HoneyMire Hub

Public stats

Aggregate attack telemetry from users who opted into the public feed. Auto-refreshes every 30s.

Total attacks555,929all-time
Attacks 24h4,468last 24 hours
Unique attackers31,6241,155 in 24h
Returning attackers8,81127.9% of uniques
Auth success rate97.5%398,302 of 408,663 known
Avg commands5.7per session
Avg session50.6 sduration
Public reporters1opted-in users
World coverage15.0%3/20 areas
Countries covered4honeypot locations
Public honeypots54 online · 1 offline
Commands captured1,978,942across all sessions
Avg severity37174,182 high/critical
CVE attempts0CVE-ID references seen
Pre-session probes20,274,432connects before sessions
Bandwidth in175.6 MiBfrom attackers
Bandwidth out182.6 MiBhoneypot replies
Avg response4 mshoneypot latency

Activity over time

Attacks per hour

Last 24 hours, hourly buckets.

Attacks per day

Last 7 days, midnight-UTC buckets.

Time of day (UTC)

All-time activity by UTC hour — when attackers hit the hub.

Time of day (attacker-local)

All-time activity by hour in the attacker's local time, approximated from their country code (DST ignored).

Day of week (UTC)

All-time activity by UTC weekday.

Honeypot fleet

World coverage

Coverage score is based on 20 practical deployment areas. One public honeypot in each area reaches 100%; extra honeypots add resilience but do not inflate the score.

Western Europe
3
North America - East
1
Southeast Asia
1

Honeypot countries

🇱🇺Luxembourg
2
🇫🇷France
1
🇸🇬Singapore
1
🇺🇸United States
1
CountryHoneypots
🇱🇺Luxembourg 2
🇫🇷France 1
🇸🇬Singapore 1
🇺🇸United States 1

Hardware boards

ESP32 variants reporting to public feeds.

docker-edge 4 80.0%
esp32-c3-supermini 1 20.0%
BoardCount
docker-edge 4
esp32-c3-supermini 1

Firmware versions

FirmwareCount
0.1.0 4
1.1.0 1

Sensors online/offline

Online = reported in the last 15 minutes.

online 4 80.0%
offline 1 20.0%

Sensor uptime distribution

How long each honeypot has been up since its last reboot, last reported by the firmware.

< 1 hour
1
7 – 30 days
1
30+ days
3

Attack geography

Top source countries

🇨🇳China
97652
🇳🇱The Netherlands
87634
🇵🇰Pakistan
73628
🇺🇸United States
69759
🇷🇺Russia
23889
🇬🇧United Kingdom
21067
🇩🇪Germany
15185
🇵🇱Poland
15008
🇮🇳India
11763
🇧🇷Brazil
11278
CountryAttacks
🇨🇳China 97652
🇳🇱The Netherlands 87634
🇵🇰Pakistan 73628
🇺🇸United States 69759
🇷🇺Russia 23889
🇬🇧United Kingdom 21067
🇩🇪Germany 15185
🇵🇱Poland 15008
🇮🇳India 11763
🇧🇷Brazil 11278

Top target countries

🇱🇺Luxembourg
260821
🇫🇷France
108148
🇸🇬Singapore
105878
🇺🇸United States
81082
CountryAttacks
🇱🇺Luxembourg 260821
🇫🇷France 108148
🇸🇬Singapore 105878
🇺🇸United States 81082

Attacker → target countries

AttackerTargetCount
🇵🇰Pakistan 🇱🇺Luxembourg 72239
🇨🇳China 🇱🇺Luxembourg 60722
🇳🇱The Netherlands 🇱🇺Luxembourg 31234
🇳🇱The Netherlands 🇫🇷France 24662
🇳🇱The Netherlands 🇸🇬Singapore 23126
🇺🇸United States 🇱🇺Luxembourg 22759
🇷🇺Russia 🇱🇺Luxembourg 21830
🇺🇸United States 🇸🇬Singapore 17221
🇺🇸United States 🇺🇸United States 15189
🇨🇳China 🇫🇷France 15007
🇺🇸United States 🇫🇷France 14590
🇨🇳China 🇺🇸United States 12669
🇵🇱Poland 🇸🇬Singapore 9502
🇨🇳China 🇸🇬Singapore 9254
🇩🇪Germany 🇺🇸United States 9094

Attack attributes

Protocol split

telnet 356480 64.1%
ssh 199449 35.9%

Top target ports

Destination port the attacker connected to on the honeypot. Inferred from protocol when not reported.

