Below are the latest honeypot stats from SparTech Software’s in-house honeypot.
Event volume by severity
Last 14 days. Tall pale bars are ordinary background scanning; dark segments are attempts that carried credentials or a payload.
- Recon (sev 1-2)
- Loot hunting (sev 3)
- Attack (sev 4-5)
- Critical (sev 6)
Show data table
| Day | Recon (sev 1-2) | Loot hunting (sev 3) | Attack (sev 4-5) | Total |
|---|---|---|---|---|
| 21 Jul | 0 | 0 | 0 | 0 |
| 22 Jul | 0 | 0 | 0 | 0 |
| 23 Jul | 0 | 0 | 0 | 0 |
| 24 Jul | 0 | 0 | 0 | 0 |
| 25 Jul | 0 | 0 | 0 | 0 |
| 26 Jul | 0 | 0 | 0 | 0 |
| 27 Jul | 0 | 0 | 0 | 0 |
| 28 Jul | 0 | 0 | 0 | 0 |
| 29 Jul | 0 | 0 | 0 | 0 |
| 30 Jul | 0 | 0 | 0 | 0 |
| 31 Jul | 0 | 0 | 0 | 0 |
| 1 Aug | 33 | 2 | 549 | 585 |
| 2 Aug | 94 | 0 | 27 | 121 |
| 3 Aug | 51 | 0 | 0 | 51 |
Severity mix
The scale measures engagement depth. 1-2 is recon, 3 is hunting for loot, 4 is an exploit being attempted, 5 is an attack on the login or upload surface, and 6 means somebody acted on what they took.
Show data table
| Severity | Level | Events | Share |
|---|---|---|---|
| 1 | Informational | 25 | 3% |
| 2 | Targeted recon | 153 | 20% |
| 3 | Loot hunting | 2 | 0% |
| 4 | Exploitation attempt | 98 | 13% |
| 5 | Credential or upload attack | 478 | 63% |
| 6 | Critical — hands-on | 1 | 0% |
Activity by hour of day
Flat coverage across all 24 hours is the signature of automation. Humans cluster into working hours, and the shaded band is the stretch nobody is choosing to work through.
- Daytime and evening
- Small hours (00:00-05:59)
Show data table
| Hour | Events |
|---|---|
| 00:00 | 0 |
| 01:00 | 0 |
| 02:00 | 1 |
| 03:00 | 0 |
| 04:00 | 1 |
| 05:00 | 0 |
| 06:00 | 29 |
| 07:00 | 56 |
| 08:00 | 60 |
| 09:00 | 0 |
| 10:00 | 200 |
| 11:00 | 247 |
| 12:00 | 116 |
| 13:00 | 13 |
| 14:00 | 5 |
| 15:00 | 4 |
| 16:00 | 0 |
| 17:00 | 0 |
| 18:00 | 2 |
| 19:00 | 3 |
| 20:00 | 2 |
| 21:00 | 0 |
| 22:00 | 17 |
| 23:00 | 1 |
Top event types
What the honeypot caught people doing, counted over everything it has recorded.
Show data table
| Value | Events |
|---|---|
| bait_path | 710 |
| login_attempt | 27 |
| not_found_scan | 18 |
| campaign | 1 |
| user_enumeration | 1 |
Attacker tooling
The software making the requests, identified from how each client presents itself. Commodity scanners dominate; anything hand-driven stands out.
Show data table
| Value | Events |
|---|---|
| search-crawler | 98 |
| seo-crawler | 20 |
| curl | 15 |
| java-http | 7 |
| headless-client | 4 |
| python-http | 1 |
Most common attacks
Each label is one recognised technique or vulnerable endpoint.
Show data table
| Value | Events |
|---|---|
| exploit-backup-migration | 95 |
| exploit-ultimate-member | 95 |
| exploit-elementor | 95 |
| exploit-revslider | 95 |
| exploit-duplicator | 93 |
| decoy-asset-probe | 83 |
| exploit-wp-file-manager | 75 |
| advertised-plugin-probe | 58 |
| wp-login | 27 |
| /favicon.png | 7 |
| xmlrpc | 7 |
| author-enum | 5 |
Where the attacks come from
Resolved from the busiest source addresses, which between them account for 77% of all recorded events. Countries are read from the addresses traffic arrives from, which is where it was routed from rather than necessarily where whoever sent it is.
