🔴 high 🤖 qwen2.5:1.5b

Honeypot Threat Analysis — August 9, 2026

High severity threat level — sustained SSH brute-force campaigns and MSSQL probing.

ssh-brute-forcehoneypotthreat-intelligencemulti-protocolhigh-severitythreat-analysis

Cybersecurity Threat Intelligence Analysis — August 9, 2026

Threat Landscape Overview

During the 24-hour observation cycle on August 9, 2026, Honey-AI.Dev recorded an active threat surface comprising 14280 telemetry events generated by 142 distinct adversarial sources.

The primary threat vector centered around SSH credential stuffing from APAC subnets alongside automated MSSQL dictionary sweeps..

Top Identified Threat Actors

  1. 47.112.237.28 — High-frequency dictionary attack engine targeting core SSH and database authentication sockets.
  2. 118.70.146.82 — Persistent credential spray probing RDP (3389/tcp) and MySQL (3306/tcp).
  3. 77.90.185.30 — Automated vulnerability scanning crawler inspecting CMS endpoints and exposed configuration files.

Protocol Breakdown & Attack Vector Analysis

  • SSH & Remote Terminal (22/tcp, 23/tcp): Recorded 684 connection attempts with 312 credential brute-force payloads. Top attempted usernames included root, admin, ubuntu, and service.
  • Database & Data Layer (3306/tcp, 1433/tcp, 6379/tcp): Sustained unauthenticated discovery commands targeting exposed relational and key-value datastores.
  • Web Application Fuzzing (Galah LLM Honeypot): Captured 112 HTTP requests probing for sensitive administrative routes, .env leakage, and arbitrary remote code execution paths.

Automated Defensive Actions

  • Community Threat Sharing: Dispatched 128 automated abuse reports to AbuseIPDB, Blocklist.de, SANS DShield, and AlienVault OTX.
  • Dynamic Firewall Mitigation: Real-time synchronization pushed active IP blocks across all perimeter nodes via CrowdSec multi-node decision mesh.