Port 9001 (Tor)

HoneyLabs honeypots recorded 1,239 probes against destination port 9001 (Tor) from 288 distinct source IP addresses in the last 7 days.

First observed 2026-09-23 02:59:51, most recently 2026-09-30 01:39:39 (UTC).

Most active source addresses

Source IPProbesNetworkCountry
176.65.149.152273Pfcloud UG (haftungsbeschrankt)NL
93.174.93.12114IP Volume incNL
165.22.182.10640DigitalOcean, LLCUS
45.33.60.21140Akamai Connected CloudUS
159.223.163.16540DigitalOcean, LLCUS
138.68.238.8140DigitalOcean, LLCUS
80.82.77.20234IP Volume incNL
89.248.171.2433IP Volume incNL

Networks it comes from

ASNOrganisationProbesSource IPs
AS51396Pfcloud UG (haftungsbeschrankt)2815
AS202425IP Volume inc1967
AS14061DigitalOcean, LLC15425
AS6939Hurricane Electric LLC14982
AS16509Amazon.com, Inc.759
AS396982Google LLC4646

Where it comes from

CountryProbes
United States541
The Netherlands477
Hong Kong50
Russia33
Iran29
China17

Client strings seen on this port

User agentProbes
Python/3.10 aiohttp/3.8.4179
visionheight.com/scan Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Chrome/126.0.0.0 Safari/537.3649
Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity40
Mozilla/5.0 zgrab/0.x34
Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)24

Port report

Port report

Loading live data…