Below are the latest honeypot stats from SparTech Software’s in-house honeypot.

SparTech Software Honeypot Project

9,790Events recorded
49Today
1,045Distinct sources
4,598Attacks on login or upload
299Hands-on intrusions
6Enumeration sweeps

Event volume by severity

Last 14 days. Tall pale bars are ordinary background scanning; dark segments are attempts that carried credentials or a payload.

  • Recon (sev 1-2)
  • Loot hunting (sev 3)
  • Attack (sev 4-5)
  • Critical (sev 6)
03006005 Sep — Recon (sev 1-2): 585 Sep — Attack (sev 4-5): 1422005 Sep6 Sep — Recon (sev 1-2): 516 Sep — Loot hunting (sev 3): 16 Sep — Attack (sev 4-5): 2923466 Sep7 Sep — Recon (sev 1-2): 597 Sep — Attack (sev 4-5): 461057 Sep8 Sep — Recon (sev 1-2): 558 Sep — Attack (sev 4-5): 1011568 Sep9 Sep — Recon (sev 1-2): 549 Sep — Attack (sev 4-5): 2823369 Sep10 Sep — Recon (sev 1-2): 6010 Sep — Attack (sev 4-5): 12518510 Sep11 Sep — Recon (sev 1-2): 8811 Sep — Loot hunting (sev 3): 111 Sep — Attack (sev 4-5): 29738611 Sep12 Sep — Recon (sev 1-2): 7512 Sep — Attack (sev 4-5): 10017612 Sep13 Sep — Recon (sev 1-2): 8313 Sep — Loot hunting (sev 3): 813 Sep — Attack (sev 4-5): 6515613 Sep14 Sep — Recon (sev 1-2): 8314 Sep — Loot hunting (sev 3): 1514 Sep — Attack (sev 4-5): 44854814 Sep15 Sep — Recon (sev 1-2): 7415 Sep — Loot hunting (sev 3): 1215 Sep — Attack (sev 4-5): 15424015 Sep16 Sep — Recon (sev 1-2): 6616 Sep — Loot hunting (sev 3): 516 Sep — Attack (sev 4-5): 6013116 Sep17 Sep — Recon (sev 1-2): 5117 Sep — Attack (sev 4-5): 38643717 Sep18 Sep — Recon (sev 1-2): 2818 Sep — Loot hunting (sev 3): 1218 Sep — Attack (sev 4-5): 94918 Sep
Show data table
DayRecon (sev 1-2)Loot hunting (sev 3)Attack (sev 4-5)Total
5 Sep580142200
6 Sep511292346
7 Sep59046105
8 Sep550101156
9 Sep540282336
10 Sep600125185
11 Sep881297386
12 Sep750100176
13 Sep83865156
14 Sep8315448548
15 Sep7412154240
16 Sep66560131
17 Sep510386437
18 Sep2812949

Severity mix

The scale measures engagement depth. 1-2 is recon, 3 is hunting for loot, 4 is an exploit being attempted, 5 is an attack on the login or upload surface, and 6 means somebody acted on what they took.

Severity 1, Informational — 2,581 events (26%)Severity 2, Targeted recon — 1,113 events (11%)Severity 3, Loot hunting — 79 events (1%)Severity 4, Exploitation attempt — 1,419 events (15%)Severity 5, Credential or upload attack — 4,299 events (44%)Severity 6, Critical — hands-on — 299 events (3%)9,790eventsInformational2,581 · 26%Targeted recon1,113 · 11%Loot hunting79 · 1%Exploitation attempt1,419 · 15%Credential or upload attack4,299 · 44%Critical — hands-on299 · 3%
Show data table
SeverityLevelEventsShare
1Informational2,58126%
2Targeted recon1,11311%
3Loot hunting791%
4Exploitation attempt1,41915%
5Credential or upload attack4,29944%
6Critical — hands-on2993%

Activity by hour of day

Flat coverage across all 24 hours is the signature of automation. Humans cluster into working hours, and the shaded band is the stretch nobody is choosing to work through.

