HoneyMire Hub

Public stats

Aggregate attack telemetry from users who opted into the public feed. Auto-refreshes every 30s.

Total attacks555,590all-time
Attacks 24h4,393last 24 hours
Unique attackers31,5861,161 in 24h
Returning attackers8,80427.9% of uniques
Auth success rate97.5%398,040 of 408,401 known
Avg commands5.7per session
Avg session50.6 sduration
Public reporters1opted-in users
World coverage15.0%3/20 areas
Countries covered4honeypot locations
Public honeypots54 online · 1 offline
Commands captured1,978,749across all sessions
Avg severity37174,124 high/critical
CVE attempts0CVE-ID references seen
Pre-session probes20,272,764connects before sessions
Bandwidth in175.4 MiBfrom attackers
Bandwidth out182.5 MiBhoneypot replies
Avg response4 mshoneypot latency

Activity over time

Attacks per hour

Last 24 hours, hourly buckets.

Attacks per day

Last 7 days, midnight-UTC buckets.

Time of day (UTC)

All-time activity by UTC hour — when attackers hit the hub.

Time of day (attacker-local)

All-time activity by hour in the attacker's local time, approximated from their country code (DST ignored).

Day of week (UTC)

All-time activity by UTC weekday.

Honeypot fleet

World coverage

Coverage score is based on 20 practical deployment areas. One public honeypot in each area reaches 100%; extra honeypots add resilience but do not inflate the score.

Western Europe
3
North America - East
1
Southeast Asia
1

Honeypot countries

🇱🇺Luxembourg
2
🇫🇷France
1
🇸🇬Singapore
1
🇺🇸United States
1
CountryHoneypots
🇱🇺Luxembourg 2
🇫🇷France 1
🇸🇬Singapore 1
🇺🇸United States 1

Hardware boards

ESP32 variants reporting to public feeds.

docker-edge 4 80.0%
esp32-c3-supermini 1 20.0%
BoardCount
docker-edge 4
esp32-c3-supermini 1

Firmware versions

FirmwareCount
0.1.0 4
1.1.0 1

Sensors online/offline

Online = reported in the last 15 minutes.

online 4 80.0%
offline 1 20.0%

Sensor uptime distribution

How long each honeypot has been up since its last reboot, last reported by the firmware.

< 1 hour
1
7 – 30 days
1
30+ days
3

Attack geography

Top source countries

🇨🇳China
97641
🇳🇱The Netherlands
87521
🇵🇰Pakistan
73628
🇺🇸United States
69719
🇷🇺Russia
23885
🇬🇧United Kingdom
21049
🇩🇪Germany
15162
🇵🇱Poland
15008
🇮🇳India
11763
🇧🇷Brazil
11278
CountryAttacks
🇨🇳China 97641
🇳🇱The Netherlands 87521
🇵🇰Pakistan 73628
🇺🇸United States 69719
🇷🇺Russia 23885
🇬🇧United Kingdom 21049
🇩🇪Germany 15162
🇵🇱Poland 15008
🇮🇳India 11763
🇧🇷Brazil 11278

Top target countries

🇱🇺Luxembourg
260757
🇫🇷France
108092
🇸🇬Singapore
105788
🇺🇸United States
80953
CountryAttacks
🇱🇺Luxembourg 260757
🇫🇷France 108092
🇸🇬Singapore 105788
🇺🇸United States 80953

Attacker → target countries

AttackerTargetCount
🇵🇰Pakistan 🇱🇺Luxembourg 72239
🇨🇳China 🇱🇺Luxembourg 60720
🇳🇱The Netherlands 🇱🇺Luxembourg 31200
🇳🇱The Netherlands 🇫🇷France 24650
🇳🇱The Netherlands 🇸🇬Singapore 23096
🇺🇸United States 🇱🇺Luxembourg 22755
🇷🇺Russia 🇱🇺Luxembourg 21828
🇺🇸United States 🇸🇬Singapore 17221
🇺🇸United States 🇺🇸United States 15156
🇨🇳China 🇫🇷France 15003
🇺🇸United States 🇫🇷France 14587
🇨🇳China 🇺🇸United States 12668
🇵🇱Poland 🇸🇬Singapore 9502
🇨🇳China 🇸🇬Singapore 9250
🇩🇪Germany 🇺🇸United States 9075

Attack attributes

Protocol split

telnet 356386 64.1%
ssh 199204 35.9%

Top target ports

Destination port the attacker connected to on the honeypot. Inferred from protocol when not reported.

