← Back to feeds
IOCFREE Searchable

Honeypot infrastructure watch

A community-maintained watchlist of IP infrastructure observed through honeypot telemetry. Historical observations include original tags, hit counts, and first/last-seen dates.

488,541
Indicators
IOC
Feed type
9/21/2026
Latest indicator
Open
Access
honeypothistorical
Free

This community feed is publicly available for research.

Open this feed in app
Publisher
UQC4BL9h…w4tDk7
@hookgab

IOC feed · 488,541 indicators

Community
View researchers
Wallet-based publisher identity

Latest indicators

Live indicator delivery for this feed.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 23. Country: France.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 62864. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 27 times. Targeted ports: 445. Country: Russia. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 5 times. Targeted ports: 26383. Country: Hong Kong.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 65 times. Targeted ports: 10002. Country: United States.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 16 times. Targeted ports: 53. Country: Belgium.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 4434. Country: United States.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 6 times. Targeted ports: 53. Country: Belgium.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 51088. Country: Philippines.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 35616. Country: Brazil.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 6107. Country: United States.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 443. Country: United Kingdom.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 17 times. Targeted ports: 445, 1433. Country: Indonesia. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 3 times. Targeted ports: 1433. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 14 times. Targeted ports: 8443. Country: United States. Reputation: known attacker.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 10 times. Targeted ports: 53. Country: Belgium.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 23. Country: Ukraine.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 5 times. Targeted ports: 60023. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 60023. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 60023. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 9 times. Targeted ports: 60023. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 60023. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 16 times. Targeted ports: 1723. Country: The Netherlands.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 5 times. Targeted ports: 60023. Country: China.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 28175. Country: Brazil.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 28 times. Targeted ports: 445. Country: Vietnam. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 293 times. Targeted ports: 389. Country: Belgium. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction, SURICATA Applayer Mismatch protocol both directions, SURICATA TLS invalid record type. Usernames: cn=mndpepwndyasqcawikdr, cn=sojofiznaclewvbbzazu.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 13 times. Targeted ports: 2375. Country: United States.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 3 times. Targeted ports: 427. Country: United States.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 3 times. Targeted ports: 993. Country: United Kingdom.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 5985. Country: Pakistan. Reputation: known attacker.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 6 times. Targeted ports: 23. Country: United States.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 5985. Country: Pakistan.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 34551. Country: Brazil.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 36292. Country: Brazil.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 14 times. Targeted ports: 445. Country: India. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 28 times. Targeted ports: 7777. Country: United States.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 14 times. Targeted ports: 23. Country: Egypt.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 30 times. Targeted ports: 4000. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 6 times. Targeted ports: 23. Country: Russia.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 9110. Country: Brazil. Reputation: known attacker.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 5 times. Targeted ports: 23. Country: China. Reputation: known attacker.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 13 times. Targeted ports: 5985. Country: South Korea. Reputation: known attacker. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with broken ack.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 10 times. Targeted ports: 9230. Country: France.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 21 times. Targeted ports: 1337. Country: United States.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 27 times. Targeted ports: 8888. Country: United States.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 22 times. Targeted ports: 11742. Country: United States. Reputation: known attacker.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 3 times. Targeted ports: 1433. Country: United States. Reputation: known attacker.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 183 times. Targeted ports: 80, 1024, 7000, 7777. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction, SURICATA HTTP request missing protocol.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 23 times. Targeted ports: 5601. Country: United States.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 23. Country: Myanmar.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 27 times. Targeted ports: 5173. Country: United States.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 21938. Country: Brazil. Reputation: known attacker.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 9 times. Targeted ports: 26337, 26373. Country: Hong Kong. Reputation: known attacker.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 27 times. Targeted ports: 6000. Country: United States.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 59632. Country: Uzbekistan.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 9009. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 9009. Country: China. Reputation: known attacker.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 9009. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 6 times. Targeted ports: 9009. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 10 times. Targeted ports: 9009. Country: China.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 17318. Country: Brazil.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 32306. Country: Brazil.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 23 times. Targeted ports: 445. Country: Mexico. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 40443. Country: United States.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 3389. Country: United States.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 23. Country: Uzbekistan.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 14 times. Targeted ports: 445. Country: Nepal. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 9 times. Targeted ports: 445. Country: Nepal. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 44734. Country: Mexico.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 193 times. Targeted ports: 23. Country: Pakistan.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 32 times. Targeted ports: 80, 443. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 3 times. Targeted ports: 119. Country: United States. Reputation: known attacker.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 4365. Country: Uruguay.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 9 times. Targeted ports: 3120. Country: Poland.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 26370. Country: Seychelles. Reputation: known attacker.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 9 times. Targeted ports: 8545. Country: The Netherlands.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 9 times. Targeted ports: 2947. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 2947. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 10 times. Targeted ports: 2947. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 2947. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 19 times. Targeted ports: 445. Country: Vietnam.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 6 times. Targeted ports: 2947. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 8545. Country: Canada.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Country: United States.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 10 times. Targeted ports: 8545. Country: Canada.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 9 times. Targeted ports: 9231. Country: Germany.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 24 times. Targeted ports: 445. Country: India. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 542 times. Targeted ports: 23. Country: Belgium. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Mismatch protocol both directions. Usernames: ;  � admin.$cmd �� hello �? .

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 5 times. Targeted ports: 22. Country: United Kingdom.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 187 times. Targeted ports: 23. Country: China.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 443. Country: United Kingdom.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 17 times. Targeted ports: 445, 1433. Country: Egypt. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 28 times. Targeted ports: 445. Country: Russia. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 5 times. Targeted ports: 26369. Country: Seychelles. Reputation: known attacker.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 111. Country: United States.

Last observed Jul 28, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 30003. Country: Brazil.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 26 times. Targeted ports: 4782. Country: India.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 6 times. Targeted ports: 16020. Country: United Kingdom.

Last observed Jul 28, 2026First observed Jul 28, 2026Source: tpot-honeypot

Observed 6 times. Targeted ports: 16020. Country: United Kingdom.