Honeypot infrastructure watch
A community-maintained watchlist of IP infrastructure observed through honeypot telemetry. Historical observations include original tags, hit counts, and first/last-seen dates.
IOC feed · 484,024 indicators
Latest indicators
Live indicator delivery for this feed.
Observed 5 times. Targeted ports: 8443. Country: United Kingdom.
Observed 13 times. Targeted ports: 80. Country: Germany. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA HTTP Request excessive header repetition.
Observed 7 times. Targeted ports: 23. Country: Ukraine.
Observed 26 times. Targeted ports: 8595. Country: United States.
Observed 5 times. Targeted ports: 8443. Country: United States.
Observed 80 times. Targeted ports: 9222. Country: United States.
Observed 18 times. Targeted ports: 9013. Country: Germany. Reputation: known attacker.
Observed 6 times. Targeted ports: 7547. Country: China.
Observed 7 times. Targeted ports: 7547. Country: China.
Observed 11 times. Targeted ports: 3389. Country: Brazil.
Observed 7 times. Targeted ports: 7547. Country: China. Reputation: known attacker.
Observed 8 times. Targeted ports: 7547. Country: China.
Observed 1 times. Targeted ports: 11806. Country: Brazil.
Observed 8 times. Targeted ports: 23. Country: Russia.
Observed 4 times. Targeted ports: 2375. Country: United States. Reputation: known attacker.
Observed 59 times. Targeted ports: 27019. Country: United States.
Observed 2 times. Targeted ports: 8080. Country: China.
Observed 3 times. Targeted ports: 443. Country: Seychelles.
Observed 1 times. Targeted ports: 520. Country: Germany.
Observed 12 times. Targeted ports: 22, 23. Country: Ukraine.
Observed 4 times. Targeted ports: 23. Country: China. Reputation: known attacker.
Observed 1 times. Targeted ports: 5060. Country: Seychelles.
Observed 6 times. Targeted ports: 20000. Country: Mongolia. Reputation: known attacker.
Observed 5 times. Targeted ports: 8161. Country: Germany. Reputation: known attacker.
Observed 1 times. Targeted ports: 8080. Country: Vietnam.
Observed 6 times. Targeted ports: 22222. Country: China.
Observed 5 times. Targeted ports: 9032. Country: Singapore. Reputation: known attacker.
Observed 1 times. Targeted ports: 32999. Country: Bangladesh.
Observed 5 times. Targeted ports: 23. Country: Russia.
Observed 16 times. Targeted ports: 10443. Country: Germany.
Observed 1 times. Targeted ports: 40864. Country: Ukraine. Reputation: known attacker.
Observed 2 times. Targeted ports: 5000. Country: Hong Kong.
Observed 32 times. Targeted ports: 23. Country: Pakistan.
Observed 4 times. Targeted ports: 49152. Country: China.
Observed 4 times. Targeted ports: 9443. Country: United States. Reputation: known attacker.
Observed 1 times. Targeted ports: 53563. Country: Brazil. Reputation: known attacker.
Observed 6 times. Targeted ports: 23. Country: Uzbekistan.
Observed 3 times. Targeted ports: 27802. Country: United States. Reputation: known attacker.
Observed 22 times. Targeted ports: 3323. Country: United States. Reputation: known attacker.
Observed 5 times. Targeted ports: 3389. Country: China.
Observed 29 times. Targeted ports: 80. Country: United States.
Observed 1 times. Targeted ports: 5060. Country: South Korea.
Observed 16 times. Targeted ports: 22. Country: China. Alert categories: Misc activity. Signatures: ET INFO SSH session in progress on Expected Port.
Observed 18 times. Targeted ports: 3323. Country: United States. Reputation: known attacker.
Observed 2 times. Targeted ports: 8080. Country: United States.
Observed 18 times. Targeted ports: 445. Country: Georgia. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 4 times. Targeted ports: 23. Country: Ukraine.
Observed 1 times. Targeted ports: 14473. Country: Spain. Reputation: known attacker.
Observed 6 times. Targeted ports: 5937. Country: Iran.
Observed 5 times. Targeted ports: 10307. Country: China.
Observed 7 times. Targeted ports: 7443. Country: United States.
Observed 32 times. Targeted ports: 443, 2095, 2096, 8088, 8443, 8888. Country: United States.
Observed 11 times. Targeted ports: 2222. Country: Malaysia. Reputation: known attacker.
Observed 1 times. Targeted ports: 8059. Country: Spain.
Observed 4 times. Targeted ports: 7080. Country: Germany. Reputation: known attacker.
Observed 106 times. Targeted ports: 443. Country: United States. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Wrong direction first Data.
Observed 5 times. Targeted ports: 9302. Country: United States. Reputation: known attacker.
Observed 1 times. Targeted ports: 23. Country: United Kingdom. Reputation: known attacker.