23 (telnet)
356386
22 (ssh)
199204

Authentication outcomes

Whether the honeypot let the attacker in (after its configured threshold).

authenticated 398040 71.6%
unknown 147189 26.5%
rejected 10361 1.9%

Attacker profiles

Behavioral classification from the firmware.

creds-only 211358 38.0%
mirai 209187 37.7%
scripted 123378 22.2%
creds-probe 9913 1.8%
iot-loader 1343 0.2%
scanner 410 0.1%
recon-script 1 0.0%
ProfileCount
creds-only 211358
mirai 209187
scripted 123378
creds-probe 9913
iot-loader 1343
scanner 410
recon-script 1

Network / ASN

Top ASNs

ASNCount
AS47890 UNMANAGED LTD 70954
AS4837 CHINA UNICOM China169 Backbone 51738
AS14061 DigitalOcean, LLC 36029
AS9541 Cyber Internet Services (Pvt) Ltd. 27844
AS4134 CHINANET BACKBONE 24587
AS8359 MTS PJSC 16128
AS48090 TECHOFF SRV LIMITED 13530
AS138423 CMPak Limited 11886
AS398101 GoDaddy.com, LLC 9397
AS201814 MEVSPACE sp. z o.o. 8514

Network types

unknown 223019 40.1%
isp 151110 27.2%
residential 90068 16.2%
cdn 88644 16.0%
enterprise 2654 0.5%
education 95 0.0%
TypeCount
unknown 223019
isp 151110
residential 90068
cdn 88644
enterprise 2654
education 95

Top network providers

ProviderCount
Unmanaged LTD 70954
China Unicom 51749
DigitalOcean 36032
China Telecom 32757
Cyber Internet Services 27844
CMPak Limited 17051
Mobile TeleSystems PJSC 16128
Techoff SRV Limited 13530
GoDaddy.com, LLC 9397
Mevspace 8514

Target exposure by provider

Target ISP / networkCount
POST Luxembourg 166941
OVH SAS 108092
M247 Europe SRL 105788
Servers.com, Inc. 93816
HostPapa 80953

Network confidence

medium 332571 59.9%
low 222759 40.1%
unknown 260 0.0%

ASN → target countries

ASNTargetCount
AS4837 CHINA UNICOM China169 Backbone 🇱🇺Luxembourg 46501
AS47890 UNMANAGED LTD 🇱🇺Luxembourg 28915
AS9541 Cyber Internet Services (Pvt) Ltd. 🇱🇺Luxembourg 27392
AS47890 UNMANAGED LTD 🇫🇷France 18128
AS47890 UNMANAGED LTD 🇸🇬Singapore 16163
AS8359 MTS PJSC 🇱🇺Luxembourg 16072
AS138423 CMPak Limited 🇱🇺Luxembourg 11787
AS14061 DigitalOcean, LLC 🇫🇷France 10737
AS14061 DigitalOcean, LLC 🇱🇺Luxembourg 9790
AS14061 DigitalOcean, LLC 🇺🇸United States 8845
AS47890 UNMANAGED LTD 🇺🇸United States 7748
AS23888 National Telecommunication Corporation HQ, 🇱🇺Luxembourg 7603
AS201814 MEVSPACE sp. z o.o. 🇸🇬Singapore 7397
AS48090 TECHOFF SRV LIMITED 🇫🇷France 7284
AS4134 CHINANET BACKBONE 🇺🇸United States 7132

