Daily Threat Report
792 SSH Connections
415 Login Attempts
620 Commands Run
67 SSH Unique IPs
18,450 Protocol Events
136 Protocol IPs
145 Web Hits
31 Web Service IPs
8 Reverse Scans
8 Scan Hits
Top Attacker IPs
- ๐ 118.70.146.82 BGPโ
- ๐ 62.164.177.254 BGPโ
- ๐ 117.72.52.15 BGPโ
- ๐ 47.112.237.28 BGPโ
- ๐ 83.65.143.95 BGPโ
Top Passwords Tried
- admin2026
- root
- 12345
- guest
- oracle
๐ WEB HONEYPOT โ HoneyAI HTTP
AI-generated fake HTTP responses served to 145 scanner requests from 31 unique IPs (local, offline).
Top Paths Probed
- /
- /login
- /wp-admin
- /dispatch.asp
- /.env
- /solr/admin/info/system
Top User-Agents
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
- Go-http-client/1.1
- curl/7.88.1
- Mozilla/5.0 (X11; Linux x86_64)
๐ฅ OPERATION SPINE โ Reverse Port Scanning
Active defense back-profiling: HoneyAI executed **8** reverse port-scans against active attacker IPs. Out of these, **8** hosts were found with open services.
# Automatic multi-platform threat intel reporting $ honeypot-report.sh --since 24h โ 146 IPs โ AbuseIPDB (community confidence scores updated) โ 146 IPs โ AlienVault OTX (pulse indicators added) โ 146 IPs โ Blocklist.de (auto-ban list updated) โ 146 IPs โ DShield/SANS (global threat feed updated)
๐คฃ ATTACKER COMEDY CORNER
Real attempts. No actors were harmed in the making of this honeypot.
๐ Hall of Shame โ Passwords
admin2026 hunter2 letmein123 ๐ป Commands They Tried
export PATH=$PATH:/tmp cat /etc/shadow 2>/dev/null rm -rf /root/.bash_history These are real credentials and commands attempted by automated scanners and script kiddies. Logged, reported, and immortalized.
Daily Threat Intelligence Report โ 2026-08-10
Executive Overview
On August 10, 2026, the Honey-AI.Dev sensor grid logged 18450 threat events from 168 unique attacking IP addresses. Attack vectors spanned SSH, Telnet, HTTP, MySQL, MSSQL, and RDP.
Key Metrics Summary
- Total Alert Events: 18450
- Unique Attacker IPs: 168
- SSH Connections: 792 (415 auth attempts, 620 commands executed)
- Web Exploitation Requests (Galah): 145 across 31 unique endpoints
- Threat Intel Reports Dispatched: 146 IPs reported to AbuseIPDB, Blocklist.de, DShield, and OTX.