Port ranking #
The main table of the experiment: which ports attackers were most interested in. Sort by any column, filter by server, and search for a specific port, range or service name. Every row can be linked to, for example #port-3389.
| Port | Protocol | Typical service | Server | Attempts | Unique IPs | Share |
|---|---|---|---|---|---|---|
| 22 | tcp | SSH | srv4 | 61,829 | 3,364 | 1.5% |
| 22 | tcp | SSH | srv3 | 77,679 | 3,625 | 5.3% |
| 22 | tcp | SSH | both servers | 139,508 | 5,790 | 2.5% |
| 5800 | tcp | VNC HTTP | both servers | 159,507 | 152 | 2.9% |
| 5800 | tcp | VNC HTTP | srv4 | 159,507 | 152 | 4.0% |
| 1080 | tcp | SOCKS | both servers | 270,186 | 278 | 4.9% |
| 1080 | tcp | SOCKS | srv4 | 270,186 | 278 | 6.7% |
| 8082 | tcp | HTTP alt | both servers | 323,345 | 259 | 5.9% |
| 8082 | tcp | HTTP alt | srv4 | 323,345 | 259 | 8.1% |
| 8787 | tcp | — | both servers | 340,499 | 49 | 6.2% |
- Time window
- 2026-08-21 – 2026-09-16
- Source data
- honeypot-ports-aggregated-20260922.csv
- Script
- to be published
- Format
- field documentation
Traffic over time #
Event volume over time, split into campaigns and baseline noise, with the number of unique IP addresses below it. According to the agents’ journals, single campaigns could produce most of a day’s traffic. Without the split the chart would mislead: a campaign would look like a trend and its end like a collection outage.
Exactly how campaigns are separated from baseline noise is defined by the script listed below the chart.
Events
- Baseline noise
- Campaigns
Unique IP addresses
Distinct source IP addresses on each day.
- srv3
- srv4
Unique IP addresses cannot be summed across servers – the same address may have attacked both. Each server therefore gets a line of its own.
Dimmed columns and hollow markers are incomplete periods: the collection window opens and closes at 12:00 UTC, and a period cut short by the chosen range is shorter than the rest. Don’t compare them with their neighbours.
Show values as a table
| Day (UTC) | Events | Campaigns | Baseline noise | Unique IPs srv3 | Unique IPs srv4 |
|---|---|---|---|---|---|
| 2026-08-22 · incomplete | 82,303 | 59,843 | 22,460 | 547 | 1,870 |
| 2026-08-23 | 79,276 | 34,177 | 45,099 | 1,292 | 3,529 |
| 2026-08-24 | 48,928 | 10,775 | 38,153 | 1,429 | 3,309 |
| 2026-08-25 | 69,902 | 29,825 | 40,077 | 1,552 | 3,824 |
| 2026-08-26 | 68,792 | 28,709 | 40,083 | 1,552 | 3,775 |
| 2026-08-27 | 204,306 | 161,642 | 42,664 | 1,585 | 4,301 |
| 2026-08-28 | 201,823 | 159,044 | 42,779 | 1,364 | 4,083 |
| 2026-08-29 | 206,275 | 171,641 | 34,634 | 1,029 | 3,853 |
| 2026-08-30 | 185,689 | 148,263 | 37,426 | 975 | 4,176 |
| 2026-08-31 | 539,919 | 504,248 | 35,671 | 1,488 | 4,183 |
| 2026-09-01 | 720,200 | 666,265 | 53,935 | 1,573 | 4,500 |
| 2026-09-02 | 275,758 | 209,955 | 65,803 | 1,859 | 4,281 |
| 2026-09-03 | 274,675 | 227,972 | 46,703 | 1,621 | 4,343 |
