Honeypot infrastructure watch
A community-maintained watchlist of IP infrastructure observed through honeypot telemetry. Historical observations include original tags, hit counts, and first/last-seen dates.
IOC feed · 488,541 indicators
Latest indicators
Live indicator delivery for this feed.
Observed 6 times. Targeted ports: 1723. Country: United States.
Observed 3 times. Targeted ports: 23. Country: Indonesia.
Observed 1 times. Targeted ports: 65360. Country: Brazil.
Observed 1 times. Targeted ports: 20939. Country: Mexico.
Observed 15 times. Targeted ports: 1025, 8161. Country: China.
Observed 1 times. Targeted ports: 4231. Country: Ecuador.
Observed 8 times. Targeted ports: 22222. Country: China. Reputation: known attacker.
Observed 1 times. Targeted ports: 5770. Country: South Africa.
Observed 1 times. Targeted ports: 22061. Country: Brazil.
Observed 2 times. Targeted ports: 44298, 63872. Country: Mexico.
Observed 25 times. Targeted ports: 52869. Country: United States. Reputation: known attacker. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA HTTP Unexpected Request body.
Observed 4 times. Targeted ports: 3389. Country: Singapore.
Observed 5 times. Targeted ports: 8443. Country: United States.
Observed 1 times. Targeted ports: 14995.
Observed 20 times. Targeted ports: 22. Country: China. Reputation: known attacker. Alert categories: Misc activity. Signatures: ET INFO SSH session in progress on Expected Port.
Observed 132 times. Targeted ports: 22, 226, 2222, 5122, 5322, 7022. Country: Bolivia. Alert categories: Misc activity. Signatures: ET INFO SSH session in progress on Expected Port, ET INFO SSH session in progress on Unusual Port. Usernames: git, guest.
Observed 6 times. Targeted ports: 23. Country: Ukraine.
Observed 1 times. Targeted ports: 8080. Country: United States. Reputation: known attacker.
Observed 1 times. Targeted ports: 10836. Country: Ireland.
Observed 19 times. Targeted ports: 22. Country: Germany. Reputation: known attacker. Alert categories: Misc activity. Signatures: ET INFO SSH session in progress on Expected Port. Usernames: kb, root.
Observed 9 times. Targeted ports: 1717. Country: China.
Observed 1 times. Targeted ports: 5147. Country: Spain.
Observed 6 times. Targeted ports: 5905. Country: Singapore.
Observed 9 times. Targeted ports: 1717. Country: China. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM spurious retransmission.
Observed 6 times. Targeted ports: 1717. Country: China.
Observed 6 times. Targeted ports: 23. Country: Bonaire, Sint Eustatius and Saba.
Observed 1 times. Targeted ports: 46623. Country: Brazil.
Observed 1 times. Targeted ports: 60425. Country: France.
Observed 1 times. Targeted ports: 46364. Country: Brazil.
Observed 33 times. Targeted ports: 10080. Country: France. Reputation: known attacker.
Observed 1 times. Targeted ports: 57017. Country: Brazil.
Observed 5 times. Targeted ports: 3354. Country: United States. Reputation: known attacker.
Observed 1 times. Targeted ports: 6300. Country: Brazil.
Observed 3 times. Targeted ports: 8080. Country: China.
Observed 6 times. Targeted ports: 23. Country: Azerbaijan.
Observed 1 times. Targeted ports: 31944. Country: Brazil.
Observed 1 times. Targeted ports: 2389. Country: Brazil. Reputation: known attacker.
Observed 7 times. Targeted ports: 5005. Country: China.
Observed 5 times. Targeted ports: 21. Country: Germany.
Observed 11 times. Targeted ports: 80. Country: Singapore.
Observed 62 times. Targeted ports: 8015. Country: United States.
Observed 1 times. Targeted ports: 39688. Country: Brazil.
Observed 1 times. Targeted ports: 23290. Country: Venezuela.
Observed 2 times. Targeted ports: 6881, 11211. Country: Hong Kong. Reputation: known attacker.
Observed 110 times. Targeted ports: 29092. Country: United States. Reputation: known attacker.
