logo

Unmasking Deception: Navigating Red Herrings and Honeypots

ID: 99bfe74a-e446-5781-bdee-7dd99aaede99

STIX ID: report--99bfe74a-e446-5781-bdee-7dd99aaede99

Feed Name: Censys Blog

Threat Score
35/100

Date Published: 2023-10-11

Date Updated: 2026-04-27

Author: Ivonne Francia; The Censys Research Team

...
...

Censys researchers detected and analyzed a large set of deceptive hosts that generate oversized, noisy HTTP responses (including 37kB Server headers) built from Nuclei matchers, Rapid7 Recog examples, and a GitHub dataset. These services—characterized as tarpit-like and likely intended to confuse or pollute internet scanners—were concentrated in AWS autonomous systems (with early activity linked to China-operated AWS blocks), affected tens of thousands of services, and appear designed to trigger many vulnerability-identification rules rather than to directly exploit victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.