Skip to content

Honeypot experiment

Results

Statistics from both honeypots. Every chart and table states its time window, the source CSV and the script that computed it – so anyone can recompute the numbers their own way.

Data updated: 2026-10-03 10:31:16 UTC+02:00

Report a problem

Port ranking #


The main table of the experiment: which ports attackers were most interested in. Sort by any column, filter by server, and search for a specific port, range or service name. Every row can be linked to, for example #port-3389.

For srv4, the real destination port from hptcp is used. Redirect ports (42222, 42223, 42280, 42443) are not counted as destination ports.
Port Protocol Typical service Server Attempts Unique IPs Share
9000 tcp PHP-FPM both servers 8,044 871 0.1%
2376 tcp Docker TLS both servers 8,020 329 0.1%
8443 tcp HTTPS alt srv4 7,903 949 0.2%
3389 tcp RDP srv3 7,549 1,281 0.5%
8443 tcp HTTPS alt srv3 7,522 1,135 0.5%
2375 tcp Docker API both servers 7,294 489 0.1%
8080 tcp HTTP proxy both servers 7,250 1,153 0.1%
1433 tcp MSSQL both servers 7,198 540 0.1%
8080 tcp HTTP proxy srv4 6,445 994 0.2%
8000 tcp HTTP alt srv3 6,316 622 0.4%
Time window
2026-08-21 – 2026-09-16
Source data
honeypot-ports-aggregated-20260922.csv
Script
to be published
Format
field documentation

Traffic over time #


Event volume over time, split into campaigns and baseline noise, with the number of unique IP addresses below it. According to the agents’ journals, single campaigns could produce most of a day’s traffic. Without the split the chart would mislead: a campaign would look like a trend and its end like a collection outage.

Exactly how campaigns are separated from baseline noise is defined by the script listed below the chart.

Events

  • Baseline noise
  • Campaigns
0200k400k600k800k08-222026-08-22 Baseline noise: 22,460 Campaigns: 59,843 Total: 82,303 Incomplete period – data for 12 h / 24 h2026-08-23 Baseline noise: 45,099 Campaigns: 34,177 Total: 79,2762026-08-24 Baseline noise: 38,153 Campaigns: 10,775 Total: 48,92808-252026-08-25 Baseline noise: 40,077 Campaigns: 29,825 Total: 69,9022026-08-26 Baseline noise: 40,083 Campaigns: 28,709 Total: 68,7922026-08-27 Baseline noise: 42,664 Campaigns: 161,642 Total: 204,30608-282026-08-28 Baseline noise: 42,779 Campaigns: 159,044 Total: 201,8232026-08-29 Baseline noise: 34,634 Campaigns: 171,641 Total: 206,2752026-08-30 Baseline noise: 37,426 Campaigns: 148,263 Total: 185,68908-312026-08-31 Baseline noise: 35,671 Campaigns: 504,248 Total: 539,9192026-09-01 Baseline noise: 53,935 Campaigns: 666,265 Total: 720,2002026-09-02 Baseline noise: 65,803 Campaigns: 209,955 Total: 275,75809-032026-09-03 Baseline noise: 46,703 Campaigns: 227,972 Total: 274,6752026-09-04 Baseline noise: 51,972 Campaigns: 167,450 Total: 219,4222026-09-05 Baseline noise: 58,392 Campaigns: 95,631 Total: 154,02309-062026-09-06 Baseline noise: 85,408 Campaigns: 46,399 Total: 131,8072026-09-07 Baseline noise: 89,526 Campaigns: 94,877 Total: 184,4032026-09-08 Baseline noise: 109,966 Campaigns: 59,781 Total: 169,74709-092026-09-09 Baseline noise: 128,711 Campaigns: 48,861 Total: 177,5722026-09-10 Baseline noise: 132,528 Campaigns: 60,866 Total: 193,3942026-09-11 Baseline noise: 147,151 Campaigns: 63,267 Total: 210,41809-122026-09-12 Baseline noise: 171,996 Campaigns: 82,831 Total: 254,8272026-09-13 Baseline noise: 131,895 Campaigns: 105,016 Total: 236,9112026-09-14 Baseline noise: 129,805 Campaigns: 83,835 Total: 213,64009-152026-09-15 Baseline noise: 112,933 Campaigns: 159,141 Total: 272,0742026-09-16 Baseline noise: 72,402 Campaigns: 28,713 Total: 101,115 Incomplete period – data for 12 h / 24 h

Unique IP addresses

Distinct source IP addresses on each day.

