Honeypot infrastructure watch
A community-maintained watchlist of IP infrastructure observed through honeypot telemetry. Historical observations include original tags, hit counts, and first/last-seen dates.
IOC feed · 488,541 indicators
Latest indicators
Live indicator delivery for this feed.
Observed 8 times. Targeted ports: 9303. Country: China.
Observed 6 times. Targeted ports: 9303. Country: China.
Observed 1 times. Targeted ports: 123. Country: China.
Observed 30 times. Targeted ports: 80. Country: The Netherlands.
Observed 33 times. Targeted ports: 8804. Country: Malaysia.
Observed 24 times. Targeted ports: 8443. Country: United States.
Observed 1 times. Targeted ports: 44171. Country: Poland.
Observed 40 times. Targeted ports: 8443. Country: United States.
Observed 24 times. Targeted ports: 8443. Country: United States.
Observed 34 times. Targeted ports: 8443. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 7 times. Targeted ports: 23. Country: Malaysia.
Observed 24 times. Targeted ports: 445. Country: Vietnam. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 3 times. Targeted ports: 5432. Country: United States. Reputation: known attacker.
Observed 278 times. Targeted ports: 3319. Country: United States.
Observed 1 times. Targeted ports: 58739. Country: Brazil.
Observed 1 times. Targeted ports: 63996. Country: United States.
Observed 1 times. Targeted ports: 6610. Country: China.
Observed 52 times. Targeted ports: 8443. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 7 times. Targeted ports: 23. Country: Taiwan.
Observed 1 times. Targeted ports: 2720. Country: United States.
Observed 13 times. Targeted ports: 23. Country: South Korea.
Observed 24 times. Targeted ports: 445. Country: Türkiye. Alert categories: Generic Protocol Command Decode, Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use, SURICATA STREAM Packet with broken ack.
Observed 14 times. Targeted ports: 80. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA HTTP Request excessive header repetition.
Observed 3 times. Targeted ports: 873. Country: United States.
Observed 341 times. Targeted ports: 22. Country: Algeria. Reputation: known attacker. Alert categories: Misc activity. Signatures: ET INFO SSH session in progress on Expected Port. Usernames: root.
Observed 5 times. Targeted ports: 26000. Country: United States.
Observed 31 times. Targeted ports: 8178. Country: Japan.
Observed 1 times. Targeted ports: 24316. Country: Albania.
Observed 1 times. Targeted ports: 40489. Country: Ecuador. Reputation: known attacker.
Observed 3 times. Targeted ports: 5060. Country: Seychelles. Reputation: known attacker.
Observed 33 times. Targeted ports: 8443. Country: United States.
Observed 25 times. Targeted ports: 8443. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 35 times. Targeted ports: 8443. Country: United States.
Observed 6 times. Targeted ports: 389. Country: United States. Reputation: known attacker.
Observed 52 times. Targeted ports: 8443. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 9 times. Targeted ports: 8080. Country: Hong Kong.
Observed 41 times. Targeted ports: 8443. Country: United States.
Observed 10 times. Targeted ports: 7010. Country: United States.
Observed 5 times. Targeted ports: 27782. Country: China. Reputation: known attacker.
Observed 6 times. Targeted ports: 9999. Country: United States. Reputation: known attacker.
Observed 17 times. Targeted ports: 8443. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 6 times. Targeted ports: 10050. Country: United States.
Observed 58 times. Targeted ports: 10086. Country: United States.
Observed 24 times. Targeted ports: 2087. Country: United States.
Observed 8 times. Targeted ports: 5984. Country: China.
Observed 1 times. Targeted ports: 16581. Country: Italy.
Observed 5 times. Targeted ports: 3389. Country: United States.
Observed 249 times. Targeted ports: 6379. Country: Belgium. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction.
Observed 1 times. Targeted ports: 16598. Country: United States.
Observed 24 times. Targeted ports: 8443. Country: United States.
