HONEYPOT_ARRAY
What happens when you leave a server on the internet
A T-Pot honeypot sits on my home network and pretends to be a vulnerable server. Bots and attackers find it within minutes, try default passwords, drop malware, and probe for web exploits. This page visualizes that traffic as it happens.
Cowrie
Emulates SSH and Telnet services. Captures every username, password, and shell command attackers try.
Dionaea
Mimics services like SMB, FTP, and HTTP to lure in malware droppers. Saves every binary that lands.
Tanner / Snare
A fake web application that classifies incoming requests — SQL injection, XSS, path traversal, and more.
Total attacks
4,636
-69 since last update
Unique source IPs
170
Distinct attacker addresses seen in the current window.
Top targeted service
SMB (88%)
Port 445 via DIONAEA
Malware captures
0
Malware binaries caught by Dionaea in the current window.
Credential attempts
195
Login attempts caught across SSH, Telnet, FTP, and other exposed services.
Web attack events
193
Hostile web requests classified by Tanner in the current window.
Attack timeline
Hourly event counts over the past week.
LAST_168_HOURS
Sensor status
Attacker origins
Where the attacks are coming from, based on source IP geolocation.
GEO_DENSITY
Top source countries
| # | Country | Attacks | IPs |
|---|---|---|---|
| 1 | Brazil | 3,169 | 11 |
| 2 | United States | 519 | 47 |
| 3 | Romania | 269 | 6 |
| 4 | Bulgaria | 239 | 4 |
| 5 | Singapore | 73 | 10 |
| 6 | Türkiye | 70 | 2 |
| 7 | Germany | 38 | 13 |
| 8 | Vietnam | 34 | 2 |
| 9 | China | 33 | 3 |
| 10 | United Kingdom | 21 | 9 |
Protocol and service breakdown
Which services attackers are going after the most.
SERVICE_MIX
Protocol and service breakdown: Horizontal bar chart showing the most targeted services and ports in the current honeypot snapshot.
events
Web attack categories
Types of web exploits attempted against the fake application.
WEB_SIGS
Web attack categories: Horizontal bar chart showing the most common classified web attack categories in the current snapshot.
requests
Credential attempts
The most common username and password combinations attackers try across all exposed services.
AUTH_PRESSURE
| # | Username | Password | Attempts |
|---|---|---|---|
| 1 | support | support | 20 |
| 2 | root | 123456 | 6 |
| 3 | root | 111111 | 4 |
| 4 | root | 123123 | 4 |
| 5 | admin | 12345678 | 3 |
| 6 | admin | P@ssw0rd | 3 |
| 7 | admin | admin | 3 |
| 8 | support | supportAtlanta | 3 |
| 9 | admin1 | 123123 | 1 |
| 10 | deploy | 123456 | 1 |
| 11 | fox | fox | 1 |
| 12 | michala | michala | 1 |
| 13 | michala | michala1 | 1 |
| 14 | michala | michala123 | 1 |
| 15 | peri | peri | 1 |
| 16 | peri | peri1 | 1 |
| 17 | peri | peri123 | 1 |
Malware captures
Binaries that attackers dropped onto the honeypot. Each hash links to VirusTotal for analysis.
PAYLOAD_INDEX
| SHA-256 | Type | Captures | First seen |
|---|---|---|---|
| No malware samples captured yet. | |||
What's happening
AI-generated summary of the latest 24-hour window of honeypot activity.
AI_SUMMARY
In the last 24 hours, 4,636 attacks were detected from 170 unique source IPs. The top sources of attacks were Brazil with 3,169 attacks from 11 IPs, the United States with 519 attacks from 47 IPs, and Romania with 269 attacks from 6 IPs. The most targeted services were SMB on port 445 with 3,185 events, SSH on port 22 with 245 events, and HTTP on port 80 with 193 events, with attackers trying 5 unique username/password pairs, the most attempted 20 times, and no malware captures were made.
Generated by Llama 4 Scout via Cloudflare Workers AI