has seen a significant uptick in malicious activity, particularly targeting SSH brute force attempts and HTTP GET requests with sensitive paths. The total number of attackers reached over 257 entities, with a notable increase in multi-protocol access events.

Geographical Analysis

The honeypot has experienced attacks originating from multiple locations, primarily concentrated within the United States (349 IPs), China (262 IPs), and United Kingdom (88 IPs). The geographical distribution reflects the global nature of cybersecurity threats, with a heightened presence in these regions due to varying levels of internet penetration and regulatory measures.

SSH Brute Force

SSH brute force attempts increased significantly over the past day, surpassing 476 login attempts. This surge is concerning as it indicates ongoing exploitation efforts targeting our honeypot infrastructure. The top few IPs involved were:

  • 185.16.38.216
  • 186.225.144.106
  • 200.8.235.210

These attacks highlight the importance of robust password management and secure SSH configurations.

Post-Exploitation

The honeypot has seen 7514 multi-protocol events, primarily focused on exploiting vulnerabilities in SSH, Telnet, FTP, SMTP, MySQL, Redis, Git, VNC, RDP, and other common network protocols. The increase in these activities suggests a continuous effort to compromise our environment for further exploitation.

Web Scanning

The honeypot has experienced over 88 HTTP requests per day, with paths such as /SDK/webLanguage, /, /login, /onvif/device_service, and /onvif/device being accessed. This indicates an active presence of reconnaissance tools aimed at identifying vulnerabilities in web applications.

IDS & Scan Intel

The honeypot has logged 12465 alerts from the Suricata Intrusion Detection System, with a critical severity level indicating that these incidents represent significant threats. The top IPs involved are:

  • 185.16.38.216
  • 186.225.144.106
  • 200.8.235.210

The critical alerts suggest ongoing exploitation attempts, highlighting the need for enhanced monitoring and incident response procedures.

Malware

Despite no malware being captured on our honeypot, it’s worth noting that abuse IPs have reported numerous incidents of malicious activity. This underscores the importance of a comprehensive defense strategy to detect and mitigate even subtle forms of malicious behavior.

Tarpit Analysis

We’ve successfully tarpitted 189 connections from 99 IPs over the past day, spending negligible time on these sessions. This proactive approach is crucial in maintaining the integrity of our honeypot environment.

Canarytokens

The honeypot has detected 19 triggers for AWS tokens, indicating that users are attempting to exploit security gaps related to API access via the aws-cli tool suite. The IPs involved include:

  • 107.189.11.111
  • 192.42.116.12

These findings highlight the necessity of strong authentication mechanisms and ongoing vigilance in securing sensitive data.

MCP Trap

The honeypot has experienced 9 requests from 3 IPs for a tool we identified as “MCP trap,” which indicates that there is an active presence of tools targeting our environment for exploitation. This finding underscores the need to implement effective monitoring and detection mechanisms for such sophisticated attacks.

Portscans & AI Defense

No port scans or attempts at exploiting vulnerabilities in our network infrastructure were detected over the past day, suggesting a stable and secure environment in terms of port-based exploits.

In summary, while the honeypot has seen an increase in malicious activity targeting SSH and HTTP endpoints, it remains largely intact. The high number of attackers underscores the importance of continuous monitoring, robust security measures, and proactive defense strategies to mitigate such threats effectively.


This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.