Daily Threat Report
590 SSH Connections
275 Login Attempts
460 Commands Run
49 SSH Unique IPs
11,840 Protocol Events
92 Protocol IPs
85 Web Hits
19 Web Service IPs
8 Reverse Scans
8 Scan Hits
Top Attacker IPs
- ๐ 194.165.16.162 BGPโ
- ๐ 77.90.185.30 BGPโ
- ๐ 143.0.66.14 BGPโ
- ๐ 118.70.146.82 BGPโ
- ๐ 83.65.143.95 BGPโ
Top Passwords Tried
- password123
- admin123
- root
- 123456
- ftpuser
๐ WEB HONEYPOT โ HoneyAI HTTP
AI-generated fake HTTP responses served to 85 scanner requests from 19 unique IPs (local, offline).
Top Paths Probed
- /
- /login
- /wp-admin
- /dispatch.asp
- /.env
- /solr/admin/info/system
Top User-Agents
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
- Go-http-client/1.1
- curl/7.88.1
- Mozilla/5.0 (X11; Linux x86_64)
๐ฅ OPERATION SPINE โ Reverse Port Scanning
Active defense back-profiling: HoneyAI executed **8** reverse port-scans against active attacker IPs. Out of these, **8** hosts were found with open services.
# Automatic multi-platform threat intel reporting $ honeypot-report.sh --since 24h โ 108 IPs โ AbuseIPDB (community confidence scores updated) โ 108 IPs โ AlienVault OTX (pulse indicators added) โ 108 IPs โ Blocklist.de (auto-ban list updated) โ 108 IPs โ DShield/SANS (global threat feed updated)
๐คฃ ATTACKER COMEDY CORNER
Real attempts. No actors were harmed in the making of this honeypot.
๐ Hall of Shame โ Passwords
password123 hunter2 letmein123 ๐ป Commands They Tried
export PATH=$PATH:/tmp cat /etc/shadow 2>/dev/null rm -rf /root/.bash_history These are real credentials and commands attempted by automated scanners and script kiddies. Logged, reported, and immortalized.
Daily Threat Intelligence Report โ 2026-08-13
Executive Overview
On August 13, 2026, the Honey-AI.Dev sensor grid logged 11840 threat events from 122 unique attacking IP addresses. Attack vectors spanned SSH, Telnet, HTTP, MySQL, MSSQL, and RDP.
Key Metrics Summary
- Total Alert Events: 11840
- Unique Attacker IPs: 122
- SSH Connections: 590 (275 auth attempts, 460 commands executed)
- Web Exploitation Requests (Galah): 85 across 19 unique endpoints
- Threat Intel Reports Dispatched: 108 IPs reported to AbuseIPDB, Blocklist.de, DShield, and OTX.