Honeypot Threat Analysis — June 21, 2026
Critical threat level — massive coordinated attack activity across all honeypot services.
2026-06-21 Analysis of Honey-Pi 5
Day Summary: Over the course of the day on June 21, 2026, multiple threats were detected and managed by the Raspberry Pi honeypot system. The system logged a total of 88 connections as tarpitted due to abuse IP detection, totaling approximately 46 hours wasted. There was also one malware scan that triggered an alert but did not result in any actual malware being captured.
Top Attackers:
-
Top IPs by number of attacks:
-
84.241.6.17(930) – High severity
-
213.209.159.115(760) – High severity
-
91.92.40.240(698)
-
103.84.56.209(685)
-
72.255.59.42(660)
-
-
Top IPs by connection counts:
-
84.241.6.17(23) – High severity
-
213.209.159.115(22)
-
91.92.40.240(21)
-
103.84.56.209(20)
-
72.255.59.42(19)
-
SSH Brute Force:
- The system encountered a high volume of SSH brute force attempts, with over 2,800 commands and 3,000 IP addresses involved in the process.
- A total of 7,100 attacks were recorded, totaling approximately 46 hours wasted. Among these, 96 attackers reported to abuse IPDB.
Post-Exploitation:
- Multiple post-exploitation tactics were observed:
- Sessions for
ssh-rsaauthentication - Enumeration using tools like
uname,cat /proc/cpuinfo, andlockr - Attempts to escalate privileges through tftp and
sudocommands
- Sessions for
Web Scanning:
- The system detected a high volume of web requests, including
/SDK/webLanguage,/manager/html, and/backend/.env. This activity suggests that the honeypot is being used for reconnaissance purposes.
IDS & Scan Intel:
- Suricata IDS reported 72 alerts from 567 IPs. The highest severity was critical.
- Analysis of network traffic logs revealed multiple attempts to port scan, but no malware or backfire scans were detected.
Malware:
- There were no reports of malware being captured on the system.
Tarpit:
- Tarpitted 88 connections from 33 IPs, totaling approximately 46 hours wasted. This indicates that some attackers are exploiting the system for abuse purposes rather than genuine engagement.
Canarytokens:
- No canary tokens were detected or triggered by any of the activities observed on the honeypot.
MCP Trap:
- The MCP trap did not trigger, indicating that the honeypot was not actively monitored and analyzed during this period.
Portscans & MSSQL/SNMP:
- There were no port scans recorded, and only 38 out of 18 connections involved SNMP (Simple Network Management Protocol) activity.
AI Defense:
- No injection or leak attacks were detected on the system, maintaining high security standards.
Community Defense:
- The community defense tools remained inactive throughout the day, suggesting that the honeypot was not under active threat analysis.
Overall Threat Overview:
- The overall threat level on the honeypot was high due to the large number of attacks and attempts at exploitation. However, the system’s ability to detect threats and block them effectively ensured minimal damage or disruption to network operations.
In summary, despite a significant volume of activity, the honeypot managed to maintain its security posture throughout June 21, 2026, with high levels of detection and mitigation capabilities in place. This analysis highlights the importance of robust threat management systems for networks that utilize honeypots as part of their defense strategy.
This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.