Honeypot infrastructure watch
A community-maintained watchlist of IP infrastructure observed through honeypot telemetry. Historical observations include original tags, hit counts, and first/last-seen dates.
IOC feed · 488,541 indicators
Latest indicators
Live indicator delivery for this feed.
Observed 24 times. Targeted ports: 8443. Country: Türkiye. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 12 times. Targeted ports: 22, 23. Country: Philippines.
Observed 9 times. Targeted ports: 9200. Country: France. Reputation: mass scanner.
Observed 29 times. Targeted ports: 22, 23. Country: Argentina.
Observed 1 times. Targeted ports: 8163. Country: Chile.
Observed 1 times. Targeted ports: 43335. Country: Brazil.
Observed 1 times. Targeted ports: 52679. Country: Ukraine.
Observed 27 times. Targeted ports: 445. Country: Brazil. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 14 times. Targeted ports: 23. Country: Tunisia.
Observed 32 times. Targeted ports: 445, 1433, 3306. Country: Russia. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use. Usernames: root.
Observed 14 times. Targeted ports: 25568. Country: The Netherlands.
Observed 1 times. Targeted ports: 28074. Country: Moldova. Reputation: known attacker.
Observed 15 times. Targeted ports: 3390. Country: Germany.
Observed 9 times. Targeted ports: 8004. Country: China.
Observed 9 times. Targeted ports: 8004. Country: China.
Observed 8 times. Targeted ports: 8004. Country: China.
Observed 10 times. Targeted ports: 8004. Country: China.
Observed 6 times. Targeted ports: 8004. Country: China.
Observed 8 times. Targeted ports: 80. Country: India.
Observed 1 times. Targeted ports: 32165. Country: Brazil.
Observed 4 times. Targeted ports: 9200. Country: Switzerland.
Observed 8 times. Targeted ports: 5985. Country: Hong Kong.
Observed 3 times. Targeted ports: 587. Country: United States. Reputation: known attacker.
Observed 1 times. Targeted ports: 41641. Country: Uzbekistan.
Observed 8 times. Targeted ports: 23. Country: Ukraine.
Observed 13 times. Targeted ports: 23. Country: South Korea.
Observed 1 times. Targeted ports: 51319. Country: Australia.
Observed 6 times. Targeted ports: 23. Country: Italy.
Observed 24 times. Targeted ports: 8443. Country: Russia. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 22 times. Targeted ports: 8443. Country: Russia. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 6 times. Targeted ports: 23. Country: Uruguay.
Observed 8 times. Targeted ports: 9307. Country: China.
Observed 8 times. Targeted ports: 9307. Country: China.
Observed 7 times. Targeted ports: 9307. Country: China.
Observed 6 times. Targeted ports: 9307. Country: China.
Observed 24 times. Targeted ports: 22, 23. Country: Ukraine. Reputation: bot, crawler.
Observed 1 times. Targeted ports: 53. Country: The Netherlands.
Observed 31 times. Targeted ports: 22, 23. Country: Tunisia.
Observed 59 times. Targeted ports: 5671. Country: United States.
Observed 11 times. Targeted ports: 8188. Country: Kazakhstan.
Observed 5 times. Targeted ports: 1194. Country: United States. Reputation: known attacker.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 388 times. Targeted ports: 21, 23, 53, 143, 179, 389, 443, 593, 853, 873, 902, 999, 1080, 1234, 1241, 1300, 1311, 1443, 2000, 2159, 2443, 2483, 2484, 4145, 4333, 4899, 5004, 5222, 5555, 5601, 5900, 5985, 6000, 6667, 6697, 7000, 7443, 7899, 8081, 9001, 9943, 10000, 11111, 18562, 29341, 30001, 30002, 32682, 33060, 33333, 44444, 55555. Country: Switzerland. Reputation: known attacker.
Observed 681 times. Targeted ports: 23, 25, 53, 79, 80, 113, 443, 554, 1025, 1194, 1234, 1293, 1443, 1723, 1883, 2049, 2082, 2159, 2375, 2376, 3333, 3389, 3690, 4333, 4899, 5060, 5222, 5500, 5555, 5631, 5986, 6000, 7680, 7777, 8200, 8800, 9002, 9050, 9300, 9513, 10443, 13136, 16514, 18553, 18562, 18845, 19226, 27654, 28080, 29341, 30001, 34537, 49663, 55555. Country: Switzerland. Reputation: known attacker. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Mismatch protocol both directions, SURICATA Applayer Wrong direction first Data.
