Honeypot infrastructure watch
A community-maintained watchlist of IP infrastructure observed through honeypot telemetry. Historical observations include original tags, hit counts, and first/last-seen dates.
IOC feed · 488,541 indicators
Latest indicators
Live indicator delivery for this feed.
Observed 16 times. Targeted ports: 2086, 2087. Country: Germany. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with broken ack.
Observed 1 times. Targeted ports: 53079. Country: United States.
Observed 2 times. Targeted ports: 1433. Country: Egypt. Reputation: known attacker.
Observed 7 times. Targeted ports: 10022. Country: United States.
Observed 1 times. Targeted ports: 32181. Country: Brazil. Reputation: known attacker.
Observed 48 times. Targeted ports: 445. Country: Argentina. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 5 times. Targeted ports: 23. Country: Argentina.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 1 times. Targeted ports: 51534. Country: South Africa.
Observed 1 times. Targeted ports: 36484. Country: Argentina.
Observed 95 times. Targeted ports: 443. Country: The Netherlands. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 1 times. Targeted ports: 123. Country: Japan.
Observed 7 times. Targeted ports: 23. Country: Ukraine.
Observed 30 times. Targeted ports: 22, 23. Country: Brazil.
Observed 1 times. Targeted ports: 58519. Country: France.
Observed 2 times. Targeted ports: 8080. Country: France.
Observed 1 times. Targeted ports: 43447. Country: Colombia.
Observed 1 times. Targeted ports: 17247. Country: United States.
Observed 1 times. Targeted ports: 63339. Country: Bangladesh.
Observed 30 times. Targeted ports: 22. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Mismatch protocol both directions.
Observed 1 times. Targeted ports: 41548. Country: Brazil.
Observed 1 times. Targeted ports: 42366. Country: Brazil. Reputation: known attacker.
Observed 20 times. Targeted ports: 22, 23. Country: Tunisia.
Observed 16 times. Targeted ports: 22. Country: Argentina.
Observed 1 times. Targeted ports: 42539. Country: Brazil.
Observed 7 times. Targeted ports: 23. Country: Iraq.
Observed 6 times. Targeted ports: 23. Country: China.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 17 times. Targeted ports: 23. Country: Iceland. Reputation: tor exit node. Usernames: root, user.
Observed 9 times. Targeted ports: 8080. Country: Pakistan.
Observed 23 times. Targeted ports: 22, 23. Country: Egypt.
Observed 23 times. Targeted ports: 8443. Country: United Arab Emirates. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 8 times. Targeted ports: 23. Country: China.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 14 times. Targeted ports: 23. Country: India.
Observed 5 times. Targeted ports: 1433. Country: China.
Observed 26 times. Targeted ports: 443. Country: China.
Observed 22 times. Targeted ports: 445. Country: Mexico. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 3 times. Targeted ports: 1433. Country: Bangladesh.
Observed 1 times. Targeted ports: 8. Country: Ukraine. Reputation: known attacker.
Observed 23 times. Targeted ports: 3978, 9339, 28270, 28443. Country: United States. Reputation: known attacker.
Observed 25 times. Targeted ports: 22, 23. Country: Pakistan.
Observed 60 times. Targeted ports: 3978. Country: United States.
Observed 2 times. Targeted ports: 1433. Country: Iran.
Observed 1 times. Targeted ports: 17029. Country: Ethiopia.
Observed 6 times. Targeted ports: 25282. Country: China.
Observed 11 times. Targeted ports: 25282. Country: China.
Observed 9 times. Targeted ports: 25282. Country: China.
Observed 28 times. Targeted ports: 22, 23. Country: Vietnam.
Observed 23 times. Targeted ports: 22, 23. Country: Indonesia. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with broken ack.
Observed 5 times. Targeted ports: 23. Country: Taiwan.
Observed 7 times. Targeted ports: 30000. Country: Finland. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with broken ack.
Observed 21 times. Targeted ports: 22, 23. Country: Syria.
Observed 6 times. Targeted ports: 23. Country: China.
Observed 16 times. Targeted ports: 53. Country: United States.
