HoneyMire Hub

Public stats

Aggregate attack telemetry from users who opted into the public feed. Auto-refreshes every 30s.

Total attacks555,452all-time
Attacks 24h4,399last 24 hours
Unique attackers31,5601,161 in 24h
Returning attackers8,80327.9% of uniques
Auth success rate97.5%397,942 of 408,303 known
Avg commands5.7per session
Avg session50.6 sduration
Public reporters1opted-in users
World coverage15.0%3/20 areas
Countries covered4honeypot locations
Public honeypots54 online · 1 offline
Commands captured1,978,686across all sessions
Avg severity37174,099 high/critical
CVE attempts0CVE-ID references seen
Pre-session probes20,272,171connects before sessions
Bandwidth in175.3 MiBfrom attackers
Bandwidth out182.5 MiBhoneypot replies
Avg response4 mshoneypot latency

Activity over time

Attacks per hour

Last 24 hours, hourly buckets.

Attacks per day

Last 7 days, midnight-UTC buckets.

Time of day (UTC)

All-time activity by UTC hour — when attackers hit the hub.

Time of day (attacker-local)

All-time activity by hour in the attacker's local time, approximated from their country code (DST ignored).

Day of week (UTC)

All-time activity by UTC weekday.

Honeypot fleet

World coverage

Coverage score is based on 20 practical deployment areas. One public honeypot in each area reaches 100%; extra honeypots add resilience but do not inflate the score.

Western Europe
3
North America - East
1
Southeast Asia
1

Honeypot countries

🇱🇺Luxembourg
2
🇫🇷France
1
🇸🇬Singapore
1
🇺🇸United States
1
CountryHoneypots
🇱🇺Luxembourg 2
🇫🇷France 1
🇸🇬Singapore 1
🇺🇸United States 1

Hardware boards

ESP32 variants reporting to public feeds.

docker-edge 4 80.0%
esp32-c3-supermini 1 20.0%
BoardCount
docker-edge 4
esp32-c3-supermini 1

Firmware versions

FirmwareCount
0.1.0 4
1.1.0 1

Sensors online/offline

Online = reported in the last 15 minutes.

online 4 80.0%
offline 1 20.0%

Sensor uptime distribution

How long each honeypot has been up since its last reboot, last reported by the firmware.

< 1 hour
1
7 – 30 days
1
30+ days
3

Attack geography

Top source countries

🇨🇳China
97638
🇳🇱The Netherlands
87475
🇵🇰Pakistan
73625
🇺🇸United States
69710
🇷🇺Russia
23885
🇬🇧United Kingdom
21036
🇩🇪Germany
15153
🇵🇱Poland
15008
🇮🇳India
11763
🇧🇷Brazil
11276
CountryAttacks
🇨🇳China 97638
🇳🇱The Netherlands 87475
🇵🇰Pakistan 73625
🇺🇸United States 69710
🇷🇺Russia 23885
🇬🇧United Kingdom 21036
🇩🇪Germany 15153
🇵🇱Poland 15008
🇮🇳India 11763
🇧🇷Brazil 11276

Top target countries

🇱🇺Luxembourg
260724
🇫🇷France
108063
🇸🇬Singapore
105756
🇺🇸United States
80909
CountryAttacks
🇱🇺Luxembourg 260724
🇫🇷France 108063
🇸🇬Singapore 105756
🇺🇸United States 80909

Attacker → target countries

AttackerTargetCount
🇵🇰Pakistan 🇱🇺Luxembourg 72236
🇨🇳China 🇱🇺Luxembourg 60718
🇳🇱The Netherlands 🇱🇺Luxembourg 31185
🇳🇱The Netherlands 🇫🇷France 24648
🇳🇱The Netherlands 🇸🇬Singapore 23090
🇺🇸United States 🇱🇺Luxembourg 22749
🇷🇺Russia 🇱🇺Luxembourg 21828
🇺🇸United States 🇸🇬Singapore 17221
🇺🇸United States 🇺🇸United States 15153
🇨🇳China 🇫🇷France 15003
🇺🇸United States 🇫🇷France 14587
🇨🇳China 🇺🇸United States 12667
🇵🇱Poland 🇸🇬Singapore 9502
🇨🇳China 🇸🇬Singapore 9250
🇩🇪Germany 🇺🇸United States 9067

Attack attributes

Protocol split

telnet 356339 64.2%
ssh 199113 35.8%

Top target ports

Destination port the attacker connected to on the honeypot. Inferred from protocol when not reported.

