Honeypot infrastructure watch
A community-maintained watchlist of IP infrastructure observed through honeypot telemetry. Historical observations include original tags, hit counts, and first/last-seen dates.
IOC feed · 488,541 indicators
Latest indicators
Live indicator delivery for this feed.
Observed 5 times. Targeted ports: 1433. Country: China.
Observed 30 times. Targeted ports: 22, 23. Country: Argentina.
Observed 5 times. Targeted ports: 1433. Country: China.
Observed 1 times. Targeted ports: 24562. Country: France.
Observed 15 times. Targeted ports: 8883. Country: United States.
Observed 320 times. Targeted ports: 443. Country: Germany.
Observed 30 times. Targeted ports: 22, 23. Country: Argentina.
Observed 28 times. Targeted ports: 4449. Country: United States.
Observed 6 times. Targeted ports: 23. Country: China.
Observed 137 times. Targeted ports: 80, 81, 82, 83, 84, 85, 88, 90, 8001, 8080, 8081, 8082, 8090, 9000, 65004. Country: Germany. Reputation: known attacker. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA HTTP Request excessive header repetition.
Observed 33 times. Targeted ports: 3389. Country: Russia.
Observed 1 times. Country: Indonesia.
Observed 4 times. Targeted ports: 80. Country: China.
Observed 1 times. Targeted ports: 58189. Country: Brazil.
Observed 8 times. Targeted ports: 10423. Country: China.
Observed 1 times. Targeted ports: 28462. Country: Brazil.
Observed 2 times. Targeted ports: 8080. Country: China. Reputation: known attacker.
Observed 13 times. Targeted ports: 23. Country: China.
Observed 33 times. Targeted ports: 22, 23. Country: Ukraine. Alert categories: Misc activity. Signatures: ET INFO SSH session in progress on Expected Port.
Observed 26 times. Targeted ports: 445, 636. Country: Belgium.
Observed 9 times. Targeted ports: 23. Country: Belgium.
Observed 1349 times. Targeted ports: 3389. Country: Australia.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 5 times. Targeted ports: 1433. Country: China.
Observed 8 times. Targeted ports: 23. Country: Latvia.
Observed 3 times. Targeted ports: 1433. Country: India.
Observed 29 times. Targeted ports: 8089. Country: United States.
Observed 1 times. Targeted ports: 4003. Country: Uruguay.
Observed 16 times. Targeted ports: 22. Country: Ukraine.
Observed 8 times. Targeted ports: 23. Country: Ukraine.
Observed 22 times. Targeted ports: 8081. Country: Thailand.
Observed 3 times. Targeted ports: 1433. Country: China.
Observed 8 times. Targeted ports: 23. Country: Kyrgyzstan.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 1 times. Targeted ports: 11230. Country: Canada.
Observed 10 times. Targeted ports: 445. Country: India. Reputation: known attacker. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 14 times. Targeted ports: 445. Country: India. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 27 times. Targeted ports: 8880. Country: United States.
Observed 42 times. Targeted ports: 10443. Country: Iran.
Observed 8 times. Targeted ports: 8728. Country: Albania.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 6 times. Targeted ports: 2376. Country: Germany. Reputation: known attacker.
Observed 28 times. Targeted ports: 6000. Country: United States.
Observed 10 times. Targeted ports: 23. Country: China.
Observed 1 times. Targeted ports: 51917. Country: France.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 17 times. Targeted ports: 22. Country: Myanmar.
Observed 5 times. Targeted ports: 23. Country: Philippines.
Observed 7 times. Targeted ports: 5985. Country: Uzbekistan.
Observed 42 times. Targeted ports: 1080, 8636. Country: China.
Observed 17 times. Targeted ports: 8188. Country: Russia.
Observed 15 times. Targeted ports: 8084. Country: China.
Observed 5 times. Targeted ports: 1433. Country: China.
Observed 15 times. Targeted ports: 8883. Country: Canada.
Observed 2 times. Targeted ports: 8080. Country: Singapore.
Observed 44 times. Targeted ports: 445. Country: Kazakhstan. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 25 times. Targeted ports: 22, 23. Country: Ukraine.
Observed 15 times. Targeted ports: 53. Country: United States.
Observed 28 times. Targeted ports: 22, 23. Country: Brazil.
Observed 6 times. Targeted ports: 2344. Country: China.
Observed 2 times. Country: China.
Observed 2 times. Targeted ports: 8080. Country: Singapore.
Observed 1 times. Targeted ports: 6389. Country: Mexico.
Observed 6 times. Targeted ports: 27017. Country: China.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 27 times. Targeted ports: 22, 23. Country: United States.
Observed 30 times. Targeted ports: 22, 23. Country: Argentina.
Observed 20 times. Targeted ports: 445. Country: Russia.
