HoneyMire Hub

Attack #555381 telnet

Captured 2026-08-13 19:07:22Z by Ka on honeypot LU2 - SERVERS ⬜ docker-edge · firmware 0.1.0.

Source109.105.210.52:29118
Target port23
Authenticatedyes
Commands3
Duration0.3s

Session recording

Loading session…

Transcript

Server output and attacker input as captured, line-grain. Malware URLs are obscured until sign-in.

Welcome to Ubuntu 22.04.1 LTS (GNU/Linux 5.15.0-91-generic x86_64)

 * Documentation:  hxxps://help[.]ubuntu[.]com
 * Management:     hxxps://landscape[.]canonical[.]com
 * Support:        hxxps://ubuntu[.]com/advantage

  System information as of 6299610

  System load:  0.08              Processes:           98
  Usage of /:   23.4% of 19.56GB  Users logged in:     0
  Memory usage: 28%               IP address for eth0: 10.0.0.42
  Swap usage:   0%

0 packages can be updated.
0 updates are security updates.

Last login: Mon Sep  4 09:14:21 2023 from 192.168.1.5
ubuntu@ubuntu-server:~$ 
ubuntu@ubuntu-server:~$ 
ubuntu@ubuntu-server:~$ #
-bash: #: command not found
ubuntu@ubuntu-server:~$ ^C
ubuntu@ubuntu-server:~$ ^C
ubuntu@ubuntu-server:~$ ^C
ubuntu@ubuntu-server:~$ 
ubuntu@ubuntu-server:~$ +^C
ubuntu@ubuntu-server:~$ ^C
ubuntu@ubuntu-server:~$ -3&$ �[��{FŶ���M5P=����
-bash: 3&$: command not found
ubuntu@ubuntu-server:~$ �L�!���t

Credentials

Username:

Password:

3 login attempt(s) before disconnect.

Geolocation hub-resolved

🇺🇸United States · Texas · Dallas

Zenlayer Inc · AS21859 Zenlayer Inc · 32.78,-96.80

Network: cdn · Zenlayer Inc · Content · peeringdb · medium confidence

Behavioral classification

🤖 55% confidence

Automated tool, unknown family — uniform timing but no matched signature.

Command summary

#
-3&$ �[��{FŶ���M5P=����
�L�!���t

Reported to threat intel

none

HoneyMire Hub · open feed: / · API: /api · docs: /docs · blocklists: /blocklists · about: /about · firmware: github.com/HoneyMire/HoneyMire