MIRE ∩ TOCE · Dec 2025 – Jul 2026

Two honeypots.
One guest book.

MIRE catches whoever probes the website. TOCE catches whoever knocks on raw ports. For seven months they kept separate lists — then we joined them, and almost nobody was on both.

91,602 MIRE · web 100,836 TOCE · ports 1,405 the sliver both honeypots know by name
0IPs attacked the web tarpit
0IPs hit the canary ports
0did both — 1.5% of either world

Two populations of a hundred thousand attackers each, almost perfectly disjoint. The intersection is where the operators live — and this is their story.

Act I — The Tide

Port scans are the weather forecast for web attacks.

Of the 1,405 shared visitors, 70% found the canary before the website — 757 of them by more than a month. The tide comes in on raw ports first; the webshells follow.

How hard did they try? — engagement across both honeypots

interested · under 100 everywhere
739
drive-by · ≤5 web, ≤10 canary
412
web-heavy · 100+ MIRE only
103
canary-heavy · 100+ TOCE only
101
mentalist · 100+ on both
50

Together they logged 154,392 web requests and 287,033 canary events. But the whole story lives in the bottom row: fifty mentalists — IPs that invested a hundred-plus hits on each front.

Interlude — The Census

A third of the intersection isn't attacking anyone.

453 of the shared IPs are the internet's census-takers — research scanners that visit everything, so of course they visited both. But the league table isn't what you'd guess.

InternetMeasurement
220
Palo Alto Expanse
199
CensysInspect
34

driftnet.io's InternetMeasurement and Palo Alto's Expanse own the intersection between them. Censys — the famous name — barely registers. Strip all 453 out, and what remains is genuinely hostile.

Act II — The Campaign

159 cloaked attackers.
One operator.

Strip the census and the drive-bys, and most of the serious residue is one repeating shape: an IP whose entire canary footprint is VNC on port 5901, arriving cloaked — VPN exit nodes rented from M247, DataCamp and friends — and probing the website on the side.

The cloaks, by tailor — VPN egress families

146.70.x · M247
27
45.149.x
12
85.204.x
11
185.193.x
10
169.150.x · DataCamp
9
143.244.x · DataCamp
9
+ 8 more families
81

The classic substrate of consumer VPN services. Fourteen prefix families, one behaviour.

The fingerprint

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36

A browser build from 2019, presented in 2026 — by 86 of 159 cloaks. Another 33 send a blank user agent. Three quarters of the wardrobe, two signatures, one toolkit.

VNC · 5901 only 13,634 web hits 43,593 canary events 26 cloaks still in use

Act II — The Reversal

This one cases the website first.

The general population scans ports, then tries the web — 70% TOCE-first. The VNC campaign moves against that tide: two thirds of its cloaks touched MIRE before they ever tried the canary. Web reconnaissance first, credentials second. That inversion is fingerprint-grade behaviour.

30%
of all 1,405 hit the web first
64%
of the VNC cohort hit the web first
45d
average life of a cloak on the web side
56
cloaks burned in under 48 hours
Jul 2026
26 cloaks still in use — this campaign is not history

Act III — The Tell

Dressed as everyone.
Spelled like no one.

MIRE's most obsessive visitor — 62.169.29.85, 15,533 requests in two months — wore 21 different user agents. Twenty were competent forgeries. The twenty-first gave the whole game away:

Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36

Three misspellings, none of them ours. Years ago a bot author hand-mangled a Galaxy S8 user agent into their tool, and that exact broken string has shipped inside exploit kits ever since — nobody proofreads malware. No real Android has ever said Mozlila. The camouflage became the fingerprint.

The tell collapses 21 "browsers" into one scripted client — which makes what happened next legible: on 12 June, still mid-campaign, the same address opened an SSH front on the canary. 238 attempts in 72 hours, then the SSH job ended, and three days later the web traffic stopped too. A rented box, repointed at the end of a contract — and the join watched the handover.

Apr May Jun Jul web · 15,533 requests SSH · 238 in 72h silence

Act III — Careers

Two more operators, two trajectories.

The pair — 81.29.142.6 / .100

Same /24, same eight-port template — including nonstandard 33306, a port only a shared config produces. Overlapping runs through spring, ~350 hits each per front, and both went silent the same day: 7 May. Two boxes, one operator, one kill switch.

The two-front — 77.90.185.12

The heavyweight of the fifty: 24,055 RDP attempts on the canary while methodically working the web tarpit with 1,104 requests. Most attackers pick a trade. This one runs both, simultaneously, from one address.

Epilogue

One sensor logs traffic.
Two sensors resolve operators.

On its own, TOCE saw scattered VNC brute-force sources. On its own, MIRE saw scattered web probes with a stale browser string. Neither could see a campaign. The join could: same cloaks, same toolkit, same rhythm — one actor behind 159 addresses, still running as this page went to press.

Port scans forecast web attacks — by a month.

One operator can wear 159 cloaks. Spelling gives them away.

The interesting adversaries show up on two surfaces.

0

IPs both honeypots know by name — 1.5% of either world, and where all of the story lives.

The OpenCanary Experience →