← Back to feeds
IOCFREE Searchable

Honeypot infrastructure watch

A community-maintained watchlist of IP infrastructure observed through honeypot telemetry. Historical observations include original tags, hit counts, and first/last-seen dates.

485,918
Indicators
0
Subscribers
8/13/2026
Last update
Open
Access
honeypothistorical
Free

This community feed is publicly available for research.

Open this feed in app
Publisher
UQC4BL9h…w4tDk7
@hookgab

IOC feed · 485,918 indicators

Community
View researchers
Wallet-based publisher identity

Latest indicators

Live indicator delivery for this feed.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 9 times. Targeted ports: 9200. Country: United States. Reputation: known attacker.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 11 times. Targeted ports: 80. Country: United States. Reputation: known attacker.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 443. Country: United States. Reputation: known attacker.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 23. Country: Chile.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 10 times. Targeted ports: 3389. Country: United States. Reputation: known attacker. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Mismatch protocol both directions, SURICATA TLS invalid record type.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 7547. Country: United States. Reputation: known attacker.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 8882. Country: China.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 31337. Country: United States. Reputation: known attacker. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 9 times. Targeted ports: 9200. Country: United States.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 20 times. Targeted ports: 445. Country: Venezuela. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 6 times. Targeted ports: 5985. Country: Dominican Republic.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 61159. Country: Brazil.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 16071. Country: Morocco.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 16 times. Targeted ports: 8899, 34567. Country: United States.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 3389. Country: Pakistan.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 1337. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 6 times. Targeted ports: 1337. Country: China.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 1337. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Country: The Netherlands. Reputation: known attacker.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 6 times. Targeted ports: 1337. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 1337. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 5276. Country: Burkina Faso.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 31046. Country: Colombia.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 23. Country: Russia.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 38 times. Targeted ports: 27751. Country: United States.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 3 times. Targeted ports: 2121. Country: United States. Reputation: known attacker.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 80. Country: Germany. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with broken ack.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 49 times. Targeted ports: 2906. Country: United States.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 17 times. Targeted ports: 23. Country: Russia.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 55845. Country: Peru.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 25 times. Targeted ports: 23. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 1027. Country: Germany.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 8443. Country: United States.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 52 times. Targeted ports: 27750. Country: United States. Reputation: known attacker.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 23. Country: Russia.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 27 times. Targeted ports: 3389. Country: Belgium. Alert categories: Detection of a Network Scan, Generic Protocol Command Decode. Signatures: ET SCAN RDP Connection Attempt from Nmap, SURICATA Applayer Mismatch protocol both directions, SURICATA TLS invalid record type.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 3389. Country: Belgium.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 3389. Country: Belgium.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 11 times. Targeted ports: 80. Country: Pakistan.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 29197. Country: United States.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 10759. Country: China. Reputation: known attacker.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 58853. Country: Senegal.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 23. Country: China.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 20 times. Targeted ports: 26196. Country: The Netherlands. Reputation: known attacker. Alert categories: Misc activity. Signatures: ET INFO SSH session in progress on Unusual Port.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 5 times. Targeted ports: 23. Country: Syria.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 2 times. Targeted ports: 389. Country: Brazil.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 5 times. Targeted ports: 445. Country: Mexico. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with broken ack.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 23. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 27017. Country: United States. Reputation: known attacker.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 23. Country: China.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 35 times. Targeted ports: 7004. Country: Japan.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 5 times. Targeted ports: 23. Country: Argentina.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 59367. Country: Brazil.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 6 times. Targeted ports: 3389. Country: Switzerland.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 46136. Country: Brazil.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 23. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 5 times. Targeted ports: 50001. Country: United States.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 35406. Country: United Kingdom.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 23. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 23. Country: Brazil.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 52 times. Targeted ports: 27749. Country: United States. Reputation: known attacker.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 23. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 22. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 36011. Country: Brazil.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 445. Country: Nigeria.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 14 times. Targeted ports: 22, 23. Country: Ecuador.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 19 times. Targeted ports: 445. Country: Algeria. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 63862. Country: Brazil.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 23. Country: Brazil.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 2 times. Targeted ports: 1433. Country: Ethiopia.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 5 times. Targeted ports: 5985. Country: India. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with broken ack.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 23. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 18562. Country: Russia.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 54295. Country: Brazil.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 37 times. Targeted ports: 23. Country: Pakistan.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 13 times. Targeted ports: 22, 23. Country: Ukraine.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 38565. Country: Brazil. Reputation: known attacker.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 5 times. Targeted ports: 7777. Country: Australia.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 4 times. Targeted ports: 23. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 45396. Country: Brazil.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 10431. Country: China. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM spurious retransmission.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 10431. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 10431. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 10431. Country: China.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 10431. Country: China. Reputation: known attacker.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 18 times. Targeted ports: 23. Country: Pakistan.

Last observed Aug 31, 2026First observed Aug 31, 2026Source: tpot-honeypot

Observed 8 times. Targeted ports: 8080. Country: Pakistan.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 7 times. Targeted ports: 3389. Country: Germany.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 34972. Country: United States.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 2 times. Targeted ports: 139. Country: Indonesia.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 27020. Country: United States. Reputation: known attacker.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 6 times. Targeted ports: 2222. Country: China.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 6 times. Targeted ports: 5038. Country: United Kingdom. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA STREAM Packet with broken ack.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 3 times. Targeted ports: 80. Country: Germany.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 2 times. Targeted ports: 5900. Country: Bulgaria. Reputation: known attacker.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 57047. Country: Mexico.

Last observed Aug 31, 2026Source: tpot-honeypot

Observed 1 times. Targeted ports: 1433. Country: Venezuela.