  • Daytime and evening
  • Small hours (00:00-05:59)
035070000:00-00:59 — 490 events0001:00-01:59 — 590 events02:00-02:59 — 296 events03:00-03:59 — 555 events0304:00-04:59 — 505 events05:00-05:59 — 482 events06:00-06:59 — 512 events0607:00-07:59 — 623 events08:00-08:59 — 344 events09:00-09:59 — 337 events0910:00-10:59 — 664 events11:00-11:59 — 617 events12:00-12:59 — 392 events1213:00-13:59 — 250 events14:00-14:59 — 205 events15:00-15:59 — 255 events1516:00-16:59 — 268 events17:00-17:59 — 645 events18:00-18:59 — 242 events1819:00-19:59 — 241 events20:00-20:59 — 200 events21:00-21:59 — 259 events2122:00-22:59 — 395 events23:00-23:59 — 423 events
Show data table
HourEvents
00:00490
01:00590
02:00296
03:00555
04:00505
05:00482
06:00512
07:00623
08:00344
09:00337
10:00664
11:00617
12:00392
13:00250
14:00205
15:00255
16:00268
17:00645
18:00242
19:00241
20:00200
21:00259
22:00395
23:00423

Top event types

What the honeypot caught people doing, counted over everything it has recorded.

xmlrpc_credentialsxmlrpc_credentials — 3,9803,980not_found_scannot_found_scan — 2,1092,109bait_pathbait_path — 1,5711,571security_probesecurity_probe — 1,3861,386login_attemptlogin_attempt — 604604trap_enumtrap_enum — 6060user_enumerationuser_enumeration — 4040xmlrpc_callxmlrpc_call — 1414contact_messagecontact_message — 99contact_spamcontact_spam — 88login_successlogin_success — 55file_uploadfile_upload — 22
Show data table
ValueEvents
xmlrpc_credentials3,980
not_found_scan2,109
bait_path1,571
security_probe1,386
login_attempt604
trap_enum60
user_enumeration40
xmlrpc_call14
contact_message9
contact_spam8
login_success5
file_upload2

Attacker tooling

The software making the requests, identified from how each client presents itself. Commodity scanners dominate; anything hand-driven stands out.

headless-clientheadless-client — 3,4683,468search-crawlersearch-crawler — 350350seo-crawlerseo-crawler — 157157curlcurl — 1616java-httpjava-http — 88scripted-clientscripted-client — 88python-httppython-http — 22
Show data table
ValueEvents
headless-client3,468
search-crawler350
seo-crawler157
curl16
java-http8
scripted-client8
python-http2

Most common attacks

Each label is one recognised technique or vulnerable endpoint.

metaWeblog.newPostmetaWeblog.newPost — 3,7533,753/wp-content/plugins/wordfence/imag…/wp-content/plugins/wordfence/images/wordfence-logo.svg — 2,0442,044security-plugin-probesecurity-plugin-probe — 1,3861,386decoy-asset-probedecoy-asset-probe — 612612own-asset-fetchown-asset-fetch — 396396wp-loginwp-login — 313313advertised-plugin-probeadvertised-plugin-probe — 297297wp-login-harvested-identitywp-login-harvested-identity — 291291system.multicallsystem.multicall — 134134wp.getUsersBlogswp.getUsersBlogs — 107107author-enumauthor-enum — 6161author-enumerationauthor-enumeration — 5454
Show data table
ValueEvents
metaWeblog.newPost3,753
/wp-content/plugins/wordfence/images/wordfence-logo.svg2,044
security-plugin-probe1,386
decoy-asset-probe612
own-asset-fetch396
wp-login313
advertised-plugin-probe297
wp-login-harvested-identity291
system.multicall134
wp.getUsersBlogs107
author-enum61
author-enumeration54

Adversary techniques observed

Each bar is a MITRE ATT&CK technique, counted from the events this honeypot recorded. These are techniques currently being used against small business websites, not a theoretical list.

