HoneyMire Hub

Attack #837598 telnet

Captured 2026-09-27 21:43:05Z by Ka on honeypot NY1 ⬜ docker-edge · firmware 0.1.0.

Source64.227.90.185:51856
Target port23
Authenticatedyes
Commands1
Duration1.2s

Session recording

Loading session…

Transcript

Server output and attacker input as captured, line-grain. Malware URLs are obscured until sign-in.

BusyBox v1.35.0 (2022-12-01) built-in shell (ash)
Enter 'help' for a list of built-in commands.

router:~# #

Credentials

Username:

Password:

3 login attempt(s) before disconnect.

Geolocation hub-resolved

🇺🇸United States · California · Santa Clara

DigitalOcean, LLC · AS14061 DigitalOcean, LLC · 37.35,-121.97

Network: cdn · DigitalOcean · Content · peeringdb · medium confidence

Behavioral classification

🤖 55% confidence

Automated tool, unknown family — uniform timing but no matched signature.

Command summary

#

Reported to threat intel

none

HoneyMire Hub · open feed: / · API: /api · docs: /docs · blocklists: /blocklists · about: /about · firmware: github.com/HoneyMire/HoneyMire