HoneyMire Hub

Attack #292124 telnet

Captured 2026-06-29 19:49:50Z by Ka on honeypot LU2 - SERVERS ⬜ docker-edge · firmware 0.1.0.

Source103.249.87.183:40028
Target port23
Authenticatedyes
Commands2
Duration53.3s

Session recording

Loading session…

Transcript

Server output and attacker input as captured, line-grain. Malware URLs are obscured until sign-in.

BusyBox v1.35.0 (2022-12-01) built-in shell (ash)
Enter 'help' for a list of built-in commands.

router:~# sh
router:~# /bin/busybox UNSTABLE
UNSTABLE: applet not found
router:~# 

Credentials

Username: system

Password: shell

3 login attempt(s) before disconnect.

Geolocation hub-resolved

🇲🇾Malaysia · Selangor · Cyberjaya

Invision Seven Solutions · AS55720 Gigabit Hosting Sdn Bhd · 2.92,101.66

Network: cdn · TheGigabit · Content · peeringdb · medium confidence

Behavioral classification

🦠 80% confidence

Mirai-family IoT botnet — wget + chmod + exec; tries common router/IP-cam credentials.

Matched signals:

Command summary

sh
/bin/busybox UNSTABLE

Reported to threat intel

none

HoneyMire Hub · open feed: / · API: /api · docs: /docs · blocklists: /blocklists · about: /about · firmware: github.com/HoneyMire/HoneyMire