TECH Signal 346
Harvesting SSH Credentials: Insights from My Honeypot Network
The volume of automated login attempts demonstrates that any SSH server exposed on Port 22/TCP will be continuously targeted with brute-force credential attacks. Engineers should note the disproportionate attack volume originating from European IPs, particularly the Netherlands, which suggests heavily abused infrastructure in that region.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
The honeypot network captured 1,531,053 total login attempts using 131,922 unique credential pairs over a 30-day period.
While Asia accounted for 60.1% of unique attacking IPs, Europe generated 60.2% of total login attempts, with the Netherlands alone responsible for 44.8% of all attempts.
Major cloud and hosting providers Microsoft Corporation, CHINANET BACKBONE, and DigitalOcean, LLC represented the top ASNs by unique attacking IPs.
THE CLUSTER