Below are the latest honeypot stats from SparTech Software’s in-house honeypot.

757Events recorded
51Today
105Distinct sources
479Attacks on login or upload
1Hands-on intrusions

Event volume by severity

Last 14 days. Tall pale bars are ordinary background scanning; dark segments are attempts that carried credentials or a payload.

  • Recon (sev 1-2)
  • Loot hunting (sev 3)
  • Attack (sev 4-5)
  • Critical (sev 6)
030060021 Jul22 Jul23 Jul24 Jul25 Jul26 Jul27 Jul28 Jul29 Jul30 Jul31 Jul1 Aug — Recon (sev 1-2): 331 Aug — Loot hunting (sev 3): 21 Aug — Attack (sev 4-5): 5495851 Aug2 Aug — Recon (sev 1-2): 942 Aug — Attack (sev 4-5): 271212 Aug3 Aug — Recon (sev 1-2): 51513 Aug
Show data table
DayRecon (sev 1-2)Loot hunting (sev 3)Attack (sev 4-5)Total
21 Jul0000
22 Jul0000
23 Jul0000
24 Jul0000
25 Jul0000
26 Jul0000
27 Jul0000
28 Jul0000
29 Jul0000
30 Jul0000
31 Jul0000
1 Aug332549585
2 Aug94027121
3 Aug510051

Severity mix

The scale measures engagement depth. 1-2 is recon, 3 is hunting for loot, 4 is an exploit being attempted, 5 is an attack on the login or upload surface, and 6 means somebody acted on what they took.

Severity 1, Informational — 25 events (3%)Severity 2, Targeted recon — 153 events (20%)Severity 3, Loot hunting — 2 events (0%)Severity 4, Exploitation attempt — 98 events (13%)Severity 5, Credential or upload attack — 478 events (63%)Severity 6, Critical — hands-on — 1 events (0%)757eventsInformational25 · 3%Targeted recon153 · 20%Loot hunting2 · 0%Exploitation attempt98 · 13%Credential or upload attack478 · 63%Critical — hands-on1 · 0%
Show data table
SeverityLevelEventsShare
1Informational253%
2Targeted recon15320%
3Loot hunting20%
4Exploitation attempt9813%
5Credential or upload attack47863%
6Critical — hands-on10%

Activity by hour of day

Flat coverage across all 24 hours is the signature of automation. Humans cluster into working hours, and the shaded band is the stretch nobody is choosing to work through.

  • Daytime and evening
  • Small hours (00:00-05:59)
01252500002:00-02:59 — 1 events0304:00-04:59 — 1 events06:00-06:59 — 29 events0607:00-07:59 — 56 events08:00-08:59 — 60 events0910:00-10:59 — 200 events11:00-11:59 — 247 events12:00-12:59 — 116 events1213:00-13:59 — 13 events14:00-14:59 — 5 events15:00-15:59 — 4 events1518:00-18:59 — 2 events1819:00-19:59 — 3 events20:00-20:59 — 2 events2122:00-22:59 — 17 events23:00-23:59 — 1 events
Show data table
HourEvents
00:000
01:000
02:001
03:000
04:001
05:000
06:0029
07:0056
08:0060
09:000
10:00200
11:00247
12:00116
13:0013
14:005
15:004
16:000
17:000
18:002
19:003
20:002
21:000
22:0017
23:001

Top event types

What the honeypot caught people doing, counted over everything it has recorded.

bait_pathbait_path — 710710login_attemptlogin_attempt — 2727not_found_scannot_found_scan — 1818campaigncampaign — 11user_enumerationuser_enumeration — 11
Show data table
ValueEvents
bait_path710
login_attempt27
not_found_scan18
campaign1
user_enumeration1

Attacker tooling

The software making the requests, identified from how each client presents itself. Commodity scanners dominate; anything hand-driven stands out.

search-crawlersearch-crawler — 9898seo-crawlerseo-crawler — 2020curlcurl — 1515java-httpjava-http — 77headless-clientheadless-client — 44python-httppython-http — 11
Show data table
ValueEvents
search-crawler98
seo-crawler20
curl15
java-http7
headless-client4
python-http1

Most common attacks

Each label is one recognised technique or vulnerable endpoint.

exploit-backup-migrationexploit-backup-migration — 9595exploit-ultimate-memberexploit-ultimate-member — 9595exploit-elementorexploit-elementor — 9595exploit-revsliderexploit-revslider — 9595exploit-duplicatorexploit-duplicator — 9393decoy-asset-probedecoy-asset-probe — 8383exploit-wp-file-managerexploit-wp-file-manager — 7575advertised-plugin-probeadvertised-plugin-probe — 5858wp-loginwp-login — 2727/favicon.png/favicon.png — 77xmlrpcxmlrpc — 77author-enumauthor-enum — 55
Show data table
ValueEvents
exploit-backup-migration95
exploit-ultimate-member95
exploit-elementor95
exploit-revslider95
exploit-duplicator93
decoy-asset-probe83
exploit-wp-file-manager75
advertised-plugin-probe58
wp-login27
/favicon.png7
xmlrpc7
author-enum5

Where the attacks come from

Resolved from the busiest source addresses, which between them account for 77% of all recorded events. Countries are read from the addresses traffic arrives from, which is where it was routed from rather than necessarily where whoever sent it is.

