HoneyLens Threat Intelligence

Welcome to HoneyLens — an independent research and educational project focused on network security, intrusion detection, and threat intelligence. Our honeypot sensor network captures, analyzes, and publishes real-time threat advisories on malicious IP addresses observed attacking internet-facing services.

Latest Threat Advisories

LOW 79.124.62.134

Our sensors detected sustained automated probe activity from IP 79.124.62.134 (Bulgaria/AS207812) between April 1-June 9, 2026, targeting multiple network services including MySQL. This appears to be …

HIGH 81.30.98.144

Iranian-origin threat actor at 81.30.98.144 conducted sustained SMTP credential harvesting operations targeting mail infrastructure over 17-day period, generating 174,000+ malicious events with focus …

LOW 93.123.109.127

Malicious activity detected from 93.123.109.127 (NL, AS48090). 629 events observed across SMTP, TCP. AI verdict: NOISE.

MEDIUM 178.16.54.22

An IP address from Düsseldorf, Germany (178.16.54.22) has been observed engaging in credential capture attempts and SMTP probing over a three-day period. The activity is assessed as noise but warrants…

HIGH 81.30.98.44

An IP address (81.30.98.44) has been observed engaging in credential capture attempts and SMTP probing activities over a period of 7 days, primarily targeting port 25/TCP. The activity is assessed as …

View all advisories →