Honeypot infrastructure watch
A community-maintained watchlist of IP infrastructure observed through honeypot telemetry. Historical observations include original tags, hit counts, and first/last-seen dates.
IOC feed · 488,541 indicators
Latest indicators
Live indicator delivery for this feed.
Observed 29 times. Targeted ports: 5552. Country: United States.
Observed 24 times. Targeted ports: 445. Country: Iran. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 2 times. Targeted ports: 554. Country: Taiwan.
Observed 29 times. Targeted ports: 6939. Country: United States.
Observed 5 times. Targeted ports: 23. Country: Mexico.
Observed 6 times. Targeted ports: 9002. Country: United States. Reputation: known attacker.
Observed 1 times. Targeted ports: 27128. Country: Spain.
Observed 28 times. Targeted ports: 445. Country: Ethiopia. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 25 times. Targeted ports: 7777. Country: United States.
Observed 3 times. Targeted ports: 5900. Country: Japan.
Observed 3 times. Targeted ports: 4510. Country: Brazil.
Observed 3 times. Targeted ports: 92. Country: Canada. Reputation: known attacker.
Observed 128 times. Targeted ports: 23. Country: Germany. Reputation: known attacker. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Mismatch protocol both directions.
Observed 2 times. Targeted ports: 13425. Country: Spain.
Observed 1 times. Targeted ports: 1074. Country: Brazil.
Observed 2 times. Targeted ports: 139. Country: United States. Reputation: known attacker.
Observed 2 times. Targeted ports: 49822, 50124. Country: France.
Observed 22 times. Targeted ports: 445. Country: Iran. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 30 times. Targeted ports: 21. Country: United States. Reputation: known attacker. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction.
Observed 3 times. Targeted ports: 91. Country: United States. Reputation: known attacker.
Observed 18 times. Targeted ports: 6277, 9059, 17684, 19651, 30654, 37301, 64878. Country: Russia.
Observed 22 times. Targeted ports: 445. Country: Iran. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 1 times. Targeted ports: 50780. Country: Brazil.
Observed 8 times. Targeted ports: 23. Country: Ukraine.
Observed 14 times. Targeted ports: 1194. Country: United States.
Observed 17 times. Targeted ports: 445, 1433. Country: Indonesia. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 29 times. Targeted ports: 9000. Country: United Kingdom.
Observed 5 times. Targeted ports: 60001. Country: United States. Reputation: known attacker.
Observed 3 times. Targeted ports: 69. Country: Singapore. Reputation: known attacker.
Observed 6 times. Targeted ports: 2333. Country: China.
Observed 9 times. Targeted ports: 2333. Country: China. Reputation: known attacker.
Observed 9 times. Targeted ports: 2333. Country: China.
Observed 5 times. Targeted ports: 2333. Country: China.
Observed 1 times. Targeted ports: 25571. Country: Brazil.
Observed 1 times. Targeted ports: 52192. Country: Brazil.
Observed 6 times. Targeted ports: 8088. Country: United States.
Observed 9 times. Targeted ports: 8545. Country: The Netherlands.
Observed 1 times. Targeted ports: 27015. Country: China. Reputation: known attacker.
Observed 6 times. Targeted ports: 23. Country: Belgium.
Observed 2 times. Country: France.
Observed 2 times. Country: France.
Observed 13 times. Targeted ports: 990, 3389. Country: Belgium.
Observed 28 times. Targeted ports: 15000. Country: The Netherlands.
Observed 14 times. Targeted ports: 3389. Country: United States.
Observed 3 times. Targeted ports: 3306. Country: United States.
Observed 1 times. Country: United States.
Observed 1 times. Country: United States.
Observed 1 times. Targeted ports: 45980. Country: France.
Observed 2 times. Country: The Netherlands.
Observed 1 times. Targeted ports: 54753. Country: United States.
Observed 2 times. Country: Canada.
Observed 1 times. Targeted ports: 62290. Country: Brazil. Reputation: known attacker.
Observed 8 times. Targeted ports: 23. Country: Azerbaijan.
Observed 22 times. Targeted ports: 445. Country: India. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 278 times. Targeted ports: 5432, 6379. Country: Belgium. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction, SURICATA TLS invalid record type.
Observed 1 times. Country: United States.
Observed 1 times. Country: United States.
Observed 14 times. Targeted ports: 80. Country: South Korea. Reputation: bot, crawler. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA HTTP Request excessive header repetition.
Observed 1 times. Targeted ports: 6849. Country: Mexico.
Observed 5 times. Targeted ports: 22. Country: Belgium.
Observed 5 times. Targeted ports: 22. Country: Belgium.
Observed 3 times. Targeted ports: 81. Country: United States. Reputation: known attacker.
Observed 23 times. Targeted ports: 2083. Country: United States.
Observed 255 times. Targeted ports: 6379. Country: Belgium. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction.
Observed 1 times. Targeted ports: 1261. Country: China.
Observed 1 times. Targeted ports: 29249. Country: Brazil.
Observed 23 times. Targeted ports: 445. Country: China. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 2 times. Country: Türkiye.
Observed 2 times. Country: Spain.
Observed 2 times. Country: United Kingdom.
Observed 1 times. Targeted ports: 27087. Country: China.
Observed 20 times. Targeted ports: 445, 1433. Country: Vietnam. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 22 times. Targeted ports: 445. Country: Hong Kong. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 305 times. Targeted ports: 389, 445. Country: Belgium. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction, SURICATA Applayer Mismatch protocol both directions. Usernames: cn=mdgdiijdmzanmtlhsxhv, cn=skkqcxmvdspgxjwtdsua.
Observed 1 times. Targeted ports: 17157. Country: Mexico.
Observed 10 times. Targeted ports: 8545. Country: The Netherlands.
Observed 1 times. Targeted ports: 53746. Country: Brazil.
Observed 1 times. Targeted ports: 21238. Country: Argentina.
Observed 1 times. Targeted ports: 7193. Country: Brazil. Reputation: known attacker.
Observed 1 times. Targeted ports: 873. Country: United States.
Observed 5 times. Targeted ports: 6889. Country: United States. Reputation: known attacker.
Observed 29 times. Targeted ports: 5173. Country: United States.
Observed 1 times. Targeted ports: 29959. Country: Brazil.
Observed 3 times. Targeted ports: 89. Country: Germany.
Observed 28 times. Targeted ports: 33333. Country: United States.
Observed 11 times. Targeted ports: 445, 1433. Country: Indonesia.
Observed 40 times. Targeted ports: 12400. Country: Germany.
Observed 2 times. Country: Malaysia.
Observed 32 times. Targeted ports: 4000. Country: India. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction.
Observed 3 times. Country: United States.
Observed 5 times. Targeted ports: 1433. Country: India.
Observed 5 times. Targeted ports: 9443. Country: United States. Reputation: known attacker.
Observed 11 times. Targeted ports: 80, 443, 8080. Country: United States.
Observed 6 times. Targeted ports: 4433. Country: United States.
Observed 7 times. Targeted ports: 23. Country: Ukraine.
Observed 5 times. Targeted ports: 80. Country: China.
Observed 1 times. Targeted ports: 36594. Country: Brazil.
Observed 29 times. Targeted ports: 8443. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 23 times. Targeted ports: 445. Country: Russia. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.