Skip to content

Honeypot experiment

Results

Statistics from both honeypots. Every chart and table states its time window, the source CSV and the script that computed it – so anyone can recompute the numbers their own way.

Data updated: 2026-10-03 10:31:16 UTC+02:00

Report a problem

Port ranking #


The main table of the experiment: which ports attackers were most interested in. Sort by any column, filter by server, and search for a specific port, range or service name. Every row can be linked to, for example #port-3389.

For srv4, the real destination port from hptcp is used. Redirect ports (42222, 42223, 42280, 42443) are not counted as destination ports.
Port Protocol Typical service Server Attempts Unique IPs Share
5901 tcp VNC both servers 883,864 801 16.1%
3389 tcp RDP both servers 734,148 2,425 13.4%
3389 tcp RDP srv4 726,599 1,515 18.1%
5900 tcp VNC both servers 707,172 1,343 12.9%
445 tcp SMB both servers 459,930 6,055 8.4%
5901 tcp VNC srv4 449,586 598 11.2%
5901 tcp VNC srv3 434,278 655 29.7%
445 tcp SMB srv3 415,953 5,570 28.4%
5900 tcp VNC srv4 360,884 1,098 9.0%
5900 tcp VNC srv3 346,288 1,176 23.7%
Time window
2026-08-21 – 2026-09-16
Source data
honeypot-ports-aggregated-20260922.csv
Script
to be published
Format
field documentation

Traffic over time #


Event volume over time, split into campaigns and baseline noise, with the number of unique IP addresses below it. According to the agents’ journals, single campaigns could produce most of a day’s traffic. Without the split the chart would mislead: a campaign would look like a trend and its end like a collection outage.

Exactly how campaigns are separated from baseline noise is defined by the script listed below the chart.

Events

  • Baseline noise
  • Campaigns
0200k400k600k800k08-222026-08-22 Baseline noise: 22,460 Campaigns: 59,843 Total: 82,303 Incomplete period – data for 12 h / 24 h2026-08-23 Baseline noise: 45,099 Campaigns: 34,177 Total: 79,2762026-08-24 Baseline noise: 38,153 Campaigns: 10,775 Total: 48,92808-252026-08-25 Baseline noise: 40,077 Campaigns: 29,825 Total: 69,9022026-08-26 Baseline noise: 40,083 Campaigns: 28,709 Total: 68,7922026-08-27 Baseline noise: 42,664 Campaigns: 161,642 Total: 204,30608-282026-08-28 Baseline noise: 42,779 Campaigns: 159,044 Total: 201,8232026-08-29 Baseline noise: 34,634 Campaigns: 171,641 Total: 206,2752026-08-30 Baseline noise: 37,426 Campaigns: 148,263 Total: 185,68908-312026-08-31 Baseline noise: 35,671 Campaigns: 504,248 Total: 539,9192026-09-01 Baseline noise: 53,935 Campaigns: 666,265 Total: 720,2002026-09-02 Baseline noise: 65,803 Campaigns: 209,955 Total: 275,75809-032026-09-03 Baseline noise: 46,703 Campaigns: 227,972 Total: 274,6752026-09-04 Baseline noise: 51,972 Campaigns: 167,450 Total: 219,4222026-09-05 Baseline noise: 58,392 Campaigns: 95,631 Total: 154,02309-062026-09-06 Baseline noise: 85,408 Campaigns: 46,399 Total: 131,8072026-09-07 Baseline noise: 89,526 Campaigns: 94,877 Total: 184,4032026-09-08 Baseline noise: 109,966 Campaigns: 59,781 Total: 169,74709-092026-09-09 Baseline noise: 128,711 Campaigns: 48,861 Total: 177,5722026-09-10 Baseline noise: 132,528 Campaigns: 60,866 Total: 193,3942026-09-11 Baseline noise: 147,151 Campaigns: 63,267 Total: 210,41809-122026-09-12 Baseline noise: 171,996 Campaigns: 82,831 Total: 254,8272026-09-13 Baseline noise: 131,895 Campaigns: 105,016 Total: 236,9112026-09-14 Baseline noise: 129,805 Campaigns: 83,835 Total: 213,64009-152026-09-15 Baseline noise: 112,933 Campaigns: 159,141 Total: 272,0742026-09-16 Baseline noise: 72,402 Campaigns: 28,713 Total: 101,115 Incomplete period – data for 12 h / 24 h

Unique IP addresses

Distinct source IP addresses on each day.

