Below are the latest honeypot stats from SparTech Software’s in-house honeypot.
SparTech Software Honeypot Project
Event volume by severity
Last 14 days. Tall pale bars are ordinary background scanning; dark segments are attempts that carried credentials or a payload.
- Recon (sev 1-2)
- Loot hunting (sev 3)
- Attack (sev 4-5)
- Critical (sev 6)
Show data table
| Day | Recon (sev 1-2) | Loot hunting (sev 3) | Attack (sev 4-5) | Total |
|---|---|---|---|---|
| 5 Sep | 58 | 0 | 142 | 200 |
| 6 Sep | 51 | 1 | 292 | 346 |
| 7 Sep | 59 | 0 | 46 | 105 |
| 8 Sep | 55 | 0 | 101 | 156 |
| 9 Sep | 54 | 0 | 282 | 336 |
| 10 Sep | 60 | 0 | 125 | 185 |
| 11 Sep | 88 | 1 | 297 | 386 |
| 12 Sep | 75 | 0 | 100 | 176 |
| 13 Sep | 83 | 8 | 65 | 156 |
| 14 Sep | 83 | 15 | 448 | 548 |
| 15 Sep | 74 | 12 | 154 | 240 |
| 16 Sep | 66 | 5 | 60 | 131 |
| 17 Sep | 51 | 0 | 386 | 437 |
| 18 Sep | 28 | 12 | 9 | 49 |
Severity mix
The scale measures engagement depth. 1-2 is recon, 3 is hunting for loot, 4 is an exploit being attempted, 5 is an attack on the login or upload surface, and 6 means somebody acted on what they took.
Show data table
| Severity | Level | Events | Share |
|---|---|---|---|
| 1 | Informational | 2,581 | 26% |
| 2 | Targeted recon | 1,113 | 11% |
| 3 | Loot hunting | 79 | 1% |
| 4 | Exploitation attempt | 1,419 | 15% |
| 5 | Credential or upload attack | 4,299 | 44% |
| 6 | Critical — hands-on | 299 | 3% |
Activity by hour of day
Flat coverage across all 24 hours is the signature of automation. Humans cluster into working hours, and the shaded band is the stretch nobody is choosing to work through.
- Daytime and evening
- Small hours (00:00-05:59)
Show data table
| Hour | Events |
|---|---|
| 00:00 | 490 |
| 01:00 | 590 |
| 02:00 | 296 |
| 03:00 | 555 |
| 04:00 | 505 |
| 05:00 | 482 |
| 06:00 | 512 |
| 07:00 | 623 |
| 08:00 | 344 |
| 09:00 | 337 |
| 10:00 | 664 |
| 11:00 | 617 |
| 12:00 | 392 |
| 13:00 | 250 |
| 14:00 | 205 |
| 15:00 | 255 |
| 16:00 | 268 |
| 17:00 | 645 |
| 18:00 | 242 |
| 19:00 | 241 |
| 20:00 | 200 |
| 21:00 | 259 |
| 22:00 | 395 |
| 23:00 | 423 |
Top event types
What the honeypot caught people doing, counted over everything it has recorded.
Show data table
| Value | Events |
|---|---|
| xmlrpc_credentials | 3,980 |
| not_found_scan | 2,109 |
| bait_path | 1,571 |
| security_probe | 1,386 |
| login_attempt | 604 |
| trap_enum | 60 |
| user_enumeration | 40 |
| xmlrpc_call | 14 |
| contact_message | 9 |
| contact_spam | 8 |
| login_success | 5 |
| file_upload | 2 |
Attacker tooling
The software making the requests, identified from how each client presents itself. Commodity scanners dominate; anything hand-driven stands out.
Show data table
| Value | Events |
|---|---|
| headless-client | 3,468 |
| search-crawler | 350 |
| seo-crawler | 157 |
| curl | 16 |
| java-http | 8 |
| scripted-client | 8 |
| python-http | 2 |
Most common attacks
Each label is one recognised technique or vulnerable endpoint.