ASN → target ASN

Attacker ASNTarget ASNCount
AS4837 CHINA UNICOM China169 Backbone AS6661 POST Luxembourg 44436
AS47890 UNMANAGED LTD AS7979 Servers.com, Inc. 28914
AS9541 Cyber Internet Services (Pvt) Ltd. AS6661 POST Luxembourg 26993
AS47890 UNMANAGED LTD AS16276 OVH SAS 18128
AS47890 UNMANAGED LTD AS9009 M247 Europe SRL 16163
AS8359 MTS PJSC AS6661 POST Luxembourg 16043
AS138423 CMPak Limited AS6661 POST Luxembourg 11677
AS14061 DigitalOcean, LLC AS16276 OVH SAS 10737
AS14061 DigitalOcean, LLC AS36352 HostPapa 8845
AS47890 UNMANAGED LTD AS36352 HostPapa 7748
AS23888 National Telecommunication Corporation HQ, AS6661 POST Luxembourg 7574
AS201814 MEVSPACE sp. z o.o. AS9009 M247 Europe SRL 7397
AS48090 TECHOFF SRV LIMITED AS16276 OVH SAS 7284
AS4134 CHINANET BACKBONE AS36352 HostPapa 7132
AS4134 CHINANET BACKBONE AS16276 OVH SAS 6909

Network type → target countries

Network typeTargetCount
isp 🇱🇺Luxembourg 109384
unknown 🇱🇺Luxembourg 82927
unknown 🇫🇷France 55351
residential 🇱🇺Luxembourg 51847
unknown 🇸🇬Singapore 47633
unknown 🇺🇸United States 37108
cdn 🇫🇷France 28096
cdn 🇸🇬Singapore 22578
cdn 🇺🇸United States 22025
residential 🇸🇬Singapore 21166
cdn 🇱🇺Luxembourg 15945
isp 🇫🇷France 14666
isp 🇺🇸United States 13759
isp 🇸🇬Singapore 13301
residential 🇫🇷France 9569

Credentials & content

Top attacker IPs

Most active source addresses on the public feed.

IPCount
80.94.92.128 13743
193.34.212.136 7022
146.0.42.48 6805
87.251.64.176 6115
210.245.120.117 5213
80.94.92.167 5175
195.178.110.30 4939
80.94.92.177 4697
80.94.92.164 4565
80.94.92.187 4553

Top credential pairs

Aggregated across public feeds.

user : passCount
system:shell 37566
support:support 11819
0:0 10758
admin:admin 8111
admin:admin123 7869
root:Zte521 6828
root: 5447
sol:sol 4915
root:root 4226
admin:1234 4085

Top usernames

Aggregated across public feeds.

UsernameCount
root 150247
admin 76177
system 38424
support 14537
sol 13425
0 10758
solana 8924
ubuntu 8550
guest 7105
user 6799

Top passwords

Aggregated across public feeds.

PasswordCount
shell 37569
123456 16348
1234 14760
admin 13628
support 11830
0 10860
admin123 8546
12345 8425
Zte521 6828
12345678 6388

Top command chains

Command chainCount
/bin/./uname -s -v -n -r -m 53397
sh /bin/busybox UNSTABLE 26962
uname -s -v -n -r -m 24863
uname -a 15214
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH uname=$(uname -s -v -n -m 2>/dev/null || /bin/uname -s -v -n -m 2>/dev/null || /usr/bin/uname -s -... 15078
cd ~; chattr -ia .ssh; lockr -ia .ssh 11406
sh 6768
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH uname=$(uname -s -v -n -m 2>/dev/null) arch=$(uname -m 2>/dev/null) uptime=$(cat /proc/uptime 2>/d... 5322
start enable config terminal system linuxshell su shell sh >/var/run/.x&&cd /var/run;>/mnt/.x&&cd /mnt;>/usr/.x&&cd /usr;>/dev/.x&&cd /dev;>/dev/shm/.x&&cd /dev/shm;>/tmp/.x&&cd... 3012
start enable config terminal system linuxshell su shell sh >/var/run/.x&&cd /var/run;>/mnt/.x&&cd /mnt;>/usr/.x&&cd /usr;>/dev/.x&&cd /dev;>/dev/shm/.x&&cd /dev/shm;>/tmp/.x&&cd... 2974