  • srv3
  • srv4
02k4k6ksrv4srv308-2208-2508-2808-3109-0309-0609-0909-1209-152026-08-22 srv3: 547 srv4: 1,870 Incomplete period – data for 12 h / 24 h2026-08-23 srv3: 1,292 srv4: 3,5292026-08-24 srv3: 1,429 srv4: 3,3092026-08-25 srv3: 1,552 srv4: 3,8242026-08-26 srv3: 1,552 srv4: 3,7752026-08-27 srv3: 1,585 srv4: 4,3012026-08-28 srv3: 1,364 srv4: 4,0832026-08-29 srv3: 1,029 srv4: 3,8532026-08-30 srv3: 975 srv4: 4,1762026-08-31 srv3: 1,488 srv4: 4,1832026-09-01 srv3: 1,573 srv4: 4,5002026-09-02 srv3: 1,859 srv4: 4,2812026-09-03 srv3: 1,621 srv4: 4,3432026-09-04 srv3: 1,628 srv4: 4,0872026-09-05 srv3: 1,535 srv4: 4,1172026-09-06 srv3: 1,637 srv4: 4,3492026-09-07 srv3: 1,494 srv4: 4,4022026-09-08 srv3: 1,758 srv4: 4,6092026-09-09 srv3: 1,733 srv4: 4,6712026-09-10 srv3: 1,818 srv4: 5,0952026-09-11 srv3: 1,747 srv4: 5,4022026-09-12 srv3: 1,859 srv4: 5,4502026-09-13 srv3: 1,854 srv4: 5,4342026-09-14 srv3: 1,994 srv4: 5,5162026-09-15 srv3: 1,884 srv4: 5,3032026-09-16 srv3: 1,386 srv4: 3,449 Incomplete period – data for 12 h / 24 h

Unique IP addresses cannot be summed across servers – the same address may have attacked both. Each server therefore gets a line of its own.

Dimmed columns and hollow markers are incomplete periods: the collection window opens and closes at 12:00 UTC, and a period cut short by the chosen range is shorter than the rest. Don’t compare them with their neighbours.

Show values as a table
Day (UTC) Events Campaigns Baseline noise Unique IPs srv3 Unique IPs srv4
2026-08-22 · incomplete 82,303 59,843 22,460 547 1,870
2026-08-23 79,276 34,177 45,099 1,292 3,529
2026-08-24 48,928 10,775 38,153 1,429 3,309
2026-08-25 69,902 29,825 40,077 1,552 3,824
2026-08-26 68,792 28,709 40,083 1,552 3,775
2026-08-27 204,306 161,642 42,664 1,585 4,301
2026-08-28 201,823 159,044 42,779 1,364 4,083
2026-08-29 206,275 171,641 34,634 1,029 3,853
2026-08-30 185,689 148,263 37,426 975 4,176
2026-08-31 539,919 504,248 35,671 1,488 4,183
2026-09-01 720,200 666,265 53,935 1,573 4,500
2026-09-02 275,758 209,955 65,803 1,859 4,281
2026-09-03 274,675 227,972 46,703 1,621 4,343
2026-09-04 219,422 167,450 51,972 1,628 4,087
2026-09-05 154,023 95,631 58,392 1,535 4,117
2026-09-06 131,807 46,399 85,408 1,637 4,349
2026-09-07 184,403 94,877 89,526 1,494 4,402
2026-09-08 169,747 59,781 109,966 1,758 4,609
2026-09-09 177,572 48,861 128,711 1,733 4,671
2026-09-10 193,394 60,866 132,528 1,818 5,095
2026-09-11 210,418 63,267 147,151 1,747 5,402
2026-09-12 254,827 82,831 171,996 1,859 5,450
2026-09-13 236,911 105,016 131,895 1,854 5,434
2026-09-14 213,640 83,835 129,805 1,994 5,516
2026-09-15 272,074 159,141 112,933 1,884 5,303
2026-09-16 · incomplete 101,115 28,713 72,402 1,386 3,449
Time window
2026-08-21 – 2026-09-16
Source data
timeline-aggregated not available yet
Script
to be published
Format
field documentation

Where the connections came from #


The origin of the connections. A country is the one the IP address is registered in, not where the attacker actually sits – behind an address there may be a rented server or a compromised machine anywhere in the world. The exact numbers are in the tables below.

