Honeypot infrastructure watch
A community-maintained watchlist of IP infrastructure observed through honeypot telemetry. Historical observations include original tags, hit counts, and first/last-seen dates.
IOC feed · 488,541 indicators
Latest indicators
Live indicator delivery for this feed.
Observed 1 times. Targeted ports: 62336. Country: United States.
Observed 2 times. Targeted ports: 23. Country: China.
Observed 6 times. Targeted ports: 23. Country: Colombia.
Observed 22 times. Targeted ports: 6036. Country: India.
Observed 3 times. Targeted ports: 23. Country: Belarus.
Observed 1 times. Targeted ports: 3. Country: Brazil.
Observed 6 times. Targeted ports: 23. Country: China.
Observed 15 times. Targeted ports: 445. Country: The Netherlands.
Observed 1 times. Country: United States.
Observed 2 times. Targeted ports: 23. Country: Pakistan.
Observed 1 times. Targeted ports: 20780. Country: Brazil.
Observed 5 times. Targeted ports: 21. Country: Canada.
Observed 1 times. Targeted ports: 6232. Country: France.
Observed 1 times. Targeted ports: 45012. Country: Morocco.
Observed 1 times. Targeted ports: 35190. Country: Nepal.
Observed 28 times. Targeted ports: 445. Country: Cambodia. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 9 times. Targeted ports: 21. Country: United States.
Observed 1 times. Targeted ports: 9398. Country: Brazil.
Observed 1 times. Targeted ports: 50703. Country: Brazil. Reputation: known attacker.
Observed 1 times. Targeted ports: 31724. Country: Brazil.
Observed 1 times. Targeted ports: 61700. Country: Brazil.
Observed 16 times. Targeted ports: 9200. Country: United States. Reputation: known attacker. Alert categories: Detection of a Network Scan. Signatures: ET SCAN Zmap User-Agent (Inbound).
Observed 2 times. Targeted ports: 23. Country: Hong Kong.
Observed 1 times. Targeted ports: 21301. Country: Moldova. Reputation: known attacker.
Observed 3 times. Targeted ports: 23. Country: Costa Rica.
Observed 2 times. Targeted ports: 6379. Country: United States.
Observed 5 times. Targeted ports: 8873. Country: Switzerland.
Observed 6 times. Targeted ports: 8873. Country: Belgium.
Observed 1 times. Targeted ports: 7347. Country: Russia.
Observed 1 times. Targeted ports: 29840. Country: The Netherlands.
Observed 28 times. Targeted ports: 445. Country: Peru. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 1 times. Targeted ports: 7991. Country: Germany.
Observed 8 times. Targeted ports: 2495. Country: China.
Observed 7 times. Targeted ports: 2495. Country: China.
Observed 11 times. Targeted ports: 2495. Country: China.
Observed 7 times. Targeted ports: 2495. Country: China.
Observed 3 times. Targeted ports: 23. Country: Taiwan.
Observed 1 times. Targeted ports: 36995. Country: Brazil.
Observed 28 times. Targeted ports: 8001. Country: Canada.
Observed 1 times. Targeted ports: 38653. Country: Brazil.
Observed 1 times. Targeted ports: 31526. Country: Brazil.
Observed 1 times. Targeted ports: 58163. Country: Brazil.
Observed 2 times. Targeted ports: 42801, 51797. Country: China.
Observed 1 times. Targeted ports: 45855. Country: Brazil.
Observed 3 times. Targeted ports: 119. Country: China.
Observed 3 times. Targeted ports: 23. Country: Uzbekistan.
Observed 131 times. Targeted ports: 8443. Country: United Kingdom. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 178 times. Targeted ports: 8443. Country: Germany. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 1 times. Targeted ports: 36788. Country: United States. Reputation: known attacker.
Observed 183 times. Targeted ports: 8443. Country: United Kingdom. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 182 times. Targeted ports: 8443. Country: Germany. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 1 times. Targeted ports: 28507. Country: Brazil.
Observed 141 times. Targeted ports: 8443. Country: United Kingdom. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 191 times. Targeted ports: 8443. Country: United Kingdom. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 93 times. Targeted ports: 8443. Country: Germany. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 6 times. Targeted ports: 23. Country: Paraguay.
Observed 11 times. Targeted ports: 80.
Observed 1 times. Targeted ports: 2033. Country: Mexico.
Observed 1 times. Targeted ports: 8773. Country: Brazil.
Observed 1 times. Targeted ports: 60679. Country: Mexico.
Observed 1 times. Targeted ports: 123. Country: United States.
Observed 1 times. Targeted ports: 54137. Country: Chile.
Observed 27 times. Targeted ports: 80. Country: The Netherlands.
Observed 14 times. Targeted ports: 4840. Country: The Netherlands.
Observed 1 times. Targeted ports: 16486. Country: Ukraine.
Observed 15 times. Targeted ports: 8945. Country: United States.
Observed 1 times. Targeted ports: 42785. Country: Sweden.
Observed 1 times. Targeted ports: 21250. Country: Brazil.
Observed 1 times. Targeted ports: 26620. Country: Portugal.
Observed 1 times. Targeted ports: 31310. Country: China. Reputation: known attacker.
Observed 1 times. Targeted ports: 57207. Country: Switzerland.
Observed 1 times. Targeted ports: 45589. Country: Colombia.
Observed 2 times. Targeted ports: 57988. Country: United Kingdom. Reputation: known attacker.
Observed 28 times. Targeted ports: 445. Country: Colombia. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 3 times. Targeted ports: 23. Country: Russia.
Observed 1 times. Targeted ports: 36227. Country: Morocco.
Observed 1 times. Targeted ports: 20443.
Observed 2 times. Targeted ports: 23. Country: Egypt.
Observed 27 times. Targeted ports: 445. Country: Egypt. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 5 times. Targeted ports: 80. Country: China.
Observed 1 times. Targeted ports: 24033. Country: Brazil.
Observed 10 times. Targeted ports: 80. Country: Brazil. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM spurious retransmission.
Observed 1 times. Targeted ports: 42591. Country: Brazil.
Observed 8 times. Targeted ports: 5985. Country: Japan.
Observed 1 times. Targeted ports: 59364. Country: Brazil.
Observed 32 times. Targeted ports: 80. Country: Germany.
Observed 5 times. Targeted ports: 5555. Country: Germany.
Observed 2 times. Targeted ports: 1827, 23521. Country: Nepal.
Observed 1 times. Targeted ports: 57860. Country: Brazil. Reputation: known attacker.
Observed 3 times. Targeted ports: 79. Country: United States. Reputation: known attacker.
Observed 5 times. Targeted ports: 17001. Country: Uruguay. Reputation: known attacker.
Observed 1 times. Targeted ports: 28597. Country: Brazil.
Observed 1 times. Targeted ports: 54429. Country: Kenya.
Observed 1 times. Targeted ports: 11939. Country: Spain.
Observed 1 times. Targeted ports: 28603. Country: Portugal.
Observed 12 times. Targeted ports: 25. Country: United States.
Observed 1 times. Targeted ports: 7151. Country: Colombia.
Observed 1 times. Targeted ports: 24808. Country: Brazil.