HoneyMire Hub

Attack #555968 telnet

Captured 2026-08-13 22:23:22Z by Ka on honeypot NY1 ⬜ docker-edge · firmware 0.1.0.

Source106.114.48.109:29989
Target port23
Authenticatedyes
Commands1
Duration35.3s

Session recording

Loading session…

Transcript

Server output and attacker input as captured, line-grain. Malware URLs are obscured until sign-in.

[MikroTik] > echo -e "\x47\x41\x59\x46\x47\x54"
-e x47x41x59x46x47x54
[MikroTik] > 

Credentials

Username: shel

Password: sh

3 login attempt(s) before disconnect.

Geolocation hub-resolved

🇨🇳China · Hebei · Shijiazhuang

Chinanet · AS4134 CHINANET BACKBONE · 38.04,114.47

Network: isp · China Telecom · NSP · peeringdb · medium confidence

Behavioral classification

🤖 55% confidence

Automated tool, unknown family — uniform timing but no matched signature.

Command summary

echo -e "\x47\x41\x59\x46\x47\x54"

Reported to threat intel

none

HoneyMire Hub · open feed: / · API: /api · docs: /docs · blocklists: /blocklists · about: /about · firmware: github.com/HoneyMire/HoneyMire