Ana SayfaHome Tehdit VeritabanıThreat Database Tehdit RaporlarıThreat Reports BlogBlog
RehberlerGuides
Tehdit İstihbaratı Nedir?What Is Threat Intelligence? MISP Nedir?What Is MISP? IP Blocklist Nedir?What Is an IP Blocklist? FortiGate'e Feed EklemeAdd Feed to FortiGate Ücretsiz CTİ KaynaklarıFree CTI Resources
Veri & ListelerData & Lists
Tüm ListelerAll Lists Feed ListeleriFeed Lists USOM Domain FeedUSOM Domain Feed SiberKapan Phishing URL FeedSiberKapan Phishing URL Feed FortiGate Saldırı HaritasıFortiGate Attack Map BGP / IP SorgulaBGP / IP Lookup Malware ÖrnekleriMalware Samples
Sisteminize EkleyinAdd to Your System
🔓 Feed Ekleme Rehberi🔓 Feed Setup Guide MISP Feed TAXII 2.1 STIX 2.1 RSS CVE Feed RSS IOC Feed
Veri GönderinContribute Data
FortiGate Webhook KurulumuFortiGate Webhook Setup HoneypotKapan KurSetup HoneypotKapan Nginx Watcher KurSetup Nginx Watcher API DokümantasyonAPI Documentation
HakkındaAbout
HakkımızdaAbout Us MetodolojiMethodology BaşarılarAchievements İletişimContact
HoneypotKapan

Saldırganları Tuzağa Düşür,
Topluluğu Koru
Trap Attackers,
Protect the Community

HoneypotKapan, SiberKapan platformuyla entegre çalışan açık kaynak bir honeypot sistemidir. Tek komutla kur — SSH, RDP, FTP ve 8 farklı servis üzerinden saldırganları tuzağa düşür, credential'larını logla ve SiberKapan topluluğuyla otomatik paylaş. HoneypotKapan is an open-source honeypot that integrates with the SiberKapan platform. Install with one command — trap attackers via SSH, RDP, FTP and 8 other services, log their credentials, and automatically share with the SiberKapan community.

Kurulum — tek komut Installation — single command
$ wget https://siberkapan.org/honeypot/install.py
$ sudo python3 install.py
Canlı Honeypot İstatistikleri Live Honeypot Statistics
283328
Toplam Yakalanan Olay Total Captured Events
21501
Unique Saldırgan IP Unique Attacker IPs
4
Aktif Honeypot Sensörü Active Honeypot Sensors
SSH
En Çok Hedeflenen Servis Most Targeted Service

Servis Bazlı Saldırı Dağılımı Attacks by Service

SSH
142794
TELNET
93794
HTTP
24552
SMTP
15825
RDP
2909
SMB
2496
VNC
449
FTP
258
MYSQL
211
MSSQL
41

En Çok Denenen Kullanıcı Adları Most Attempted Usernames

root
64589
Poot
43603
admin
13475
Pdmin
12986
Proot
10031
ubuntu
7367
user
4598
Padmin
2787
Pupport
1565
test
1495

Son Yakalanan IP'ler Recently Captured IPs

IPIP ServisService ÜlkeCountry TekrarHits Son GörülmeLast Seen
113.44.184.134 SSH — x67 08.10 02:10
77.239.124.152 SSH — x102 08.10 02:10
66.116.224.33 SSH India x6 08.10 02:06
95.47.175.5 TELNET — x6 08.10 02:05
102.220.161.126 SMTP Slovenia x44 08.10 02:00
176.53.159.198 SSH Turkey x3211 08.10 01:53
223.16.154.241 TELNET Hong Kong x4 08.10 01:51
80.94.92.55 SSH The Netherlands x441 08.10 01:46
101.96.202.144 SSH — x2 08.10 01:45
164.92.115.22 TELNET United States x153 08.10 01:45

Malware Örnek Yakalama Malware Sample Capture

Saldırganlar SSH honeypot'a "girdiğinde" indirmeye çalıştıkları zararlı yazılımlar güvenli şekilde yakalanır ve SHA256 ile imzalanır — dosyanın kendisi hiçbir zaman diskimize kaydedilmez veya çalıştırılmaz, sadece parmak izi (hash) MalwareBazaar'da bilinen ailelerle karşılaştırılır. When attackers "log into" the SSH honeypot and attempt to download malware, it is safely captured and fingerprinted with SHA256 — the file itself is never saved to disk or executed, only its hash is checked against known families on MalwareBazaar.

134
Yakalanan Örnek Samples Captured
108
Bilinen Aile (MalwareBazaar) Known Family (MalwareBazaar)
Tüm Örnekleri İncele → View All Samples →
Nasıl Çalışır? How Does It Work?
1
⬇️
Kur Install
Ubuntu sunucuna tek script ile kur. SiberKapan API anahtarını gir, servisler otomatik başlar. Install on your Ubuntu server with a single script. Enter your SiberKapan API key and services start automatically.
2
🎣
Tuzağa Düşür Trap
Firewall'ında NAT kuralı oluştur. Saldırganlar sahte servislere düşer, credential'ları loglanır. Create a NAT rule in your firewall. Attackers fall into fake services, credentials are logged.
3
🛡️
Topluluğu Koru Protect Community
3 denemeden sonra ya da bir zararlı örnek yakalandığında anında SiberKapan'a bildirim. Saldırgan IP tüm toplulukla paylaşılır. After 3 attempts, or immediately when a malware sample is captured, SiberKapan is notified. Attacker IP is shared with the entire community.
Saldırgan          Firewall            HoneypotKapan        SiberKapan
    │                   │                    │                    │
    │── SSH :22 ────────▶│                    │                    │
    │                   │── NAT :10022 ──────▶│                    │
    │◀──────────── SSH Banner (OpenSSH 8.9) ──│                    │
    │── user: admin ─────────────────────────▶│                    │
    │── pass: 123456 ────────────────────────▶│ Log: events.log    │
    │── pass: test ──────────────────────────▶│ Log: credentials   │
    │                                         │── 3. denemede ────▶│
    │                                         │   POST /feed/      │
    │                                         │   honeypot         │
    │                                         │                    │── DB'ye ekle
    │                                         │                    │── Blocklist güncelle
                                                                   Tüm topluluk korunur
Desteklenen Servisler Supported Services
:22

SSH

User + PasswordUser + Password

:3389

RDP

Bağlantı + UserConnection + User

:21

FTP

User + PasswordUser + Password

:23

Telnet

User + PasswordUser + Password

:445

SMB

Bağlantı + UserConnection + User

:1433

MSSQL

User adıUsername

:3306

MySQL

User adıUsername

:5900

VNC

Şifre hash'iPassword hash

:8080

HTTP

User + PasswordUser + Password

:5060

SIP/VoIP

SIP user adıSIP username

:25

SMTP

Auth denemesi + relayAuth attempt + relay

Başlamak İçin API Anahtarı Gerekiyor An API Key Is Required to Get Started

SiberKapan'a ücretsiz kayıt olun, API anahtarınızı alın ve kuruluma başlayın. Register for free on SiberKapan, get your API key, and start the installation.