  • srv3
  • srv4
02k4k6ksrv4srv308-2208-2508-2808-3109-0309-0609-0909-1209-152026-08-22 srv3: 547 srv4: 1,870 Incomplete period – data for 12 h / 24 h2026-08-23 srv3: 1,292 srv4: 3,5292026-08-24 srv3: 1,429 srv4: 3,3092026-08-25 srv3: 1,552 srv4: 3,8242026-08-26 srv3: 1,552 srv4: 3,7752026-08-27 srv3: 1,585 srv4: 4,3012026-08-28 srv3: 1,364 srv4: 4,0832026-08-29 srv3: 1,029 srv4: 3,8532026-08-30 srv3: 975 srv4: 4,1762026-08-31 srv3: 1,488 srv4: 4,1832026-09-01 srv3: 1,573 srv4: 4,5002026-09-02 srv3: 1,859 srv4: 4,2812026-09-03 srv3: 1,621 srv4: 4,3432026-09-04 srv3: 1,628 srv4: 4,0872026-09-05 srv3: 1,535 srv4: 4,1172026-09-06 srv3: 1,637 srv4: 4,3492026-09-07 srv3: 1,494 srv4: 4,4022026-09-08 srv3: 1,758 srv4: 4,6092026-09-09 srv3: 1,733 srv4: 4,6712026-09-10 srv3: 1,818 srv4: 5,0952026-09-11 srv3: 1,747 srv4: 5,4022026-09-12 srv3: 1,859 srv4: 5,4502026-09-13 srv3: 1,854 srv4: 5,4342026-09-14 srv3: 1,994 srv4: 5,5162026-09-15 srv3: 1,884 srv4: 5,3032026-09-16 srv3: 1,386 srv4: 3,449 Incomplete period – data for 12 h / 24 h

Unique IP addresses cannot be summed across servers – the same address may have attacked both. Each server therefore gets a line of its own.

Dimmed columns and hollow markers are incomplete periods: the collection window opens and closes at 12:00 UTC, and a period cut short by the chosen range is shorter than the rest. Don’t compare them with their neighbours.

Show values as a table
Day (UTC) Events Campaigns Baseline noise Unique IPs srv3 Unique IPs srv4
2026-08-22 · incomplete 82,303 59,843 22,460 547 1,870
2026-08-23 79,276 34,177 45,099 1,292 3,529
2026-08-24 48,928 10,775 38,153 1,429 3,309
2026-08-25 69,902 29,825 40,077 1,552 3,824
2026-08-26 68,792 28,709 40,083 1,552 3,775
2026-08-27 204,306 161,642 42,664 1,585 4,301
2026-08-28 201,823 159,044 42,779 1,364 4,083
2026-08-29 206,275 171,641 34,634 1,029 3,853
2026-08-30 185,689 148,263 37,426 975 4,176
2026-08-31 539,919 504,248 35,671 1,488 4,183
2026-09-01 720,200 666,265 53,935 1,573 4,500
2026-09-02 275,758 209,955 65,803 1,859 4,281
2026-09-03 274,675 227,972 46,703 1,621 4,343
2026-09-04 219,422 167,450 51,972 1,628 4,087
2026-09-05 154,023 95,631 58,392 1,535 4,117
2026-09-06 131,807 46,399 85,408 1,637 4,349
2026-09-07 184,403 94,877 89,526 1,494 4,402
2026-09-08 169,747 59,781 109,966 1,758 4,609
2026-09-09 177,572 48,861 128,711 1,733 4,671
2026-09-10 193,394 60,866 132,528 1,818 5,095
2026-09-11 210,418 63,267 147,151 1,747 5,402
2026-09-12 254,827 82,831 171,996 1,859 5,450
2026-09-13 236,911 105,016 131,895 1,854 5,434
2026-09-14 213,640 83,835 129,805 1,994 5,516
2026-09-15 272,074 159,141 112,933 1,884 5,303
2026-09-16 · incomplete 101,115 28,713 72,402 1,386 3,449
Time window
2026-08-21 – 2026-09-16
Source data
timeline-aggregated not available yet
Script
to be published
Format
field documentation

Where the connections came from #


The origin of the connections. A country is the one the IP address is registered in, not where the attacker actually sits – behind an address there may be a rented server or a compromised machine anywhere in the world. The exact numbers are in the tables below.

