Live Cowrie honeypot Β· Collecting since March 21, 2026
β οΈ This is real attack data captured by a Cowrie SSH honeypot deployed on production infrastructure.
Every IP, credential, command, and malware hash shown here is from actual attacks against this network.
The honeypot is one layer in a multi-tier defense system β attackers see a fake server while real services remain untouched.
Live All data below auto-refreshes from the honeypot every 15 minutes
April 15, 2026 Β· 15:14 UTC 43.99.20.50 β Alibaba Cloud, Hong Kong SSH-2.0-makiko (Rust)
makiko Rust SSH library β an automated botnet scanner, not a human./dev/tcp builtin β bypasses wget/curl detection. Executes with encrypted base64 C2 config.
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β INTERNET (The Wild West) β
ββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββ
β
ββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββ
β LAYER 1: MikroTik CCR1009 Hardware Firewall β
β βββ RAW prerouting: IPs dropped pre-conntrack β
β βββ Filter: 67 rules, SYN flood protection, port scan detect β
β βββ CrowdSec bouncer: real-time ban sync via API β
β βββ NAT: SSH port β Cowrie honeypot (port 2222) β
ββββββββββββββββ¬βββββββββββββββββββββββββββ¬βββββββββββββββββββββββ
β β
Real Services Fake SSH (Honeypot)
β β
ββββββββββββββββΌβββββββββββββββ ββββββββββΌββββββββββββββββββββββ
β LAYER 2: Traefik Proxy β β π― Cowrie SSH Honeypot β
β βββ TLS termination β β βββ Fake filesystem β
β βββ Rate limiting β β βββ Credential capture β
β βββ Security headers β β βββ Command logging β
β βββ Request logging β CS β β βββ Malware capture β
ββββββββββββββββ¬βββββββββββββββ β βββ Telegram alerts β
β ββββββββββββββββββββββββββββββββ
ββββββββββββββββΌβββββββββββββββ
β LAYER 3: CrowdSec Engine β
β βββ Behavioral analysis β
β βββ Community blocklist β
β βββ Threat intel feeds β
β βββ Auto-ban β MikroTik β
ββββββββββββββββ¬βββββββββββββββ
β
ββββββββββββββββΌβββββββββββββββ
β LAYER 4: Authelia SSO β
β βββ Multi-factor auth β
β βββ WebAuthn/FIDO2 keys β
β βββ Per-service ACLs β
β βββ Session management β
βββββββββββββββββββββββββββββββ
In β days, β unique attackers from around the world attempted β logins with β unique passwords.
They deployed β different malware binaries and ran β post-exploitation commands. All of this was captured, analyzed, and neutralized β automatically.
The honeypot sees what gets past the firewall's SSH redirect. Meanwhile, CrowdSec handles HTTP attacks, and MikroTik drops β known-bad IPs at the hardware level before they even reach the server.
Every layer works independently. If one fails, the others still protect. Nothing reaches the real services.