Honeypot Threat Analysis — June 22, 2026
Critical threat level — massive coordinated attack activity across all honeypot services.
2026-06-22 Honey-AI Dev Blog
Threat Overview
On June 22nd, 2026, we witnessed a substantial increase in the number of SSH brute force attempts and malicious HTTP requests directed towards our honeypot setup. This was primarily due to an influx of compromised devices attempting to exploit vulnerabilities or engage in DDoS attacks.
Geographic Analysis
The primary geographic distribution showed that the majority of attackers are coming from locations within Asia, with a strong presence in Southeast Asia (e.g., Singapore and Indonesia), China, and India. A notable number of attacks also originated from the United States, reflecting an increasingly globalized approach to cybercrime.
SSH Brute Force
SSH brute force attempts were among the most frequent threats observed on this day. We identified 471 unique connections within a short period, each with varying degrees of legitimacy or malicious intent. The top IP addresses responsible for these attacks included:
- 213.209.159.115
- 72.255.18.185
- 223.123.71.54
- 223.123.73.146
- 72.255.33.152
These high-risk IP addresses were responsible for a significant portion of the total login attempts, indicating potential areas that need to be strengthened in our defenses.
Post-Exploitation Attempts and Web Scanning
The day was marked by a surge in HTTP requests, particularly targeting various endpoints such as SDK/webLanguage, authLogin.cgi, solr/admin/cores?action=STATUSGALAH_PATHS_PHwt=json, .git/config. The tarpit activity has also seen an uptick, indicating that these devices are engaging in prolonged attacks rather than immediate exploitation.
IDS & Scan Intel
The day was characterized by a high number of Suricata Intrusion Detection System (IDS) alerts, with 17494 events observed across 560 IPs. The severity level for this period was primarily critical, indicating that our defenses may need to be further enhanced in terms of detection capabilities.
Malware
There were no malware captures identified on this day, which is a promising sign but underscores the importance of continuous monitoring and proactive defense mechanisms.
Tarpit Activity
Despite being tarpitted 86 connections from 39 IPs throughout the day, there was minimal impact due to our network’s capacity. This suggests that while we are handling a significant volume of traffic, our infrastructure can still manage it effectively under normal conditions.
Canarytokens
We observed three “canarytokens” on this day, including an AWS token and two instances where devices were attempting to access sensitive information using the aws-sdk-js/3.1070.0 user-agent string. This activity underscores the importance of maintaining a vigilant posture against such potential threats.
MCP Trap
Two sessions were tarpitted with 2 requests each from IPs, indicating that these connections had been identified as potentially malicious but not yet fully compromised. The low volume suggests this is an ongoing challenge for our detection systems.
Portscans and Tarpit Activity
The day saw a notable increase in portscans (0/0), which could indicate a shift towards more sophisticated or automated attacks. However, the tarpit activity remained relatively stable at 86 connections per hour, suggesting that the network infrastructure can handle this level of traffic efficiently.
Community Defense
Our community defense efforts were not hindered by any reported incidents on this day, indicating that our defensive strategies are effective in maintaining a secure environment for our honeypot system.
In summary, while June 22nd marked significant activity across several dimensions, the overall health and resilience of our network infrastructure continued to be robust. Our continuous monitoring and adaptive security measures remain key to maintaining high levels of security for our honeypot setup.
Pi5/Spain/open-source
This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.