The map is drawn by Datawrapper; loading it connects the browser to their servers. Open the map on its own

Geography and networks #


Where traffic came from according to source IP geolocation, and which autonomous systems (ASNs) the addresses belong to. Geolocation shows where an address is registered, not where the attacker sits.

Top countries

  1. US 37.6%2,057,660
  2. DE 22.5%1,230,744
  3. CN 10.2%556,778
  4. GB 8.9%486,870
  5. SC 3.4%184,746
  6. NL 2.2%120,671
  7. TN 1.8%96,601
  8. VN 1.2%64,512
  9. MX 1.1%59,561
  10. IN 0.9%49,705
  11. SG 0.9%49,368
  12. BR 0.8%44,530
  13. RU 0.8%42,439
  14. HK 0.7%38,439
  15. RO 0.7%37,368

Largest networks (ASN)

ASN Network Events Unique IPs Share
29125 TATINT-AS
RU
1 1 0.0%
41960 NEXTPERTISE Nextpertise
NL
1 1 0.0%
136461 VNP-AS-AP Virtual Network Pvt.Ltd
NP
1 1 0.0%
61902 Bahialink Technology Ltda
BR
1 1 0.0%
25150 DCTEL-AS Nezavisimoy Ukraini
UA
1 1 0.0%
61870 Gcu Servicos de Provedor Ltda
BR
1 1 0.0%
141039 PACKETHUBSA-AS-AP PacketHub S.A.
PA
1 1 0.0%
136297 VISIONHI-AS-IN Vision Hi-speed Technology Pvt.ltd.
IN
1 1 0.0%
202619 DOVECOM
RU
1 1 0.0%
51279 ASSUTYRIN
UA
1 1 0.0%
Show values as a table
Country Events Unique IPs Share
US 2,057,660 13,624 37.6%
DE 1,230,744 1,111 22.5%
CN 556,778 5,671 10.2%
GB 486,870 2,870 8.9%
SC 184,746 319 3.4%
NL 120,671 174 2.2%
TN 96,601 94 1.8%
VN 64,512 644 1.2%
MX 59,561 281 1.1%
IN 49,705 850 0.9%
Time window
2026-08-21 – 2026-09-16
Source data
geo-aggregated not available yet
Script
to be published
Format
field documentation

Credentials #


Username and password combinations attackers tried, and the most-tried usernames. Values are shown exactly as they arrived.

Most-tried usernames

  1. root 4,665 passwords43,470
  2. admin 722 passwords10,909
  3. enable\x00 2 passwords2,938
  4. user 216 passwords2,100
  5. sa 83 passwords2,049
  6. support 178 passwords1,551
  7. test 215 passwords1,518
  8. ubuntu 100 passwords1,456
  9. cloud 148 passwords1,281
  10. postgres 93 passwords1,198
  11. batacek 147 passwords1,164
  12. srv 147 passwords1,154
  13. shell\x00 1 passwords965
  14. deploy 66 passwords925
  15. ftp 459 passwords876

Most common combinations

Username Password Attempts Unique IPs
root (empty) 3,084 219
admin admin 2,649 849
enable\x00 linuxshell\x00 1,955 24
admin (empty) 1,939 69
root xc3511 1,591 76
root admin 1,529 160
root vizxv 1,523 120
root 123456 1,207 142
support support 990 129
enable\x00 system\x00 983 27
Time window
2026-08-21 – 2026-09-16
Source data
credentials-aggregated not available yet
Script
to be published
Format
field documentation

What happened after login #


Commands attackers typed into the emulated shell, ordered by frequency. This is attacker input, not code that actually ran on the server.