23 (telnet)
356480
22 (ssh)
199449

Authentication outcomes

Whether the honeypot let the attacker in (after its configured threshold).

authenticated 398302 71.6%
unknown 147266 26.5%
rejected 10361 1.9%

Attacker profiles

Behavioral classification from the firmware.

creds-only 211508 38.0%
mirai 209249 37.6%
scripted 123505 22.2%
creds-probe 9913 1.8%
iot-loader 1343 0.2%
scanner 410 0.1%
recon-script 1 0.0%
ProfileCount
creds-only 211508
mirai 209249
scripted 123505
creds-probe 9913
iot-loader 1343
scanner 410
recon-script 1

Network / ASN

Top ASNs

ASNCount
AS47890 UNMANAGED LTD 71055
AS4837 CHINA UNICOM China169 Backbone 51741
AS14061 DigitalOcean, LLC 36031
AS9541 Cyber Internet Services (Pvt) Ltd. 27844
AS4134 CHINANET BACKBONE 24590
AS8359 MTS PJSC 16128
AS48090 TECHOFF SRV LIMITED 13573
AS138423 CMPak Limited 11886
AS398101 GoDaddy.com, LLC 9409
AS201814 MEVSPACE sp. z o.o. 8514

Network types

unknown 223234 40.2%
isp 151133 27.2%
residential 90142 16.2%
cdn 88670 15.9%
enterprise 2655 0.5%
education 95 0.0%
TypeCount
unknown 223234
isp 151133
residential 90142
cdn 88670
enterprise 2655
education 95

Top network providers

ProviderCount
Unmanaged LTD 71055
China Unicom 51752
DigitalOcean 36034
China Telecom 32760
Cyber Internet Services 27844
CMPak Limited 17051
Mobile TeleSystems PJSC 16128
Techoff SRV Limited 13573
GoDaddy.com, LLC 9409
Mevspace 8514

Target exposure by provider

Target ISP / networkCount
POST Luxembourg 166941
OVH SAS 108148
M247 Europe SRL 105878
Servers.com, Inc. 93880
HostPapa 81082

Network confidence

medium 332695 59.8%
low 222974 40.1%
unknown 260 0.0%

ASN → target countries

ASNTargetCount
AS4837 CHINA UNICOM China169 Backbone 🇱🇺Luxembourg 46501
AS47890 UNMANAGED LTD 🇱🇺Luxembourg 28952
AS9541 Cyber Internet Services (Pvt) Ltd. 🇱🇺Luxembourg 27392
AS47890 UNMANAGED LTD 🇫🇷France 18132
AS47890 UNMANAGED LTD 🇸🇬Singapore 16168
AS8359 MTS PJSC 🇱🇺Luxembourg 16072
AS138423 CMPak Limited 🇱🇺Luxembourg 11787
AS14061 DigitalOcean, LLC 🇫🇷France 10737
AS14061 DigitalOcean, LLC 🇱🇺Luxembourg 9790
AS14061 DigitalOcean, LLC 🇺🇸United States 8845
AS47890 UNMANAGED LTD 🇺🇸United States 7803
AS23888 National Telecommunication Corporation HQ, 🇱🇺Luxembourg 7603
AS201814 MEVSPACE sp. z o.o. 🇸🇬Singapore 7397
AS48090 TECHOFF SRV LIMITED 🇫🇷France 7302
AS4134 CHINANET BACKBONE 🇺🇸United States 7133

