Daily Threat Report
740 SSH Connections
360 Login Attempts
580 Commands Run
63 SSH Unique IPs
16,720 Protocol Events
128 Protocol IPs
130 Web Hits
28 Web Service IPs
8 Reverse Scans
8 Scan Hits
Top Attacker IPs
- ๐ 46.151.182.247 BGPโ
- ๐ 118.70.146.82 BGPโ
- ๐ 47.112.237.28 BGPโ
- ๐ 62.164.177.254 BGPโ
- ๐ 117.72.52.15 BGPโ
Top Passwords Tried
- root
- cisco
- 1234
- superman
- 123456789
๐ WEB HONEYPOT โ HoneyAI HTTP
AI-generated fake HTTP responses served to 130 scanner requests from 28 unique IPs (local, offline).
Top Paths Probed
- /
- /login
- /wp-admin
- /dispatch.asp
- /.env
- /solr/admin/info/system
Top User-Agents
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
- Go-http-client/1.1
- curl/7.88.1
- Mozilla/5.0 (X11; Linux x86_64)
๐ฅ OPERATION SPINE โ Reverse Port Scanning
Active defense back-profiling: HoneyAI executed **8** reverse port-scans against active attacker IPs. Out of these, **8** hosts were found with open services.
# Automatic multi-platform threat intel reporting $ honeypot-report.sh --since 24h โ 138 IPs โ AbuseIPDB (community confidence scores updated) โ 138 IPs โ AlienVault OTX (pulse indicators added) โ 138 IPs โ Blocklist.de (auto-ban list updated) โ 138 IPs โ DShield/SANS (global threat feed updated)
๐คฃ ATTACKER COMEDY CORNER
Real attempts. No actors were harmed in the making of this honeypot.
๐ Hall of Shame โ Passwords
root hunter2 letmein123 ๐ป Commands They Tried
export PATH=$PATH:/tmp cat /etc/shadow 2>/dev/null rm -rf /root/.bash_history These are real credentials and commands attempted by automated scanners and script kiddies. Logged, reported, and immortalized.
Daily Threat Intelligence Report โ 2026-08-12
Executive Overview
On August 12, 2026, the Honey-AI.Dev sensor grid logged 16720 threat events from 155 unique attacking IP addresses. Attack vectors spanned SSH, Telnet, HTTP, MySQL, MSSQL, and RDP.
Key Metrics Summary
- Total Alert Events: 16720
- Unique Attacker IPs: 155
- SSH Connections: 740 (360 auth attempts, 580 commands executed)
- Web Exploitation Requests (Galah): 130 across 28 unique endpoints
- Threat Intel Reports Dispatched: 138 IPs reported to AbuseIPDB, Blocklist.de, DShield, and OTX.