The map is drawn by Datawrapper; loading it connects the browser to their servers. Open the map on its own

Geography and networks #


Where traffic came from according to source IP geolocation, and which autonomous systems (ASNs) the addresses belong to. Geolocation shows where an address is registered, not where the attacker sits.

Top countries

  1. US 37.6%2,057,660
  2. DE 22.5%1,230,744
  3. CN 10.2%556,778
  4. GB 8.9%486,870
  5. SC 3.4%184,746
  6. NL 2.2%120,671
  7. TN 1.8%96,601
  8. VN 1.2%64,512
  9. MX 1.1%59,561
  10. IN 0.9%49,705
  11. SG 0.9%49,368
  12. BR 0.8%44,530
  13. RU 0.8%42,439
  14. HK 0.7%38,439
  15. RO 0.7%37,368

Largest networks (ASN)

ASN Network Events Unique IPs Share
263269 RAGTEK TECNOLOGIA
BR
1 1 0.0%
28753 LEASEWEB-DE-FRA-10
DE
1 1 0.0%
329678 High-Speed-Access-Company
LY
1 1 0.0%
197125 UA-BROVIS-AS ISP-Brovis
UA
1 1 0.0%
263424 Fonelight Telecomunicacoes SA
BR
1 1 0.0%
131398 LDCC-AS-VN LOTTE INNOVATE VIETNAM COMPANY LIMITED
VN
1 1 0.0%
35122 SATNET-AS
BG
1 1 0.0%
25299 TRINITY-AS
RU
1 1 0.0%
2519 VECTANT ARTERIA Networks Corporation
JP
1 1 0.0%
34534 BULLIONET
FR
1 1 0.0%
Show values as a table
Country Events Unique IPs Share
US 2,057,660 13,624 37.6%
DE 1,230,744 1,111 22.5%
CN 556,778 5,671 10.2%
GB 486,870 2,870 8.9%
SC 184,746 319 3.4%
NL 120,671 174 2.2%
TN 96,601 94 1.8%
VN 64,512 644 1.2%
MX 59,561 281 1.1%
IN 49,705 850 0.9%
Time window
2026-08-21 – 2026-09-16
Source data
geo-aggregated not available yet
Script
to be published
Format
field documentation

Credentials #


Username and password combinations attackers tried, and the most-tried usernames. Values are shown exactly as they arrived.

Most-tried usernames

  1. root 4,665 passwords43,470
  2. admin 722 passwords10,909
  3. enable\x00 2 passwords2,938
  4. user 216 passwords2,100
  5. sa 83 passwords2,049
  6. support 178 passwords1,551
  7. test 215 passwords1,518
  8. ubuntu 100 passwords1,456
  9. cloud 148 passwords1,281
  10. postgres 93 passwords1,198
  11. batacek 147 passwords1,164
  12. srv 147 passwords1,154
  13. shell\x00 1 passwords965
  14. deploy 66 passwords925
  15. ftp 459 passwords876

Most common combinations

Username Password Attempts Unique IPs
root 1234 680 128
sa (empty) 667 18
root anko 582 24
user user 563 99
root password 543 119
admin admin1234 531 68
root pass 521 69
postgres (empty) 509 23
admin smcadmin 499 27
root 1111 455 32
Time window
2026-08-21 – 2026-09-16
Source data
credentials-aggregated not available yet
Script
to be published
Format
field documentation

What happened after login #


Commands attackers typed into the emulated shell, ordered by frequency. This is attacker input, not code that actually ran on the server.