Observed 5 times. Targeted ports: 23. Country: Argentina.
Observed 557 times. Targeted ports: 22. Country: Vietnam. Alert categories: Generic Protocol Command Decode, Misc activity. Signatures: ET INFO SSH session in progress on Expected Port, SURICATA STREAM spurious retransmission. Usernames: admin, anton, auto, belkinstyle, cf1c22 and 24 more.
Observed 1123 times. Targeted ports: 5432, 27017. Country: Belgium. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction, SURICATA Applayer Mismatch protocol both directions.
Observed 2 times. Targeted ports: 80. Country: Mexico. Reputation: known attacker.
Observed 266 times. Targeted ports: 22. Country: Vietnam. Alert categories: Generic Protocol Command Decode, Misc activity. Signatures: ET INFO SSH session in progress on Expected Port, SURICATA STREAM CLOSEWAIT FIN out of window, SURICATA STREAM spurious retransmission. Usernames: admian, admin, btf, cisco, guest1 and 4 more.
Observed 427 times. Targeted ports: 22, 2077, 2087, 3001, 4443, 8083, 10000, 10001, 19000, 24002, 30001, 34567. Country: United States. Alert categories: Misc activity. Signatures: ET INFO SSH session in progress on Expected Port.
Observed 5 times. Targeted ports: 23. Country: Taiwan.
Observed 16 times. Targeted ports: 22. Country: Belgium.
Observed 6 times. Targeted ports: 23. Country: China.
Observed 5 times. Targeted ports: 23. Country: Taiwan.
Observed 18 times. Targeted ports: 445, 1433. Country: Pakistan. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 20 times. Targeted ports: 53. Country: Belgium.
Observed 2 times. Targeted ports: 123. Country: Belgium.
Observed 12 times. Targeted ports: 23. Country: Italy.
Observed 54 times. Targeted ports: 1900. Country: United States.
Observed 17 times. Targeted ports: 22. Country: Belgium.
Observed 289 times. Targeted ports: 389. Country: Belgium. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction, SURICATA Applayer Mismatch protocol both directions. Usernames: cn=pvrwsowvfdcypcyymnko, cn=rehzcbdtooymwdivvagl.
Observed 5 times. Targeted ports: 27017. Country: Canada.
Observed 21 times. Targeted ports: 53. Country: Belgium.
Observed 1009 times. Targeted ports: 5500, 5800, 5900, 5901, 5902, 5903, 5904, 5905, 5906, 5907, 5908, 5909, 5910, 5911, 5912, 5913, 5914, 5915, 5916, 5917, 5918, 5919, 5920, 5921, 5922, 5923, 5924, 5925, 5926, 5927, 5928, 5929, 5930, 5931, 5932, 5933, 5934, 5935, 5936, 5937, 5938, 5939, 5940, 5941, 5942, 5943, 5944, 5945, 5946, 5947, 5948, 5949, 5950, 5951, 5952, 5953, 5954, 5955, 5956, 5957, 5958, 5959, 5960, 5961, 5962, 5963, 5964, 5965, 5966, 5967, 5968, 5969, 5970, 5971, 5972, 5973, 5974, 5975, 5976, 5977, 5978, 5979, 5980, 5981, 5982, 5983, 5984, 5985, 5986, 5987, 5988, 5989, 5990, 5991, 5992, 5993, 5994, 5995, 5996, 5997, 5998, 5999, 6000, 6001, 6002, 6003, 6004, 6005, 6006, 6007, 6008, 6009, 6010, 6011, 6020, 6021, 6022, 6036, 6050, 6060, 6061, 6070, 6080, 6081, 6100, 6102, 6134, 6161, 6262, 6363, 6443, 6482, 6500, 6512, 6633, 6653, 6667, 6697, 7000, 7001, 7415, 7434, 7634, 9000, 9999, 10000, 10001, 10002, 10134, 10348. Country: Germany. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with broken ack.
Observed 28 times. Targeted ports: 445. Country: Indonesia. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 5 times. Targeted ports: 22. Country: Türkiye.
Observed 159 times. Targeted ports: 22. Country: Vietnam. Alert categories: Generic Protocol Command Decode, Misc activity. Signatures: ET INFO SSH session in progress on Expected Port, SURICATA STREAM spurious retransmission. Usernames: 1234, admin, guest, nikita, root and 1 more.
Observed 6 times. Targeted ports: 60000. Country: United States.
Observed 5 times. Targeted ports: 9306. Country: Brazil.
Observed 53 times. Targeted ports: 5671. Country: United States.
Observed 3 times. Targeted ports: 1433. Country: Cambodia.
Observed 3 times. Targeted ports: 993. Country: United States.
Observed 6 times. Targeted ports: 23. Country: China.