ASN → target ASN

Attacker ASNTarget ASNCount
AS4837 CHINA UNICOM China169 Backbone AS6661 POST Luxembourg 44436
AS47890 UNMANAGED LTD AS7979 Servers.com, Inc. 28951
AS9541 Cyber Internet Services (Pvt) Ltd. AS6661 POST Luxembourg 26993
AS47890 UNMANAGED LTD AS16276 OVH SAS 18132
AS47890 UNMANAGED LTD AS9009 M247 Europe SRL 16168
AS8359 MTS PJSC AS6661 POST Luxembourg 16043
AS138423 CMPak Limited AS6661 POST Luxembourg 11677
AS14061 DigitalOcean, LLC AS16276 OVH SAS 10737
AS14061 DigitalOcean, LLC AS36352 HostPapa 8845
AS47890 UNMANAGED LTD AS36352 HostPapa 7803
AS23888 National Telecommunication Corporation HQ, AS6661 POST Luxembourg 7574
AS201814 MEVSPACE sp. z o.o. AS9009 M247 Europe SRL 7397
AS48090 TECHOFF SRV LIMITED AS16276 OVH SAS 7302
AS4134 CHINANET BACKBONE AS36352 HostPapa 7133
AS4134 CHINANET BACKBONE AS16276 OVH SAS 6909

Network type → target countries

Network typeTargetCount
isp 🇱🇺Luxembourg 109392
unknown 🇱🇺Luxembourg 82971
unknown 🇫🇷France 55387
residential 🇱🇺Luxembourg 51858
unknown 🇸🇬Singapore 47668
unknown 🇺🇸United States 37208
cdn 🇫🇷France 28098
cdn 🇸🇬Singapore 22582
cdn 🇺🇸United States 22044
residential 🇸🇬Singapore 21212
cdn 🇱🇺Luxembourg 15946
isp 🇫🇷France 14674
isp 🇺🇸United States 13761
isp 🇸🇬Singapore 13306
residential 🇫🇷France 9579

Credentials & content

Top attacker IPs

Most active source addresses on the public feed.

IPCount
80.94.92.128 13773
193.34.212.136 7022
146.0.42.48 6824
87.251.64.176 6115
210.245.120.117 5250
80.94.92.167 5175
195.178.110.30 4947
80.94.92.177 4697
80.94.92.164 4565
80.94.92.187 4553

Top credential pairs

Aggregated across public feeds.

user : passCount
system:shell 37581
support:support 11824
0:0 10784
admin:admin 8117
admin:admin123 7888
root:Zte521 6828
root: 5450
sol:sol 4918
root:root 4230
admin:1234 4086

Top usernames

Aggregated across public feeds.

UsernameCount
root 150305
admin 76215
system 38439
support 14542
sol 13432
0 10784
solana 8928
ubuntu 8559
guest 7106
user 6800

Top passwords

Aggregated across public feeds.

PasswordCount
shell 37584
123456 16351
1234 14777
admin 13634
support 11835
0 10886
admin123 8567
12345 8428
Zte521 6828
12345678 6392

Top command chains

Command chainCount
/bin/./uname -s -v -n -r -m 53468
sh /bin/busybox UNSTABLE 26966
uname -s -v -n -r -m 24894
uname -a 15215
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH uname=$(uname -s -v -n -m 2>/dev/null || /bin/uname -s -v -n -m 2>/dev/null || /usr/bin/uname -s -... 15136
cd ~; chattr -ia .ssh; lockr -ia .ssh 11414
sh 6779
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH uname=$(uname -s -v -n -m 2>/dev/null) arch=$(uname -m 2>/dev/null) uptime=$(cat /proc/uptime 2>/d... 5322
start enable config terminal system linuxshell su shell sh >/var/run/.x&&cd /var/run;>/mnt/.x&&cd /mnt;>/usr/.x&&cd /usr;>/dev/.x&&cd /dev;>/dev/shm/.x&&cd /dev/shm;>/tmp/.x&&cd... 3012
start enable config terminal system linuxshell su shell sh >/var/run/.x&&cd /var/run;>/mnt/.x&&cd /mnt;>/usr/.x&&cd /usr;>/dev/.x&&cd /dev;>/dev/shm/.x&&cd /dev/shm;>/tmp/.x&&cd... 2974