T1110.003 Brute Force: Password Spray…T1110.003 Brute Force: Password Spraying — Credential Access — 3,9903,990T1518 Software DiscoveryT1518 Software Discovery — Discovery — 2,3412,341T1595.003 Active Scanning: Wordlist S…T1595.003 Active Scanning: Wordlist Scanning — Reconnaissance — 2,1712,171T1083 File and Directory DiscoveryT1083 File and Directory Discovery — Discovery — 1,5711,571T1595.002 Active Scanning: Vulnerabil…T1595.002 Active Scanning: Vulnerability Scanning — Reconnaissance — 1,4131,413T1110.001 Brute Force: Password Guess…T1110.001 Brute Force: Password Guessing — Credential Access — 765765T1078 Valid AccountsT1078 Valid Accounts — Initial Access — 609609T1592.002 Gather Victim Host Informat…T1592.002 Gather Victim Host Information: Software — Reconnaissance — 322322T1552.001 Unsecured Credentials: Cred…T1552.001 Unsecured Credentials: Credentials In Files — Credential Access — 297297T1087 Account DiscoveryT1087 Account Discovery — Discovery — 198198T1589 Gather Victim Identity Informat…T1589 Gather Victim Identity Information — Reconnaissance — 192192T1595 Active ScanningT1595 Active Scanning — Reconnaissance — 4343
Show data table
IDTechniqueTacticEvents
T1110.003Brute Force: Password SprayingCredential Access3,990
T1518Software DiscoveryDiscovery2,341
T1595.003Active Scanning: Wordlist ScanningReconnaissance2,171
T1083File and Directory DiscoveryDiscovery1,571
T1595.002Active Scanning: Vulnerability ScanningReconnaissance1,413
T1110.001Brute Force: Password GuessingCredential Access765
T1078Valid AccountsInitial Access609
T1592.002Gather Victim Host Information: SoftwareReconnaissance322
T1552.001Unsecured Credentials: Credentials In FilesCredential Access297
T1087Account DiscoveryDiscovery198
T1589Gather Victim Identity InformationReconnaissance192
T1595Active ScanningReconnaissance43

Where the attacks come from

Resolved from the busiest source addresses, which between them account for 35% of all recorded events. Countries are read from the addresses traffic arrives from, which is where it was routed from rather than necessarily where whoever sent it is.

🇬🇧 United Kingdom🇬🇧 United Kingdom — 2,0882,088🇮🇳 India🇮🇳 India — 468468🇧🇩 Bangladesh🇧🇩 Bangladesh — 316316🇵🇰 Pakistan🇵🇰 Pakistan — 133133🇸🇦 Saudi Arabia🇸🇦 Saudi Arabia — 104104🇺🇸 United States🇺🇸 United States — 8383🇳🇵 Nepal🇳🇵 Nepal — 7474🇦🇷 Argentina🇦🇷 Argentina — 6666🇧🇷 Brazil🇧🇷 Brazil — 6565🇨🇩 Democratic Republic of the Cong…🇨🇩 Democratic Republic of the Congo — 6161
Show data table
ValueEvents
🇬🇧 United Kingdom2,088
🇮🇳 India468
🇧🇩 Bangladesh316
🇵🇰 Pakistan133
🇸🇦 Saudi Arabia104
🇺🇸 United States83
🇳🇵 Nepal74
🇦🇷 Argentina66
🇧🇷 Brazil65
🇨🇩 Democratic Republic of the Congo61

How far attackers got

Distinct source addresses, counted once each at the deepest level they reached. Every bar contains the ones below it, so the width can only shrink; the drop from one bar to the next is how many stopped at that step.

InformationalInformational — 1,045 sources (100% of all)1,045 (100%)Targeted reconTargeted recon — 987 sources (94% of all)987 (94%)58 stopped hereLoot huntingLoot hunting — 734 sources (70% of all)734 (70%)253 stopped hereExploitation attemptExploitation attempt — 720 sources (69% of all)720 (69%)14 stopped hereCredential or upload attackCredential or upload attack — 642 sources (61% of all)642 (61%)78 stopped hereCritical — hands-onCritical — hands-on — 163 sources (16% of all)163 (16%)479 stopped here
Show data table
Reached at leastSourcesShareStopped here
Informational1,045100%
Targeted recon98794%58
Loot hunting73470%253
Exploitation attempt72069%14
Credential or upload attack64261%78
Critical — hands-on16316%479

Critical events

5 critical events in the last 14 days. Each mark is a day something reached the top of the severity ladder — a canary token fired from off-site, a shell uploaded, a decoy account used. Clusters matter more than the count: several in one day is usually one operator working.