🇺🇸 United States🇺🇸 United States — 345345🇵🇱 Poland🇵🇱 Poland — 6868🇳🇱 Netherlands🇳🇱 Netherlands — 5757🇧🇷 Brazil🇧🇷 Brazil — 3434🇬🇧 United Kingdom🇬🇧 United Kingdom — 3131🇩🇪 Germany🇩🇪 Germany — 1717🇮🇹 Italy🇮🇹 Italy — 1717🇫🇮 Finland🇫🇮 Finland — 1717
Show data table
ValueEvents
🇺🇸 United States345
🇵🇱 Poland68
🇳🇱 Netherlands57
🇧🇷 Brazil34
🇬🇧 United Kingdom31
🇩🇪 Germany17
🇮🇹 Italy17
🇫🇮 Finland17

How far attackers got

Distinct source addresses, counted once each at the deepest level they reached. Every bar contains the ones below it, so the width can only shrink; the drop from one bar to the next is how many stopped at that step.

InformationalInformational — 105 sources (100% of all)105 (100%)Targeted reconTargeted recon — 93 sources (89% of all)93 (89%)12 stopped hereLoot huntingLoot hunting — 42 sources (40% of all)42 (40%)51 stopped hereExploitation attemptExploitation attempt — 42 sources (40% of all)42 (40%)Credential or upload attackCredential or upload attack — 42 sources (40% of all)42 (40%)Critical — hands-onCritical — hands-on — 1 sources (1% of all)1 (1%)41 stopped here
Show data table
Reached at leastSourcesShareStopped here
Informational105100%
Targeted recon9389%12
Loot hunting4240%51
Exploitation attempt4240%0
Credential or upload attack4240%0
Critical — hands-on11%41

Critical events

1 critical event in the last 14 days. Each mark is a day something reached the top of the severity ladder — a canary token fired from off-site, a shell uploaded, a decoy account used. Clusters matter more than the count: several in one day is usually one operator working.

21 Jul22 Jul23 Jul24 Jul25 Jul26 Jul27 Jul28 Jul29 Jul30 Jul31 Jul1 Aug — 1 critical events11 Aug2 Aug3 Aug
Show data table
DayCritical events
21 Jul0
22 Jul0
23 Jul0
24 Jul0
25 Jul0
26 Jul0
27 Jul0
28 Jul0
29 Jul0
30 Jul0
31 Jul0
1 Aug1
2 Aug0
3 Aug0

New and returning sources

Distinct addresses per day. "First time" means never seen before at all, not merely not seen that day. Churn of one-off addresses is ordinary background scanning; addresses that keep coming back are worth a closer look.

  • Seen before
  • First time
0255021 Jul22 Jul23 Jul24 Jul25 Jul26 Jul27 Jul28 Jul29 Jul30 Jul31 Jul1 Aug — First time: 39391 Aug2 Aug — First time: 50502 Aug3 Aug — First time: 16163 Aug
Show data table
DayFirst timeSeen beforeTotal
21 Jul000
22 Jul000
23 Jul000
24 Jul000
25 Jul000
26 Jul000
27 Jul000
28 Jul000
29 Jul000
30 Jul000
31 Jul000
1 Aug39039
2 Aug50050
3 Aug16016

Activity by day of the week

A flat week is automation, which does not know what a weekend is. A weekday-shaped week means a person is choosing when to work — the same reading as the hourly chart, at a scale that shows a pattern the hours cannot.

  • Weekday
  • Weekend
0300600Mon — 5151MonTueWedThuFriSat — 585585SatSun — 121121Sun
Show data table
DayEvents
Mon51
Tue0
Wed0
Thu0
Fri0
Sat585
Sun121

Busiest source addresses

Addresses are shared, reassigned and often spoofed, so treat these as traffic sources rather than as identities.

2600:6c86:b640:3:a9cd:ccfc:cc4a:56…2600:6c86:b640:3:a9cd:ccfc:cc4a:56b6 — 838316.144.58.9516.144.58.95 — 343435.92.233.4835.92.233.48 — 3434205.169.39.183205.169.39.183 — 232398.93.157.498.93.157.4 — 1818212.201.100.163212.201.100.163 — 17172a04:ad80:1:c9::ec5b2a04:ad80:1:c9::ec5b — 1717103.196.9.185103.196.9.185 — 1717172.111.15.224172.111.15.224 — 171734.118.96.7434.118.96.74 — 1717
Show data table
ValueEvents
2600:6c86:b640:3:a9cd:ccfc:cc4a:56b683
16.144.58.9534
35.92.233.4834
205.169.39.18323
98.93.157.418
212.201.100.16317
2a04:ad80:1:c9::ec5b17
103.196.9.18517
172.111.15.22417
34.118.96.7417

Most tried usernames

The account names attackers guessed at.

MonitoringMonitoring — 99tbibasmashtbibasmash — 99adminadmin — 99
Show data table
ValueEvents
Monitoring9
tbibasmash9
admin9

Most tried passwords

Taken from the dictionaries currently in circulation. If one of these is familiar, change it.

passpass — 33passwordpassword — 33user%02user%02 — 33Monitoring2025Monitoring2025 — 11tbibasmash2025tbibasmash2025 — 11admin2025admin2025 — 11adminadminadminadmin — 11tbibasmashtbibasmashtbibasmashtbibasmash — 11MonitoringMonitoringMonitoringMonitoring — 11admin123admin123 — 11
Show data table
ValueEvents
pass3
password3
user%023
Monitoring20251
tbibasmash20251
admin20251
adminadmin1
tbibasmashtbibasmash1
MonitoringMonitoring1
admin1231

Updated 57 minutes ago. Source: SparTech Software Honeypot Project.