Top malware URLs

URLCount
http://192.168.1.1:8088/i 30432
http://90.224.208.161:48263/i 17937
http://81.229.60.159:58639/i 12711
http://90.228.239.131:37930/i 9987
http://174.105.154.212:40964/i 9771
http://46.236.65.235:51725/i 9093
http://109.236.46.215:59913/i 8850
http://123.232.142.200:55377/i 8787
http://42.224.99.236:38337/i 8553
http://90.224.208.190:45821/i 7485

Threat assessment

Severity distribution

Hub-computed score (0-100) per attack: informational ≤ 1, low < 40, medium < 70, high < 90, critical ≥ 90. Older rows that pre-date scoring show as unscored.

informational 154227 27.7%
low 191047 34.4%
medium 36473 6.6%
high 174168 31.3%
critical 14 0.0%
BandCount
informational 154227
low 191047
medium 36473
high 174168
critical 14

Top CVE references

CVE-IDs extracted from command summaries (and explicit firmware reports). Useful for spotting CVE-driven scanner waves.

No CVE references seen yet.

Top reverse-DNS suffixes

Last 2-3 labels of the PTR record per attacker IP. Local resolver only — no third-party intel feeds.

SuffixCount
ny.adsl 19721
mts-chita.ru 16167
server-hosting.expert 6824
secureserver.net 5274
com.vn 5250
lionwire.com 4480
kbacarparts.co.uk 4475
tronicsat.com 4388
personaliseplus.com 3379
as55666.net 3027
unifiedlayer.com 2834
fastcloud.id 2717

Client fingerprints

Top client banners

Raw banner the attacker tool announced (e.g. SSH-2.0-libssh_0.9.6).

BannerCount
SSH-2.0-Go 150292
root 65705
admin 40989
SSH-2.0-PuTTY_Release_0.84 14261
SSH-2.0-libssh_0.9.6 10326
SSH-2.0-libssh2_1.8.1 6363
SSH-2.0-OpenSSH_7.4 4923
guest 3430
super 3323
support 2784

Top HASSH fingerprints

MD5 over SSH client KEXINIT algorithm lists.

No HASSH fingerprints yet — firmware must capture and report.

Top JA3 fingerprints

MD5 over TLS ClientHello (only applicable when the listener speaks TLS).

No JA3 fingerprints yet — firmware must capture and report.

SSH probing

SSH key types

Algorithm of public keys offered before any password attempt.

ssh-rsa 17 63.0%
ssh-dss 8 29.6%
ssh-ed25519 2 7.4%
Key typeCount
ssh-rsa 17
ssh-dss 8
ssh-ed25519 2

Top SSH key fingerprints

FingerprintCount
SHA256:/JLp6z6uGE3BPcs70RQob6QOdEWQ6nDC0xY7ejPOCc0 8
SHA256:WL+QR9x+2QKzI6U4Ks7LPXWa0Vb22vjSn0groO1Ao8k 8
SHA256:f2HQeWaKQsmlbtBgUTxZfhSKRYU54OtEtSRitoTmOp4 6
SHA256:TVLyd6EqeDPt6s0oQtYUYAUCygiABg6kAEGstS2pq7U 2
SHA256:78ZIMBycE34nu4OXOrklc4gUgR6i0acuh6yeM6tGRA8 1
SHA256:pjD1AGDXnd8PXgnrLAv7WTkPeV0xGAL0xooPKb2uyFI 1
SHA256:Wv4u5KOGs5/xiDvId+VaJ36TLUAy1ACQMDZSt441gP8 1

Threat-intel reporting

Reported-to services

Where the firmware has already submitted these attacks (for cross-referencing — the hub does NOT re-submit).

ServiceCount
otx 87385

HoneyMire Hub · open feed: / · API: /api · docs: /docs · blocklists: /blocklists · about: /about · firmware: github.com/HoneyMire/HoneyMire