5 Sep6 Sep — 2 critical events26 Sep7 Sep8 Sep9 Sep10 Sep11 Sep12 Sep — 1 critical events112 Sep13 Sep14 Sep — 2 critical events214 Sep15 Sep16 Sep17 Sep18 Sep
Show data table
DayCritical events
5 Sep0
6 Sep2
7 Sep0
8 Sep0
9 Sep0
10 Sep0
11 Sep0
12 Sep1
13 Sep0
14 Sep2
15 Sep0
16 Sep0
17 Sep0
18 Sep0

New and returning sources

Distinct addresses per day. "First time" means never seen before at all, not merely not seen that day. Churn of one-off addresses is ordinary background scanning; addresses that keep coming back are worth a closer look.

  • Seen before
  • First time
0601205 Sep — Seen before: 55 Sep — First time: 20255 Sep6 Sep — Seen before: 46 Sep — First time: 14186 Sep7 Sep — Seen before: 57 Sep — First time: 167 Sep8 Sep — Seen before: 48 Sep — First time: 8128 Sep9 Sep — Seen before: 59 Sep — First time: 14199 Sep10 Sep — Seen before: 510 Sep — First time: 162110 Sep11 Sep — Seen before: 611 Sep — First time: 121811 Sep12 Sep — Seen before: 412 Sep — First time: 91312 Sep13 Sep — Seen before: 413 Sep — First time: 172113 Sep14 Sep — Seen before: 714 Sep — First time: 9910614 Sep15 Sep — Seen before: 415 Sep — First time: 101415 Sep16 Sep — Seen before: 716 Sep — First time: 142116 Sep17 Sep — Seen before: 417 Sep — First time: 151917 Sep18 Sep — Seen before: 318 Sep — First time: 2518 Sep
Show data table
DayFirst timeSeen beforeTotal
5 Sep20525
6 Sep14418
7 Sep156
8 Sep8412
9 Sep14519
10 Sep16521
11 Sep12618
12 Sep9413
13 Sep17421
14 Sep997106
15 Sep10414
16 Sep14721
17 Sep15419
18 Sep235

Activity by day of the week

A flat week is automation, which does not know what a weekend is. A weekday-shaped week means a person is choosing when to work — the same reading as the hourly chart, at a scale that shows a pattern the hours cannot.

  • Weekday
  • Weekend
01,0002,000Mon — 1,5161,516MonTue — 1,2641,264TueWed — 1,3741,374WedThu — 1,3471,347ThuFri — 1,2211,221FriSat — 1,8771,877SatSun — 1,1911,191Sun
Show data table
DayEvents
Mon1,516
Tue1,264
Wed1,374
Thu1,347
Fri1,221
Sat1,877
Sun1,191

Busiest source addresses

Addresses are shared, reassigned and often spoofed, so treat these as traffic sources rather than as identities.

80.76.57.1380.76.57.13 — 32632688.97.176.20588.97.176.205 — 26926986.18.50.10386.18.50.103 — 24824845.150.145.1545.150.145.15 — 22622678.148.77.21078.148.77.210 — 16516584.43.29.21484.43.29.214 — 159159103.153.130.34103.153.130.34 — 142142116.90.101.224116.90.101.224 — 13313378.148.66.18978.148.66.189 — 132132103.44.52.132103.44.52.132 — 128128
Show data table
ValueEvents
80.76.57.13326
88.97.176.205269
86.18.50.103248
45.150.145.15226
78.148.77.210165
84.43.29.214159
103.153.130.34142
116.90.101.224133
78.148.66.189132
103.44.52.132128

Most tried usernames

The account names attackers guessed at.

adminadmin — 268268MonitoringMonitoring — 130130EditorialEditorial — 8080DeployDeploy — 7979jmorrisjmorris — 3030devopsdevops — 2727tbibasmashtbibasmash — 2626contentcontent — 2323tbiba@smashtheman.comtbiba@smashtheman.com — 55rootroot — 33
Show data table
ValueEvents
admin268
Monitoring130
Editorial80
Deploy79
jmorris30
devops27
tbibasmash26
content23
tbiba@smashtheman.com5
root3

Most tried passwords

Taken from the dictionaries currently in circulation. If one of these is familiar, change it.

adminadmin — 4242passpass — 3232passwordpassword — 2727user%02user%02 — 2121MonitoringMonitoring — 2020stoneandrazorbarberstoneandrazorbarber — 1919adminadminadminadmin — 1717admin2025admin2025 — 1616stoneandrazorbarber123stoneandrazorbarber123 — 1616admin123admin123 — 1515
Show data table
ValueEvents
admin42
pass32
password27
user%0221
Monitoring20
stoneandrazorbarber19
adminadmin17
admin202516
stoneandrazorbarber12316
admin12315

Updated 42 minutes ago. Source: SparTech Software Honeypot Project.

