violet's honeypot
DashboardAnalysis
threat analysis · ml

Attack Intelligence

What the traffic reveals: who the attackers are, what they want, and where it's heading.

7
botnet campaigns
99%
intent model accuracy
188
anomalous actors
1564
ips profiled
password length distribution
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
password makeup
01lowercase only
27590
02letters+digits
19433
03digits only
18075
04has symbol
12792
05letters only
487
most-tried user : password
01345gs5662d34 : 345gs5662d34
1045
02admin : admin
733
03root : 3245gs5662d34
494
04root : 123456
300
05root : gVgaB=gr4hc7nsC-va7t
237
06user : root
219
attacks by hour (utc) · day of week
Sun
Mon
Tue
Wed
Thu
Fri
Sat
attack volume · hourly, with 24h forecast
attacker intent (from captured commands)
01persistence
1122
02recon
116
03other
71
04miner
66
05malware_install
61
botnet campaigns (clustered)
#01499 ip🇨🇳345gs5662d34 : 345gs5662d3426.4/ip
models: dbscan clustering · tf-idf + random forest intent · isolationforest anomalies · seasonal forecast
07
root : abcd1234
209
attacker networks (asn)
01unknown
11166
02AS51396 Pfcloud UG
8958
03AS197170 TechTies Inc.
6531
04AS8075 Microsoft Corporation
3455
05AS401152 Ace Data Centers II, L.L.C.
3387
06AS47890 UNMANAGED LTD
3384
07AS14061 DigitalOcean, LLC
2631
0
6
12
18
now
#1
12 ip
🇳🇱
rock : rock
750.8/ip
#37 ip🇩🇪root : 2/ip
#25 ip🇹🇷root : 123@@@189.8/ip
#42 ip🇳🇱root : 111111207.5/ip
#52 ip🇳🇱root : kali1590/ip
#62 ip🇧🇬RPM : RPM856/ip