Primary record, shown exactly as it was produced.
Command Count Sessions
uname -s -v -n -r -m 41,470 41,470
system 21,144 21,143
shell 21,044 21,044
sh 21,015 21,014
enable 20,259 20,258
linuxshell 18,836 18,834
echo -e "\x47\x41\x59\x46\x47\x54" 4,749 493
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH uname=$(uname -s -v -n -m 2>/dev/null || /bin/uname -s -v -n -m 2>/dev/null || /usr/bin/uname -s -v -n -m 2>/dev/null || busybox uname -s -v -n -m 2>/dev/null || ( [ -f /proc/version ] && head -1 /proc/version | cut -d' ' -f1 ) || ( [ -f /etc/os-release ] && grep '^ID=' /etc/os-release | cut -d= -f2 | tr -d '"' ) || echo "") arch=$(uname -m 2>/dev/null || /bin/uname -m 2>/dev/null || /usr/bin/uname -m 2>/dev/null || busybox uname -m 2>/dev/null || ( [ -f /proc/cpuinfo ] && grep -q "lm" /proc/cpuinfo && echo x86_64 ) || ( [ -f /proc/cpuinfo ] && grep -q "CPU architecture: 8" /proc/cpuinfo && echo aarch64 ) || ( [ -f /proc/cpuinfo ] && grep -q "CPU architecture: 7" /proc/cpuinfo && echo armv7l ) || echo "") uptime=$(cat /proc/uptime 2>/dev/null || busybox cat /proc/uptime 2>/dev/null) cpus=$(nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || busybox nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null) cpu_model=$( { lscpu 2>/dev/null | awk -F: '/Model name/ {print $2}'; grep -m1 -E "^model name" /proc/cpuinfo 2>/dev/null | cut -d: -f2-; grep -m1 -E "^Hardware" /proc/cpuinfo 2>/dev/null | cut -d: -f2-; cat /proc/device-tree/model 2>/dev/null; } | sed '/^$/d; /unknown/d; s/^[[:space:]]*//; s/[[:space:]]*$//; s/ AArch64 Processor$//; s/ Processor$//; s/ CPU$//' | head -1 ) gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia; busybox lspci 2>/dev/null | grep -i vga; busybox lspci 2>/dev/null | grep -i nvidia) 2>/dev/null ) last_output=$(last 2>/dev/null) filter_output=$( ( export LANG=C LC_ALL=C; echo '===SHELL_BEHAVIOR==='; printf 'path_err='; ( ./xxxxxx 2>&1 || true ) | ( head -c 250 2>/dev/null || busybox head -c 250 2>/dev/null || dd bs=250 count=1 2>/dev/null ) | ( tr -d '\n' 2>/dev/null || busybox tr -d '\n' 2>/dev/null || cat ); printf '\n'; printf 'cmd_err='; ( xxxxxx 2>&1 || true ) | ( head -c 250 2>/dev/null || busybox head -c 250 2>/dev/null || dd bs=250 count=1 2>/dev/null ) | ( tr -d '\n' 2>/dev/null || busybox tr -d '\n' 2>/dev/null || cat ); printf '\n'; printf 'execute_err='; out=$(bash -c 'printf "#!/bin/bash\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); case "$out" in *xxxxxx*) ;; *) out=$(/bin/bash -c 'printf "#!/bin/bash\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); case "$out" in *xxxxxx*) ;; *) out=$(/usr/bin/bash -c 'printf "#!/bin/bash\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); case "$out" in *xxxxxx*) ;; *) out=$(busybox sh -c 'printf "#!/bin/sh\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1 || sh -c 'printf "#!/bin/sh\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); esac; esac; esac; printf '%s' "$out" | ( head -c 250 2>/dev/null || busybox head -c 250 2>/dev/null || dd bs=250 count=1 2>/dev/null ) | ( tr -d '\n' 2>/dev/null || busybox tr -d '\n' 2>/dev/null || cat ); printf '\n'; echo '===DONE===' ) 2>&1 ) echo "UNAME:$uname" echo "ARCH:$arch" echo "UPTIME:$uptime" echo "CPUS:$cpus" echo "CPU_MODEL:$cpu_model" echo "GPU:$gpu_info" echo "LAST:$last_output" echo "FILTER:$filter_output" 4,333 4,332
/bin/busybox 3,149 312
/bin/./uname -s -v -n -r -m 2,275 2,275
Time window
2026-08-21 – 2026-09-16
Source data
attacker-commands-aggregated not available yet
Script
to be published
Format
field documentation

Captured samples #


Files attackers tried to download or upload, by type and architecture.

