💀 critical 🤖 qwen2.5:1.5b

Honeypot Threat Analysis — August 29, 2026

Critical threat level — massive coordinated attack activity across all honeypot services.

ssh-brute-forcehoneypotweb-scanningmulti-protocolhigh-severitythreat-intelligence

Cybersecurity Analysis of the Honey-ai.dev Setup for August 29, 2026

Data Overview:

  • SSH Connections: 650 connections from 311 IPs (8% growth over the previous day)
  • Multi-Protocol Events: 19,247 events from 34 IPs (1.5x growth compared to the previous day)
  • HTTP Requests: 25 requests from 17 IPs
  • Suricata IDS Alerts: 15,624 alerts from 733 IPs (0.8x increase from the previous day)
  • Severity: Critical level for most events
  • Attackers Total: Approximately 71 attackers

Top Attackers:

  • IPs Reported Abused by AbuseIPDB: [85.239.151.18, 109.205.211.107, 109.205.211.106, 94.26.68.38]
  • Top Passwords: [“7804a56a5c7636cc”, “4813494d137e1631”, “8c6976e5b5410415”]

HTTP Paths:

  • Common paths include: [”/”, “/login”, “/v1/models”, “/SDK/webLanguage”, “/hachk.php”]
  • Top paths analyzed are likely login attempts, system files access, and possibly scanning activities.

Geographical Analysis:

  • Top Countries:
    • United States (29%)
    • China (10%)
    • Taiwan (6%)
    • Romania (5%)
    • Singapore (4%)
    • Netherlands (4%)
    • Turkey (4%)

Threat Overview

The setup witnessed a significant increase in both SSH and HTTP traffic, indicating a growing number of attackers targeting the honeypot. The multi-protocol events suggest an advanced level of threat actors with multiple tools at their disposal.

Geographic Analysis:

  • The majority of attacks originated from the United States, China, Taiwan, Romania, Singapore, Netherlands, Turkey, Seychelles, Germany, and Sweden.
  • These geographical distributions are indicative of international cybercrime networks operating across different countries.

SSH Brute Force

The increase in SSH connections to 650 is a concerning sign. The attackers have likely been engaged in password brute force attacks targeting the system’s default credentials or common weak passwords. The use of multiple IPs suggests coordinated efforts by the attackers, indicating a sophisticated level of planning and resource allocation.

Post-Exploitation

The presence of commands such as uname -s -v -n -r -m and cat /proc/cpuinfo grep name head -n 1 ... suggest that some attackers are probing for administrative access or system configuration details. This is a critical stage in the exploitation process, where attackers aim to gather information about the target’s environment.

Web Scanning

The increased number of HTTP requests (25) and the paths analyzed (e.g., “/login”, “/v1/models”, etc.) indicate that attackers are actively scanning for vulnerabilities or attempting to find a way into the honeypot. The use of specific endpoints suggests targeted probing rather than random web browsing.

IDS & Scan Intel

The high number of Suricata IDS alerts (15,624) is concerning. This indicates a large volume of suspicious activity that has been detected by the intrusion detection system, suggesting potential for malicious actors to be actively trying to exploit vulnerabilities in the environment.

Malware Capture:

  • No malware was captured during this period.
  • The absence of malware suggests that the honeypot remains a relatively safe and effective deterrent against malware attacks.

Tarpit

The fact that 120 connections were trapped but not exploited, indicating successful tarpitting (the process of slowing down an attacker to make them give up), is encouraging. This shows that the honeypot has been effectively detecting attackers’ attempts to exploit vulnerabilities, albeit without causing any damage.

Canarytokens

  • The presence of one trigger for a specific AWS token suggests that there may be ongoing monitoring or testing activities by security researchers.
  • It’s important to note that this should not necessarily indicate malicious intent but rather the effectiveness of continuous monitoring and the ability to detect such activity promptly.

MCP Trap

  • No requests were captured from the MCP trap, indicating that it has yet to successfully trigger an alert on any known malicious traffic patterns.
  • This could be due to a variety of reasons, including misconfiguration or non-relevant traffic that does not match the expected profile for this type of detection mechanism.

Portscans

  • No significant activity in port scans was observed, suggesting that the honeypot is effectively filtering and preventing such types of attacks. This is reassuring but highlights the importance of continuous monitoring to ensure no overlooked vulnerabilities are left unaddressed.

AI Defense

The absence of any injection or leak blocking indicates that the honeypot is primarily focused on collecting data rather than actively defending against real threats. The lack of proactive measures suggests a need for improved defense strategies to better secure the environment.

TTY Commands:

  • With 41 sessions being monitored, attackers are using a variety of commands to test various system vulnerabilities and functionalities.
  • This indicates that the honeypot is effective in detecting these types of activities but may require more comprehensive defense mechanisms to prevent actual exploitation attempts.

Conclusion

The setup on August 29, 2026, remains an active environment with ongoing threat detection efforts. The presence of multiple IP addresses and a high volume of events suggests a sophisticated level of attackers engaged in various stages of cybercrime activities. The combination of tarpitting, post-exploitation probing, and continuous IDS monitoring provides a robust defense system but requires further enhancement to address all potential threats comprehensively.

This setup serves as an excellent example for security professionals looking to create effective honeypots that can help identify and mitigate advanced persistent threats without causing actual harm.


This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.