Honeypot infrastructure watch
A community-maintained watchlist of IP infrastructure observed through honeypot telemetry. Historical observations include original tags, hit counts, and first/last-seen dates.
IOC feed · 488,541 indicators
Latest indicators
Live indicator delivery for this feed.
Observed 5 times. Targeted ports: 443. Country: Finland.
Observed 11 times. Targeted ports: 23. Country: Ukraine. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM CLOSEWAIT FIN out of window.
Observed 18 times. Targeted ports: 445, 1433. Country: Bangladesh. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 367 times. Targeted ports: 22. Country: Vietnam. Alert categories: Generic Protocol Command Decode, Misc activity. Signatures: ET INFO SSH session in progress on Expected Port, SURICATA STREAM spurious retransmission. Usernames: 1234, admin, ftpuser, installer, kim and 10 more.
Observed 5 times. Targeted ports: 3369. Country: United States.
Observed 8 times. Targeted ports: 23. Country: China.
Observed 3 times. Targeted ports: 83. Country: United States.
Observed 268 times. Targeted ports: 23, 25. Country: Belgium. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Mismatch protocol both directions. Usernames: ; � admin.$cmd �� hello �? .
Observed 5 times. Targeted ports: 9000. Country: United States.
Observed 6 times. Targeted ports: 445. Country: Taiwan.
Observed 57 times. Targeted ports: 9201. Country: United States.
Observed 21 times. Targeted ports: 9221, 9444. Country: United States.
Observed 3 times. Targeted ports: 8080. Country: United States. Reputation: known attacker.
Observed 8 times. Targeted ports: 445. Country: Thailand. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 8 times. Targeted ports: 12226. Country: China.
Observed 8 times. Targeted ports: 12226. Country: China.
Observed 8 times. Targeted ports: 12226. Country: China.
Observed 22 times. Targeted ports: 445. Country: Brazil. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 8 times. Targeted ports: 12226. Country: China.
Observed 6 times. Targeted ports: 12226. Country: China.
Observed 13 times. Targeted ports: 445. Country: Indonesia. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 4 times. Targeted ports: 23. Country: Pakistan.
Observed 8 times. Targeted ports: 23. Country: Israel.
Observed 1 times. Targeted ports: 51179. Country: Brazil.
Observed 5 times. Targeted ports: 10004. Country: China.
Observed 10 times. Targeted ports: 10004. Country: China.
Observed 8 times. Targeted ports: 10004. Country: China.
Observed 1 times. Targeted ports: 26590. Country: South Korea.
Observed 6 times. Targeted ports: 10004. Country: China.
Observed 8 times. Targeted ports: 23. Country: Iran.
Observed 6 times. Targeted ports: 18246. Country: United States. Reputation: known attacker.
Observed 1 times. Targeted ports: 57276. Country: Brazil. Reputation: known attacker.
Observed 22 times. Targeted ports: 445. Country: Iran. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 5 times. Targeted ports: 8443. Country: United States. Reputation: known attacker.
Observed 14 times. Targeted ports: 23. Country: Pakistan.
Observed 1 times. Targeted ports: 7069. Country: Mexico.
Observed 269 times. Targeted ports: 27017. Country: Belgium.
Observed 265 times. Targeted ports: 23. Country: Belgium. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Mismatch protocol both directions. Usernames: ; � admin.$cmd �� hello �? .
Observed 1 times. Targeted ports: 49127. Country: Brazil. Reputation: known attacker.
Observed 8 times. Targeted ports: 23. Country: Ukraine.
Observed 6 times. Targeted ports: 3320. Country: United States. Reputation: known attacker.
Observed 24 times. Targeted ports: 443. Country: China.
Observed 8 times. Targeted ports: 5985. Country: Mexico.
Observed 4 times. Targeted ports: 443. Country: United States.
Observed 6 times. Targeted ports: 23. Country: Brazil.
Observed 5 times. Targeted ports: 23. Country: Brazil.
Observed 3 times. Targeted ports: 1521. Country: United States.
