Home › Guides › Where Bot Traffic Comes From
✓ data: two open honeypot datasets published by CSIRT-UPJS (Pavol Jozef Šafárik University in Košice), CC BY 4.0, downloaded 2 October 2026 · method · caveats · download the data
Which countries does automated attack traffic come from? Honeypots are decoy servers that exist only to be attacked, so almost everything that reaches them is bots: scanners, password-guessers and malware spreading itself. We analysed two openly licensed datasets from one university security team’s honeypots. Between them they cover 26.5 million recorded attacks across 329 days, from November 2024 to December 2025.
Read this first. This is what one honeypot network saw, not a global ranking. The published files name only the top 10 source countries in each period. A handful of IP addresses can move a country up or down, and a country is where an IP address is registered, not where the person controlling it is. We did not use our own site’s traffic: Cloudflare has only just started logging it, so there is less than a day of data, and much of it is our own tools.
attacks recorded 26.5 milliontop source, Jul–Dec 2025 United States, 13.1%top source, Nov 2024–Apr 2025 Taiwan, 23.7%countries in both top 10s 7
Headline numbers
- Tens of thousands of attacks a day. The honeypots logged 14,768,895 attacks from 4 Nov 2024 to 3 Apr 2025 (97,807 a day) and 11,739,398 from 7 Jul 2025 to 31 Dec 2025 (65,952 a day).
- The top 10 countries account for about two-thirds of attacks. The ten named countries sent 67.1% of all attacks in the first period and 63.7% in the second. The datasets don’t break down the rest.
- The United States moved to the top. US addresses sent 13.1% of all attacks in July–December 2025, more than any other country, up from 7.9% (fourth place) in November 2024–April 2025. They were also among the steadiest: US attacks were recorded on all 178 days, and the five busiest days made up only 5.6% of the total.
- Rankings change a lot from one period to the next. Taiwan was the biggest source in the first period (23.7% of all attacks) and wasn’t in the top 10 in the second. The Netherlands wasn’t in the first top 10 and came second in the later one (11.2%). 7 countries made both lists: China, France, Germany, India, Indonesia, Russia and the United States.
- Some countries’ totals come from a few bursts. 85.1% of attacks from French addresses in the second period arrived on just five days. The busiest, 29 Nov 2025, brought 338,079. Germany (58.6% in the first period) and Vietnam (45.9% in the second) show the same pattern. Taiwan’s first-period lead was steadier: its five busiest days made up 12.0% of its total.
- A small number of sources does most of the work. In a typical half hour the honeypots saw a median of 38 distinct IP addresses in the first period and 36 in the second, generating a median of 1,549.5 and 898.5 attacks. That is dozens of attacks per address.
- Most attacks target remote logins. The SSH/Telnet honeypot (Cowrie) took 74.8% of attacks in the first period and 63.8% in the second. Dionaea, which imitates file-sharing, database and other services that malware targets, took 15.1% and 21.8%.
Share of attacks by source country
November 2024 – April 2025
| # | Country | Attacks | Share of all attacks | Days with attacks | Share on 5 busiest days | Busiest day (attacks) |
|---|---|---|---|---|---|---|
| 1 | Taiwan | 3,504,450 | 23.7% | 126 | 12.0% | 22 Feb 2025 (93,407) |
| 2 | France | 1,260,667 | 8.5% | 147 | 54.7% | 12 Feb 2025 (193,595) |
| 3 | China | 1,174,484 | 8.0% | 151 | 14.0% | 10 Nov 2024 (64,213) |
| 4 | United States | 1,163,085 | 7.9% | 151 | 26.3% | 15 Jan 2025 (111,305) |
| 5 | India | 682,237 | 4.6% | 151 | 19.9% | 19 Dec 2024 (59,889) |
| 6 | Germany | 508,930 | 3.4% | 137 | 58.6% | 10 Nov 2024 (250,217) |
| 7 | Russia | 476,393 | 3.2% | 146 | 10.6% | 14 Dec 2024 (13,782) |
| 8 | South Korea | 402,975 | 2.7% | 146 | 22.6% | 21 Feb 2025 (24,492) |
| 9 | Estonia | 378,106 | 2.6% | 69 | 19.0% | 27 Jan 2025 (19,063) |
| 10 | Indonesia | 357,563 | 2.4% | 150 | 11.3% | 15 Feb 2025 (12,160) |
July – December 2025
| # | Country | Attacks | Share of all attacks | Days with attacks | Share on 5 busiest days | Busiest day (attacks) |
|---|---|---|---|---|---|---|
| 1 | United States | 1,532,402 | 13.1% | 178 | 5.6% | 23 Nov 2025 (19,009) |
| 2 | Netherlands | 1,313,752 | 11.2% | 177 | 12.2% | 23 Nov 2025 (52,209) |
| 3 | France | 1,160,298 | 9.9% | 134 | 85.1% | 29 Nov 2025 (338,079) |