Show data table
| Value | Events |
|---|---|
| metaWeblog.newPost | 3,753 |
| /wp-content/plugins/wordfence/images/wordfence-logo.svg | 2,044 |
| security-plugin-probe | 1,386 |
| decoy-asset-probe | 612 |
| own-asset-fetch | 396 |
| wp-login | 313 |
| advertised-plugin-probe | 297 |
| wp-login-harvested-identity | 291 |
| system.multicall | 134 |
| wp.getUsersBlogs | 107 |
| author-enum | 61 |
| author-enumeration | 54 |
Adversary techniques observed
Each bar is a MITRE ATT&CK technique, counted from the events this honeypot recorded. These are techniques currently being used against small business websites, not a theoretical list.
Show data table
| ID | Technique | Tactic | Events |
|---|---|---|---|
| T1110.003 | Brute Force: Password Spraying | Credential Access | 3,990 |
| T1518 | Software Discovery | Discovery | 2,341 |
| T1595.003 | Active Scanning: Wordlist Scanning | Reconnaissance | 2,171 |
| T1083 | File and Directory Discovery | Discovery | 1,571 |
| T1595.002 | Active Scanning: Vulnerability Scanning | Reconnaissance | 1,413 |
| T1110.001 | Brute Force: Password Guessing | Credential Access | 765 |
| T1078 | Valid Accounts | Initial Access | 609 |
| T1592.002 | Gather Victim Host Information: Software | Reconnaissance | 322 |
| T1552.001 | Unsecured Credentials: Credentials In Files | Credential Access | 297 |
| T1087 | Account Discovery | Discovery | 198 |
| T1589 | Gather Victim Identity Information | Reconnaissance | 192 |
| T1595 | Active Scanning | Reconnaissance | 43 |
Where the attacks come from
Resolved from the busiest source addresses, which between them account for 35% of all recorded events. Countries are read from the addresses traffic arrives from, which is where it was routed from rather than necessarily where whoever sent it is.
Show data table
| Value | Events |
|---|---|
| 🇬🇧 United Kingdom | 2,088 |
| 🇮🇳 India | 468 |
| 🇧🇩 Bangladesh | 316 |
| 🇵🇰 Pakistan | 133 |
| 🇸🇦 Saudi Arabia | 104 |
| 🇺🇸 United States | 83 |
| 🇳🇵 Nepal | 74 |
| 🇦🇷 Argentina | 66 |
| 🇧🇷 Brazil | 65 |
| 🇨🇩 Democratic Republic of the Congo | 61 |
How far attackers got
Distinct source addresses, counted once each at the deepest level they reached. Every bar contains the ones below it, so the width can only shrink; the drop from one bar to the next is how many stopped at that step.
Show data table
| Reached at least | Sources | Share | Stopped here |
|---|---|---|---|
| Informational | 1,045 | 100% | — |
| Targeted recon | 987 | 94% | 58 |
| Loot hunting | 734 | 70% | 253 |
| Exploitation attempt | 720 | 69% | 14 |
| Credential or upload attack | 642 | 61% | 78 |
| Critical — hands-on | 163 | 16% | 479 |
Critical events
5 critical events in the last 14 days. Each mark is a day something reached the top of the severity ladder — a canary token fired from off-site, a shell uploaded, a decoy account used. Clusters matter more than the count: several in one day is usually one operator working.
Show data table
| Day | Critical events |
|---|---|
| 5 Sep | 0 |
| 6 Sep | 2 |
| 7 Sep | 0 |
| 8 Sep | 0 |
| 9 Sep | 0 |
| 10 Sep | 0 |
| 11 Sep | 0 |
| 12 Sep | 1 |
| 13 Sep | 0 |
| 14 Sep | 2 |
| 15 Sep | 0 |
| 16 Sep | 0 |
| 17 Sep | 0 |
| 18 Sep | 0 |
New and returning sources
Distinct addresses per day. "First time" means never seen before at all, not merely not seen that day. Churn of one-off addresses is ordinary background scanning; addresses that keep coming back are worth a closer look.
