HoneyMire Hub

Attack #837971 ssh

Captured 2026-09-27 22:42:16Z by Ka on honeypot LU2 - SERVERS ⬜ docker-edge · firmware 0.1.0.

Source38.253.224.42:34360
Target port22
Authenticatedyes
Commands1
Duration1.6s

Session recording

Loading session…

Transcript

Server output and attacker input as captured, line-grain. Malware URLs are obscured until sign-in.

echo OK
OK

Credentials

Username: root

Password: gogia1

1 login attempt(s) before disconnect.

Geolocation hub-resolved

🇮🇩Indonesia · East Java · Ponorogo

Cogent Communications · AS139952 PT Trisari Data Indonusa · -7.93,111.50

Network: residential · Trisari Data Indonusa · Cable/DSL/ISP · peeringdb · medium confidence

Behavioral classification

🤖 55% confidence

Automated tool, unknown family — uniform timing but no matched signature.

Command summary

echo OK

Reported to threat intel

none

HoneyMire Hub · open feed: / · API: /api · docs: /docs · blocklists: /blocklists · about: /about · firmware: github.com/HoneyMire/HoneyMire