Skip to content

Build1 publisher3 min readPublished

Scan logs from a $6 Frankfurt honeypot name a different top port under each count

One $6 Frankfurt server received its first unsolicited packet 3.77 seconds after its listener opened, according to a write-up on dev.to. Ranked by events, addresses or networks, the same log puts a different port at the top each time.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Scan logs from a $6 Frankfurt honeypot name a different top port under each count
Generated illustration

What happened

  • Over 75 minutes the collector logged 1,212 events from 84 addresses across 15 ports.
  • The first HTTP request arrived 4 minutes 36 seconds in and asked for /.env, the file where people keep database passwords and API keys.
  • SMB drew 890 events, 73% of the total, but all of that traffic came from two hosts, one of them never stopping.
  • Counted by distinct addresses, Postgres led with 31, all owned by one UK company, Driftnet Ltd, whose connections touched port 5432 and nothing else.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision Any lockdown applied by hand after first login lands minutes after scanners have asked the box for its secrets file, so it has to ship in the image or in cloud-init.
  • constraint Port rankings from different scan reports cannot be compared unless each states its counting unit, because one operator's address pool or one host's loop can set the order.
  • cost Filtering by user agent is cheap but only removes scanners that announce themselves; the 108 requests with no user agent still need another way to be classified.

The listener opened 99 seconds after the droplet was created at 18:18:36 UTC [7], so the first logged probe arrived about 103 seconds into the machine's life [1]. It was a TLS ClientHello aimed at port 8443 from a host in a Linode range [2]. Nothing was logging during those first 99 seconds, so the address may have been probed earlier [7].

The sensor is well built. Cloud-init moves the real sshd to port 62222, then starts a single asyncio program that holds port 22 and 25 others [4]. The program never authenticates anyone or executes anything. It sends a protocol-appropriate banner, reads what the client says, writes one JSON line and hangs up [5]. There is nothing behind the banners to pivot through, and the author's own SSH port is left out of every count [6]. Eleven of the 26 listening ports logged no events in the window [2].

Credential attempts used the obvious names. The first password guess came at 8 minutes 27 seconds, over telnet, with the username admin; across the window root was tried five times and admin four [9]. Every SSH client identified itself as SSH-2.0-Go, with no OpenSSH, libssh or Paramiko among them [16]. SSH scanners in this window agreed on a language, if on nothing else. Moving sshd off port 22, the one hardening step in this build, ran in cloud-init before any listener was up [4].

Both misleading rankings measured one sender's setup: a loop that never stopped, or a pool of addresses [c10, c11]. Set SMB aside and 322 events remain across every other port combined [6]. Driftnet's pool accounts for 37% of the 84 addresses the box saw [3], at under 1.4 connections per address [4]. "Any chart built on event counts is a chart of who has the loudest loop," the author wrote [21]. Grouped by distinct network, HTTPS leads with 13, HTTP has 7 and SSH has 6 [12]. "The unit you pick decides the finding," the author wrote [13].

That surviving order is thin. HTTP sits one network ahead of SSH [5], and the whole sample is 31 networks in 16 countries [19], from one Frankfurt droplet in a single short window [c3, c4]. For the 3.77-second figure or the port order to describe another host, that host would need to sit in a range scanned as heavily as this one, at a similar hour. The write-up measured one address, once [1].

The HTTP paths show what the scanners wanted. CONNECT icanhazip.com:443 arrived 53 times from 4 addresses, open-proxy hunting that outnumbered every real URL on the box, according to the author [14]. Requests for /.env came 16 times, and /SDK/webLanguage probed for a specific brand of IP camera [15]. Three visitors named themselves in the user agent: Censys, zgrab and Palo Alto Networks, the last with a link to a page explaining its scans [17]. The author wrote that "a decent share of background radiation is research rather than attack, and the good citizens make themselves trivially easy to filter out" [20].

What to watch

  • Repeat runs on other providers, regions and hours: if time-to-first-probe stays in seconds outside this Frankfurt range, the case for locking hosts down before they boot applies broadly.
  • A multi-day run from the same sensor would show whether web ports keep their lead once more networks appear in the data.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories