Archiv obsahuje ziveho malwaru zachyceneho honeypotem. Heslo: infected. Nerozbaluj na stroji, na kterem ti zalezi.
Files to download #
The aggregated CSVs are kilobytes and anyone can grab them; the raw data is orders of magnitude larger. Files that have not been generated yet are marked.
Malware samples
Malware captured by the honeypots, in a password-protected archive.
Archiv obsahuje ziveho malwaru zachyceneho honeypotem. Heslo: infected. Nerozbaluj na stroji, na kterem ti zalezi.
Build your own chart #
Pick one of the published CSV files, a column for the X axis and a value for the Y axis, and narrow the rows with WHERE conditions if you like. The chart is computed on the server straight from these files – no other file or column than the ones listed here can be read.
SUM(events) by date
52 of 52 rows match the conditions; the X axis has 26 distinct values.
The first and last day of the window are half days – the window opens and closes at 12:00 UTC.
Show values as a table
date |
SUM(events) |
Rows |
|---|---|---|
| 2026-08-22 | 82,303 | 2 |
| 2026-08-23 | 79,276 | 2 |
| 2026-08-24 | 48,928 | 2 |
| 2026-08-25 | 69,902 | 2 |
| 2026-08-26 | 68,792 | 2 |
| 2026-08-27 | 204,306 | 2 |
| 2026-08-28 | 201,823 | 2 |
| 2026-08-29 | 206,275 | 2 |
| 2026-08-30 | 185,689 | 2 |
| 2026-08-31 | 539,919 | 2 |
| 2026-09-01 | 720,200 | 2 |
| 2026-09-02 | 275,758 | 2 |
| 2026-09-03 | 274,675 | 2 |
| 2026-09-04 | 219,422 | 2 |
| 2026-09-05 | 154,023 | 2 |
| 2026-09-06 | 131,807 | 2 |
| 2026-09-07 | 184,403 | 2 |
| 2026-09-08 | 169,747 | 2 |
| 2026-09-09 | 177,572 | 2 |
| 2026-09-10 | 193,394 | 2 |
| 2026-09-11 | 210,418 | 2 |
| 2026-09-12 | 254,827 | 2 |
| 2026-09-13 | 236,911 | 2 |
| 2026-09-14 | 213,640 | 2 |
| 2026-09-15 | 272,074 | 2 |
| 2026-09-16 | 101,115 | 2 |
- Source data
- honeypot-timeline-20260922.csv
- Time window
- 2026-08-22 12:00:00 UTC – 2026-09-16 12:00:00 UTC
- Script
hp_aggregate.py· d60ff11- Format
- field documentation
- Equivalent SQL
SELECT date, SUM(events) FROM timeline.csv GROUP BY date ORDER BY date
Format documentation #
For every published file: field name, type, meaning and an example. The examples illustrate the format; they are not values from the data.
ports.csv
One row per combination of port, protocol and server.
| Field | Type | Meaning | Example |
|---|---|---|---|
port |
integer | Destination port. For srv4, the real port the attacker aimed at (from hptcp), not the port after redirection. | 22 |
protocol |
string | Transport protocol. | tcp |
service |
string | The service that usually runs on the port. A label, not detection of the actual traffic. | SSH |
server |
srv3 | srv4 | both | srv3, srv4, or both for a row covering both servers together. | srv4 |
attempts |
integer | Number of connection attempts to the port over the whole time window. | 12345 |
unique_ips |
integer | Number of distinct source IP addresses. | 678 |
share_pct |
decimal | Share of attempts on this port, in percent. | 9.1 |
timeline.csv
One row per day and server.
| Field | Type | Meaning | Example |
|---|---|---|---|
date |
date (YYYY-MM-DD) | Calendar day. | 2026-08-22 |
server |
srv3 | srv4 | srv3 or srv4. | srv4 |
events |
integer | Number of events that day. | 12345 |
unique_ips |
integer | Number of distinct source IP addresses that day. | 678 |
campaign_events |
integer | Events attributed to campaigns. | 10000 |
baseline_events |
integer | Baseline noise events. events = campaign_events + baseline_events. | 2345 |
geo.csv
One row per combination of country and autonomous system.
| Field | Type | Meaning | Example |
|---|---|---|---|
country |
ISO 3166-1 alpha-2 | Country code from source IP geolocation. | NL |
asn |
string | Autonomous system number. | AS64500 |
asn_name |
string | Autonomous system name. | Example Networks |
events |
integer | Number of events. | 12345 |
unique_ips |
integer | Number of distinct source IP addresses. | 678 |
share_pct |
decimal | Share of all events, in percent. | 9.1 |
credentials.csv
One row per username and password combination.
| Field | Type | Meaning | Example |
|---|---|---|---|
username |
string | Username tried, unmodified. | root |
password |
string | Password tried, unmodified. | 123456 |
attempts |
integer | Number of attempts with this combination. | 12345 |
unique_ips |
integer | Number of distinct IP addresses that tried the combination. | 678 |
attacker_commands.csv
One row per unique command.
| Field | Type | Meaning | Example |
|---|---|---|---|
command |
string | The command exactly as the attacker typed it. | uname -a |
count |
integer | How many times the command was entered. | 12345 |
unique_sessions |
integer | In how many distinct sessions it appeared. | 678 |
samples.csv
One row per unique sample by SHA-256.
| Field | Type | Meaning | Example |
|---|---|---|---|
sha256 |
hex (64) | SHA-256 hash of the file. | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
file_type |
string | File type. | ELF |
architecture |
string | Target architecture for executables. | x86-64 |
size_bytes |
integer | Size in bytes. | 12345 |
first_seen |
datetime (ISO 8601) | When the sample was first captured. | 2026-08-22T14:03:11Z |
times_seen |
integer | How many times it was captured. | 12 |
commands.csv
Log of the commands agents and the operator ran on the servers. One row per command; command outputs are not included.
| Field | Type | Meaning | Example |
|---|---|---|---|
timestamp |
datetime (ISO 8601) | When the command was run. | 2026-08-21T09:15:02Z |
server |
srv3 | srv4 | srv3 or srv4. | srv3 |
source |
agent | operator | agent (the language model) or operator (a human). | agent |
command |
string | The command that was run. | uptime |
exit_code |
integer | Exit code. | 0 |
duration_ms |
integer | Run time in milliseconds. | 42 |
Agent chats and journals
Each session comes in two forms: Markdown (the agent’s readable text, reasoning summaries, commands and outputs) and a raw JSON export for machine processing. Both are in the original language. If an English translation of a session exists, it is a separate file and always labelled as a translation on the site.
Individual events
The raw event format differs by sensor and by server. Field documentation will be added when the data is published.
Licence #
The data and the scripts each have their own licence. You may use them at work or in research – just credit the source.
- Data
- CC BY-NC 4.0
- Scripts
- to be added
- Script repository
- to be published
How to cite #
If you use the data, please credit the source. One line is enough:
Barták, Tomáš (2026). Honeypot dataset: 25 days of traffic from two honeypots, 22 Aug – 16 Sep 2026 [Data set]. https://batacek.eu/honeypot/
BibTeX
@misc{bartak2026honeypot,
author = {Barták, Tomáš},
title = {Honeypot dataset: 25 days of traffic from two honeypots, 22 Aug – 16 Sep 2026},
year = {2026},
url = {https://batacek.eu/honeypot/},
note = {Data set}
}
Found a bug, missing data or a leak of sensitive information? Report a problem