ELSEIF
Your brief EB
183 stories from 71 feeds 32 clusters Refreshed 9 minutes ago next pull 13:20

TECH Signal 346

Harvesting SSH Credentials: Insights from My Honeypot Network

WHY IT MATTERS

The volume of automated login attempts demonstrates that any SSH server exposed on Port 22/TCP will be continuously targeted with brute-force credential attacks. Engineers should note the disproportionate attack volume originating from European IPs, particularly the Netherlands, which suggests heavily abused infrastructure in that region.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

The honeypot network captured 1,531,053 total login attempts using 131,922 unique credential pairs over a 30-day period.

02

While Asia accounted for 60.1% of unique attacking IPs, Europe generated 60.2% of total login attempts, with the Netherlands alone responsible for 44.8% of all attempts.

03

Major cloud and hosting providers Microsoft Corporation, CHINANET BACKBONE, and DigitalOcean, LLC represented the top ASNs by unique attacking IPs.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Hacker News Harvesting SSH Credentials: Insights from My Honeypot Network Open ↗