Primary record, shown exactly as it was produced.
Command Count Sessions
uname -s -v -n -r -m 41,470 41,470
system 21,144 21,143
shell 21,044 21,044
sh 21,015 21,014
enable 20,259 20,258
linuxshell 18,836 18,834
echo -e "\x47\x41\x59\x46\x47\x54" 4,749 493
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH uname=$(uname -s -v -n -m 2>/dev/null || /bin/uname -s -v -n -m 2>/dev/null || /usr/bin/uname -s -v -n -m 2>/dev/null || busybox uname -s -v -n -m 2>/dev/null || ( [ -f /proc/version ] && head -1 /proc/version | cut -d' ' -f1 ) || ( [ -f /etc/os-release ] && grep '^ID=' /etc/os-release | cut -d= -f2 | tr -d '"' ) || echo "") arch=$(uname -m 2>/dev/null || /bin/uname -m 2>/dev/null || /usr/bin/uname -m 2>/dev/null || busybox uname -m 2>/dev/null || ( [ -f /proc/cpuinfo ] && grep -q "lm" /proc/cpuinfo && echo x86_64 ) || ( [ -f /proc/cpuinfo ] && grep -q "CPU architecture: 8" /proc/cpuinfo && echo aarch64 ) || ( [ -f /proc/cpuinfo ] && grep -q "CPU architecture: 7" /proc/cpuinfo && echo armv7l ) || echo "") uptime=$(cat /proc/uptime 2>/dev/null || busybox cat /proc/uptime 2>/dev/null) cpus=$(nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || busybox nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null) cpu_model=$( { lscpu 2>/dev/null | awk -F: '/Model name/ {print $2}'; grep -m1 -E "^model name" /proc/cpuinfo 2>/dev/null | cut -d: -f2-; grep -m1 -E "^Hardware" /proc/cpuinfo 2>/dev/null | cut -d: -f2-; cat /proc/device-tree/model 2>/dev/null; } | sed '/^$/d; /unknown/d; s/^[[:space:]]*//; s/[[:space:]]*$//; s/ AArch64 Processor$//; s/ Processor$//; s/ CPU$//' | head -1 ) gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia; busybox lspci 2>/dev/null | grep -i vga; busybox lspci 2>/dev/null | grep -i nvidia) 2>/dev/null ) last_output=$(last 2>/dev/null) filter_output=$( ( export LANG=C LC_ALL=C; echo '===SHELL_BEHAVIOR==='; printf 'path_err='; ( ./xxxxxx 2>&1 || true ) | ( head -c 250 2>/dev/null || busybox head -c 250 2>/dev/null || dd bs=250 count=1 2>/dev/null ) | ( tr -d '\n' 2>/dev/null || busybox tr -d '\n' 2>/dev/null || cat ); printf '\n'; printf 'cmd_err='; ( xxxxxx 2>&1 || true ) | ( head -c 250 2>/dev/null || busybox head -c 250 2>/dev/null || dd bs=250 count=1 2>/dev/null ) | ( tr -d '\n' 2>/dev/null || busybox tr -d '\n' 2>/dev/null || cat ); printf '\n'; printf 'execute_err='; out=$(bash -c 'printf "#!/bin/bash\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); case "$out" in *xxxxxx*) ;; *) out=$(/bin/bash -c 'printf "#!/bin/bash\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); case "$out" in *xxxxxx*) ;; *) out=$(/usr/bin/bash -c 'printf "#!/bin/bash\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); case "$out" in *xxxxxx*) ;; *) out=$(busybox sh -c 'printf "#!/bin/sh\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1 || sh -c 'printf "#!/bin/sh\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); esac; esac; esac; printf '%s' "$out" | ( head -c 250 2>/dev/null || busybox head -c 250 2>/dev/null || dd bs=250 count=1 2>/dev/null ) | ( tr -d '\n' 2>/dev/null || busybox tr -d '\n' 2>/dev/null || cat ); printf '\n'; echo '===DONE===' ) 2>&1 ) echo "UNAME:$uname" echo "ARCH:$arch" echo "UPTIME:$uptime" echo "CPUS:$cpus" echo "CPU_MODEL:$cpu_model" echo "GPU:$gpu_info" echo "LAST:$last_output" echo "FILTER:$filter_output" 4,333 4,332
/bin/busybox 3,149 312
/bin/./uname -s -v -n -r -m 2,275 2,275
Time window
2026-08-21 – 2026-09-16
Source data
attacker-commands-aggregated not available yet
Script
to be published
Format
field documentation

Captured samples #


Files attackers tried to download or upload, by type and architecture.

