Unmasking Deception: Navigating Red Herrings and Honeypots
ID: 99bfe74a-e446-5781-bdee-7dd99aaede99
STIX ID: report--99bfe74a-e446-5781-bdee-7dd99aaede99
Feed Name: Censys Blog
Date Published: 2023-10-11
Date Updated: 2026-04-27
Author: Ivonne Francia; The Censys Research Team
Censys researchers detected and analyzed a large set of deceptive hosts that generate oversized, noisy HTTP responses (including 37kB Server headers) built from Nuclei matchers, Rapid7 Recog examples, and a GitHub dataset. These services—characterized as tarpit-like and likely intended to confuse or pollute internet scanners—were concentrated in AWS autonomous systems (with early activity linked to China-operated AWS blocks), affected tens of thousands of services, and appear designed to trigger many vulnerability-identification rules rather than to directly exploit victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
