Honeypot infrastructure watch
A community-maintained watchlist of IP infrastructure observed through honeypot telemetry. Historical observations include original tags, hit counts, and first/last-seen dates.
IOC feed · 487,109 indicators
Latest indicators
Live indicator delivery for this feed.
Observed 1 times. Targeted ports: 7051. Country: Brazil. Reputation: known attacker.
Observed 4 times. Targeted ports: 6035. Country: United Kingdom.
Observed 4 times. Targeted ports: 23. Country: China.
Observed 1 times. Targeted ports: 62183. Country: Mexico.
Observed 1 times. Targeted ports: 19552. Country: Brazil. Reputation: known attacker.
Observed 19 times. Targeted ports: 445. Country: Russia. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 3 times. Targeted ports: 61916. Country: United Kingdom.
Observed 3 times. Targeted ports: 60928. Country: United Kingdom.
Observed 2 times. Targeted ports: 264. Country: United States. Reputation: known attacker.
Observed 4 times. Targeted ports: 23. Country: Brazil.
Observed 3 times. Targeted ports: 59263. Country: United Kingdom.
Observed 34 times. Targeted ports: 8181. Country: Japan. Reputation: known attacker.
Observed 10 times. Targeted ports: 23. Country: The Netherlands.
Observed 9 times. Targeted ports: 7654. Country: United States. Reputation: known attacker.
Observed 10 times. Targeted ports: 3389. Country: Libya. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with broken ack, SURICATA STREAM spurious retransmission.
Observed 22 times. Targeted ports: 8881. Country: United States.
Observed 2 times. Targeted ports: 443. Country: Argentina.
Observed 7 times. Targeted ports: 3389. Country: Vietnam.
Observed 28 times. Targeted ports: 23. Country: Pakistan.
Observed 3 times. Targeted ports: 64240. Country: United Kingdom.
Observed 3 times. Targeted ports: 55237. Country: United Kingdom.
Observed 3 times. Targeted ports: 58538. Country: United Kingdom.
Observed 1 times. Targeted ports: 24186. Country: Senegal. Reputation: known attacker.
Observed 5 times. Targeted ports: 445. Country: Belgium.
Observed 8 times. Targeted ports: 21. Country: Belgium.
Observed 1 times. Targeted ports: 19285. Country: Ukraine.
Observed 13 times. Targeted ports: 22, 23. Country: Indonesia.
Observed 3 times. Targeted ports: 443. Country: Taiwan.
Observed 4 times. Targeted ports: 990. Country: Belgium.
Observed 24 times. Targeted ports: 5552. Country: United States.
Observed 3 times. Targeted ports: 49706. Country: United Kingdom. Reputation: known attacker.
Observed 5 times. Targeted ports: 18789. Country: Japan.
Observed 8 times. Targeted ports: 23. Country: Ukraine.
Observed 6 times. Targeted ports: 18789. Country: Japan. Reputation: known attacker.
Observed 1 times. Targeted ports: 12332. Country: Mexico.
Observed 3 times. Targeted ports: 56909. Country: The Netherlands.
Observed 1 times. Targeted ports: 46519. Country: Bangladesh.
Observed 3 times. Targeted ports: 3389. Country: Taiwan.
Observed 1 times. Targeted ports: 43391. Country: France.
Observed 31 times. Targeted ports: 23. Country: China.
Observed 1 times. Targeted ports: 27596. Country: Brazil.
Observed 8 times. Targeted ports: 5901. Country: Hong Kong.
Observed 4 times. Targeted ports: 23. Country: China.
Observed 3 times. Targeted ports: 3389. Country: Germany.
Observed 1 times. Targeted ports: 3059. Country: Brazil.
Observed 4 times. Targeted ports: 23. Country: Argentina.
Observed 5 times. Targeted ports: 22. Country: United Kingdom.
Observed 16 times. Targeted ports: 80, 443. Country: Singapore.
Observed 4 times. Targeted ports: 22. Country: Paraguay.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 5 times. Targeted ports: 23. Country: China.