- Seen before
- First time
Show data table
| Day | First time | Seen before | Total |
|---|---|---|---|
| 5 Sep | 20 | 5 | 25 |
| 6 Sep | 14 | 4 | 18 |
| 7 Sep | 1 | 5 | 6 |
| 8 Sep | 8 | 4 | 12 |
| 9 Sep | 14 | 5 | 19 |
| 10 Sep | 16 | 5 | 21 |
| 11 Sep | 12 | 6 | 18 |
| 12 Sep | 9 | 4 | 13 |
| 13 Sep | 17 | 4 | 21 |
| 14 Sep | 99 | 7 | 106 |
| 15 Sep | 10 | 4 | 14 |
| 16 Sep | 14 | 7 | 21 |
| 17 Sep | 15 | 4 | 19 |
| 18 Sep | 2 | 3 | 5 |
Activity by day of the week
A flat week is automation, which does not know what a weekend is. A weekday-shaped week means a person is choosing when to work — the same reading as the hourly chart, at a scale that shows a pattern the hours cannot.
- Weekday
- Weekend
Show data table
| Day | Events |
|---|---|
| Mon | 1,516 |
| Tue | 1,264 |
| Wed | 1,374 |
| Thu | 1,347 |
| Fri | 1,221 |
| Sat | 1,877 |
| Sun | 1,191 |
Busiest source addresses
Addresses are shared, reassigned and often spoofed, so treat these as traffic sources rather than as identities.
Show data table
| Value | Events |
|---|---|
| 80.76.57.13 | 326 |
| 88.97.176.205 | 269 |
| 86.18.50.103 | 248 |
| 45.150.145.15 | 226 |
| 78.148.77.210 | 165 |
| 84.43.29.214 | 159 |
| 103.153.130.34 | 142 |
| 116.90.101.224 | 133 |
| 78.148.66.189 | 132 |
| 103.44.52.132 | 128 |
Most tried usernames
The account names attackers guessed at.
Show data table
| Value | Events |
|---|---|
| admin | 268 |
| Monitoring | 130 |
| Editorial | 80 |
| Deploy | 79 |
| jmorris | 30 |
| devops | 27 |
| tbibasmash | 26 |
| content | 23 |
| tbiba@smashtheman.com | 5 |
| root | 3 |
Most tried passwords
Taken from the dictionaries currently in circulation. If one of these is familiar, change it.
Show data table
| Value | Events |
|---|---|
| admin | 42 |
| pass | 32 |
| password | 27 |
| user%02 | 21 |
| Monitoring | 20 |
| stoneandrazorbarber | 19 |
| adminadmin | 17 |
| admin2025 | 16 |
| stoneandrazorbarber123 | 16 |
| admin123 | 15 |
Updated 42 minutes ago. Source: SparTech Software Honeypot Project.
SparTech Software Honeypot Project
Event volume by severity
Last 14 days. Tall pale bars are ordinary background scanning; dark segments are attempts that carried credentials or a payload.
- Recon (sev 1-2)
- Loot hunting (sev 3)
- Attack (sev 4-5)
- Critical (sev 6)
Show data table
| Day | Recon (sev 1-2) | Loot hunting (sev 3) | Attack (sev 4-5) | Total |
|---|---|---|---|---|
| 5 Sep | 49 | 0 | 47 | 96 |
| 6 Sep | 46 | 0 | 41 | 87 |
| 7 Sep | 52 | 0 | 45 | 97 |
| 8 Sep | 49 | 0 | 44 | 93 |
| 9 Sep | 47 | 1 | 37 | 85 |
| 10 Sep | 64 | 0 | 46 | 110 |
| 11 Sep | 58 | 0 | 45 | 103 |
| 12 Sep | 50 | 0 | 47 | 98 |
| 13 Sep | 51 | 1 | 63 | 115 |
| 14 Sep | 71 | 15 | 46 | 134 |
| 15 Sep | 55 | 0 | 47 | 102 |
| 16 Sep | 56 | 0 | 45 | 101 |
| 17 Sep | 77 | 16 | 49 | 142 |
| 18 Sep | 7 | 0 | 6 | 13 |
Severity mix
The scale measures engagement depth. 1-2 is recon, 3 is hunting for loot, 4 is an exploit being attempted, 5 is an attack on the login or upload surface, and 6 means somebody acted on what they took.
Show data table
| Severity | Level | Events | Share |
|---|---|---|---|
| 1 | Informational | 2,250 | 51% |
| 2 | Targeted recon | 400 | 9% |
| 3 | Loot hunting | 56 | 1% |
| 4 | Exploitation attempt | 1,412 | 32% |
| 5 | Credential or upload attack | 246 | 6% |
| 6 | Critical — hands-on | 14 | 0% |
Activity by hour of day
Flat coverage across all 24 hours is the signature of automation. Humans cluster into working hours, and the shaded band is the stretch nobody is choosing to work through.