23 (telnet)
356339
22 (ssh)
199113

Authentication outcomes

Whether the honeypot let the attacker in (after its configured threshold).

authenticated 397942 71.6%
unknown 147149 26.5%
rejected 10361 1.9%

Attacker profiles

Behavioral classification from the firmware.

creds-only 211280 38.0%
mirai 209158 37.7%
scripted 123347 22.2%
creds-probe 9913 1.8%
iot-loader 1343 0.2%
scanner 410 0.1%
recon-script 1 0.0%
ProfileCount
creds-only 211280
mirai 209158
scripted 123347
creds-probe 9913
iot-loader 1343
scanner 410
recon-script 1

Network / ASN

Top ASNs

ASNCount
AS47890 UNMANAGED LTD 70912
AS4837 CHINA UNICOM China169 Backbone 51736
AS14061 DigitalOcean, LLC 36029
AS9541 Cyber Internet Services (Pvt) Ltd. 27844
AS4134 CHINANET BACKBONE 24586
AS8359 MTS PJSC 16128
AS48090 TECHOFF SRV LIMITED 13524
AS138423 CMPak Limited 11884
AS398101 GoDaddy.com, LLC 9394
AS201814 MEVSPACE sp. z o.o. 8514

Network types

unknown 222934 40.1%
isp 151102 27.2%
residential 90033 16.2%
cdn 88635 16.0%
enterprise 2653 0.5%
education 95 0.0%
TypeCount
unknown 222934
isp 151102
residential 90033
cdn 88635
enterprise 2653
education 95

Top network providers

ProviderCount
Unmanaged LTD 70912
China Unicom 51747
DigitalOcean 36032
China Telecom 32756
Cyber Internet Services 27844
CMPak Limited 17049
Mobile TeleSystems PJSC 16128
Techoff SRV Limited 13524
GoDaddy.com, LLC 9394
Mevspace 8514

Target exposure by provider

Target ISP / networkCount
POST Luxembourg 166941
OVH SAS 108063
M247 Europe SRL 105756
Servers.com, Inc. 93783
HostPapa 80909

Network confidence

medium 332518 59.9%
low 222674 40.1%
unknown 260 0.0%

ASN → target countries

ASNTargetCount
AS4837 CHINA UNICOM China169 Backbone 🇱🇺Luxembourg 46499
AS47890 UNMANAGED LTD 🇱🇺Luxembourg 28896
AS9541 Cyber Internet Services (Pvt) Ltd. 🇱🇺Luxembourg 27392
AS47890 UNMANAGED LTD 🇫🇷France 18125
AS47890 UNMANAGED LTD 🇸🇬Singapore 16160
AS8359 MTS PJSC 🇱🇺Luxembourg 16072
AS138423 CMPak Limited 🇱🇺Luxembourg 11785
AS14061 DigitalOcean, LLC 🇫🇷France 10737
AS14061 DigitalOcean, LLC 🇱🇺Luxembourg 9790
AS14061 DigitalOcean, LLC 🇺🇸United States 8845
AS47890 UNMANAGED LTD 🇺🇸United States 7731
AS23888 National Telecommunication Corporation HQ, 🇱🇺Luxembourg 7603
AS201814 MEVSPACE sp. z o.o. 🇸🇬Singapore 7397
AS48090 TECHOFF SRV LIMITED 🇫🇷France 7278
AS4134 CHINANET BACKBONE 🇺🇸United States 7131

