Honeypot infrastructure watch
A community-maintained watchlist of IP infrastructure observed through honeypot telemetry. Historical observations include original tags, hit counts, and first/last-seen dates.
IOC feed · 488,541 indicators
Latest indicators
Live indicator delivery for this feed.
Observed 63 times. Targeted ports: 26978. Country: Hong Kong. Reputation: known attacker.
Observed 20 times. Targeted ports: 54321. Country: United States.
Observed 8 times. Targeted ports: 23. Country: Brazil.
Observed 17 times. Targeted ports: 22. Country: Paraguay.
Observed 4 times. Targeted ports: 445. Country: Brazil.
Observed 1 times. Targeted ports: 39301. Country: China. Reputation: known attacker.
Observed 1 times. Targeted ports: 3399. Country: Ireland.
Observed 1 times. Targeted ports: 55552. Country: Mexico.
Observed 28 times. Targeted ports: 22, 23. Country: Uzbekistan.
Observed 6 times. Targeted ports: 23. Country: Guatemala.
Observed 9 times. Targeted ports: 3389. Country: United States.
Observed 8 times. Targeted ports: 10000. Country: China.
Observed 8 times. Targeted ports: 10000. Country: China.
Observed 11 times. Targeted ports: 10000. Country: China. Reputation: known attacker. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA HTTP missing Host header.
Observed 17 times. Targeted ports: 9092, 10000. Country: China.
Observed 9 times. Targeted ports: 10000. Country: China.
Observed 11 times. Targeted ports: 10000. Country: China.
Observed 55 times. Targeted ports: 22222. Country: United States. Alert categories: Generic Protocol Command Decode, Misc activity. Signatures: ET INFO SSH session in progress on Unusual Port, SURICATA Applayer Detect protocol only one direction, SURICATA SSH invalid banner.
Observed 12 times. Targeted ports: 22. Country: Brazil.
Observed 10 times. Targeted ports: 22. Country: Russia.
Observed 3 times. Targeted ports: 20. Country: China.
Observed 1 times. Targeted ports: 22876. Country: Mexico. Reputation: known attacker.
Observed 1340 times. Targeted ports: 5500, 5800, 5900, 5901, 5902, 5903, 5904, 5905, 5906, 5907, 5908, 5909, 5910, 5911, 5912, 5913, 5914, 5915, 5916, 5917, 5918, 5919, 5920, 5921, 5922, 5923, 5924, 5925, 5926, 5927, 5928, 5929, 5930, 5931, 5932, 5933, 5934, 5935, 5936, 5937, 5939, 5940, 5941, 5942, 5943, 5944, 5945, 5946, 5947, 5948, 5949, 5950, 5951, 5952, 5953, 5954, 5955, 5956, 5957, 5958, 5959, 5960, 5961, 5962, 5963, 5964, 5965, 5966, 5967, 5968, 5969, 5970, 5971, 5972, 5973, 5974, 5975, 5976, 5977, 5978, 5979, 5980, 5981, 5982, 5983, 5984, 5985, 5986, 5987, 5988, 5989, 5990, 5991, 5992, 5993, 5994, 5995, 5996, 5997, 5998, 5999, 6000, 6001, 6002, 6003, 6004, 6005, 6006, 6007, 6008, 6009, 6010, 6011, 6020, 6021, 6022, 6036, 6050, 6060, 6061, 6070, 6080, 6081, 6100, 6102, 6134, 6161, 6262, 6363, 6443, 6482, 6500, 6512, 6633, 6653, 6667, 6697, 7000, 7001, 7415, 7434, 7634, 9000, 9999, 10000, 10001, 10002, 10134, 10348. Country: Vietnam. Reputation: known attacker. Alert categories: Generic Protocol Command Decode, Misc activity. Signatures: GPL ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited, SURICATA STREAM Packet with broken ack, SURICATA STREAM spurious retransmission.
Observed 1 times. Targeted ports: 18157. Country: Peru. Reputation: known attacker.
Observed 16 times. Targeted ports: 22. Country: Ecuador.
Observed 1 times. Targeted ports: 5280. Country: Bolivia. Reputation: known attacker.
Observed 28 times. Targeted ports: 2222. Country: United States. Reputation: known attacker. Alert categories: Detection of a Network Scan. Signatures: ET SCAN Zmap User-Agent (Inbound).
Observed 115 times. Targeted ports: 1434. Country: United States.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 6 times. Targeted ports: 23. Country: Argentina.
Observed 8 times. Targeted ports: 22. Country: Indonesia.
Observed 203 times. Targeted ports: 23. Country: Pakistan.
