HAPNIC Honeynet · Threat Intel
● LIVE
◷ data as of …
Ranking window: last 30 days · ranked by events
Scopes the overview, the list tabs and their trend charts. Entity dossiers stay all-time.
→
—
unique IPs
—
ASNs
—
economies
—
payload URLs
—
malware hashes
Everything on the page follows the selected window.
Lists, metrics and daily trend charts all cover exactly the window you pick. Entity dossiers are the exception: they show all-time totals for that entity.
Events
—
in window
Published campaigns
42
analyst-managed
Tracked IPs
2.4M
distinct source IPs observed
History
454 days
of trend data

Honeypot status

active · event in the last hour quiet · within 24h offline · 24h+

What's new

Global source IPs

malicious-heavy high volume

Unique source IPs / day

Trends →

Honeypot mix

Top source economies

All →

Top source IPs

Full list →
Source IPEconomyNetworkClassificationEventsLast seen

Source concentration · source IPs by ASN

tile size ∝ unique IPs / ASN

Malware families captured

All malware →

Notable events — live

Malware · exploits · logins →

Distinct payloads

Browse all →
Pivot explorer · drill through the notable-event slice, keeping full context
Break down by
Window

Top economies

EconomyEventsUnique IPs
Loading…
Click a row to drill deeper; ↗ opens its dossier.
Each row shows activity within the breadcrumb context. Clicking a row turns it into a filter and moves you one level down. Pivots run over the retained notable-event window and are cached, so a broad first pivot can take a couple of seconds.

Credential intelligence

Credentials most-tried against the honeypots.
Attacker brute-force guesses, mostly dictionary or default credentials. Admin-only; access is audited.
Loading…

APNIC regional threat distribution

The 56 APNIC economies, by sub-region.
APNIC is the Regional Internet Registry serving Asia-Pacific. Share is of the APNIC-region total, and each sub-region shows how many of its economies are active.
Loading…

Portal health

Live status of the portal and its upstreams.
Refreshed on each visit and cached server-side for about 30 seconds. Admin-only.
Loading…

Unique source IPs / day

Source IPs by network (ASN)

Source IPs observed

ranked by all-time events · click a row to open its dossier
Source IPEconomyNetworkEventsLast seen
Loading…
203.101.186.23 Active
🇵🇰 Pakistan · AS9541 Cyber Internet Services
● Malicious why? SSH Bruteforcer Telnet Bruteforcer Malware Downloader Mirai Loader
First seen
2025-11-14
Last seen
2 min ago
Total events
48,213
Active span
—
Sensors hit
—
Honeypot types
—

Activity

SSH 22 · Telnet 23
No per-IP daily series is retained.
The curated store keeps per-IP totals plus the intel event slice, not a daily histogram. Use Total events and Active span above, and the Evidence tab below, for this IP's activity.
Notable intel events · most recent
A curated slice — malware downloads, exploit attempts, successful logins, credential submissions — not every packet or connection attempt. Honeypots that only log connections/credentials (OpenCanary, Fortinet) rarely produce rows here; that's expected, not missing data.
Timestamp · UTCSensorProtoSignatureRaw
🛡️ Sensor identities are pseudonymised (honeypot type + economy only) to protect honeypot placement.

Network fingerprint · HASSH

—
SSH/Telnet client fingerprint (HASSH).
A shared HASSH means the same client toolkit — useful for tying separate addresses to one actor.

Network metadata

ASN
—
Organisation
—
Economy
—

Sensor coverage

Honeypot types
—
Target ports
—

Related IPs · shared HASSH

External enrichment

Classification comes from honeynet behaviour — see the Evidence tab.
No per-IP external reputation (GreyNoise, OTX, Shodan) is integrated; everything here is what our own sensors observed.

Campaign history

Events / day

Source IPs by economy

Networks (ASN) observed

ranked by source IPs · click to open
ASNOrganisationSource IPs
Loading…
AS9541 Active
Cyber Internet Services (Pvt) Ltd · 🇵🇰 Pakistan · RIR APNIC · 14 prefixes
● High abuse Mirai source SSH / Telnet bruteforce
First seen
2025-08-21
Last seen
2 min ago
Source IPs
1,240
Malicious IPs
890
Events · total
312K

ASN activity — events / day · last 30 days

Source IPs in this network

Source IPEconomyClassificationEventsLast seen

Top signatures from this ASN

Malware samples fetched by source IPs in this network

top by fetch count · click a hash to open it
SHA-256MalwareFetches
—

Network

ASN
—
Organisation
—
Economy
—

Abuse posture · from honeynet

Source IPs
—
Malicious IPs
—
Malicious ratio
—

External registration

Metrics are from observed honeynet activity.
RDAP, abuse-contact and prefix registration are not integrated, so none of this reflects external reputation.

