HoneyMire Hub

Attack #837599 telnet

Captured 2026-09-27 21:43:05Z by Ka on honeypot NY1 ⬜ docker-edge · firmware 0.1.0.

Source64.227.90.185:51782
Target port23
Authenticatedyes
Commands3
Duration1.4s

Session recording

Loading session…

Transcript

Server output and attacker input as captured, line-grain. Malware URLs are obscured until sign-in.

[MikroTik] > �,�0�̨̩̪�+�/��$�(k�#�'g�
bad command name ��$�(k�#�g� (line 1 column 1)
[MikroTik] > �9��3��=<5/�^C
[MikroTik] > 
[MikroTik] > 
[MikroTik] > #
bad command name # (line 1 column 1)
[MikroTik] > 0.^C
[MikroTik] > ^C
[MikroTik] > ^C
[MikroTik] > 
[MikroTik] > ^C
[MikroTik] > ^C
[MikroTik] > ^C
[MikroTik] > ^C
[MikroTik] > ^C
[MikroTik] > ^C
[MikroTik] > ^C
[MikroTik] > ^C
[MikroTik] > ^C
[MikroTik] > ^C
[MikroTik] > -3&$ ŤV���UY6ͷ�����!d^cD�M���Y�b

Credentials

Username:

Password:

3 login attempt(s) before disconnect.

Geolocation hub-resolved

🇺🇸United States · California · Santa Clara

DigitalOcean, LLC · AS14061 DigitalOcean, LLC · 37.35,-121.97

Network: cdn · DigitalOcean · Content · peeringdb · medium confidence

Behavioral classification

🤖 55% confidence

Automated tool, unknown family — uniform timing but no matched signature.

Command summary

�,�0�̨̩̪�+�/��$�(k�#�'g�
#
-3&$ ŤV���UY6ͷ�����!d^cD�M���Y�b

Reported to threat intel

none

HoneyMire Hub · open feed: / · API: /api · docs: /docs · blocklists: /blocklists · about: /about · firmware: github.com/HoneyMire/HoneyMire