ASN → target ASN

Attacker ASNTarget ASNCount
AS4837 CHINA UNICOM China169 Backbone AS6661 POST Luxembourg 44436
AS47890 UNMANAGED LTD AS7979 Servers.com, Inc. 28895
AS9541 Cyber Internet Services (Pvt) Ltd. AS6661 POST Luxembourg 26993
AS47890 UNMANAGED LTD AS16276 OVH SAS 18125
AS47890 UNMANAGED LTD AS9009 M247 Europe SRL 16160
AS8359 MTS PJSC AS6661 POST Luxembourg 16043
AS138423 CMPak Limited AS6661 POST Luxembourg 11677
AS14061 DigitalOcean, LLC AS16276 OVH SAS 10737
AS14061 DigitalOcean, LLC AS36352 HostPapa 8845
AS47890 UNMANAGED LTD AS36352 HostPapa 7731
AS23888 National Telecommunication Corporation HQ, AS6661 POST Luxembourg 7574
AS201814 MEVSPACE sp. z o.o. AS9009 M247 Europe SRL 7397
AS48090 TECHOFF SRV LIMITED AS16276 OVH SAS 7278
AS4134 CHINANET BACKBONE AS36352 HostPapa 7131
AS4134 CHINANET BACKBONE AS16276 OVH SAS 6909

Network type → target countries

Network typeTargetCount
isp 🇱🇺Luxembourg 109380
unknown 🇱🇺Luxembourg 82903
unknown 🇫🇷France 55334
residential 🇱🇺Luxembourg 51842
unknown 🇸🇬Singapore 47621
unknown 🇺🇸United States 37076
cdn 🇫🇷France 28095
cdn 🇸🇬Singapore 22578
cdn 🇺🇸United States 22017
residential 🇸🇬Singapore 21148
cdn 🇱🇺Luxembourg 15945
isp 🇫🇷France 14665
isp 🇺🇸United States 13757
isp 🇸🇬Singapore 13300
residential 🇫🇷France 9559

Credentials & content

Top attacker IPs

Most active source addresses on the public feed.

IPCount
80.94.92.128 13731
193.34.212.136 7022
146.0.42.48 6797
87.251.64.176 6115
210.245.120.117 5201
80.94.92.167 5175
195.178.110.30 4939
80.94.92.177 4697
80.94.92.164 4565
80.94.92.187 4553

Top credential pairs

Aggregated across public feeds.

user : passCount
system:shell 37561
support:support 11816
0:0 10746
admin:admin 8107
admin:admin123 7861
root:Zte521 6828
root: 5446
sol:sol 4914
root:root 4224
admin:1234 4085

Top usernames

Aggregated across public feeds.

UsernameCount
root 150217
admin 76158
system 38419
support 14534
sol 13423
0 10746
solana 8924
ubuntu 8549
guest 7105
user 6798

Top passwords

Aggregated across public feeds.

PasswordCount
shell 37564
123456 16346
1234 14755
admin 13623
support 11827
0 10848
admin123 8538
12345 8423
Zte521 6828
12345678 6388

Top command chains

Command chainCount
/bin/./uname -s -v -n -r -m 53385
sh /bin/busybox UNSTABLE 26959
uname -s -v -n -r -m 24850
uname -a 15214
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH uname=$(uname -s -v -n -m 2>/dev/null || /bin/uname -s -v -n -m 2>/dev/null || /usr/bin/uname -s -... 15053
cd ~; chattr -ia .ssh; lockr -ia .ssh 11406
sh 6766
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH uname=$(uname -s -v -n -m 2>/dev/null) arch=$(uname -m 2>/dev/null) uptime=$(cat /proc/uptime 2>/d... 5322
start enable config terminal system linuxshell su shell sh >/var/run/.x&&cd /var/run;>/mnt/.x&&cd /mnt;>/usr/.x&&cd /usr;>/dev/.x&&cd /dev;>/dev/shm/.x&&cd /dev/shm;>/tmp/.x&&cd... 3012
start enable config terminal system linuxshell su shell sh >/var/run/.x&&cd /var/run;>/mnt/.x&&cd /mnt;>/usr/.x&&cd /usr;>/dev/.x&&cd /dev;>/dev/shm/.x&&cd /dev/shm;>/tmp/.x&&cd... 2974

