Daily Threat Report
684 SSH Connections
312 Login Attempts
548 Commands Run
58 SSH Unique IPs
14,280 Protocol Events
114 Protocol IPs
112 Web Hits
24 Web Service IPs
8 Reverse Scans
8 Scan Hits
Top Attacker IPs
- ๐ 47.112.237.28 BGPโ
- ๐ 118.70.146.82 BGPโ
- ๐ 77.90.185.30 BGPโ
- ๐ 194.165.16.162 BGPโ
- ๐ 46.151.182.247 BGPโ
Top Passwords Tried
- root123
- admin
- 123456
- password
- support
๐ WEB HONEYPOT โ HoneyAI HTTP
AI-generated fake HTTP responses served to 112 scanner requests from 24 unique IPs (local, offline).
Top Paths Probed
- /
- /login
- /wp-admin
- /dispatch.asp
- /.env
- /solr/admin/info/system
Top User-Agents
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
- Go-http-client/1.1
- curl/7.88.1
- Mozilla/5.0 (X11; Linux x86_64)
๐ฅ OPERATION SPINE โ Reverse Port Scanning
Active defense back-profiling: HoneyAI executed **8** reverse port-scans against active attacker IPs. Out of these, **8** hosts were found with open services.
# Automatic multi-platform threat intel reporting $ honeypot-report.sh --since 24h โ 128 IPs โ AbuseIPDB (community confidence scores updated) โ 128 IPs โ AlienVault OTX (pulse indicators added) โ 128 IPs โ Blocklist.de (auto-ban list updated) โ 128 IPs โ DShield/SANS (global threat feed updated)
๐คฃ ATTACKER COMEDY CORNER
Real attempts. No actors were harmed in the making of this honeypot.
๐ Hall of Shame โ Passwords
root123 hunter2 letmein123 ๐ป Commands They Tried
export PATH=$PATH:/tmp cat /etc/shadow 2>/dev/null rm -rf /root/.bash_history These are real credentials and commands attempted by automated scanners and script kiddies. Logged, reported, and immortalized.
Daily Threat Intelligence Report โ 2026-08-09
Executive Overview
On August 9, 2026, the Honey-AI.Dev sensor grid logged 14280 threat events from 142 unique attacking IP addresses. Attack vectors spanned SSH, Telnet, HTTP, MySQL, MSSQL, and RDP.
Key Metrics Summary
- Total Alert Events: 14280
- Unique Attacker IPs: 142
- SSH Connections: 684 (312 auth attempts, 548 commands executed)
- Web Exploitation Requests (Galah): 112 across 24 unique endpoints
- Threat Intel Reports Dispatched: 128 IPs reported to AbuseIPDB, Blocklist.de, DShield, and OTX.