SparTech Software Honeypot Project

4,378Events recorded
13Today
576Distinct sources
260Attacks on login or upload
14Hands-on intrusions
2Enumeration sweeps

Event volume by severity

Last 14 days. Tall pale bars are ordinary background scanning; dark segments are attempts that carried credentials or a payload.

  • Recon (sev 1-2)
  • Loot hunting (sev 3)
  • Attack (sev 4-5)
  • Critical (sev 6)
0801605 Sep — Recon (sev 1-2): 495 Sep — Attack (sev 4-5): 47965 Sep6 Sep — Recon (sev 1-2): 466 Sep — Attack (sev 4-5): 41876 Sep7 Sep — Recon (sev 1-2): 527 Sep — Attack (sev 4-5): 45977 Sep8 Sep — Recon (sev 1-2): 498 Sep — Attack (sev 4-5): 44938 Sep9 Sep — Recon (sev 1-2): 479 Sep — Loot hunting (sev 3): 19 Sep — Attack (sev 4-5): 37859 Sep10 Sep — Recon (sev 1-2): 6410 Sep — Attack (sev 4-5): 4611010 Sep11 Sep — Recon (sev 1-2): 5811 Sep — Attack (sev 4-5): 4510311 Sep12 Sep — Recon (sev 1-2): 5012 Sep — Attack (sev 4-5): 479812 Sep13 Sep — Recon (sev 1-2): 5113 Sep — Loot hunting (sev 3): 113 Sep — Attack (sev 4-5): 6311513 Sep14 Sep — Recon (sev 1-2): 7114 Sep — Loot hunting (sev 3): 1514 Sep — Attack (sev 4-5): 4613414 Sep15 Sep — Recon (sev 1-2): 5515 Sep — Attack (sev 4-5): 4710215 Sep16 Sep — Recon (sev 1-2): 5616 Sep — Attack (sev 4-5): 4510116 Sep17 Sep — Recon (sev 1-2): 7717 Sep — Loot hunting (sev 3): 1617 Sep — Attack (sev 4-5): 4914217 Sep18 Sep — Recon (sev 1-2): 718 Sep — Attack (sev 4-5): 61318 Sep
Show data table
DayRecon (sev 1-2)Loot hunting (sev 3)Attack (sev 4-5)Total
5 Sep4904796
6 Sep4604187
7 Sep5204597
8 Sep4904493
9 Sep4713785
10 Sep64046110
11 Sep58045103
12 Sep5004798
13 Sep51163115
14 Sep711546134
15 Sep55047102
16 Sep56045101
17 Sep771649142
18 Sep70613

Severity mix

The scale measures engagement depth. 1-2 is recon, 3 is hunting for loot, 4 is an exploit being attempted, 5 is an attack on the login or upload surface, and 6 means somebody acted on what they took.

Severity 1, Informational — 2,250 events (51%)Severity 2, Targeted recon — 400 events (9%)Severity 3, Loot hunting — 56 events (1%)Severity 4, Exploitation attempt — 1,412 events (32%)Severity 5, Credential or upload attack — 246 events (6%)Severity 6, Critical — hands-on — 14 events (0%)4,378eventsInformational2,250 · 51%Targeted recon400 · 9%Loot hunting56 · 1%Exploitation attempt1,412 · 32%Credential or upload attack246 · 6%Critical — hands-on14 · 0%
Show data table
SeverityLevelEventsShare
1Informational2,25051%
2Targeted recon4009%
3Loot hunting561%
4Exploitation attempt1,41232%
5Credential or upload attack2466%
6Critical — hands-on140%

Activity by hour of day

Flat coverage across all 24 hours is the signature of automation. Humans cluster into working hours, and the shaded band is the stretch nobody is choosing to work through.

