🔴 high 🤖 qwen2.5:1.5b

Honeypot Threat Analysis — August 13, 2026

High severity threat level — continuous FTP authentication spray and Redis unauthenticated scans.

ssh-brute-forcehoneypotthreat-intelligencemulti-protocolhigh-severitythreat-analysis

Cybersecurity Threat Intelligence Analysis — August 13, 2026

Threat Landscape Overview

During the 24-hour observation cycle on August 13, 2026, Honey-AI.Dev recorded an active threat surface comprising 11840 telemetry events generated by 122 distinct adversarial sources.

The primary threat vector centered around Brute-force campaigns on legacy FTP endpoints coupled with unauthenticated Redis INFO queries..

Top Identified Threat Actors

  1. 194.165.16.162 — High-frequency dictionary attack engine targeting core SSH and database authentication sockets.
  2. 77.90.185.30 — Persistent credential spray probing RDP (3389/tcp) and MySQL (3306/tcp).
  3. 143.0.66.14 — Automated vulnerability scanning crawler inspecting CMS endpoints and exposed configuration files.

Protocol Breakdown & Attack Vector Analysis

  • SSH & Remote Terminal (22/tcp, 23/tcp): Recorded 590 connection attempts with 275 credential brute-force payloads. Top attempted usernames included root, admin, ubuntu, and service.
  • Database & Data Layer (3306/tcp, 1433/tcp, 6379/tcp): Sustained unauthenticated discovery commands targeting exposed relational and key-value datastores.
  • Web Application Fuzzing (Galah LLM Honeypot): Captured 85 HTTP requests probing for sensitive administrative routes, .env leakage, and arbitrary remote code execution paths.

Automated Defensive Actions

  • Community Threat Sharing: Dispatched 108 automated abuse reports to AbuseIPDB, Blocklist.de, SANS DShield, and AlienVault OTX.
  • Dynamic Firewall Mitigation: Real-time synchronization pushed active IP blocks across all perimeter nodes via CrowdSec multi-node decision mesh.