HoneyLabs
iAnonymous lookups: 30/hr per source IP. Sign in (free) to lift the limit, run heavier queries, and get an API key for MCP / HTTP.

Filtered actors · live query

Edit and re-run: add AND country:NL, OR port:3389, NOT tag:scanner  ·  full syntax

1 unique IPs · 8 events · 1 countries · 1 ASNs

Top source networks · click to refine

Turn this query into a daily email digest or an IOC feed URL.Save as feed

Sample payloads

top distinct probes matching this query
ProtocolPortProbe / payloadHitsExample
-445/SMB00 00 00 88 ff 53 4d 42 73 00 00 00 00 18 07 c0 00 00 00 00 00 00 00 00 …(140 bytes)1190.75.89.162 →
-445/SMB00 00 00 4a ff 53 4d 42 25 00 00 00 00 18 01 28 00 00 00 00 00 00 00 00 …(78 bytes)1190.75.89.162 →
-445/SMB00 00 00 5c ff 53 4d 42 75 00 00 00 00 18 07 c0 00 00 00 00 00 00 00 00 …(96 bytes)1190.75.89.162 →
-445/SMB00 00 00 63 ff 53 4d 42 73 00 00 00 00 18 01 20 00 00 00 00 00 00 00 00 …(103 bytes)1190.75.89.162 →
-445/SMB00 00 00 4e ff 53 4d 42 32 00 00 00 00 18 07 c0 00 00 00 00 00 00 00 00 …(82 bytes)1190.75.89.162 →
-445/SMB��SMBrS���@bPC NETWORK PROGRAM 1.0LANMAN1.0Windows for Workgroups 3.1aLM1.2X002LANMAN2.1NT LM 0.121190.75.89.162 →
-445/SMB[�SMBu /K�^�\\172.16.1.115\IPC$?????EPATH_REPLACE__?????1190.75.89.162 →
-445/SMBT�SMBr(/K�^1LANMAN1.0LM1.2X002NT LANMAN 1.0NT LM 0.121190.75.89.162 →
IPCountryASNTop portsEvents
Showing top 50 by event count over the last 1h. Country, ASN and port cells narrow this query; any IP opens its full report scoped to it.