  • Daytime and evening
  • Small hours (00:00-05:59)
020040000:00-00:59 — 158 events0001:00-01:59 — 182 events02:00-02:59 — 180 events03:00-03:59 — 156 events0304:00-04:59 — 192 events05:00-05:59 — 143 events06:00-06:59 — 167 events0607:00-07:59 — 195 events08:00-08:59 — 170 events09:00-09:59 — 125 events0910:00-10:59 — 172 events11:00-11:59 — 175 events12:00-12:59 — 216 events1213:00-13:59 — 156 events14:00-14:59 — 172 events15:00-15:59 — 186 events1516:00-16:59 — 191 events17:00-17:59 — 171 events18:00-18:59 — 203 events1819:00-19:59 — 154 events20:00-20:59 — 177 events21:00-21:59 — 160 events2122:00-22:59 — 184 events23:00-23:59 — 393 events
Show data table
HourEvents
00:00158
01:00182
02:00180
03:00156
04:00192
05:00143
06:00167
07:00195
08:00170
09:00125
10:00172
11:00175
12:00216
13:00156
14:00172
15:00186
16:00191
17:00171
18:00203
19:00154
20:00177
21:00160
22:00184
23:00393

Top event types

What the honeypot caught people doing, counted over everything it has recorded.

not_found_scannot_found_scan — 2,1572,157security_probesecurity_probe — 1,3771,377bait_pathbait_path — 489489xmlrpc_credentialsxmlrpc_credentials — 216216trap_enumtrap_enum — 5757login_attemptlogin_attempt — 3737user_enumerationuser_enumeration — 1616xmlrpc_callxmlrpc_call — 1212attack_payloadattack_payload — 44contact_messagecontact_message — 33contact_cached_formcontact_cached_form — 33login_successlogin_success — 33
Show data table
ValueEvents
not_found_scan2,157
security_probe1,377
bait_path489
xmlrpc_credentials216
trap_enum57
login_attempt37
user_enumeration16
xmlrpc_call12
attack_payload4
contact_message3
contact_cached_form3
login_success3

Attacker tooling

The software making the requests, identified from how each client presents itself. Commodity scanners dominate; anything hand-driven stands out.

headless-clientheadless-client — 3,4703,470search-crawlersearch-crawler — 180180seo-crawlerseo-crawler — 112112python-httppython-http — 6464java-httpjava-http — 77curlcurl — 11
Show data table
ValueEvents
headless-client3,470
search-crawler180
seo-crawler112
python-http64
java-http7
curl1

Most common attacks

Each label is one recognised technique or vulnerable endpoint.

/wp-content/plugins/wordfence/imag…/wp-content/plugins/wordfence/images/wordfence-logo.svg — 2,0512,051security-plugin-probesecurity-plugin-probe — 1,3771,377decoy-asset-probedecoy-asset-probe — 273273system.multicallsystem.multicall — 220220author-enumauthor-enum — 6161login-pagelogin-page — 5858author-enumerationauthor-enumeration — 5555wp-loginwp-login — 3434own-asset-fetchown-asset-fetch — 1818rest-usersrest-users — 1616plugin-version-probeplugin-version-probe — 1515/.well-known/security.txt/.well-known/security.txt — 1414
Show data table
ValueEvents
/wp-content/plugins/wordfence/images/wordfence-logo.svg2,051
security-plugin-probe1,377
decoy-asset-probe273
system.multicall220
author-enum61
login-page58
author-enumeration55
wp-login34
own-asset-fetch18
rest-users16
plugin-version-probe15
/.well-known/security.txt14

Adversary techniques observed

Each bar is a MITRE ATT&CK technique, counted from the events this honeypot recorded. These are techniques currently being used against small business websites, not a theoretical list.