Observed 1 times. Targeted ports: 2023. Country: China.
Observed 4 times. Targeted ports: 23. Country: China.
Observed 3 times. Targeted ports: 2023. Country: China. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction.
Observed 5 times. Targeted ports: 2023. Country: China.
Observed 9 times. Targeted ports: 2023. Country: China. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction.
Observed 10 times. Targeted ports: 2023. Country: China. Alert categories: Generic Protocol Command Decode. Signatures: SURICATA Applayer Detect protocol only one direction.
Observed 2 times. Targeted ports: 1433. Country: Vietnam.
Observed 1 times. Targeted ports: 39657. Country: Ecuador. Reputation: known attacker.
Observed 4 times. Targeted ports: 23. Country: China.
Observed 2 times. Targeted ports: 5900. Country: United Arab Emirates.
Observed 1 times. Targeted ports: 36259.
Observed 1 times. Targeted ports: 23. Country: Vietnam.
Observed 23 times. Targeted ports: 14000. Country: United States.
Observed 23 times. Targeted ports: 6936. Country: Germany.
Observed 4 times. Targeted ports: 2053. Country: United States.
Observed 592 times. Targeted ports: 203, 1405, 1639, 1659, 2176, 2304, 2420, 2872, 3067, 3700, 4557, 4671, 5018, 5581, 5683, 5741, 5933, 6349, 6832, 8029, 8555, 8614, 8762, 8899, 9099, 9295, 10724, 11159, 11482, 11824, 12162, 12828, 13637, 14716, 15288, 15376, 15384, 15444, 16780, 17279, 17593, 17599, 18530, 20338, 20346, 20702, 20736, 20997, 21433, 22930, 23599, 24485, 24739, 24857, 26418, 26704, 27411, 27817, 28381, 30518, 30532, 30844, 30916, 31099, 31103, 31169, 32568, 32961, 33347, 34300, 34632, 34760, 34803, 34895, 35054, 36273, 37073, 37450, 37500, 37636, 37728, 37850, 38226, 39383, 39807, 41335, 42259, 42837, 43048, 43257, 43560, 43940, 44291, 44717, 44952, 45029, 45042, 45216, 45224, 46036, 46585, 47332, 48592, 50032, 50248, 50378, 50547, 50972, 51250, 51710, 53380, 53794, 54321, 54752, 55973, 55997, 56273, 56297, 56301, 56315, 56461, 56730, 57211, 57605, 57875, 59126, 59599, 59857, 60562, 60695, 60956, 61099, 63293, 63624, 64196, 64700, 65047. Country: Sweden.
Observed 1 times. Targeted ports: 23094. Country: Colombia.
Observed 345 times. Targeted ports: 80, 443, 2082, 2083, 2086, 2087, 2095, 2096, 8080, 8443. Country: United States.
Observed 1 times. Targeted ports: 19325. Country: Brazil. Reputation: known attacker.
Observed 41 times. Targeted ports: 10086. Country: United States. Reputation: known attacker.
Observed 1 times. Targeted ports: 23. Country: China.
Observed 6 times. Targeted ports: 22. Country: Myanmar.
Observed 16 times. Targeted ports: 22. Country: South Korea. Alert categories: Misc activity. Signatures: ET INFO SSH session in progress on Expected Port. Usernames: root.
Observed 1 times. Targeted ports: 49181. Country: United States.
Observed 7 times. Targeted ports: 2222. Country: China.
Observed 10 times. Targeted ports: 22. Country: United States. Alert categories: Misc activity. Signatures: ET INFO SSH session in progress on Expected Port. Usernames: vet.
Observed 1 times. Targeted ports: 10007. Country: Argentina.
Observed 23 times. Targeted ports: 5003. Country: United States.
Observed 5 times. Targeted ports: 8443. Country: United States.
Observed 1 times. Targeted ports: 18085. Country: China.
Observed 104 times. Targeted ports: 22. Country: Vietnam. Reputation: known attacker. Alert categories: Generic Protocol Command Decode, Misc activity. Signatures: ET INFO SSH session in progress on Expected Port, SURICATA STREAM spurious retransmission. Usernames: root.
Observed 6 times. Targeted ports: 50050. Country: United States.
Observed 5 times. Targeted ports: 23. Country: Mexico.
Observed 19 times. Targeted ports: 445. Country: Argentina. Alert categories: Not Suspicious Traffic. Signatures: ET INFO Potentially unsafe SMBv1 protocol in use.
Observed 3 times. Targeted ports: 37777. Country: Moldova.
Observed 9 times. Targeted ports: 1224. Country: United States. Reputation: known attacker.
Observed 5 times. Targeted ports: 3232. Country: United States. Reputation: known attacker.
Observed 5 times. Targeted ports: 12443. Country: United States.