Observed 8 times. Targeted ports: 23. Country: China.
Observed 8 times. Targeted ports: 23. Country: China.
Observed 181 times. Targeted ports: 23. Country: China.
Observed 1 times. Targeted ports: 40631. Country: Brazil.
Observed 4 times. Targeted ports: 23. Country: Pakistan.
Observed 5 times. Targeted ports: 23. Country: Brazil.
Observed 1 times. Targeted ports: 26963. Country: Ireland.
Observed 5 times. Targeted ports: 23. Country: Brazil.
Observed 6 times. Targeted ports: 23. Country: China.
Observed 1 times. Targeted ports: 59950. Country: Brazil.
Observed 29 times. Targeted ports: 22, 23. Country: Argentina.
Observed 9 times. Targeted ports: 23. Country: China.
Observed 6 times. Targeted ports: 23. Country: China.
Observed 4 times. Targeted ports: 2222. Country: Germany. Reputation: known attacker.
Observed 1 times. Targeted ports: 3389. Country: Portugal. Reputation: known attacker.
Observed 1 times. Targeted ports: 44713. Country: Brazil.
Observed 15 times. Targeted ports: 23. Country: Indonesia.
Observed 11 times. Targeted ports: 5555. Country: United States.
Observed 126 times. Targeted ports: 3389. Country: Brazil.
Observed 25 times. Targeted ports: 445. Country: Iran. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 16 times. Targeted ports: 22. Country: Argentina.
Observed 1 times. Targeted ports: 2124. Country: Brazil.
Observed 25 times. Targeted ports: 22, 23. Country: United States. Reputation: known attacker.
Observed 4 times. Targeted ports: 80, 443. Country: United States.
Observed 5 times. Targeted ports: 5555. Country: United States. Reputation: mass scanner.
Observed 6 times. Targeted ports: 23. Country: China.
Observed 4 times. Targeted ports: 80. Country: Finland.
Observed 1 times. Targeted ports: 41033. Country: Brazil.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 1 times. Targeted ports: 22867. Country: Brazil. Reputation: known attacker.
Observed 1 times. Targeted ports: 51644. Country: United States.
Observed 8 times. Targeted ports: 22. Country: Uzbekistan.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 5 times. Targeted ports: 23. Country: Chile.
Observed 6 times. Targeted ports: 59100. Country: China.
Observed 11 times. Targeted ports: 8545. Country: United States.
Observed 1 times. Targeted ports: 51315. Country: United States.
Observed 6 times. Targeted ports: 59100. Country: China.
Observed 5 times. Targeted ports: 53. Country: United States.
Observed 72 times. Targeted ports: 445. Country: Türkiye. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 1 times. Targeted ports: 6715. Country: The Netherlands.
Observed 1 times. Targeted ports: 18211. Country: Brazil.
Observed 1 times. Targeted ports: 5351. Country: Singapore.
Observed 8 times. Targeted ports: 23. Country: Ukraine.
Observed 21 times. Targeted ports: 3389, 3390. Country: United States.
Observed 10 times. Targeted ports: 9092. Country: China.
Observed 8 times. Targeted ports: 9092. Country: China.
Observed 7 times. Targeted ports: 9092. Country: China.
Observed 6 times. Targeted ports: 9092. Country: China.
Observed 7 times. Targeted ports: 9092. Country: China.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 1 times. Targeted ports: 8036. Country: Philippines.
Observed 62 times. Targeted ports: 22. Country: Russia. Alert categories: Misc activity. Signatures: ET INFO SSH session in progress on Expected Port. Usernames: ben, car, root.
Observed 1 times. Targeted ports: 25485. Country: Brazil.
Observed 32 times. Targeted ports: 22. Country: Hong Kong. Reputation: known attacker. Alert categories: Generic Protocol Command Decode, Misc activity. Signatures: ET INFO SSH session in progress on Expected Port, SURICATA STREAM spurious retransmission. Usernames: bitcoin.
Observed 21 times. Targeted ports: 3389, 3391, 3392, 3393. Country: Seychelles.
Observed 32 times. Targeted ports: 22. Country: Russia. Reputation: known attacker. Alert categories: Misc activity. Signatures: ET INFO SSH session in progress on Expected Port. Usernames: bitcoin.
Observed 1 times. Targeted ports: 44292. Country: Brazil.
Observed 6 times. Targeted ports: 23. Country: China.
Observed 6 times. Targeted ports: 23. Country: China.
Observed 1 times. Targeted ports: 52865. Country: Brazil.
Observed 81 times. Targeted ports: 3389. Country: Egypt. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with broken ack.
Observed 5 times. Targeted ports: 23. Country: China.