| 2026-09-04 | 219,422 | 167,450 | 51,972 | 1,628 | 4,087 |
| 2026-09-05 | 154,023 | 95,631 | 58,392 | 1,535 | 4,117 |
| 2026-09-06 | 131,807 | 46,399 | 85,408 | 1,637 | 4,349 |
| 2026-09-07 | 184,403 | 94,877 | 89,526 | 1,494 | 4,402 |
| 2026-09-08 | 169,747 | 59,781 | 109,966 | 1,758 | 4,609 |
| 2026-09-09 | 177,572 | 48,861 | 128,711 | 1,733 | 4,671 |
| 2026-09-10 | 193,394 | 60,866 | 132,528 | 1,818 | 5,095 |
| 2026-09-11 | 210,418 | 63,267 | 147,151 | 1,747 | 5,402 |
| 2026-09-12 | 254,827 | 82,831 | 171,996 | 1,859 | 5,450 |
| 2026-09-13 | 236,911 | 105,016 | 131,895 | 1,854 | 5,434 |
| 2026-09-14 | 213,640 | 83,835 | 129,805 | 1,994 | 5,516 |
| 2026-09-15 | 272,074 | 159,141 | 112,933 | 1,884 | 5,303 |
| 2026-09-16 · incomplete | 101,115 | 28,713 | 72,402 | 1,386 | 3,449 |
- Time window
- 2026-08-21 – 2026-09-16
- Source data
- timeline-aggregated not available yet
- Script
- to be published
- Format
- field documentation
Where the connections came from #
The origin of the connections. A country is the one the IP address is registered in, not where the attacker actually sits – behind an address there may be a rented server or a compromised machine anywhere in the world. The exact numbers are in the tables below.
The map is drawn by Datawrapper; loading it connects the browser to their servers. Open the map on its own
Geography and networks #
Where traffic came from according to source IP geolocation, and which autonomous systems (ASNs) the addresses belong to. Geolocation shows where an address is registered, not where the attacker sits.
Top countries
Largest networks (ASN)
| ASN | Network | Events | Unique IPs | Share |
|---|---|---|---|---|
| 265356 | NET PLANETY INFOTELECOM LTDA ME BR |
1 | 1 | 0.0% |
| 48092 | NSB-AS T2 Russia Network RU |
1 | 1 | 0.0% |
| 37642 | Comnet-Lesotho-AS LS |
1 | 1 | 0.0% |
| 41244 | ZMM-AS UA |
1 | 1 | 0.0% |
| 31234 | KRAM-AS UA |
1 | 1 | 0.0% |
| 8542 | EVINY-AS8542 Norway NO |
1 | 1 | 0.0% |
| 52698 | OPENTEL Comercio e Servicos Ltda BR |
1 | 1 | 0.0% |
| 39406 | CONVEX-ZARECNY RU |
1 | 1 | 0.0% |
| 198589 | JT-AS IQ |
1 | 1 | 0.0% |
| 135212 | DIGIWAY-AS-IN Digiway Net Pvt Ltd IN |
1 | 1 | 0.0% |
Show values as a table
| Country | Events | Unique IPs | Share |
|---|---|---|---|
| US | 2,057,660 | 13,624 | 37.6% |
| DE | 1,230,744 | 1,111 | 22.5% |
| CN | 556,778 | 5,671 | 10.2% |
| GB | 486,870 | 2,870 | 8.9% |
| SC | 184,746 | 319 | 3.4% |
| NL | 120,671 | 174 | 2.2% |
| TN | 96,601 | 94 | 1.8% |
| VN | 64,512 | 644 | 1.2% |
| MX | 59,561 | 281 | 1.1% |
| IN | 49,705 | 850 | 0.9% |
- Time window
- 2026-08-21 – 2026-09-16
- Source data
- geo-aggregated not available yet
- Script
- to be published
- Format
- field documentation
Credentials #
Username and password combinations attackers tried, and the most-tried usernames. Values are shown exactly as they arrived.
Most-tried usernames
Most common combinations
| Username | Password | Attempts | Unique IPs |
|---|---|---|---|
root |
(empty) | 3,084 | 219 |
admin |
admin |
2,649 | 849 |
enable\x00 |
linuxshell\x00 |
1,955 | 24 |
admin |
(empty) | 1,939 | 69 |
root |
xc3511 |
1,591 | 76 |
root |
admin |
1,529 | 160 |
root |
vizxv |
1,523 | 120 |
root |
123456 |
1,207 | 142 |
support |
support |
990 | 129 |
enable\x00 |
system\x00 |
983 | 27 |
- Time window
- 2026-08-21 – 2026-09-16
- Source data
- credentials-aggregated not available yet
- Script
- to be published
- Format
- field documentation
What happened after login #
Commands attackers typed into the emulated shell, ordered by frequency. This is attacker input, not code that actually ran on the server.
| Command | Count | Sessions |
|---|---|---|
uname -s -v -n -r -m |
41,470 | 41,470 |
system |
21,144 | 21,143 |
shell |
21,044 | 21,044 |
sh |
21,015 | 21,014 |
enable |
20,259 | 20,258 |
linuxshell |
18,836 | 18,834 |
echo -e "\x47\x41\x59\x46\x47\x54" |
4,749 | 493 |
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH
uname=$(uname -s -v -n -m 2>/dev/null || /bin/uname -s -v -n -m 2>/dev/null || /usr/bin/uname -s -v -n -m 2>/dev/null || busybox uname -s -v -n -m 2>/dev/null || ( [ -f /proc/version ] && head -1 /proc/version | cut -d' ' -f1 ) || ( [ -f /etc/os-release ] && grep '^ID=' /etc/os-release | cut -d= -f2 | tr -d '"' ) || echo "")
arch=$(uname -m 2>/dev/null || /bin/uname -m 2>/dev/null || /usr/bin/uname -m 2>/dev/null || busybox uname -m 2>/dev/null || ( [ -f /proc/cpuinfo ] && grep -q "lm" /proc/cpuinfo && echo x86_64 ) || ( [ -f /proc/cpuinfo ] && grep -q "CPU architecture: 8" /proc/cpuinfo && echo aarch64 ) || ( [ -f /proc/cpuinfo ] && grep -q "CPU architecture: 7" /proc/cpuinfo && echo armv7l ) || echo "")
uptime=$(cat /proc/uptime 2>/dev/null || busybox cat /proc/uptime 2>/dev/null)
cpus=$(nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || busybox nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null)
cpu_model=$( { lscpu 2>/dev/null | awk -F: '/Model name/ {print $2}'; grep -m1 -E "^model name" /proc/cpuinfo 2>/dev/null | cut -d: -f2-; grep -m1 -E "^Hardware" /proc/cpuinfo 2>/dev/null | cut -d: -f2-; cat /proc/device-tree/model 2>/dev/null; } | sed '/^$/d; /unknown/d; s/^[[:space:]]*//; s/[[:space:]]*$//; s/ AArch64 Processor$//; s/ Processor$//; s/ CPU$//' | head -1 )
gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia; busybox lspci 2>/dev/null | grep -i vga; busybox lspci 2>/dev/null | grep -i nvidia) 2>/dev/null )
last_output=$(last 2>/dev/null)
filter_output=$( ( export LANG=C LC_ALL=C; echo '===SHELL_BEHAVIOR==='; printf 'path_err='; ( ./xxxxxx 2>&1 || true ) | ( head -c 250 2>/dev/null || busybox head -c 250 2>/dev/null || dd bs=250 count=1 2>/dev/null ) | ( tr -d '\n' 2>/dev/null || busybox tr -d '\n' 2>/dev/null || cat ); printf '\n'; printf 'cmd_err='; ( xxxxxx 2>&1 || true ) | ( head -c 250 2>/dev/null || busybox head -c 250 2>/dev/null || dd bs=250 count=1 2>/dev/null ) | ( tr -d '\n' 2>/dev/null || busybox tr -d '\n' 2>/dev/null || cat ); printf '\n'; printf 'execute_err='; out=$(bash -c 'printf "#!/bin/bash\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); case "$out" in *xxxxxx*) ;; *) out=$(/bin/bash -c 'printf "#!/bin/bash\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); case "$out" in *xxxxxx*) ;; *) out=$(/usr/bin/bash -c 'printf "#!/bin/bash\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); case "$out" in *xxxxxx*) ;; *) out=$(busybox sh -c 'printf "#!/bin/sh\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1 || sh -c 'printf "#!/bin/sh\necho \"xxxxxx\"\n" > filter && chmod +x filter && ./filter && rm -rf filter' 2>&1); esac; esac; esac; printf '%s' "$out" | ( head -c 250 2>/dev/null || busybox head -c 250 2>/dev/null || dd bs=250 count=1 2>/dev/null ) | ( tr -d '\n' 2>/dev/null || busybox tr -d '\n' 2>/dev/null || cat ); printf '\n'; echo '===DONE===' ) 2>&1 )
echo "UNAME:$uname"
echo "ARCH:$arch"
echo "UPTIME:$uptime"
echo "CPUS:$cpus"
echo "CPU_MODEL:$cpu_model"
echo "GPU:$gpu_info"
echo "LAST:$last_output"
echo "FILTER:$filter_output" |
4,333 | 4,332 |
/bin/busybox |
3,149 | 312 |
/bin/./uname -s -v -n -r -m |
2,275 | 2,275 |
- Time window
- 2026-08-21 – 2026-09-16
- Source data
- attacker-commands-aggregated not available yet
- Script
- to be published
- Format
- field documentation
Captured samples #
Files attackers tried to download or upload, by type and architecture.
