HoneyLabs
iAnonymous lookups: 10/min, 60/hr per source IP. Sign in (free) to lift the limit, run heavier queries, and get an API key for MCP / HTTP.

Filtered actors

port=9228

32 unique IPs · 37 events · 7 countries · 7 ASNs

Activity · last 7d

2026-06-16: 4 events2026-06-17: 5 events2026-06-18: 6 events2026-06-19: 3 events2026-06-20: 5 events2026-06-21: 4 events2026-06-22: 8 events2026-06-23: 2 events

peak 8 on 2026-06-22

Top source networks · click to refine

Refine
Turn this query into a daily email digest or an IOC feed URL.Save as feed

Sample payloads

top distinct probes matching this query
ProtocolPortProbe / payloadHitsExample
HTTP9228GET /
UA: Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpan…
23 · 20 IPs35.203.211.48 →
HTTP9228GET /..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:146.0) Gecko/20100101 Firefox/146.0
4 · 3 IPs5.187.35.142 →
-92280a3 · 3 IPs85.217.140.51 →
HTTP9228GET /.well-known/security.txt
UA: Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpan…
3 · 2 IPs162.216.149.177 →
HTTP9228GET /squid-internal-mgr/cachemgr.cgi
UA: Mozilla/5.0 zgrab/0.x
2 · 2 IPs142.93.72.196 →
HTTP9228GET /favicon.ico
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
147.77.228.238 →
TPKT9228TPKT / COTP (ISO-TSAP)03 00 00 13 0e e0 00 00 00 00 00 01 00 08 00 03 00 00 00115.204.244.83 →
IPCountryASNTop portsEvents
Showing top 50 by event count. Window is the last 7d. Add or remove filters by clicking any value on a per-IP report.