💀 critical 🤖 qwen2.5:1.5b

Honeypot Threat Analysis — August 2, 2026

Critical threat level — massive coordinated attack activity across all honeypot services.

ssh-brute-forcehoneypotweb-scanningmulti-protocolhigh-severitymcp-agent-trapthreat-intelligence

Cybersecurity Report for 2026-08-02

Threat Overview

By August 2nd, 2026, the Raspberry Pi 5 honeypot at honey-ai.dev has faced a total of 196 attackers across various protocols and activities. The primary threat vectors include SSH brute force attempts, HTTP requests, and multi-protocol interactions like FTP, Telnet, SMTP, MySQL, Redis, Git, VNC, RDP, and HTTPS/HTTP POSTs.

Geographic Analysis

The geographical distribution of the attackers reflects a mix of international interests:

  • United States: 320 (35%)
  • China: 75 (8%)
  • Belgium: 46 (5%)
  • United Kingdom: 39 (4%)
  • Pakistan: 38 (4%)
  • Germany: 38 (4%)
  • Netherlands: 33 (3%)
  • Vietnam: 19 (2%)

These regions highlight the global reach of the honeypot’s threat landscape, with a particular focus on countries known for their cybersecurity challenges.

SSH Brute Force

SSH attacks have been detected over 1250 connections and involved 658 login attempts. The most active attack source IPs include:

  • 121.229.40.225
  • 109.205.211.94
  • 37.247.230.82
  • 194.180.48.54
  • 181.78.0.82

This activity indicates a high volume of attempted SSH connections, likely part of a more extensive reconnaissance campaign.

Post-Exploitation

The honeypot is being used as a testing ground for various post-exploitation techniques:

  • Rootkits: 44x commands for rootkit installation.
  • File Encryption: 796x sessions to encrypt and decrypt files, indicating potential attempts at file-based persistence.

Web Scanning

HTTP activities have been detected through over 135 requests from 29 IPs. The most active HTTP paths include:

  • /
  • /login
  • /goform/set_LimitClient_cfg
  • /.git/logs/HEAD

These scans suggest a comprehensive effort to probe and compromise various aspects of the honeypot.

IDS & Scan Intel

The honeypot has seen 11255 alerts from the Suricata IDS, indicating high levels of activity that require immediate attention. The most severe alerts involve critical vulnerabilities being exploited, highlighting the importance of continuous security monitoring.

Malware Detection

There have been no malware activities detected on the honeypot during this period.

Tarpit Analysis

The tarpit mechanism has successfully trapped 204 connections from 58 IPs, with no wasted time reported. This suggests that the honeypot is effectively protecting against brute force attempts and other malicious activity.

Canarytokens Detection

3 unique CANARY tokens have been detected:

  • Token IP: 38.175.103.177
  • User-Agent: Boto3/1.42.88 md/Botocore#1.42.91 ua/2.1 os/macos#25.3.0 md/arch#arm64 lang/python#3.13.3 md/pyimpl#CPython m/e,D,b,Z cfg/retry-mode#legacy Botocore/1.42… This detection suggests that the honeypot is not only effective in preventing attacks but also capable of detecting and mitigating potential exploitation attempts.

MCP Trap

The MCP trap has been triggered 3 times, with 3 unique IPs involved:

  • IP: 94.102.49.155
  • Port Scans: 13 scans/13 open

This indicates that the honeypot is being used for both detecting and preventing such activities.

Portscans & AI Defense

No portscans or AI defense mechanisms have been detected on the honeypot during this period, suggesting a low level of sophistication in these types of attacks.

Community Defense

The community response to any security incidents has been minimal so far. This could be due to various reasons such as limited visibility into the network or an environment where incident response is not prioritized.

Conclusion: Cybersecurity Report for 2026-08-02

Honey-ai.dev’s Raspberry Pi honeypot continues to face a significant number of attackers, with high levels of SSH brute force attempts and comprehensive post-exploitation activity. Despite the presence of IDS alerts, malware detection remains non-existent. The tarpit mechanism has been effective in trapping attacks, while CANARY tokens suggest that potential exploitation attempts are being detected and mitigated. However, the low level of portscans and AI defense activities indicates a need for more comprehensive security measures to protect against evolving threats.

Honeypot: Raspberry Pi 5 / Spain Date: August 2nd, 2026


This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.