Observed 5 times. Targeted ports: 23. Country: Brazil.
Observed 6 times. Targeted ports: 8008. Country: United States. Reputation: known attacker.
Observed 8 times. Targeted ports: 23. Country: Chile.
Observed 1 times. Targeted ports: 51116. Country: Brazil. Reputation: known attacker.
Observed 8 times. Targeted ports: 23. Country: Brazil.
Observed 3 times. Targeted ports: 11211. Country: United States. Reputation: known attacker.
Observed 17 times. Targeted ports: 9000. Country: United States.
Observed 1 times. Targeted ports: 10859. Country: Brazil. Reputation: known attacker.
Observed 1 times. Targeted ports: 40076. Country: Peru.
Observed 6 times. Targeted ports: 8080. Country: India.
Observed 1 times. Targeted ports: 35469. Country: Brazil.
Observed 13 times. Targeted ports: 23. Country: Pakistan.
Observed 8 times. Targeted ports: 23. Country: Nigeria.
Observed 1 times. Targeted ports: 8080. Country: United States.
Observed 22 times. Targeted ports: 445. Country: India. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 1 times. Targeted ports: 60987. Country: Uzbekistan.
Observed 30 times. Targeted ports: 22, 23. Country: Germany.
Observed 5 times. Targeted ports: 8020. Country: United States. Reputation: known attacker.
Observed 3 times. Targeted ports: 111. Country: United States.
Observed 5 times. Targeted ports: 23. Country: Brazil.
Observed 292 times. Targeted ports: 389. Country: Belgium. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction, SURICATA Applayer Mismatch protocol both directions. Usernames: cn=xaiazzdznfbdbuferwly, cn=ziteromhfoqukwzzasnh.
Observed 8 times. Targeted ports: 23. Country: Colombia.
Observed 89 times. Targeted ports: 80, 443, 2077, 2078, 2082, 2083, 2086, 2087, 2095, 2096, 8088, 8443. Country: United States.
Observed 23 times. Targeted ports: 445. Country: Iran. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 1 times. Targeted ports: 64247. Country: Brazil.
Observed 7 times. Targeted ports: 23. Country: Ukraine.
Observed 14 times. Targeted ports: 80. Country: Belgium.
Observed 2 times. Targeted ports: 80. Country: Belgium.
Observed 5 times. Targeted ports: 23. Country: Argentina.
Observed 5 times. Targeted ports: 23. Country: Morocco.
Observed 6 times. Targeted ports: 23. Country: Brazil.
Observed 7 times. Targeted ports: 22222. Country: China.
Observed 154 times. Targeted ports: 5900, 5901, 5902. Country: United States.
Observed 6 times. Targeted ports: 9042. Country: United States.
Observed 5 times. Targeted ports: 23. Country: Kazakhstan.
Observed 1 times. Targeted ports: 61134. Country: Brazil.
Observed 15 times. Targeted ports: 23. Country: Argentina.
Observed 1 times. Targeted ports: 9921. Country: Brazil.
Observed 1 times. Targeted ports: 8783. Country: Brazil.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 279 times. Targeted ports: 21, 23. Country: Belgium. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Mismatch protocol both directions. Usernames: ; � admin.$cmd �� hello �? .
Observed 20 times. Targeted ports: 22, 23. Country: Pakistan.
Observed 8 times. Targeted ports: 23. Country: Chile.
Observed 3 times. Targeted ports: 5000. Country: United States.
Observed 15 times. Targeted ports: 2087. Country: China. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with broken ack.
Observed 7 times. Targeted ports: 23. Country: Russia.
Observed 22 times. Targeted ports: 445. Country: India. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 16 times. Targeted ports: 22, 23. Country: Ukraine.
Observed 8 times. Targeted ports: 5560. Country: China.
Observed 1 times. Targeted ports: 8597. Country: Colombia.
Observed 5 times. Targeted ports: 23. Country: United Arab Emirates.
Observed 28 times. Targeted ports: 22, 23. Country: United States.
Observed 6 times. Targeted ports: 5903. Country: United States.