Honeypot Threat Analysis — July 26, 2026
Critical threat level — massive coordinated attack activity across all honeypot services.
Cybersecurity Threat Overview for July 26, 2026
SSH Brute Force Attempts and Successful Logins
In the past 24 hours, a total of 172 attackers attempted to log into your Raspberry Pi honeypot using SSH. Of these attempts, 307 commands were executed on your system, with the vast majority (98%) failing due to authentication failures or incorrect passwords.
The top five sources of attack traffic are as follows:
- IP Address 1:
36.228.173.99 - IP Address 2:
46.151.182.201 - IP Address 3:
103.248.94.98 - IP Address 4:
77.90.185.30 - IP Address 5:
110.36.80.171
Top Passwords Used
The most frequently used passwords were:
- Password 1:
1af4cfa0ae8cb48c - Password 2:
48210aeb11e24e1e
These passwords are common in many Linux-based systems and can be easily cracked using basic password cracking tools.
Top HTTP Paths
Among the top HTTP paths used, the most frequently accessed were:
/(Home Page)/login/SDK/webLanguage/zc?action=getInfo/download/powershell/
These URLs are likely to be targeted by attackers for various purposes such as credential dumping or gaining access to sensitive information.
Geographic Distribution of Attacks
The majority of attacks originated from:
- United States: 1433 (27%)
- China: 717 (13%)
- Belgium: 278 (5%)
- Pakistan: 228 (4%)
- Netherlands: 224 (4%)
- Germany: 205 (3%)
- United Kingdom: 172 (3%)
- India: 156 (3%)
- Korea, Republic of: 139 (2%)
This distribution suggests that your honeypot is effectively reaching out to a wide geographical area.
IDS Alerts and Suricata Scans
Today, you encountered a total of 8279 alerts from the Suricata IDS system. Out of these, 551 IPs were reported as originating from malicious activities. This indicates that your honeypot is effectively detecting and alerting on potential threats.
Malware Capture Attempted but Failed
There was no malware captured during today’s activity within the Raspberry Pi 5 honeypot environment.
Tarpit Activity and Trapped Connections
During the day, 76 connections were tarpitted, leading to a total of 0 hours of wasted time for your honeypot. This suggests that many attackers are not fully engaging with your system but attempting to brute force or otherwise probe it.
Canarytokens Analysis
The presence of 4 triggers indicates the use of Canarytokens, which can be an indication of automated scanning tools used by attackers to check if their payloads have been detected and blocked before they attempt an actual payload attack.
MCP Trap Activity
You also experienced 6 requests from the MCP system, indicating that your honeypot was successfully triggering alerts on a monitored network. The IP address 185.172.175.203 used Boto3 and Botocore with user-agent strings suggesting automated scanning tools.
Portscans and Open Targets
No new portscans were detected during the day, indicating that your honeypot has remained free of any recent attempts to scan open ports for vulnerabilities or other reconnaissance activities.
AI Defense Activity
There was no activity recorded regarding AI-based defenses such as injection blocks or leak blocking. This suggests that while you have a system in place to protect against certain types of cyber threats, it is currently not being used effectively in your honeypot environment.
In summary, your Raspberry Pi 5 honeypot continues to be highly effective at detecting and alerting on potential threats. While it’s important to monitor for new activities and improve AI-based defenses, the current setup seems to be functioning as intended.
This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.