HoneyLabs
iAnonymous lookups: 10/min, 60/hr per source IP. Sign in (free) to lift the limit, run heavier queries, and get an API key for MCP / HTTP.

Filtered actors

port=15800

21 unique IPs · 27 events · 5 countries · 5 ASNs

Activity · last 7d

2026-06-16: 2 events2026-06-17: 6 events2026-06-18: 4 events2026-06-19: 4 events2026-06-20: 2 events2026-06-21: 9 events

peak 9 on 2026-06-21

Top source networks · click to refine

Refine
Turn this query into a daily email digest or an IOC feed URL.Save as feed

Sample payloads

top distinct probes matching this query
ProtocolPortProbe / payloadHitsExample
HTTP15800GET /
UA: Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpan…
20 · 17 IPs35.203.211.73 →
RDP15800/*�Cookie: mstshash=Administr 35.181.86.60 →
HTTP15800GET /favicon.ico
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
2 · 2 IPs111.7.96.152 →
HTTP15800GET /.well-known/security.txt
UA: Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpan…
2 · 2 IPs162.216.149.213 →
IPCountryASNTop portsEvents
Showing top 50 by event count. Window is the last 7d. Add or remove filters by clicking any value on a per-IP report.