Honeynet events / day

URLs by payload status

Malware / payload URLs observed

ranked by times served · click to open
URLHostStatusServedLast seen
Loading…
— —
First seen
2026-07-19
Last served
2 min ago
Times served
3,214
Host
175.174.52.172
Status
Online

Delivery activity — fetches / day

retained event window

Attacking source IPs that fetched this payload

Source IPEconomyNetworkPushesLast seen

Sibling payloads on the same host

PathPayloadServedStatus

Hosting infrastructure

Host IP
—
ASN
—
Open port
—
URL first seen
—

Payload

SHA-256
—
URLhaus status
—
Family/type resolved on the hash dossier.

Campaigns

Analyst-curated correlation rules.
Group activity by an IOC (URL, file hash, IP/CIDR), a URL or command pattern, an SSH fingerprint (HASSH), or any combination. You choose what is published to the public portal and feeds.
CampaignBasisDefinitionMember IPsStatusActions
● Published live on the public portal & feeds ◌ Hidden internal only — excluded from publication Deleting a campaign removes its definition only; observed events are untouched.

Change history

edits & publication changes · newest first
‹ All campaigns
— —
Basis — · —

Activity

Member IPs

Source IPEconomyNetworkEventsLast seen

Rule reach in the feed archive

Has this rule been true before?
Member IPs above come from the retained event window (about 19 days) — who is attacking us now. This checks the same rule against the historical daily feeds (2021 onwards) to show whether it has been true before, and for how long. Context only: it does not change membership.

Match conditions

Geographic spread · member IPs

Notes

—

Events / day · last 30 days

Top signatures

Protocols / services targeted

by connections
Loading…

Service mix

share of connections

Top source IPs on this honeypot

Full list →
Source IPEconomyClassificationEvents

Unique source IPs / day

Source IPs by economy

Source economies observed

ranked by source IPs · click to open
EconomySource IPs
Loading…

Events / day · last 30 days

Networks · ASN

by unique IPs · whole accounted for

Honeypots targeted

Top source IPs from this economy

Source IPNetworkFirst seenLast seenEvents

Malware samples fetched by source IPs in this economy

top by fetch count · click a hash to open it
SHA-256MalwareFetches
—

Campaign history · this economy

Source IPs
—
queryable via API
Malware hashes
—
captured payloads
CVEs tracked
—
exploit attempts
Data as of
—
newest ingested event

Feed catalog

The REST API below is the programmatic access.
These are the same endpoints this UI uses (/api/ip, /api/search, /api/campaigns, …). Structured export feeds (MISP, STIX/TAXII, CSV) are on the roadmap.

Access tiers

Public Free
Researchers · anyone
  • Search UI + entity dossiers (sensitive fields redacted)
  • Public feeds — MISP / CSV / JSON
  • API 60 req/min
Registered CERTs · operators
Verified national CERTs & honeynet operators
  • API keys · 600 req/min · bulk export
  • Restricted feeds (HASSH, per-economy, credentials)
  • Full fields — raw credentials still gated
Partner Federation
Data-sharing partners
  • Real-time STIX 2.1 / TAXII stream
  • Unmetered · full notable-event feed
  • Contribute your own honeynet data back

REST API — example

Full reference →
Look up an IP
GET /api/ip/45.144.29.201
Accept: application/json
Response · IPDossier
{
  "ip": "45.144.29.201",
  "country": "FR", "asn": 41745,
  "as_org": "FORTIS-AS …",
  "first_seen": "2025-08-24T…Z",
  "last_seen":  "2026-07-30T…Z",
  "total_events": 126425730,
  "distinct_days": 341
}
# evidence: GET /api/ip/{ip}/evidence
# search  : GET /api/search?q=…

Rate limits & access by tier

TierRate limitBulk exportReal-time (TAXII)Sensitive fields
Public60 / min——redacted
Registered600 / min✓ CSV / JSON—full · no raw creds
Partnerunmetered✓✓ STIX 2.1full
Sensors that produced attack intel in the retained window — not the whole fleet.
The portal only ingests notable events (malware downloads, exploit attempts, logins) from roughly the last three weeks, and has no raw heartbeats. A sensor that saw only scans or connection attempts in that window is healthy but does not appear here, so this count runs materially below the number of sensors actually reporting — Elasticsearch, which keeps every event for 18 months, currently sees about 200 reporting in the last 7 days against the figure shown here.