| 4 | China | 758,055 | 6.5% | 178 | 12.8% | 14 Sep 2025 (40,055) |
| 5 | Russia | 579,038 | 4.9% | 176 | 16.3% | 16 Aug 2025 (21,459) |
| 6 | Indonesia | 472,175 | 4.0% | 176 | 9.0% | 25 Sep 2025 (10,044) |
| 7 | Singapore | 429,419 | 3.7% | 159 | 18.4% | 30 Nov 2025 (34,369) |
| 8 | Vietnam | 423,002 | 3.6% | 168 | 45.9% | 26 Oct 2025 (131,570) |
| 9 | India | 417,375 | 3.6% | 175 | 13.7% | 31 Aug 2025 (20,771) |
| 10 | Germany | 391,570 | 3.3% | 173 | 25.4% | 7 Jul 2025 (51,244) |
Month by month
Steady sources and bursts
Method
- Source. “Attacks on Honeypots (October 2024 – April 2025)” (DOI 10.17632/j9zm8nj76j.1) and “Attacks on Honeypots (June 2025 – January 2026)” (DOI 10.17632/y2vvn22zkx.1), published on Mendeley Data by Vanda Matušíková (CSIRT-UPJS, Pavol Jozef Šafárik University in Košice) and licensed CC BY 4.0. We downloaded all eight CSV files on 2 October 2026 and checked each one against the SHA-256 hash Mendeley publishes.
- Coverage. Despite their titles, the files run from 4 Nov 2024 to 3 Apr 2025 and from 7 Jul 2025 to 31 Dec 2025 (UTC), in half-hour intervals. The second dataset has 3 gaps longer than six hours, the longest in mid-July 2025.
- Totals. “Attacks” is the dataset’s own count of attack events, summed over every half hour. Country totals come from the source-country file. Shares are a country’s attacks divided by all attacks in the overall attack-count file for the same period.
- Bursts. For each country and period we added up attacks per UTC day and took the share that fell on its five busiest days.
- Not used. The port files measure something different from the attack counts (their totals don’t match), so we leave them out. We checked other sources first. AbuseIPDB’s and GreyNoise’s terms don’t allow republishing their data on a commercial site. SANS ISC/DShield licenses its API data CC BY-NC-SA 4.0 (non-commercial), and its feeds page states different terms, so we would need written permission to use it here. We didn’t use Cloudflare Radar.
- Verification. A separate script re-reads the raw CSV files and recomputes every number on this page and in our CSVs.
Caveats
- One network’s view. The datasets come from one team’s honeypots and don’t say how many sensors there were or where they were hosted. Bots don’t scan everywhere evenly, so another network would see a different mix.
- Top 10 only. About a third of attacks in each period come from countries the files don’t name. A country missing from a list may simply have been 11th.
- A country is where an address is registered, not who controls it. Attackers rent cloud servers, use hijacked devices and route through proxies, so an attack from a country’s address space says little about who is behind it. Countries with big hosting industries, such as the US, the Netherlands, Germany and Singapore, may rank high partly for that reason. The dataset doesn’t say how locations were assigned.
- A few addresses can dominate. With a few dozen distinct IP addresses in a typical half hour, one busy address can move a country’s rank. That is why we show the burst measure.
- Honeypot attacks aren’t website traffic. These are mostly login attempts and exploit probes against network services, not scrapers or crawlers visiting websites. They show where automated attack traffic comes from, not where web-scraping traffic comes from.
- Dated. The newest data ends on 31 December 2025.
Download the data
- By country and period (CSV): attacks, share of all attacks, share of the top 10, days with attacks, share on the five busiest days and the busiest day, for each top-10 country.
- Monthly (CSV): attacks by source country and UTC month.
Cite as: ProxyPicker, “Where Bot Traffic Comes From: What One Honeypot Network Saw”, 2 October 2026, https://proxypicker.com/where-bot-traffic-comes-from/. Data: Matušíková, V., “Attacks on Honeypots (October 2024 – April 2025)”, Mendeley Data, V1, doi:10.17632/j9zm8nj76j.1, and “Attacks on Honeypots (June 2025 – January 2026)”, Mendeley Data, V1, doi:10.17632/y2vvn22zkx.1, both licensed CC BY 4.0. We aggregated the data (country, daily and monthly totals); the original files are unchanged on Mendeley.
Related: Residential IP Supply by Country · Residential proxy botnet timeline · Anti-Bot Census · AI Crawler Census · What’s my IP? Proxy & VPN checker.
Press & data requests: email [email protected] for interviews, the raw data behind this page, or corrections. See also our contact page.