๐Ÿ’€ critical

Daily Threat Report

820 SSH Connections
430 Login Attempts
690 Commands Run
74 SSH Unique IPs
19,800 Protocol Events
148 Protocol IPs
175 Web Hits
36 Web Service IPs
8 Reverse Scans
8 Scan Hits

Top Passwords Tried

  1. root
  2. admin
  3. 123456
  4. administrator
  5. service

๐ŸŒ WEB HONEYPOT โ€” HoneyAI HTTP

AI-generated fake HTTP responses served to 175 scanner requests from 36 unique IPs (local, offline).

Top Paths Probed

  1. /
  2. /login
  3. /wp-admin
  4. /dispatch.asp
  5. /.env
  6. /solr/admin/info/system

Top User-Agents

  1. Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
  2. Go-http-client/1.1
  3. curl/7.88.1
  4. Mozilla/5.0 (X11; Linux x86_64)

๐Ÿ’ฅ OPERATION SPINE โ€” Reverse Port Scanning

Active defense back-profiling: HoneyAI executed **8** reverse port-scans against active attacker IPs. Out of these, **8** hosts were found with open services.

# Automatic multi-platform threat intel reporting
$ honeypot-report.sh --since 24h
โ†’ 162 IPs โ†’ AbuseIPDB  (community confidence scores updated)
โ†’ 162 IPs โ†’ AlienVault OTX  (pulse indicators added)
โ†’ 162 IPs โ†’ Blocklist.de  (auto-ban list updated)
โ†’ 162 IPs โ†’ DShield/SANS  (global threat feed updated)

๐Ÿคฃ ATTACKER COMEDY CORNER

Real attempts. No actors were harmed in the making of this honeypot.

๐Ÿ”‘ Hall of Shame โ€” Passwords

root
hunter2
letmein123

๐Ÿ’ป Commands They Tried

export PATH=$PATH:/tmp
cat /etc/shadow 2>/dev/null
rm -rf /root/.bash_history

These are real credentials and commands attempted by automated scanners and script kiddies. Logged, reported, and immortalized.

Daily Threat Intelligence Report โ€” 2026-08-14

Executive Overview

On August 14, 2026, the Honey-AI.Dev sensor grid logged 19800 threat events from 178 unique attacking IP addresses. Attack vectors spanned SSH, Telnet, HTTP, MySQL, MSSQL, and RDP.

Key Metrics Summary

  • Total Alert Events: 19800
  • Unique Attacker IPs: 178
  • SSH Connections: 820 (430 auth attempts, 690 commands executed)
  • Web Exploitation Requests (Galah): 175 across 36 unique endpoints
  • Threat Intel Reports Dispatched: 162 IPs reported to AbuseIPDB, Blocklist.de, DShield, and OTX.
โ† All Reports ๐Ÿ›ก๏ธ Subscribe to blocklists โ†’