💀 critical 🤖 qwen2.5:1.5b

Honeypot Threat Analysis — August 3, 2026

Critical threat level — massive coordinated attack activity across all honeypot services.

ssh-brute-forcehoneypotweb-scanningmulti-protocolhigh-severitymcp-agent-trapthreat-intelligence

2026-08-03 - Cybersecurity Analysis

Overview of Recent Activity and Observations

As of August 3, 2026, the honeypot system at honey-ai.dev has logged significant activity. SSH connections have been active with over 7,097,245 total logins. FTP, Telnet, SMTP, MySQL, Redis, Git, VNC, and RDP events have collectively recorded 14,675 occurrences across 150 IPs. HTTP requests have totaled 59 in response to 32 IP addresses.

IDS & Scan Intel

The system has detected a high volume of critical alerts from the Suricata Intrusion Detection System (IDS), with 29,010 alerts logged against 763 IPs. The severity is categorized as “critical,” indicating severe threats that require immediate attention.

Additionally, AbuseIPDB reports have been received for 186 IP addresses, highlighting potential malicious activity.

Top Attackers and Targets

The top attackers identified by the system are predominantly from the United States (373 out of 1034 total IPs), followed by China (68), Belgium (50), United Kingdom (47), Pakistan (45), Netherlands (44), Germany (42), Sweden (27), Vietnam (24), and Unknown (25). The vast majority of these attackers have been from the U.S.

Geo-Location Analysis

The honeypot system has detected 1034 total IP addresses, with a significant concentration in the United States (373 out of 1034). Geographically speaking:

  • United States: 36%
  • China: 6%
  • Belgium: 4%
  • United Kingdom: 4%
  • Pakistan: 4%
  • Netherlands: 4%
  • Germany: 4%
  • Sweden: 2%
  • Unknown: 2%

Tarpit Activity

The system has tarpitted and trapped connections from a total of 26 IPs, totaling 42. Although no malware was captured during this period, the tarpitting activity suggests that these hosts may be part of botnets or compromised systems.

Malware Analysis

There were no malware detections reported on this day, which is consistent with the previous observations indicating high levels of IDS alerts and a significant number of connections from potentially malicious IP addresses.

Post-Exploitation Tools

The system has detected several tools used in post-exploitation attacks. One notable example includes:

  • AWS Token Abuse: Two AWS tokens were accessed from different IPs, including 41.143.178.183 (user-agent: aws-sdk-js/3.1090.0) and 66.154.119.224 (Boto3/1.43.3). These tokens indicate potential misuse of AWS services, raising concerns about unauthorized access to sensitive data.

Portscans

No port scans have been detected on the honeypot system for this date.

Backfire Scans

The system has observed 10 backfire scan attempts targeting hosts with open ports:

  • Target 1 (IP: 194.187.176.126, rdns: None): Opened 3/0 ports
  • Target 2 (IP: 151.243.11.52, rdns: None): Opened 0/1 ports
  • Target 3 (IP: 216.218.206.100, rdns: None): Opened 0/1 ports
  • Target 4 (IP: 216.218.206.96, rdns: None): Opened 0/1 ports

MCP Trap and TTY Commands

The system has intercepted a total of 6 requests for MCP traps and 2 TTY commands involving sessions:

  • MCP Trap (IP: 4 IPs):

    • 796x instances of the command uname -s -v -n -r -m
    • 44x instances of /bin/./uname -s -v -n -r -m for different IP addresses
  • TTY Commands (IP: 2 IPs):

    • 20x instances where users were prompted to enter their password via TTY commands
    • 2x instances where the command cat /proc/cpuinfo was executed, with results shown by head -n 1 ...

Conclusion

The honeypot system at honey-ai.dev has been actively monitoring for a significant period. The high volume of connections and critical alerts suggests ongoing threats from various sources. While malware was not detected, the presence of AWS tokens indicates potential misuse of AWS services.

The tarpitting activity, combined with backfire scan attempts targeting open ports, underscores the need to continuously monitor and improve security measures on such systems.


This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.