๐Ÿ’€ critical

Daily Threat Report

380 SSH Connections
310 Login Attempts
520 Commands Run
68 SSH Unique IPs
1,100 Protocol Events
44 Protocol IPs
95 Web Hits
34 Web Service IPs

Top Passwords Tried

  1. aad3f9ba1d6740cc
  2. 91566946b1d8deb0
  3. 8d969eef6ecad3c2
  4. admin123
  5. root

๐ŸŒ WEB HONEYPOT โ€” HoneyAI HTTP

AI-generated fake HTTP responses served to 95 scanner requests from 34 unique IPs (local, offline).

Top Paths Probed

  1. /SDK/webLanguage
  2. /.env
  3. /login
  4. /actuator/env
  5. /wp-login.php

Top User-Agents

  1. Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
  2. Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:132.0) Gecko/20100101 Firefox/132.0
  3. Go-http-client/1.1
  4. Mozilla/5.0
  5. curl/8.5.0
# Automatic multi-platform threat intel reporting
$ honeypot-report.sh --since 24h
โ†’ 164 IPs โ†’ AbuseIPDB  (community confidence scores updated)
โ†’ 164 IPs โ†’ AlienVault OTX  (pulse indicators added)
โ†’ 164 IPs โ†’ Blocklist.de  (auto-ban list updated)
โ†’ 164 IPs โ†’ DShield/SANS  (global threat feed updated)

๐Ÿคฃ ATTACKER COMEDY CORNER

Real attempts. No actors were harmed in the making of this honeypot.

๐Ÿ”‘ Hall of Shame โ€” Passwords

aad3f9ba1d6740cc
91566946b1d8deb0
admin123
password
root

๐Ÿ’ป Commands They Tried

cd ~ && rm -rf .ssh && mkdir .ssh && echo $_dqssh-rsa AAAAB3NzaC1yc2EAAA...mdrfckr$_dq>>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~
uname -a
/bin/./uname -s -v -n -r -m

These are real credentials and commands attempted by automated scanners and script kiddies. Logged, reported, and immortalized.

Automated report for 11 de June de 2026. Recorded 380 SSH connections and 1100 multi-protocol decoy events on HoneyAI, from 112 unique IPs. 164 IPs were automatically reported to the AbuseIPDB community database.

SSH Activity (HoneyAI)

The SSH service received 310 login attempts from 68 unique IPs. Attackers executed 520 commands after gaining simulated system access.

Multi-Protocol Decoys (HoneyAI)

Detected 1100 events across services including FTP, Telnet, SMTP, MySQL, Redis, Git, VNC, and RDP from 44 distinct IPs. All events are access attempts against simulated production services.

HTTP Web Service (HoneyAI)

The web service received 95 HTTP requests from real scanners across 34 unique IPs. Each attacker received a fake response generated in real time by the local AI engine (Ollama, no internet connection required).

Notable scanner 45.88.138.44 hammered /actuator/env, /actuator/health, /_debug, /debug/vars, and /console endpoints repeatedly. This IP was permanently blocked after sustained abuse.

Network IDS (Suricata)

The network intrusion detection system generated 20409 alerts from 1365 unique source IPs. Suricata monitors all traffic on the primary network interface using Emerging Threats + AlienVault OTX rulesets.

โ† All Reports ๐Ÿ›ก๏ธ Subscribe to blocklists โ†’