- Daytime and evening
- Small hours (00:00-05:59)
Show data table
| Hour | Events |
|---|---|
| 00:00 | 158 |
| 01:00 | 182 |
| 02:00 | 180 |
| 03:00 | 156 |
| 04:00 | 192 |
| 05:00 | 143 |
| 06:00 | 167 |
| 07:00 | 195 |
| 08:00 | 170 |
| 09:00 | 125 |
| 10:00 | 172 |
| 11:00 | 175 |
| 12:00 | 216 |
| 13:00 | 156 |
| 14:00 | 172 |
| 15:00 | 186 |
| 16:00 | 191 |
| 17:00 | 171 |
| 18:00 | 203 |
| 19:00 | 154 |
| 20:00 | 177 |
| 21:00 | 160 |
| 22:00 | 184 |
| 23:00 | 393 |
Top event types
What the honeypot caught people doing, counted over everything it has recorded.
Show data table
| Value | Events |
|---|---|
| not_found_scan | 2,157 |
| security_probe | 1,377 |
| bait_path | 489 |
| xmlrpc_credentials | 216 |
| trap_enum | 57 |
| login_attempt | 37 |
| user_enumeration | 16 |
| xmlrpc_call | 12 |
| attack_payload | 4 |
| contact_message | 3 |
| contact_cached_form | 3 |
| login_success | 3 |
Attacker tooling
The software making the requests, identified from how each client presents itself. Commodity scanners dominate; anything hand-driven stands out.
Show data table
| Value | Events |
|---|---|
| headless-client | 3,470 |
| search-crawler | 180 |
| seo-crawler | 112 |
| python-http | 64 |
| java-http | 7 |
| curl | 1 |
Most common attacks
Each label is one recognised technique or vulnerable endpoint.
Show data table
| Value | Events |
|---|---|
| /wp-content/plugins/wordfence/images/wordfence-logo.svg | 2,051 |
| security-plugin-probe | 1,377 |
| decoy-asset-probe | 273 |
| system.multicall | 220 |
| author-enum | 61 |
| login-page | 58 |
| author-enumeration | 55 |
| wp-login | 34 |
| own-asset-fetch | 18 |
| rest-users | 16 |
| plugin-version-probe | 15 |
| /.well-known/security.txt | 14 |
Adversary techniques observed
Each bar is a MITRE ATT&CK technique, counted from the events this honeypot recorded. These are techniques currently being used against small business websites, not a theoretical list.
Show data table
| ID | Technique | Tactic | Events |
|---|---|---|---|
| T1595.003 | Active Scanning: Wordlist Scanning | Reconnaissance | 2,214 |
| T1518 | Software Discovery | Discovery | 1,686 |
| T1595.002 | Active Scanning: Vulnerability Scanning | Reconnaissance | 1,392 |
| T1083 | File and Directory Discovery | Discovery | 489 |
| T1110.001 | Brute Force: Password Guessing | Credential Access | 268 |
| T1110.003 | Brute Force: Password Spraying | Credential Access | 228 |
| T1087 | Account Discovery | Discovery | 148 |
| T1589 | Gather Victim Identity Information | Reconnaissance | 146 |
| T1595 | Active Scanning | Reconnaissance | 58 |
| T1078 | Valid Accounts | Initial Access | 40 |
| T1505.003 | Server Software Component: Web Shell | Persistence | 22 |
| T1592.002 | Gather Victim Host Information: Software | Reconnaissance | 19 |
Where the attacks come from
Resolved from the busiest source addresses, which between them account for 63% of all recorded events. Countries are read from the addresses traffic arrives from, which is where it was routed from rather than necessarily where whoever sent it is.
Show data table
| Value | Events |
|---|---|
| 🇬🇧 United Kingdom | 2,685 |
| 🇳🇱 Netherlands | 35 |
| 🇪🇸 Spain | 35 |
How far attackers got
Distinct source addresses, counted once each at the deepest level they reached. Every bar contains the ones below it, so the width can only shrink; the drop from one bar to the next is how many stopped at that step.