Top malware URLs

URLCount
http://192.168.1.1:8088/i 30432
http://90.224.208.161:48263/i 17937
http://81.229.60.159:58639/i 12711
http://90.228.239.131:37930/i 9987
http://174.105.154.212:40964/i 9771
http://46.236.65.235:51725/i 9093
http://109.236.46.215:59913/i 8850
http://123.232.142.200:55377/i 8787
http://42.224.99.236:38337/i 8553
http://90.224.208.190:45821/i 7485

Threat assessment

Severity distribution

Hub-computed score (0-100) per attack: informational ≤ 1, low < 40, medium < 70, high < 90, critical ≥ 90. Older rows that pre-date scoring show as unscored.

informational 154152 27.7%
low 190845 34.3%
medium 36469 6.6%
high 174110 31.3%
critical 14 0.0%
BandCount
informational 154152
low 190845
medium 36469
high 174110
critical 14

Top CVE references

CVE-IDs extracted from command summaries (and explicit firmware reports). Useful for spotting CVE-driven scanner waves.

No CVE references seen yet.

Top reverse-DNS suffixes

Last 2-3 labels of the PTR record per attacker IP. Local resolver only — no third-party intel feeds.

SuffixCount
ny.adsl 19721
mts-chita.ru 16167
server-hosting.expert 6805
secureserver.net 5262
com.vn 5213
lionwire.com 4480
kbacarparts.co.uk 4475
tronicsat.com 4382
personaliseplus.com 3374
as55666.net 3027
unifiedlayer.com 2834
fastcloud.id 2717

Client fingerprints

Top client banners

Raw banner the attacker tool announced (e.g. SSH-2.0-libssh_0.9.6).

BannerCount
SSH-2.0-Go 150101
root 65705
admin 40989
SSH-2.0-PuTTY_Release_0.84 14246
SSH-2.0-libssh_0.9.6 10318
SSH-2.0-libssh2_1.8.1 6353
SSH-2.0-OpenSSH_7.4 4919
guest 3430
super 3323
support 2784

Top HASSH fingerprints

MD5 over SSH client KEXINIT algorithm lists.

No HASSH fingerprints yet — firmware must capture and report.

Top JA3 fingerprints

MD5 over TLS ClientHello (only applicable when the listener speaks TLS).

No JA3 fingerprints yet — firmware must capture and report.

SSH probing

SSH key types

Algorithm of public keys offered before any password attempt.

ssh-rsa 17 63.0%
ssh-dss 8 29.6%
ssh-ed25519 2 7.4%
Key typeCount
ssh-rsa 17
ssh-dss 8
ssh-ed25519 2

Top SSH key fingerprints

FingerprintCount
SHA256:/JLp6z6uGE3BPcs70RQob6QOdEWQ6nDC0xY7ejPOCc0 8
SHA256:WL+QR9x+2QKzI6U4Ks7LPXWa0Vb22vjSn0groO1Ao8k 8
SHA256:f2HQeWaKQsmlbtBgUTxZfhSKRYU54OtEtSRitoTmOp4 6
SHA256:TVLyd6EqeDPt6s0oQtYUYAUCygiABg6kAEGstS2pq7U 2
SHA256:78ZIMBycE34nu4OXOrklc4gUgR6i0acuh6yeM6tGRA8 1
SHA256:pjD1AGDXnd8PXgnrLAv7WTkPeV0xGAL0xooPKb2uyFI 1
SHA256:Wv4u5KOGs5/xiDvId+VaJ36TLUAy1ACQMDZSt441gP8 1

Threat-intel reporting

Reported-to services

Where the firmware has already submitted these attacks (for cross-referencing — the hub does NOT re-submit).

ServiceCount
otx 87385

HoneyMire Hub · open feed: / · API: /api · docs: /docs · blocklists: /blocklists · about: /about · firmware: github.com/HoneyMire/HoneyMire