This lists hashes and metadata only. The samples themselves are in a password-protected archive in Data

By file type

  1. PE1,058
  2. ELF58
  3. script39
  4. data35

By architecture

  1. —1,132
  2. x86_6424
  3. arm11
  4. x864
  5. mips4
  6. mipsel4
  7. aarch643
  8. riscv2
  9. elf-0x5d2
  10. sh1
  11. elf-0x41
  12. ppc1
  13. sparc1
SHA-256 Type Architecture Size First seen Times seen Look up
0c99433c7d433d65ab890dcee20b330f262379d532bc76f91e18f09ecfa5fb54 script — 202 B 2026-08-31 19:40:36 5 VirusTotal
0658e79b91e732723b540ee7040eb0289c497f781d750e42b25dfcf10d233f50 ELF arm 212.7 KB 2026-08-26 04:12:20 4 VirusTotal
d70f917e35813a7ae323e6b2b539d6dbbfc3a3a6599f1fed93430b14ca08b141 ELF arm 1.4 MB 2026-09-06 11:21:42 4 VirusTotal
d1cac82f44b54b0fd244a9e4122811e9ae108a197c7a65a20fd2e7552683e68e ELF aarch64 1.6 MB 2026-09-06 11:21:42 4 VirusTotal
8e1a67a5c03b3cd818f046c7a1605afccc0ee5ce437a0d099881f1872b54bc70 ELF x86 1.8 MB 2026-09-06 11:21:42 4 VirusTotal
3f3bf218089d1488617d37f8a5116bb2791eb39ce06a1b5bc9a4cdfe5e94dd39 ELF riscv 1.7 MB 2026-09-06 11:21:42 4 VirusTotal
f0aa83bbbd2c75e2f71ec16029ee5fcfad59f3a8efa30a500b815f0f6c18d987 ELF x86_64 1.9 MB 2026-09-06 11:21:42 4 VirusTotal
1193dde1c831808bf6f2db6f5b850b846b8a7f870873ec3b8a347f21cc5d96e3 data — 9 B 2026-09-12 11:28:50 3 VirusTotal
a9b1c85a7bd78dd1112ecc75c9070ea8c53078831a17aa09ebeb287fe6e21b72 data — 9 B 2026-09-12 11:28:50 3 VirusTotal
0dc95fb4077cce0bff19aa1a77109d059dff6503bbf6c1b0dd2f41fc0a4c88e7 data — 9 B 2026-09-14 19:35:40 3 VirusTotal
Time window
2026-08-21 – 2026-09-16
Source data
samples-aggregated not available yet
Script
to be published
Format
field documentation

Server comparison #


How much traffic the larger surface brought in, and how the structure differs between the two servers.

Absolute numbers of the two servers are not comparable: srv4 exposed a surface orders of magnitude larger. Compare structure and ranking, not size. More
Metric srv3 srv4 srv4 / srv3
Connection attempts (port ranking) 1,462,877 4,014,322 2.7×
Ports hit 45 58,628 1,302.8×
Events (traffic over time) 1,462,877 4,014,322 2.7×

srv3 top ports

  1. 5901/tcp VNC434,278
  2. 445/tcp SMB415,953
  3. 5900/tcp VNC346,288
  4. 22/tcp SSH77,679
  5. 443/tcp HTTPS25,880
  6. 23/tcp Telnet24,961
  7. 5060/udp SIP22,484
  8. 80/tcp HTTP18,336
  9. 3000/tcp HTTP alt9,322
  10. 3389/tcp RDP7,549

srv4 top ports

  1. 3389/tcp RDP726,599
  2. 5901/tcp VNC449,586
  3. 5900/tcp VNC360,884
  4. 1256/tcp341,276
  5. 8787/tcp340,499
  6. 8082/tcp HTTP alt323,345
  7. 1080/tcp SOCKS270,186
  8. 5800/tcp VNC HTTP159,507
  9. 22/tcp SSH61,829
  10. 445/tcp SMB43,977
Time window
2026-08-21 – 2026-09-16
Source data
honeypot-ports-aggregated-20260922.csv, timeline-aggregated not available yet
Script
to be published
Format
field documentation