Show data table
| Reached at least | Sources | Share | Stopped here |
|---|---|---|---|
| Informational | 576 | 100% | — |
| Targeted recon | 501 | 87% | 75 |
| Loot hunting | 322 | 56% | 179 |
| Exploitation attempt | 300 | 52% | 22 |
| Credential or upload attack | 222 | 39% | 78 |
| Critical — hands-on | 12 | 2% | 210 |
Critical events
3 critical events in the last 14 days. Each mark is a day something reached the top of the severity ladder — a canary token fired from off-site, a shell uploaded, a decoy account used. Clusters matter more than the count: several in one day is usually one operator working.
Show data table
| Day | Critical events |
|---|---|
| 5 Sep | 0 |
| 6 Sep | 0 |
| 7 Sep | 0 |
| 8 Sep | 0 |
| 9 Sep | 0 |
| 10 Sep | 0 |
| 11 Sep | 0 |
| 12 Sep | 1 |
| 13 Sep | 0 |
| 14 Sep | 2 |
| 15 Sep | 0 |
| 16 Sep | 0 |
| 17 Sep | 0 |
| 18 Sep | 0 |
New and returning sources
Distinct addresses per day. "First time" means never seen before at all, not merely not seen that day. Churn of one-off addresses is ordinary background scanning; addresses that keep coming back are worth a closer look.
- Seen before
- First time
Show data table
| Day | First time | Seen before | Total |
|---|---|---|---|
| 5 Sep | 2 | 4 | 6 |
| 6 Sep | 2 | 3 | 5 |
| 7 Sep | 2 | 4 | 6 |
| 8 Sep | 4 | 4 | 8 |
| 9 Sep | 6 | 2 | 8 |
| 10 Sep | 10 | 4 | 14 |
| 11 Sep | 10 | 4 | 14 |
| 12 Sep | 5 | 4 | 9 |
| 13 Sep | 17 | 9 | 26 |
| 14 Sep | 8 | 4 | 12 |
| 15 Sep | 6 | 4 | 10 |
| 16 Sep | 8 | 4 | 12 |
| 17 Sep | 9 | 3 | 12 |
| 18 Sep | 1 | 3 | 4 |
Activity by day of the week
A flat week is automation, which does not know what a weekend is. A weekday-shaped week means a person is choosing when to work — the same reading as the hourly chart, at a scale that shows a pattern the hours cannot.
- Weekday
- Weekend
Show data table
| Day | Events |
|---|---|
| Mon | 588 |
| Tue | 652 |
| Wed | 603 |
| Thu | 902 |
| Fri | 566 |
| Sat | 539 |
| Sun | 528 |
Busiest source addresses
Addresses are shared, reassigned and often spoofed, so treat these as traffic sources rather than as identities.
Show data table
| Value | Events |
|---|---|
| 80.76.57.13 | 324 |
| 86.18.50.103 | 267 |
| 88.97.176.205 | 267 |
| 45.150.145.15 | 211 |
| 78.148.77.210 | 167 |
| 84.43.29.214 | 153 |
| 78.148.66.189 | 149 |
| 88.97.176.173 | 135 |
| 86.155.134.168 | 90 |
| 86.162.205.202 | 72 |
Most tried usernames
The account names attackers guessed at.
Show data table
| Value | Events |
|---|---|
| admin | 37 |
| tbibasmash | 7 |
| nizeezci | 4 |
| admin@wordpress.com | 3 |
| Deploy | 3 |
| tbiba@smashtheman.com | 3 |
| site_admin | 3 |
| root | 3 |
| supe1user10 | 3 |
| muwy | 2 |
Most tried passwords
Taken from the dictionaries currently in circulation. If one of these is familiar, change it.
Show data table
| Value | Events |
|---|---|
| password | 5 |
| pass | 4 |
| PtXe*JMQ%jT2HS!BSRc4a$$^ | 4 |
| @StableExploitt | 4 |
| r007p455w0rd | 3 |
| adminadmin | 3 |
| admin123 | 3 |
| supe1User.gs@1z10.1 | 3 |
| K%Q6@#sBFkhM0tWRJ4N)(3#@ | 3 |
| FsSAj1bKldSAO2@! | 2 |
Updated 34 minutes ago. Source: SparTech Software Honeypot Project.