Geographic timeline · daily activity by origin country · last 7 days
Date
US USA
NL Nederländerna
DE Tyskland
BE Belgien
BR Brasilien
CA Kanada
Total
2026-08-17
112
17
53
3
7
26
254
2026-08-16
108
29
27
1
17
25
267
2026-08-15
220
35
22
3
9
2
336
2026-08-14
192
28
27
11
24
·
319
2026-08-13
90
31
17
2
16
2
187
2026-08-12
781
26
18
2
20
16
962
2026-08-11
378
42
16
112
8
7
624
2026-08-10
9
7
·
·
2
1
38
External traffic only. Dark cell = high activity from the country. Own IP addresses excluded.
11
Attack types explained
What is actually happening
Credential stuffing
0 unique IPs / 7 d
Automated Telnet connections systematically trying credentials from leaked databases. The goal is to take over routers and IoT devices to expand botnets.
CVE-targeted scanning
0 distinct protocols
Requests matching known CVE signatures — the attacker is looking for a specific vulnerability in industrial control systems, cameras or network equipment.
Disguised traffic
0 requests
OT protocol requests with browser user-agent (Mozilla/Chrome/Safari). The intent is to evade signature-based detection systems that filter out obvious scanner identities.
Counts refer to observations in honeypot data. Figures reflect attacker patterns, not actual breaches.
12
Trends
Requests per day over the last 30 and 90 days
Last 30 days
Last 90 days
Trend data is aggregated per UTC day from the internal collection pipeline and published with up to 24 hours delay.
Each bar represents the total number of incoming requests during the day, excluding own IP addresses and known scanning systems.
Days with no recorded activity are shown as zero.
13
Quarterly trends
Key KPIs per quarter — escalation over time
Quarter
Requests
Unique IPs
High-signal
Credential attempts
Residential IPs
2026-Q3
20 402
3 807
0
7
—
2026-Q2
30 457 +10 055
6 393 +2 586
0 0
68 +61
—
2026-Q1
23 345 -7 112
3 820 -2 573
112 +112
500 +432
—
Quarters with zero requests are excluded. Δ = change vs. previous quarter in the table.
14
Attack depth · resource targets, behaviour signatures and origin
What attackers are looking for
13 230
Protocol (TCP/UDP raw)
362
Document files
335
API endpoints
301
Login pages
12
Unknown
Behaviour signatures
11 103
Path enumeration
6 744
Human-like browsing
4 584
Automated scanning
2 769
Vulnerability scanning
2 523
Configuration probe
1 250
Mass scanning
966
No User-Agent
897
API probing
286
Backup probe
172
Confirmed human
152
Payment probe
95
known_scanner
Attacker network operators
2 287
Google LLC
955
Censys, Inc.
Security researcher
861
TECHOFF SRV LIMITED
707
Microsoft Corporation
663
Linode
352
UNMANAGED LTD
347
VPSVAULT.HOST LTD
240
FBW NETWORKS SAS
222
cloud
220
DigitalOcean, LLC
No IP addresses shown. ASN data via passive geo-enrichment.
15
AI agent scanning · MCP protocol probing and known actors
MCP (Model Context Protocol) — AI agent protocol, probed since May 2026
Total (all time)
152
Last 7 days
64
Known protocols
JSON-RPC 2.0 MCP/2024-11-05 Anthropic v1
Known scanners (user-agent)
okänd152
The honeypot exposes a full MCP interface with OT/ICS themes. Scanning is identified via endpoint_group=mcp_probe and attack_type=mcp_probe.