Top malware URLs

URLCount
http://192.168.1.1:8088/i 30432
http://90.224.208.161:48263/i 17937
http://81.229.60.159:58639/i 12711
http://90.228.239.131:37930/i 9987
http://174.105.154.212:40964/i 9771
http://46.236.65.235:51725/i 9093
http://109.236.46.215:59913/i 8850
http://123.232.142.200:55377/i 8787
http://42.224.99.236:38337/i 8553
http://90.224.208.190:45821/i 7485

Threat assessment

Severity distribution

Hub-computed score (0-100) per attack: informational ≤ 1, low < 40, medium < 70, high < 90, critical ≥ 90. Older rows that pre-date scoring show as unscored.

informational 154113 27.7%
low 190775 34.3%
medium 36465 6.6%
high 174085 31.3%
critical 14 0.0%
BandCount
informational 154113
low 190775
medium 36465
high 174085
critical 14

Top CVE references

CVE-IDs extracted from command summaries (and explicit firmware reports). Useful for spotting CVE-driven scanner waves.

No CVE references seen yet.

Top reverse-DNS suffixes

Last 2-3 labels of the PTR record per attacker IP. Local resolver only — no third-party intel feeds.

SuffixCount
ny.adsl 19720
mts-chita.ru 16167
server-hosting.expert 6797
secureserver.net 5259
com.vn 5201
lionwire.com 4480
kbacarparts.co.uk 4475
tronicsat.com 4378
personaliseplus.com 3371
as55666.net 3027
unifiedlayer.com 2834
fastcloud.id 2717

Client fingerprints

Top client banners

Raw banner the attacker tool announced (e.g. SSH-2.0-libssh_0.9.6).

BannerCount
SSH-2.0-Go 150035
root 65705
admin 40989
SSH-2.0-PuTTY_Release_0.84 14235
SSH-2.0-libssh_0.9.6 10318
SSH-2.0-libssh2_1.8.1 6347
SSH-2.0-OpenSSH_7.4 4918
guest 3430
super 3323
support 2784

Top HASSH fingerprints

MD5 over SSH client KEXINIT algorithm lists.

No HASSH fingerprints yet — firmware must capture and report.

Top JA3 fingerprints

MD5 over TLS ClientHello (only applicable when the listener speaks TLS).

No JA3 fingerprints yet — firmware must capture and report.

SSH probing

SSH key types

Algorithm of public keys offered before any password attempt.

ssh-rsa 17 63.0%
ssh-dss 8 29.6%
ssh-ed25519 2 7.4%
Key typeCount
ssh-rsa 17
ssh-dss 8
ssh-ed25519 2

Top SSH key fingerprints

FingerprintCount
SHA256:/JLp6z6uGE3BPcs70RQob6QOdEWQ6nDC0xY7ejPOCc0 8
SHA256:WL+QR9x+2QKzI6U4Ks7LPXWa0Vb22vjSn0groO1Ao8k 8
SHA256:f2HQeWaKQsmlbtBgUTxZfhSKRYU54OtEtSRitoTmOp4 6
SHA256:TVLyd6EqeDPt6s0oQtYUYAUCygiABg6kAEGstS2pq7U 2
SHA256:78ZIMBycE34nu4OXOrklc4gUgR6i0acuh6yeM6tGRA8 1
SHA256:pjD1AGDXnd8PXgnrLAv7WTkPeV0xGAL0xooPKb2uyFI 1
SHA256:Wv4u5KOGs5/xiDvId+VaJ36TLUAy1ACQMDZSt441gP8 1

Threat-intel reporting

Reported-to services

Where the firmware has already submitted these attacks (for cross-referencing — the hub does NOT re-submit).

ServiceCount
otx 87385

HoneyMire Hub · open feed: / · API: /api · docs: /docs · blocklists: /blocklists · about: /about · firmware: github.com/HoneyMire/HoneyMire