💀 critical 🤖 qwen2.5:1.5b

Honeypot Threat Analysis — July 12, 2026

Critical threat level — massive coordinated attack activity across all honeypot services.

ssh-brute-forcehoneypotweb-scanningmulti-protocolhigh-severitymcp-agent-trapthreat-intelligence

2026-07-12

Threat Overview

Today on July 12, 2026, our Raspberry Pi 5 honeypot experienced a significant influx of malicious activity, totaling approximately 387 attackers across various protocols and IP addresses. The primary threat vectors include SSH brute force attempts (627), HTTP requests (30), multiple multi-protocol connections (37573) via FTP, Telnet, SMTP, MySQL, Redis, Git, VNC, RDP, and others, with a notable spike in critical IDS alerts (52029).

Geographical Analysis

Our honeypot was reported by AbuseIPDB to be under attack from 167 IPs predominantly located within the United States (27%), China (13%), Belgium (5%), Netherlands (4%), and several countries including Pakistan, Germany, UK, India, and Singapore. This geographical distribution suggests a diverse range of locations engaged in our honeypot’s activity.

SSH Brute Force

The SSH brute force attacks on July 12, 2026, were particularly significant with 1675 attempts logged out of our honeypot. The most common passwords used included “3a5745a05f87ddee” (which is a very weak password), followed by other weak combinations and the default admin password.

Top IPs

The top 5 IP addresses responsible for attacks are:

  1. 41.189.178.22
  2. 104.234.32.144
  3. 104.234.32.234
  4. 173.239.213.12
  5. 185.238.231.203

These IPs exhibit a high volume of connections and commands, suggesting they may be participating in the ongoing attack or are part of an organized cybercriminal network.

HTTP Traffic

There were 142 unique HTTP requests from various IP addresses, with specific paths such as /, /dispatch.asp, /login, /judge, and /goform/set_LimitClient_cfg being frequently visited. This activity could indicate reconnaissance or exploitation techniques aimed at our honeypot’s web interface.

IDS & Scan Intel

The Suricata IDS system detected 52029 alerts, indicating a substantial level of security infrastructure intrusion attempts. These attacks are critical and warrant immediate attention to prevent further damage.

Malware

No malware was captured during the day, which is concerning given the significant traffic volume and numerous attack vectors used by the attackers.

Tarpit & Backfire Scans

Our honeypot was successfully tarpitted (73 connections from 46 IPs) but no backfire scans were detected. This suggests that our security measures are effective in preventing such activities, although it’s crucial to continuously monitor and update them for potential new tactics.

MCP Trap

A total of 12 requests were trapped using the MCP protocol on 6 IP addresses. The tools used include Boto3/1.43.36, which is likely part of an automated attack script.

Portscans

No port scans were detected during this period, indicating that our honeypot’s security measures effectively prevent common port scanning techniques.

AI Defense & Community Defense

While no injection or leak attacks were blocked, the lack of active threats suggests a strong defense against known exploits and vulnerabilities. The community defense efforts remain essential in maintaining security through collaboration with other cybersecurity organizations.

Session Analysis

The most prolific session type was 796x: uname -s -v -n -r -m, which indicates that attackers are attempting to gather information about the system’s version, release date, architecture, and more. Another common command is 44x: cd ~; chattr -ia .ssh; lockr -ia .ssh for bypassing SSH restrictions.

Community Defense

The community defense efforts continue to be a cornerstone of our security posture. Our honeypot’s vulnerability remains largely unexploited, emphasizing the importance of continuous monitoring and updates in real-time environments like ours.

This analysis underscores the need for robust security measures across multiple layers—firewalls, IDS/IPS systems, tarpits, and more—to protect against malicious activity targeting a Raspberry Pi 5 honeypot. The data provided highlights ongoing challenges but also opportunities to improve our defense strategies through continuous monitoring and updates.


This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.