By file type
By architecture
| SHA-256 | Type | Architecture | Size | First seen | Times seen | Look up |
|---|---|---|---|---|---|---|
| 01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b | data | — | 1 B | 2026-08-23 16:54:42 | 492 | VirusTotal |
| 01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b | data | — | 1 B | 2026-08-23 10:04:58 | 330 | VirusTotal |
| f2e2ffc024ab99eb49fa207756481aa80713398142f30888aebace5706909b36 | data | — | 697 B | 2026-08-23 12:07:36 | 243 | VirusTotal |
| a6296a79f44e21b76604d2d2bbf795d2cf380f70e39d45fbf166707ff3b4a6a4 | script | — | 306 B | 2026-08-22 18:09:16 | 208 | VirusTotal |
| 4af5a5c98ad132095c6fbe7b02c242153a190a01cc321e50a916a0ca46fbaa62 | data | — | 9 B | 2026-08-22 18:09:19 | 206 | VirusTotal |
| 4af5a5c98ad132095c6fbe7b02c242153a190a01cc321e50a916a0ca46fbaa62 | data | — | 9 B | 2026-08-22 15:49:53 | 205 | VirusTotal |
| a9b1c85a7bd78dd1112ecc75c9070ea8c53078831a17aa09ebeb287fe6e21b72 | data | — | 9 B | 2026-09-07 11:48:13 | 59 | VirusTotal |
| 1193dde1c831808bf6f2db6f5b850b846b8a7f870873ec3b8a347f21cc5d96e3 | data | — | 9 B | 2026-09-07 11:48:13 | 59 | VirusTotal |
| 14049d077b887cbb8060d223ff9626664a044a8c3145f6a2b95a325df36b279b | data | — | 7 B | 2026-09-13 15:31:53 | 58 | VirusTotal |
| 43728fbfb98bb39ff61a2db0fc2905bd6937997062b05b9ab8b186fdee18c09a | data | — | 399 B | 2026-08-23 00:49:29 | 47 | VirusTotal |
- Time window
- 2026-08-21 – 2026-09-16
- Source data
- samples-aggregated not available yet
- Script
- to be published
- Format
- field documentation
Server comparison #
How much traffic the larger surface brought in, and how the structure differs between the two servers.
| Metric | srv3 | srv4 | srv4 / srv3 |
|---|---|---|---|
| Connection attempts (port ranking) | 1,462,877 | 4,014,322 | 2.7× |
| Ports hit | 45 | 58,628 | 1,302.8× |
| Events (traffic over time) | 1,462,877 | 4,014,322 | 2.7× |
srv3 top ports
srv4 top ports
- Time window
- 2026-08-21 – 2026-09-16
- Source data
- honeypot-ports-aggregated-20260922.csv, timeline-aggregated not available yet
- Script
- to be published
- Format
- field documentation
Found a bug, missing data or a leak of sensitive information? Report a problem