Observed 3 times. Targeted ports: 5000. Country: United States. Reputation: known attacker.
Observed 52 times. Targeted ports: 8443. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 9 times. Targeted ports: 5984. Country: China. Reputation: known attacker.
Observed 8 times. Targeted ports: 5984. Country: China.
Observed 8 times. Targeted ports: 5984. Country: China.
Observed 7 times. Targeted ports: 5984. Country: China.
Observed 31 times. Targeted ports: 3306. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction.
Observed 9 times. Targeted ports: 5984. Country: China.
Observed 1 times. Targeted ports: 63898. Country: Brazil.
Observed 6 times. Targeted ports: 5984. Country: China.
Observed 1 times. Targeted ports: 59370. Country: Brazil. Reputation: known attacker.
Observed 17 times. Targeted ports: 8443. Country: United States.
Observed 1 times. Targeted ports: 25497. Country: United States.
Observed 1 times. Targeted ports: 40653.
Observed 4 times. Targeted ports: 22. Country: United Kingdom.
Observed 5 times. Targeted ports: 2222. Country: United States.
Observed 3 times. Targeted ports: 88. Country: United States.
Observed 4 times. Targeted ports: 443. Country: United Kingdom.
Observed 119 times. Targeted ports: 23. Country: Pakistan.
Observed 15 times. Targeted ports: 27017. Country: United States.
Observed 8 times. Targeted ports: 23. Country: China.
Observed 7 times. Targeted ports: 23. Country: United Kingdom.
Observed 8 times. Targeted ports: 23. Country: Ukraine.
Observed 1 times. Targeted ports: 41309. Country: Colombia.
Observed 2 times. Targeted ports: 1433. Country: United States.
Observed 29 times. Targeted ports: 14000. Country: United States.
Observed 36 times. Targeted ports: 23. Country: Pakistan.
Observed 6 times. Country: France.
Observed 6 times. Targeted ports: 23. Country: United Kingdom.
Observed 19 times. Targeted ports: 50070. Country: United States. Alert categories: Detection of a Network Scan. Signatures: ET SCAN Zmap User-Agent (Inbound).
Observed 10 times. Targeted ports: 8545. Country: Ukraine.
Observed 5 times. Targeted ports: 53, 443, 1195, 8080, 9201. Country: United States.
Observed 1 times. Targeted ports: 7037. Country: Indonesia.
Observed 29 times. Targeted ports: 8085. Country: United States.
Observed 1 times. Targeted ports: 27015. Country: China. Reputation: known attacker.
Observed 18 times. Targeted ports: 9999. Country: Australia.
Observed 62 times. Targeted ports: 22, 2222. Country: China. Alert categories: Generic Protocol Command Decode, Misc activity. Signatures: ET INFO SSH session in progress on Expected Port, SURICATA Applayer Mismatch protocol both directions, SURICATA HTTP missing Host header. Usernames: root.
Observed 1 times. Targeted ports: 42119. Country: Bolivia. Reputation: known attacker.
Observed 24 times. Targeted ports: 8000. Country: Taiwan. Reputation: known attacker.
Observed 12 times. Targeted ports: 4000. Country: South Korea. Reputation: known attacker. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction.
Observed 3 times. Targeted ports: 8080. Country: Australia.
Observed 1 times. Targeted ports: 15683. Country: France.
Observed 4 times. Targeted ports: 25994. Country: Seychelles. Reputation: known attacker.
Observed 2 times. Targeted ports: 1023. Country: Pakistan.
Observed 278 times. Targeted ports: 6379. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction, SURICATA TLS invalid record type.
Observed 30 times. Targeted ports: 8087. Country: India.
Observed 28 times. Targeted ports: 4782. Country: India.
Observed 5 times. Targeted ports: 25993. Country: Hong Kong.
Observed 2 times. Targeted ports: 1433. Country: Russia.
Observed 22 times. Targeted ports: 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11. Country: Australia.