💀 critical 🤖 qwen2.5:1.5b

Honeypot Threat Analysis — August 5, 2026

Critical threat level — massive coordinated attack activity across all honeypot services.

ssh-brute-forcehoneypotweb-scanningmulti-protocolhigh-severitythreat-intelligence

2026-08-05 - Honey-AI Dev’s Daily Threat Analysis

Overview

In the closing days of August 2026, our honeypot system on a Raspberry Pi 5 in Spain saw significant activity with 161 IPs and 36 unique IP addresses initiating over 1,154 commands. The total number of connections initiated from these IPs reached 483 with SSH, FTP, Telnet, SMTP, MySQL, Redis, Git, VNC, RDP, HTTP/HTTPS, Suricata IDS alerts, and more than 1,600 multi-protocol events.

The day was characterized by a high volume of abuse reports from several IP addresses, including those with reported malicious activities involving 91 reported IPs.

Top attacking IPs included:

  • 114.47.220.83
  • 61.231.53.116
  • 218.56.195.92
  • 183.129.148.70
  • 2.57.122.238

The most common passwords used were:

  • b03ddf3ca2e714a6
  • 1af4cfa0ae8cb48c
  • 4813494d137e1631

HTTP paths included:

  • /,
  • /dispatch.asp
  • /login
  • /SDK/webLanguage
  • /nice%20ports%2C/Tri%6Eity.txt%2ebak

The total number of unique IPs used to log in was 15276. The most common geographic locations were:

  • United States: 459 (36%)
  • China: 89 (7%)
  • Germany: 66 (5%)
  • United Kingdom: 58 (4%)
  • Belgium: 56 (4%)
  • Pakistan: 53 (4%)
  • Netherlands: 51 (4%)
  • Vietnam: 34 (2%)
  • Sweden: 31 (2%)
  • Unknown: 30 (2%)

Threat Analysis

The total number of attackers was approximately 231, with a high volume of abuse reports and an active tarpit session. The day’s activities suggest multiple attempts to exploit vulnerabilities within the honeypot environment.

Top threats identified include:

  • Multiple SSH brute force attacks
  • HTTP/HTTPS requests
  • Unverified URLs leading to malicious content

The primary targets were:

  • Windows-based systems with UAC enabled
  • Linux systems using non-standard configurations (e.g., /dev/ttyS0)

Malware Detection

No malware was detected during the day, indicating a lack of active infections. This is encouraging given the high volume of traffic and potential for malicious activity.

Tarpit Sessions

A significant number of sessions were successfully tarpitted due to their low security measures:

  • 97 connections from 42 IPs
  • Total downtime: 0 hours

Malware Detection

No malware was detected during the day, indicating a lack of active infections. This is encouraging given the high volume of traffic and potential for malicious activity.

Canarytokens

The honeypot detected multiple legitimate requests but did not trigger any canary tokens or AWS token leaks. The presence of these tokens suggests that the environment was relatively secure against common attack vectors.

MCP Trap

No connections were trapped, indicating a healthy balance between security measures and usability.

Portscans

  • 0 portscans were detected during the day.
  • No open ports were found on any targets within the honeypot’s scope.

AI Defense

  • 0 injection blocks
  • 0 leak blocks

Conclusion

2026-08-05 marked a period of heightened activity with a mix of legitimate traffic and potential threats. Despite the high volume of attacks, the environment demonstrated resilience by detecting no malware and minimizing tarpit time. The day’s findings underscored the importance of continuous monitoring and updating security measures to remain vigilant against evolving cyber threats.

Honey-AI Dev # Raspberry Pi 5 # Spain # Open-Source


This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.