💀 critical 🤖 qwen2.5:1.5b

Honeypot Threat Analysis — August 7, 2026

Critical threat level — massive coordinated attack activity across all honeypot services.

ssh-brute-forcehoneypotweb-scanningmulti-protocolhigh-severitythreat-intelligence

2026-08-07 - Honey-AI.dev Daily Threat Analysis

Overview (SSH Brute Force)

In the past week on August 7th, we logged a total of 1399 SSH connections with over 700 unique commands and 31 IP addresses. This is an increase from the previous day, indicating heightened activity in our honeypot environment.

The top five IPs identified were as follows:

  • 83.65.143.95: Likely originating from a Chinese-based botnet.
  • 218.173.88.175: A Russian IP with suspected malicious activities.
  • 47.112.237.28: Another Chinese source, possibly in the same botnet family.
  • 193.32.162.15: An IP from Belgium known for hosting malware servers.
  • 77.90.185.30: A French-based source with a high number of suspicious commands and events.

HTTP Traffic

On the same day, we observed 164 unique requests to our honeypot, originating from 32 different IP addresses. This represents an increase in web traffic compared to previous days, indicating that more attackers are actively probing for vulnerabilities or attempting to exploit our system.

The most frequent paths accessed were:

  • /: A common starting point for many exploits.
  • /dispatch.asp: An ASP-based path often used by malicious scripts.
  • /login: Likely a login page being tested against multiple versions of the web application.
  • /SDK/webLanguage: An SDK access route, possibly used in automated penetration tests.

IDS & Scan Intel

Our Suricata Intrusion Detection System reported 6467 alerts across 637 IPs, with a severity level of critical. This high volume suggests that our honeypot is being actively scanned by attackers looking for vulnerabilities.

The key threat indicators detected include:

  • Multiple Multi-Protocol Scans: FTP/Telnet/SMTP/MySQL/Git/VNC/RDP
  • SSH Brute Force Attempts
  • HTTP Traffic Patterns

Malware Capture

No malware was captured on this day, which is concerning considering the high number of attackers. This lack of evidence could indicate either an increased level of defensive measures or a shift in tactics by our attackers.

Tarpit & AbuseIPDB

A total of 139 connections were trapped due to malicious IP addresses identified in AbuseIPDB, but these tarpits did not consume any time from the honeypot. This suggests that the majority of attacks are coming from benign or low-risk sources.

Top IPs for tarpitting:

  • 83.65.143.95
  • 218.173.88.175

Malware Tokens

Two AWS tokens were detected in our environment, indicating that some attackers are attempting to use compromised systems or service accounts to gain access to sensitive data. The tokens involved user-agents with “Mozilla” as the primary browser type.

  • Token from 108.226.76.67: Originating from a Windows-based system.
  • Tokens from 213.136.67.156, 45.194.67.120, and 74.82.47.10: A mix of Linux and Windows systems.

MCP Trap & Portscans

No malicious activity was detected through the MCP trap mechanism or port scans on our network.

AI Defense

Our AI-based defense system did not block any injection attempts or leak detection, suggesting that while we are implementing security measures, attackers remain undeterred. This indicates a need for continuous improvement in both defensive strategies and offensive capabilities.

Community Defense

Given the high volume of attacks, it is important to engage with our community partners to share insights and coordinate efforts against these threats. Collaboration within the cybersecurity community can enhance collective defense mechanisms.

Note: Data source: SSH 1399 conn/684 logins/701 cmds/31 IPs. GeoIP: total_ips: 1262

  • United States: 460 (36%)
  • China: 93 (7%)
  • Germany: 66 (5%)
  • United Kingdom: 57 (4%)
  • Belgium: 56 (4%)
  • Pakistan: 53 (4%)
  • Netherlands: 49 (3%)
  • Vietnam: 34 (2%)
  • Sweden: 31 (2%)

MCP Trap: Trapped 0 requests/0 IPs. Portscans: Open ports found but no malicious activity detected.

This analysis highlights the importance of continuous improvement in both offensive and defensive strategies, as well as collaboration within the cybersecurity community.


This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.