Active means an intel event in the last hour, so a quiet honeypot can look stale even when it is fine. Counts are per sensor and collector instance: a sensor re-registered onto another collector (as in the agora2 migration) appears once per instance, because re-registration mints a new sensor ID.
Producing intel
—
sensor × instance, ~3w window
Active · <1h
—
intel event within the hour
Quiet · 1–24h
—
no intel event >1h
Honeypot types
—
—
Collectors
—
—

Sensors by honeypot type

Sensors by collector

Sensors

Sensor UUIDCollectorHoneypotStatusFirst seenLast eventIntel events
— —

Sensor activity — events / day

per-sensor trend — not yet wired

Top source IPs on this sensor

Full list →
Source IPEconomyClassificationEvents

Sensor

UUID
—
Honeypot
—
Collector
—
First seen
—
Last event
—
Image / ports / uptime aren't visible to the portal — it only sees the event stream.
Governance · benign scanner allowlist

Known research & commercial internet scanners are excluded from malicious classification. Their activity is labelled benign · research and kept out of threat metrics and feeds, so legitimate scanning isn't mistaken for an attack. Network owners can request an addition or correction.

Allowlisted scanners

Known scanners are not currently excluded from metrics.
The benign-scanner allowlist is not yet materialised as data — the text above describes intended governance. Research and commercial scanners (Censys, Shodan, academic) still count toward metrics; that classification pipeline is planned.

Malware families

Captures by file type

Malware / payloads captured

ranked by times captured · click to open
SHA-256FamilyTypeSizeCapturesLast seen
Loading…
4e9f2c7a…b1a7c2 Malware
Mirai · ELF ARM · 78 KB · first submitted 2026-07-19
● MiraiELF / ARMIoT botnet
First seen
2026-07-19
Last seen
2 min ago
Times captured
3,214
File size
78 KB
Family
Mirai

Captures — per day

retained event window

Attacking source IPs that fetched this sample

The intruders that fetched it, not the hosts serving it.
These addresses ran the download inside a honeypot session. The machines actually hosting the file are the payload URLs below.
Source IPEconomyNetworkFetches

Payload URLs this sample was fetched from

The distribution servers hosting the file.
URLHost ASNStatusFetches

File

SHA-256
—
MD5
—
Type
—
Size
—

Enrichment

Family and file-type come from MalwareBazaar → mwdb.
VirusTotal and Triage are not integrated, so an unclassified sample may still be known elsewhere. Campaign membership is analyst-rule-driven — see the Campaigns tab.
—
First seen
—
Last seen
—
Samples
—
Total captures
—

Captures / day all-time

Top delivering source IPs

click to open
Source IPEconomyNetworkFetches
—

Samples in this family

SHA-256File typeCapturesLast seen
—

Top economies nightly

—

Top networks (ASN) nightly

—

Exploit attempts / day

Top CVEs · by attempts

CVEs / exploits observed

ranked by attempts in the selected window · click to open
CVEExploit attemptsIP-days
Loading…
CVE-2026-46817 Actively exploited
Oracle E-Business Suite · improper privilege management · CWE-269 · CVSS 9.8
First seen · honeynet
2026-07-15
Last seen
2 min ago
Exploit attempts
1,306
CVSS
9.8
CWE
—
KEV added
—

Exploit attempts — per day · last 30 days

Attacking IPs

Exploit attempts

Captured request payloads are not surfaced here yet.
Exploit signatures for this CVE appear on the honeypot dossiers (webpot, fortinet).

Vulnerability

CVE
—
Vendor
—
Product
—
CWE
—
CVSS
—

References

CISA KEV
—
NVD
—
CVE metadata (vendor/product/CWE/CVSS/KEV) from CISA KEV + NVD enrichment.

Events / day

Top techniques

Attack signatures / techniques

ranked by events in the selected window
SignatureEventsIP-days
Loading…