๐Ÿ”ด high

Daily Threat Report

590 SSH Connections
275 Login Attempts
460 Commands Run
49 SSH Unique IPs
11,840 Protocol Events
92 Protocol IPs
85 Web Hits
19 Web Service IPs
8 Reverse Scans
8 Scan Hits

Top Passwords Tried

  1. password123
  2. admin123
  3. root
  4. 123456
  5. ftpuser

๐ŸŒ WEB HONEYPOT โ€” HoneyAI HTTP

AI-generated fake HTTP responses served to 85 scanner requests from 19 unique IPs (local, offline).

Top Paths Probed

  1. /
  2. /login
  3. /wp-admin
  4. /dispatch.asp
  5. /.env
  6. /solr/admin/info/system

Top User-Agents

  1. Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
  2. Go-http-client/1.1
  3. curl/7.88.1
  4. Mozilla/5.0 (X11; Linux x86_64)

๐Ÿ’ฅ OPERATION SPINE โ€” Reverse Port Scanning

Active defense back-profiling: HoneyAI executed **8** reverse port-scans against active attacker IPs. Out of these, **8** hosts were found with open services.

# Automatic multi-platform threat intel reporting
$ honeypot-report.sh --since 24h
โ†’ 108 IPs โ†’ AbuseIPDB  (community confidence scores updated)
โ†’ 108 IPs โ†’ AlienVault OTX  (pulse indicators added)
โ†’ 108 IPs โ†’ Blocklist.de  (auto-ban list updated)
โ†’ 108 IPs โ†’ DShield/SANS  (global threat feed updated)

๐Ÿคฃ ATTACKER COMEDY CORNER

Real attempts. No actors were harmed in the making of this honeypot.

๐Ÿ”‘ Hall of Shame โ€” Passwords

password123
hunter2
letmein123

๐Ÿ’ป Commands They Tried

export PATH=$PATH:/tmp
cat /etc/shadow 2>/dev/null
rm -rf /root/.bash_history

These are real credentials and commands attempted by automated scanners and script kiddies. Logged, reported, and immortalized.

Daily Threat Intelligence Report โ€” 2026-08-13

Executive Overview

On August 13, 2026, the Honey-AI.Dev sensor grid logged 11840 threat events from 122 unique attacking IP addresses. Attack vectors spanned SSH, Telnet, HTTP, MySQL, MSSQL, and RDP.

Key Metrics Summary

  • Total Alert Events: 11840
  • Unique Attacker IPs: 122
  • SSH Connections: 590 (275 auth attempts, 460 commands executed)
  • Web Exploitation Requests (Galah): 85 across 19 unique endpoints
  • Threat Intel Reports Dispatched: 108 IPs reported to AbuseIPDB, Blocklist.de, DShield, and OTX.
โ† All Reports ๐Ÿ›ก๏ธ Subscribe to blocklists โ†’