Observed 785 times. Targeted ports: 80, 443, 447, 448, 554, 587, 873, 1883, 2080, 2083, 3000, 3002, 3268, 4000, 5001, 5061, 5173, 5601, 5900, 5901, 5904, 5905, 5906, 6006, 6379, 7000, 7001, 7443, 8001, 8008, 8081, 8082, 8086, 8087, 8444, 8554, 8880, 8883, 8888, 8889, 9001, 9071, 9200, 9443, 9999, 10000, 10250, 15001, 27017, 50051. Country: United Kingdom. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 1046 times. Targeted ports: 21, 80, 389, 443, 446, 554, 636, 1883, 2080, 2083, 2222, 3000, 3001, 3002, 3003, 5000, 5001, 5061, 5173, 5432, 5601, 5901, 5902, 5903, 6006, 7000, 7001, 7443, 8001, 8080, 8081, 8082, 8083, 8086, 8087, 8090, 8123, 8443, 8444, 8554, 8880, 8883, 8888, 8889, 9000, 9001, 9071, 9200, 9300, 9443, 9999, 10000, 15000, 15001, 50051. Country: Slovakia. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data. Usernames: admin, anonymous, ftp, test, user.
Observed 1418 times. Targeted ports: 21, 80, 443, 449, 465, 554, 636, 993, 995, 1883, 2083, 2222, 2525, 3000, 3001, 3002, 3003, 3269, 5001, 5061, 5173, 5601, 5901, 5902, 5903, 5904, 5905, 5906, 6379, 7000, 7001, 7443, 8000, 8008, 8081, 8083, 8086, 8087, 8123, 8443, 8444, 8554, 8880, 8883, 8888, 8889, 9000, 9001, 9071, 9100, 9300, 9443, 9999, 10000, 10250, 15000, 15001, 27017, 50051. Country: Germany. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction, SURICATA Applayer Wrong direction first Data.
Observed 1240 times. Targeted ports: 21, 22, 80, 81, 143, 443, 554, 631, 993, 995, 2080, 2083, 2525, 3000, 3001, 3002, 3003, 3268, 3269, 3306, 4000, 5061, 5173, 5601, 5901, 5904, 5905, 5906, 6006, 6379, 7000, 7001, 7443, 8000, 8001, 8008, 8080, 8081, 8083, 8086, 8090, 8123, 8443, 8444, 8554, 8880, 8883, 8888, 8889, 9000, 9001, 9071, 9200, 9300, 9443, 9999, 10000, 10250, 10554, 15000, 15001, 27017, 50051. Country: Spain. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction, SURICATA Applayer Wrong direction first Data. Usernames: admin, anonymous, ftp, test, user.
Observed 478 times. Targeted ports: 21, 443, 1883, 2222, 2525, 3001, 3002, 3269, 5173, 5902, 5903, 5904, 5905, 6379, 7443, 8081, 8082, 8086, 8443, 8554, 8883, 9200, 9443, 9999, 27017. Country: Norway. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 62 times. Targeted ports: 28270. Country: United States.
Observed 17 times. Targeted ports: 22. Country: South Africa.
Observed 8 times. Targeted ports: 8010. Country: United States.
Observed 1 times. Targeted ports: 9936. Country: Brazil.
Observed 29 times. Targeted ports: 22, 23. Country: Indonesia.
Observed 459 times. Targeted ports: 23, 80, 82, 110, 444, 2080, 2083, 3000, 3001, 3003, 3268, 5001, 5061, 7001, 7443, 8000, 8008, 8083, 8090, 8443, 8444, 8888, 9000, 9001, 9300, 9999, 10250, 11211, 15000, 15001, 50051. Country: Czechia.
Observed 6 times. Targeted ports: 23. Country: China.
Observed 1 times. Targeted ports: 15998. Country: Mexico.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 5 times. Targeted ports: 5555. Country: Kazakhstan.
Observed 16 times. Targeted ports: 443, 3390. Country: Sweden.
Observed 22 times. Targeted ports: 445. Country: Brazil. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 2 times. Targeted ports: 80. Country: Brazil.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 22 times. Targeted ports: 8443. Country: The Netherlands. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 23 times. Targeted ports: 8443. Country: Russia. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 44 times. Targeted ports: 445. Country: India. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 29 times. Targeted ports: 22, 23. Country: Philippines.
Observed 16 times. Targeted ports: 22. Country: Ukraine.
Observed 4 times. Targeted ports: 23. Country: China.
Observed 8 times. Targeted ports: 50880. Country: United States.
Observed 24 times. Targeted ports: 445. Country: Argentina. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 9 times. Targeted ports: 23. Country: Luxembourg. Reputation: tor exit node. Usernames: default.
Observed 4 times. Targeted ports: 23. Country: Argentina.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 6 times. Targeted ports: 23. Country: Argentina.
Observed 5 times. Targeted ports: 23. Country: Vietnam.
Observed 60 times. Targeted ports: 10086. Country: United States.
Observed 1 times. Targeted ports: 37772. Country: Brazil. Reputation: known attacker.
Observed 5 times. Targeted ports: 5433. Country: India.