T1595.003 Active Scanning: Wordlist S…T1595.003 Active Scanning: Wordlist Scanning — Reconnaissance — 2,2142,214T1518 Software DiscoveryT1518 Software Discovery — Discovery — 1,6861,686T1595.002 Active Scanning: Vulnerabil…T1595.002 Active Scanning: Vulnerability Scanning — Reconnaissance — 1,3921,392T1083 File and Directory DiscoveryT1083 File and Directory Discovery — Discovery — 489489T1110.001 Brute Force: Password Guess…T1110.001 Brute Force: Password Guessing — Credential Access — 268268T1110.003 Brute Force: Password Spray…T1110.003 Brute Force: Password Spraying — Credential Access — 228228T1087 Account DiscoveryT1087 Account Discovery — Discovery — 148148T1589 Gather Victim Identity Informat…T1589 Gather Victim Identity Information — Reconnaissance — 146146T1595 Active ScanningT1595 Active Scanning — Reconnaissance — 5858T1078 Valid AccountsT1078 Valid Accounts — Initial Access — 4040T1505.003 Server Software Component: …T1505.003 Server Software Component: Web Shell — Persistence — 2222T1592.002 Gather Victim Host Informat…T1592.002 Gather Victim Host Information: Software — Reconnaissance — 1919
Show data table
IDTechniqueTacticEvents
T1595.003Active Scanning: Wordlist ScanningReconnaissance2,214
T1518Software DiscoveryDiscovery1,686
T1595.002Active Scanning: Vulnerability ScanningReconnaissance1,392
T1083File and Directory DiscoveryDiscovery489
T1110.001Brute Force: Password GuessingCredential Access268
T1110.003Brute Force: Password SprayingCredential Access228
T1087Account DiscoveryDiscovery148
T1589Gather Victim Identity InformationReconnaissance146
T1595Active ScanningReconnaissance58
T1078Valid AccountsInitial Access40
T1505.003Server Software Component: Web ShellPersistence22
T1592.002Gather Victim Host Information: SoftwareReconnaissance19

Where the attacks come from

Resolved from the busiest source addresses, which between them account for 63% of all recorded events. Countries are read from the addresses traffic arrives from, which is where it was routed from rather than necessarily where whoever sent it is.

🇬🇧 United Kingdom🇬🇧 United Kingdom — 2,6852,685🇳🇱 Netherlands🇳🇱 Netherlands — 3535🇪🇸 Spain🇪🇸 Spain — 3535
Show data table
ValueEvents
🇬🇧 United Kingdom2,685
🇳🇱 Netherlands35
🇪🇸 Spain35

How far attackers got

Distinct source addresses, counted once each at the deepest level they reached. Every bar contains the ones below it, so the width can only shrink; the drop from one bar to the next is how many stopped at that step.

InformationalInformational — 576 sources (100% of all)576 (100%)Targeted reconTargeted recon — 501 sources (87% of all)501 (87%)75 stopped hereLoot huntingLoot hunting — 322 sources (56% of all)322 (56%)179 stopped hereExploitation attemptExploitation attempt — 300 sources (52% of all)300 (52%)22 stopped hereCredential or upload attackCredential or upload attack — 222 sources (39% of all)222 (39%)78 stopped hereCritical — hands-onCritical — hands-on — 12 sources (2% of all)12 (2%)210 stopped here
Show data table
Reached at leastSourcesShareStopped here
Informational576100%
Targeted recon50187%75
Loot hunting32256%179
Exploitation attempt30052%22
Credential or upload attack22239%78
Critical — hands-on122%210

Critical events

3 critical events in the last 14 days. Each mark is a day something reached the top of the severity ladder — a canary token fired from off-site, a shell uploaded, a decoy account used. Clusters matter more than the count: several in one day is usually one operator working.

5 Sep6 Sep7 Sep8 Sep9 Sep10 Sep11 Sep12 Sep — 1 critical events112 Sep13 Sep14 Sep — 2 critical events214 Sep15 Sep16 Sep17 Sep18 Sep
Show data table
DayCritical events
5 Sep0
6 Sep0
7 Sep0
8 Sep0
9 Sep0
10 Sep0
11 Sep0
12 Sep1
13 Sep0
14 Sep2
15 Sep0
16 Sep0
17 Sep0
18 Sep0

New and returning sources

Distinct addresses per day. "First time" means never seen before at all, not merely not seen that day. Churn of one-off addresses is ordinary background scanning; addresses that keep coming back are worth a closer look.

