💀 critical 🤖 qwen2.5:1.5b

Honeypot Threat Analysis — July 10, 2026

Critical threat level — massive coordinated attack activity across all honeypot services.

ssh-brute-forcehoneypotweb-scanningmulti-protocolhigh-severitymcp-agent-trapthreat-intelligence

2026-07-10 Cybersecurity Analysis Report

Cybersecurity Analyst’s Daily Threat Blog for Honey-AI.dev (Raspberry Pi 5 Honeypot)

Overview

On July 10, 2026, the honeypot system collected a total of 361 attackers attempting to exploit various vulnerabilities on Raspberry Pi 5. The attackers used multi-protocol methods including FTP, Telnet, SMTP, MySQL, Redis, Git, and VNC for reconnaissance activities. Additionally, SSH was targeted with 744 login attempts leading to 135 commands executed. HTTP requests were made from 127 IPs, generating 605 alerts through Suricata IDS.

Critical Security Incidents

  • SSH Brute Force: A total of 83 connections were trapped and wasted due to SSH brute force attacks.
  • HTTP Scans & Post-Exploitation: The honeypot was subjected to multiple HTTP scans, including login attempts, which resulted in alerts from the IDS system.

Geographic Analysis

The geographical distribution of attackers highlights a significant presence from United States (1199 IP addresses), China (607 IP addresses), and Belgium (244 IP addresses). The Netherlands accounted for 192 IP addresses, Pakistan had 188 IP addresses, Germany had 185 IP addresses, the United Kingdom with 139 IP addresses, Singapore had 123 IP addresses, India had 119 IP addresses, and Russia Federation (including a single IP address from 46.137.229.175) accounted for 110 IP addresses.

Top Passwords

The top passwords identified were:

  • “4813494d137e1631”
  • “cfdc129e475d7bb8”
  • “f7600f7b1922aec6”
  • “8c6976e5b5410415”
  • “ab0c16f2769c75b4”

Web Scanning & POST Exploitation

The honeypot was subjected to a wide range of HTTP requests, including:

  • /
  • /dispatch.asp
  • /login
  • /favicon.ico
  • /query?q=SHOW+DIAGNOSTICS

These requests indicate that the attackers were primarily targeting known vulnerabilities in web applications and services.

IDS & Scan Intel

The Suricata IDS system reported 605 alerts from a total of 598 IPs, with the severity level being critical. The IDS system identified multi-protocol probes and HTTP scans, including login attempts and requests to exploit vulnerabilities within the honeypot environment.

Malware Capture Attempts

No malware was captured during this period on the honeypot. This indicates that the current setup is effective in preventing malicious software from being deployed or propagating through the network.

Tarpit & Backfire Scans

  • Tarpitting: Trapped 83 connections from 44 IPs, resulting in a waste of 0 hours.
  • Backfire Scans: There were 13 open scans targeting various IP addresses. The targets included:
    • [64.89.163.89] (Portscans)
    • [65.49.1.38]
    • [65.49.1.41]
    • [141.98.83.48]

MCP Trap

  • MCP trap: Trapped 5 requests from 3 IP addresses.

Portscans & Malware Prevention

  • Portscans were observed but no malware was captured, indicating a robust firewall configuration against port scanning attempts.
  • No injection or leak attacks were blocked during the period.

Community Defense & AI Protection

The honeypot system is continuously updated and monitored by an open-source community to ensure it remains effective in defending against known threats. The community defense measures include regular security updates, patch management, and proactive threat intelligence gathering.

Conclusion

Despite encountering a significant number of attackers (361 total attempts), the Raspberry Pi 5 honeypot system was able to detect and report critical incidents such as SSH brute force attacks and HTTP scans. The presence of various geographical IP addresses highlights an active environment for cybersecurity threats, while zero malware captures indicate strong defense against malicious software. This daily blog serves as a testament to the effectiveness of continuously updated security measures in maintaining a robust network defense system.

Endnote: Honey-AI.dev (Raspberry Pi 5 Honeypot)

  • Pi5/Spain/Open-Source
  • Last Updated: July 10, 2026

This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.