SSH Honeypot Results

August 21 2026 - 2 Minutes - Source
- -

Hello everybody! Back in 2024 I ran a a Cowrie SSH honeypot.

I routed any traffic requesting port 22 on my public IP to the server running Cowrie, and collected data for about a month!

It has been a while, but I have finally processed all of the data I have collected, and have been able to gather some interesting insights into SSH-bot traffic!

(at least from one ip on port 22 from 11/5/2024 to 12/8/2024, I assume that this has changed in these two years, and I may run this experiment again one day.)

The data

The durations of the connections follow these patterns:

Using the IP-API.com API, I located the source IPs of each connection, and graphed it here:

A graph of countries, showing that most connections came from China, India, and the United States

Here are the most common usernames used while attempting to login, these all are failed logins, as Cowrie was configured to allow any password with the username "root".

A graph of usernames, showing the most used usernames from the bots.

I do not understand where 345gs5662d34 came from, and why its such a common attempted username, the others make sense, as they are the names of common defaults or services.
If anyone does know what it means, please do get in contact, as I am curious.

These are the most common passwords used, during failed logins, I failed to collect the ones for successful logins.

A graph of passwords, showing the most used passwords from the bots.

123456 and password being so high on the list does make sense, but the same string as earlier, 345gs5662d34 appeared again, making me wonder if this is some kind of hash or something being used by the bot, or if it is some kind of default password common in some IoT/Infrastructure device. I am also somewhat surprised the sheer amount of passwords tried that follow the pattern of text@123.

Conclusion

Thank you for reading, I apologize for another short blog post, but I have been busy preparing for university. I am starting university at the end of this month, but next month's blog post will hopefully be longer than these last few.