  • Seen before
  • First time
015305 Sep — Seen before: 45 Sep — First time: 265 Sep6 Sep — Seen before: 36 Sep — First time: 256 Sep7 Sep — Seen before: 47 Sep — First time: 267 Sep8 Sep — Seen before: 48 Sep — First time: 488 Sep9 Sep — Seen before: 29 Sep — First time: 689 Sep10 Sep — Seen before: 410 Sep — First time: 101410 Sep11 Sep — Seen before: 411 Sep — First time: 101411 Sep12 Sep — Seen before: 412 Sep — First time: 5912 Sep13 Sep — Seen before: 913 Sep — First time: 172613 Sep14 Sep — Seen before: 414 Sep — First time: 81214 Sep15 Sep — Seen before: 415 Sep — First time: 61015 Sep16 Sep — Seen before: 416 Sep — First time: 81216 Sep17 Sep — Seen before: 317 Sep — First time: 91217 Sep18 Sep — Seen before: 318 Sep — First time: 1418 Sep
Show data table
DayFirst timeSeen beforeTotal
5 Sep246
6 Sep235
7 Sep246
8 Sep448
9 Sep628
10 Sep10414
11 Sep10414
12 Sep549
13 Sep17926
14 Sep8412
15 Sep6410
16 Sep8412
17 Sep9312
18 Sep134

Activity by day of the week

A flat week is automation, which does not know what a weekend is. A weekday-shaped week means a person is choosing when to work — the same reading as the hourly chart, at a scale that shows a pattern the hours cannot.

  • Weekday
  • Weekend
05001,000Mon — 588588MonTue — 652652TueWed — 603603WedThu — 902902ThuFri — 566566FriSat — 539539SatSun — 528528Sun
Show data table
DayEvents
Mon588
Tue652
Wed603
Thu902
Fri566
Sat539
Sun528

Busiest source addresses

Addresses are shared, reassigned and often spoofed, so treat these as traffic sources rather than as identities.

80.76.57.1380.76.57.13 — 32432486.18.50.10386.18.50.103 — 26726788.97.176.20588.97.176.205 — 26726745.150.145.1545.150.145.15 — 21121178.148.77.21078.148.77.210 — 16716784.43.29.21484.43.29.214 — 15315378.148.66.18978.148.66.189 — 14914988.97.176.17388.97.176.173 — 13513586.155.134.16886.155.134.168 — 909086.162.205.20286.162.205.202 — 7272
Show data table
ValueEvents
80.76.57.13324
86.18.50.103267
88.97.176.205267
45.150.145.15211
78.148.77.210167
84.43.29.214153
78.148.66.189149
88.97.176.173135
86.155.134.16890
86.162.205.20272

Most tried usernames

The account names attackers guessed at.

adminadmin — 3737tbibasmashtbibasmash — 77nizeezcinizeezci — 44admin@wordpress.comadmin@wordpress.com — 33DeployDeploy — 33tbiba@smashtheman.comtbiba@smashtheman.com — 33site_adminsite_admin — 33rootroot — 33supe1user10supe1user10 — 33muwymuwy — 22
Show data table
ValueEvents
admin37
tbibasmash7
nizeezci4
admin@wordpress.com3
Deploy3
tbiba@smashtheman.com3
site_admin3
root3
supe1user103
muwy2

Most tried passwords

Taken from the dictionaries currently in circulation. If one of these is familiar, change it.

passwordpassword — 55passpass — 44PtXe*JMQ%jT2HS!BSRc4a$$^PtXe*JMQ%jT2HS!BSRc4a$$^ — 44@StableExploitt@StableExploitt — 44r007p455w0rdr007p455w0rd — 33adminadminadminadmin — 33admin123admin123 — 33supe1User.gs@1z10.1supe1User.gs@1z10.1 — 33K%Q6@#sBFkhM0tWRJ4N)(3#@K%Q6@#sBFkhM0tWRJ4N)(3#@ — 33FsSAj1bKldSAO2@!FsSAj1bKldSAO2@! — 22
Show data table
ValueEvents
password5
pass4
PtXe*JMQ%jT2HS!BSRc4a$$^4
@StableExploitt4
r007p455w0rd3
adminadmin3
admin1233
supe1User.gs@1z10.13
K%Q6@#sBFkhM0tWRJ4N)(3#@3
FsSAj1bKldSAO2@!2

Updated 34 minutes ago. Source: SparTech Software Honeypot Project.