Observed 7 times. Targeted ports: 23. Country: Mexico. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with invalid timestamp.
Observed 1 times. Targeted ports: 46083. Country: France.
Observed 2 times. Targeted ports: 5060. Country: United Kingdom.
Observed 10 times. Targeted ports: 22, 23. Country: Thailand.
Observed 3 times. Targeted ports: 443. Country: United States. Reputation: known attacker.
Observed 3 times. Targeted ports: 53650. Country: United Kingdom.
Observed 3 times. Targeted ports: 63840. Country: United Kingdom.
Observed 21 times. Targeted ports: 445. Country: India. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 1 times. Targeted ports: 63139. Country: Brazil.
Observed 10 times. Targeted ports: 22, 23. Country: Argentina.
Observed 1 times. Targeted ports: 50662. Country: United Kingdom.
Observed 1 times. Targeted ports: 63750. Country: United Kingdom.
Observed 6 times. Targeted ports: 2443. Country: United States.
Observed 6 times. Targeted ports: 22. Country: Ivory Coast.
Observed 3 times. Targeted ports: 2443. Country: United States. Reputation: mass scanner.
Observed 3 times. Targeted ports: 50717. Country: United Kingdom.
Observed 3 times. Targeted ports: 58389. Country: United Kingdom.
Observed 1 times. Targeted ports: 123. Country: Belgium.
Observed 1 times. Targeted ports: 36863. Country: United States.
Observed 1 times. Targeted ports: 43142. Country: Colombia.
Observed 26 times. Targeted ports: 15504. Country: Japan. Reputation: known attacker.
Observed 4 times. Targeted ports: 5985. Country: China. Reputation: known attacker.
Observed 5 times. Targeted ports: 23. Country: Brazil.
Observed 4 times. Targeted ports: 9300. Country: United States.
Observed 1 times. Targeted ports: 60762. Country: France. Reputation: known attacker.
Observed 5 times. Targeted ports: 445. Country: Egypt. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with broken ack.
Observed 2 times. Targeted ports: 49312. Country: United Kingdom.
Observed 24 times. Targeted ports: 7777. Country: United States.
Observed 8 times. Targeted ports: 17791, 60194. Country: United Kingdom.
Observed 3 times. Targeted ports: 53577. Country: United Kingdom.
Observed 4 times. Targeted ports: 1433. Country: China.
Observed 3 times. Targeted ports: 60017. Country: United Kingdom.
Observed 4 times. Targeted ports: 53. Country: Belgium.
Observed 6 times. Targeted ports: 9999. Country: Hong Kong. Reputation: known attacker.
Observed 4 times. Targeted ports: 9200. Country: China.
Observed 4 times. Targeted ports: 23. Country: China.
Observed 1 times. Targeted ports: 623. Country: United Kingdom. Reputation: known attacker.
Observed 3 times. Targeted ports: 56907. Country: The Netherlands.
Observed 3 times. Targeted ports: 51059. Country: United Kingdom.
Observed 7 times. Targeted ports: 20062, 63325. Country: United Kingdom.
Observed 92 times. Targeted ports: 43380, 43381, 43383, 43384, 43385, 43386, 43387, 43388, 43389, 43390, 43391, 43392, 43393, 43394, 43395, 43396, 43398. Country: The Netherlands. Reputation: known attacker. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with broken ack.
Observed 34 times. Targeted ports: 80, 443, 4443, 8443, 8888. Country: Ukraine.
Observed 36 times. Targeted ports: 5555. Country: United States.
Observed 4 times. Targeted ports: 10135. Country: China.
Observed 3 times. Targeted ports: 55569. Country: United Kingdom.
Observed 3 times. Targeted ports: 58285. Country: United Kingdom.
Observed 9 times. Targeted ports: 57361, 62158. Country: United Kingdom.
Observed 25 times. Targeted ports: 1443. Country: Malaysia.
Observed 6 times. Targeted ports: 5985. Country: Singapore.