Observed 46 times. Targeted ports: 445. Country: South Africa. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 313 times. Targeted ports: 22, 43, 139, 464, 512, 990, 993, 1000, 1025, 1080, 1293, 1521, 1526, 2375, 2483, 2484, 3000, 3389, 4000, 5349, 5500, 5601, 5800, 6514, 6666, 7899, 8080, 8200, 8848, 9100, 9300, 14662, 16514, 18888, 19226, 30002, 32632, 34537, 40000. Country: Switzerland. Reputation: known attacker. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Mismatch protocol both directions.
Observed 8 times. Targeted ports: 23. Country: Colombia.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 5 times. Targeted ports: 23. Country: Argentina.
Observed 5 times. Targeted ports: 23. Country: Laos.
Observed 24 times. Targeted ports: 22, 23. Country: United States.
Observed 15 times. Targeted ports: 22. Country: Romania. Reputation: known attacker. Alert categories: Misc activity. Signatures: ET INFO SSH session in progress on Expected Port.
Observed 2 times. Targeted ports: 1433. Country: China.
Observed 1 times. Targeted ports: 64878. Country: Colombia.
Observed 1 times. Targeted ports: 44301. Country: Brazil.
Observed 8 times. Targeted ports: 23. Country: Russia.
Observed 7 times. Targeted ports: 23. Country: China.
Observed 25 times. Targeted ports: 22, 23. Country: Argentina.
Observed 43 times. Targeted ports: 445. Country: Guatemala. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 8 times. Targeted ports: 23. Country: United States.
Observed 23 times. Targeted ports: 8443. Country: Israel. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 23 times. Targeted ports: 8443. Country: Israel. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 26 times. Targeted ports: 8443. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data, SURICATA STREAM spurious retransmission.
Observed 48 times. Targeted ports: 8443. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 8 times. Targeted ports: 23. Country: Iran.
Observed 6 times. Targeted ports: 1911. Country: United States.
Observed 7 times. Targeted ports: 25, 137. Country: Germany.
Observed 2 times. Targeted ports: 56470. Country: Brazil.
Observed 1 times. Targeted ports: 23175. Country: Argentina.
Observed 23 times. Targeted ports: 445. Country: Mexico. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 6 times. Targeted ports: 23. Country: Brazil.
Observed 1 times. Targeted ports: 55657. Country: Brazil.
Observed 1 times. Targeted ports: 11903. Country: Morocco.
Observed 27 times. Targeted ports: 22, 23. Country: Senegal.
Observed 6 times. Targeted ports: 23. Country: Taiwan.
Observed 1 times. Targeted ports: 44054. Country: Mozambique.
Observed 1 times. Targeted ports: 51875. Country: Brazil.
Observed 1 times. Targeted ports: 48861. Country: Ireland.
Observed 9 times. Targeted ports: 11434. Country: Germany.
Observed 6 times. Targeted ports: 8805. Country: United States. Reputation: known attacker.
Observed 5 times. Targeted ports: 7002. Country: United States.
Observed 8 times. Targeted ports: 17000. Country: China.
Observed 1 times. Targeted ports: 44923. Country: Brazil.
Observed 1 times. Targeted ports: 53419. Country: Mexico.
Observed 1 times. Targeted ports: 18515. Country: Mexico. Reputation: known attacker.
Observed 8 times. Targeted ports: 17000. Country: China.
Observed 8 times. Targeted ports: 17000. Country: China.
Observed 8 times. Targeted ports: 17000. Country: China. Reputation: known attacker.
Observed 5 times. Targeted ports: 23. Country: Taiwan.
Observed 5 times. Targeted ports: 8873. Country: United States.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 9 times. Targeted ports: 23. Country: Russia.
Observed 6 times. Targeted ports: 3399. Country: United States.
Observed 6 times. Targeted ports: 49671. Country: United States.
Observed 24 times. Targeted ports: 8443. Country: Seychelles. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 23 times. Targeted ports: 8443. Country: United Kingdom. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 1 times. Targeted ports: 14242. Country: Brazil.
Observed 1 times. Targeted ports: 31937. Country: Brazil.
Observed 5 times. Targeted ports: 23. Country: Taiwan.