This lists hashes and metadata only. The samples themselves are in a password-protected archive in Data

By file type

  1. PE1,058
  2. ELF58
  3. script39
  4. data35

By architecture

  1. —1,132
  2. x86_6424
  3. arm11
  4. x864
  5. mips4
  6. mipsel4
  7. aarch643
  8. riscv2
  9. elf-0x5d2
  10. sh1
  11. elf-0x41
  12. ppc1
  13. sparc1
SHA-256 Type Architecture Size First seen Times seen Look up
af31e1e219b53e5d75dbaf221197cd9d19d1d915673c4e329e93bb5d7a143d89 PE — 5.0 MB 2026-09-15 18:16:19 UTC 0 VirusTotal
f0d9ca668edd955942521d86fc2239b969c82fa83a412da9a5aaf6f16e556b0f PE — 5.0 MB 2026-09-15 19:47:07 UTC 0 VirusTotal
0871694714370a1d2eebd1d7da119b0dcb87856b6c0702a310967a67b13f6a83 PE — 5.0 MB 2026-09-15 20:06:16 UTC 0 VirusTotal
3efc41b37210f199f69631a53a56678941297108bf02e65fddeb4d2c7c6e5a3a PE — 5.0 MB 2026-09-15 21:07:19 UTC 0 VirusTotal
031a4ab52fd076cb9b216b979bdfc3b6df96e9ee94e05818ba5bcaf9b3c70c28 PE — 5.0 MB 2026-09-15 22:38:58 UTC 0 VirusTotal
ee8b263148c92b92d0e6142afe17e36217823b008b4359c94a673258d78c8878 PE — 5.0 MB 2026-09-16 00:11:31 UTC 0 VirusTotal
88dcd93eef20e8b563447ebbd0b878efe67afcfbd4208c234d800f0f8a842e00 PE — 5.0 MB 2026-09-16 00:46:22 UTC 0 VirusTotal
b98ea070bdf32968bc3784bf3847019c0fa559c0c230a9b9bf15360dc6f413f3 PE — 5.0 MB 2026-09-16 01:32:04 UTC 0 VirusTotal
1f701c740f6250c01cc8949af015f772bf47bd9a1c77391822a4e1d70edde3a5 PE — 5.0 MB 2026-09-16 04:28:36 UTC 0 VirusTotal
ea171c7453ea7e208b2ee85b754299853bc4a0f36a9466abe26639611be375ba PE — 5.0 MB 2026-09-16 04:42:25 UTC 0 VirusTotal
Time window
2026-08-21 – 2026-09-16
Source data
samples-aggregated not available yet
Script
to be published
Format
field documentation

Server comparison #


How much traffic the larger surface brought in, and how the structure differs between the two servers.

Absolute numbers of the two servers are not comparable: srv4 exposed a surface orders of magnitude larger. Compare structure and ranking, not size. More
Metric srv3 srv4 srv4 / srv3
Connection attempts (port ranking) 1,462,877 4,014,322 2.7×
Ports hit 45 58,628 1,302.8×
Events (traffic over time) 1,462,877 4,014,322 2.7×

srv3 top ports

  1. 5901/tcp VNC434,278
  2. 445/tcp SMB415,953
  3. 5900/tcp VNC346,288
  4. 22/tcp SSH77,679
  5. 443/tcp HTTPS25,880
  6. 23/tcp Telnet24,961
  7. 5060/udp SIP22,484
  8. 80/tcp HTTP18,336
  9. 3000/tcp HTTP alt9,322
  10. 3389/tcp RDP7,549

srv4 top ports

  1. 3389/tcp RDP726,599
  2. 5901/tcp VNC449,586
  3. 5900/tcp VNC360,884
  4. 1256/tcp341,276
  5. 8787/tcp340,499
  6. 8082/tcp HTTP alt323,345
  7. 1080/tcp SOCKS270,186
  8. 5800/tcp VNC HTTP159,507
  9. 22/tcp SSH61,829
  10. 445/tcp SMB43,977
Time window
2026-08-21 – 2026-09-16
Source data
honeypot-ports-aggregated-20260922.csv, timeline-aggregated not available yet
Script
to be published
Format
field documentation