Ana SayfaHome Tehdit VeritabanıThreat Database Tehdit RaporlarıThreat Reports BlogBlog
RehberlerGuides
Tehdit İstihbaratı Nedir?What Is Threat Intelligence? MISP Nedir?What Is MISP? IP Blocklist Nedir?What Is an IP Blocklist? FortiGate'e Feed EklemeAdd Feed to FortiGate Ücretsiz CTİ KaynaklarıFree CTI Resources
Veri & ListelerData & Lists
Tüm ListelerAll Lists Feed ListeleriFeed Lists USOM Domain FeedUSOM Domain Feed SiberKapan Phishing URL FeedSiberKapan Phishing URL Feed FortiGate Saldırı HaritasıFortiGate Attack Map BGP / IP SorgulaBGP / IP Lookup Malware ÖrnekleriMalware Samples
Sisteminize EkleyinAdd to Your System
🔓 Feed Ekleme Rehberi🔓 Feed Setup Guide MISP Feed TAXII 2.1 STIX 2.1 RSS CVE Feed RSS IOC Feed
Veri GönderinContribute Data
FortiGate Webhook KurulumuFortiGate Webhook Setup HoneypotKapan KurSetup HoneypotKapan Nginx Watcher KurSetup Nginx Watcher API DokümantasyonAPI Documentation
HakkındaAbout
HakkımızdaAbout Us MetodolojiMethodology BaşarılarAchievements İletişimContact
HoneypotKapan

Saldırganları Tuzağa Düşür,
Topluluğu Koru
Trap Attackers,
Protect the Community

HoneypotKapan, SiberKapan platformuyla entegre çalışan açık kaynak bir honeypot sistemidir. Tek komutla kur — SSH, RDP, FTP ve 8 farklı servis üzerinden saldırganları tuzağa düşür, credential'larını logla ve SiberKapan topluluğuyla otomatik paylaş. HoneypotKapan is an open-source honeypot that integrates with the SiberKapan platform. Install with one command — trap attackers via SSH, RDP, FTP and 8 other services, log their credentials, and automatically share with the SiberKapan community.

Kurulum — tek komut Installation — single command
$ wget https://siberkapan.org/honeypot/install.py
$ sudo python3 install.py
Canlı Honeypot İstatistikleri Live Honeypot Statistics
226058
Toplam Yakalanan Olay Total Captured Events
18848
Unique Saldırgan IP Unique Attacker IPs
4
Aktif Honeypot Sensörü Active Honeypot Sensors
SSH
En Çok Hedeflenen Servis Most Targeted Service

Servis Bazlı Saldırı Dağılımı Attacks by Service

SSH
104372
TELNET
82141
HTTP
19482
SMTP
14231
RDP
2485
SMB
2465
VNC
449
FTP
237
MYSQL
174
MSSQL
22

En Çok Denenen Kullanıcı Adları Most Attempted Usernames

root
48739
Poot
38978
Pdmin
11567
admin
11431
Proot
9056
ubuntu
6573
user
3884
Padmin
2439
Pupport
1434
Puest
1135

Son Yakalanan IP'ler Recently Captured IPs

IPIP ServisService ÜlkeCountry TekrarHits Son GörülmeLast Seen
92.205.229.83 SSH x222 15.09 03:23
167.148.195.3 TELNET x39 15.09 03:22
176.53.159.197 SSH Turkey x2143 15.09 03:16
14.225.204.246 SSH x126 15.09 03:12
196.251.121.220 SMTP x34 15.09 03:01
139.135.45.75 TELNET x3 15.09 02:58
80.94.92.55 SSH The Netherlands x303 15.09 02:48
38.25.18.182 TELNET x8 15.09 02:38
178.178.120.138 TELNET x8 15.09 02:34
80.94.95.116 SSH x8 15.09 02:32

Malware Örnek Yakalama Malware Sample Capture

Saldırganlar SSH honeypot'a "girdiğinde" indirmeye çalıştıkları zararlı yazılımlar güvenli şekilde yakalanır ve SHA256 ile imzalanır — dosyanın kendisi hiçbir zaman diskimize kaydedilmez veya çalıştırılmaz, sadece parmak izi (hash) MalwareBazaar'da bilinen ailelerle karşılaştırılır. When attackers "log into" the SSH honeypot and attempt to download malware, it is safely captured and fingerprinted with SHA256 — the file itself is never saved to disk or executed, only its hash is checked against known families on MalwareBazaar.

97
Yakalanan Örnek Samples Captured
71
Bilinen Aile (MalwareBazaar) Known Family (MalwareBazaar)
Tüm Örnekleri İncele → View All Samples →
Nasıl Çalışır? How Does It Work?
1
⬇️
Kur Install
Ubuntu sunucuna tek script ile kur. SiberKapan API anahtarını gir, servisler otomatik başlar. Install on your Ubuntu server with a single script. Enter your SiberKapan API key and services start automatically.
2
🎣
Tuzağa Düşür Trap
Firewall'ında NAT kuralı oluştur. Saldırganlar sahte servislere düşer, credential'ları loglanır. Create a NAT rule in your firewall. Attackers fall into fake services, credentials are logged.
3
🛡️
Topluluğu Koru Protect Community
3 denemeden sonra ya da bir zararlı örnek yakalandığında anında SiberKapan'a bildirim. Saldırgan IP tüm toplulukla paylaşılır. After 3 attempts, or immediately when a malware sample is captured, SiberKapan is notified. Attacker IP is shared with the entire community.
Saldırgan          Firewall            HoneypotKapan        SiberKapan
    │                   │                    │                    │
    │── SSH :22 ────────▶│                    │                    │
    │                   │── NAT :10022 ──────▶│                    │
    │◀──────────── SSH Banner (OpenSSH 8.9) ──│                    │
    │── user: admin ─────────────────────────▶│                    │
    │── pass: 123456 ────────────────────────▶│ Log: events.log    │
    │── pass: test ──────────────────────────▶│ Log: credentials   │
    │                                         │── 3. denemede ────▶│
    │                                         │   POST /feed/      │
    │                                         │   honeypot         │
    │                                         │                    │── DB'ye ekle
    │                                         │                    │── Blocklist güncelle
                                                                   Tüm topluluk korunur
Desteklenen Servisler Supported Services
:22

SSH

User + PasswordUser + Password

:3389

RDP

Bağlantı + UserConnection + User

:21

FTP

User + PasswordUser + Password

:23

Telnet

User + PasswordUser + Password

:445

SMB

Bağlantı + UserConnection + User

:1433

MSSQL

User adıUsername

:3306

MySQL

User adıUsername

:5900

VNC

Şifre hash'iPassword hash

:8080

HTTP

User + PasswordUser + Password

:5060

SIP/VoIP

SIP user adıSIP username

:25

SMTP

Auth denemesi + relayAuth attempt + relay

Başlamak İçin API Anahtarı Gerekiyor An API Key Is Required to Get Started

SiberKapan'a ücretsiz kayıt olun, API anahtarınızı alın ve kuruluma başlayın. Register for free on SiberKapan, get your API key, and start the installation.