Show data table
| Value | Events |
|---|---|
| 🇺🇸 United States | 345 |
| 🇵🇱 Poland | 68 |
| 🇳🇱 Netherlands | 57 |
| 🇧🇷 Brazil | 34 |
| 🇬🇧 United Kingdom | 31 |
| 🇩🇪 Germany | 17 |
| 🇮🇹 Italy | 17 |
| 🇫🇮 Finland | 17 |
How far attackers got
Distinct source addresses, counted once each at the deepest level they reached. Every bar contains the ones below it, so the width can only shrink; the drop from one bar to the next is how many stopped at that step.
Show data table
| Reached at least | Sources | Share | Stopped here |
|---|---|---|---|
| Informational | 105 | 100% | — |
| Targeted recon | 93 | 89% | 12 |
| Loot hunting | 42 | 40% | 51 |
| Exploitation attempt | 42 | 40% | 0 |
| Credential or upload attack | 42 | 40% | 0 |
| Critical — hands-on | 1 | 1% | 41 |
Critical events
1 critical event in the last 14 days. Each mark is a day something reached the top of the severity ladder — a canary token fired from off-site, a shell uploaded, a decoy account used. Clusters matter more than the count: several in one day is usually one operator working.
Show data table
| Day | Critical events |
|---|---|
| 21 Jul | 0 |
| 22 Jul | 0 |
| 23 Jul | 0 |
| 24 Jul | 0 |
| 25 Jul | 0 |
| 26 Jul | 0 |
| 27 Jul | 0 |
| 28 Jul | 0 |
| 29 Jul | 0 |
| 30 Jul | 0 |
| 31 Jul | 0 |
| 1 Aug | 1 |
| 2 Aug | 0 |
| 3 Aug | 0 |
New and returning sources
Distinct addresses per day. "First time" means never seen before at all, not merely not seen that day. Churn of one-off addresses is ordinary background scanning; addresses that keep coming back are worth a closer look.
- Seen before
- First time
Show data table
| Day | First time | Seen before | Total |
|---|---|---|---|
| 21 Jul | 0 | 0 | 0 |
| 22 Jul | 0 | 0 | 0 |
| 23 Jul | 0 | 0 | 0 |
| 24 Jul | 0 | 0 | 0 |
| 25 Jul | 0 | 0 | 0 |
| 26 Jul | 0 | 0 | 0 |
| 27 Jul | 0 | 0 | 0 |
| 28 Jul | 0 | 0 | 0 |
| 29 Jul | 0 | 0 | 0 |
| 30 Jul | 0 | 0 | 0 |
| 31 Jul | 0 | 0 | 0 |
| 1 Aug | 39 | 0 | 39 |
| 2 Aug | 50 | 0 | 50 |
| 3 Aug | 16 | 0 | 16 |
Activity by day of the week
A flat week is automation, which does not know what a weekend is. A weekday-shaped week means a person is choosing when to work — the same reading as the hourly chart, at a scale that shows a pattern the hours cannot.
- Weekday
- Weekend
Show data table
| Day | Events |
|---|---|
| Mon | 51 |
| Tue | 0 |
| Wed | 0 |
| Thu | 0 |
| Fri | 0 |
| Sat | 585 |
| Sun | 121 |
Busiest source addresses
Addresses are shared, reassigned and often spoofed, so treat these as traffic sources rather than as identities.
Show data table
| Value | Events |
|---|---|
| 2600:6c86:b640:3:a9cd:ccfc:cc4a:56b6 | 83 |
| 16.144.58.95 | 34 |
| 35.92.233.48 | 34 |
| 205.169.39.183 | 23 |
| 98.93.157.4 | 18 |
| 212.201.100.163 | 17 |
| 2a04:ad80:1:c9::ec5b | 17 |
| 103.196.9.185 | 17 |
| 172.111.15.224 | 17 |
| 34.118.96.74 | 17 |
Most tried usernames
The account names attackers guessed at.
Show data table
| Value | Events |
|---|---|
| Monitoring | 9 |
| tbibasmash | 9 |
| admin | 9 |
Most tried passwords
Taken from the dictionaries currently in circulation. If one of these is familiar, change it.
Show data table
| Value | Events |
|---|---|
| pass | 3 |
| password | 3 |
| user%02 | 3 |
| Monitoring2025 | 1 |
| tbibasmash2025 | 1 |
| admin2025 | 1 |
| adminadmin | 1 |
| tbibasmashtbibasmash | 1 |
| MonitoringMonitoring | 1 |
| admin123 | 1 |
Updated 57 minutes ago. Source: SparTech Software Honeypot Project.