Observed 1 times. Targeted ports: 31269. Country: France.
Observed 163 times. Targeted ports: 23. Country: The Netherlands.
Observed 1 times. Targeted ports: 48170. Country: United States.
Observed 7 times. Targeted ports: 9200. Country: China.
Observed 11 times. Targeted ports: 9200. Country: China.
Observed 6 times. Targeted ports: 9200. Country: China.
Observed 9 times. Targeted ports: 9200. Country: China. Reputation: known attacker.
Observed 8 times. Targeted ports: 9200. Country: China.
Observed 6 times. Targeted ports: 9200. Country: China.
Observed 9 times. Targeted ports: 9200. Country: China.
Observed 1 times. Targeted ports: 36216. Country: Colombia. Reputation: known attacker.
Observed 1 times. Targeted ports: 54073. Country: Brazil.
Observed 22 times. Targeted ports: 8291. Country: United States.
Observed 1 times. Targeted ports: 443. Country: United States. Reputation: known attacker.
Observed 1 times. Targeted ports: 23034. Country: Spain.
Observed 1 times. Targeted ports: 33214. Country: Colombia. Reputation: known attacker.
Observed 2 times. Targeted ports: 40935, 60920. Country: Brazil.
Observed 13 times. Targeted ports: 80. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA HTTP Request excessive header repetition.
Observed 2 times. Targeted ports: 53973, 63496. Country: Brazil.
Observed 3 times. Targeted ports: 587. Country: United States.
Observed 1 times. Targeted ports: 53923. Country: Spain.
Observed 1 times. Targeted ports: 30419. Country: Brazil.
Observed 1 times. Targeted ports: 2043. Country: Brazil.
Observed 2 times. Targeted ports: 12235. Country: Brazil.
Observed 1 times. Targeted ports: 3867. Country: United States.
Observed 1 times. Targeted ports: 3768. Country: Brazil.
Observed 12 times. Targeted ports: 3389. Country: United States. Reputation: known attacker. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Mismatch protocol both directions, SURICATA TLS invalid record type.
Observed 1 times. Targeted ports: 443. Country: India.
Observed 31 times. Targeted ports: 9090. Country: Singapore. Reputation: known attacker.
Observed 1 times. Targeted ports: 42774. Country: Indonesia.
Observed 1 times. Targeted ports: 23498. Country: Italy.
Observed 1 times. Targeted ports: 41252. Country: United States.
Observed 24 times. Targeted ports: 445. Country: Türkiye. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 1 times. Targeted ports: 27687. Country: Ukraine.
Observed 6 times. Targeted ports: 23. Country: Ukraine.
Observed 1 times. Targeted ports: 27633. Country: China.
Observed 1 times. Targeted ports: 60480. Country: Vietnam.
Observed 7 times. Targeted ports: 22222. Country: China. Reputation: known attacker.
Observed 87 times. Targeted ports: 5060. Country: Poland.
Observed 1 times. Targeted ports: 49569. Country: Argentina.
Observed 9 times. Targeted ports: 5433, 9306. Country: Poland.
Observed 108 times. Targeted ports: 8500. Country: Germany.
Observed 8 times. Targeted ports: 18017. Country: China.
Observed 1 times. Targeted ports: 54539. Country: Brazil.
Observed 9 times. Targeted ports: 18017. Country: China.
Observed 7 times. Targeted ports: 18017. Country: China.
Observed 8 times. Targeted ports: 18017. Country: China.
Observed 6 times. Targeted ports: 18017. Country: China.
Observed 10 times. Targeted ports: 8545. Country: The Netherlands.
Observed 1 times. Targeted ports: 8151. Country: Colombia.
Observed 3 times. Targeted ports: 5060. Country: United States. Reputation: known attacker.
Observed 1 times. Targeted ports: 27015. Country: American Samoa.
Observed 1 times. Targeted ports: 39396. Country: Brazil.
Observed 5 times. Targeted ports: 8081. Country: United States. Reputation: mass scanner.
Observed 2 times. Targeted ports: 17100, 25957. Country: Canada.