2026-03-25 RDP #Honeypot IOCs - 4950 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
183.81.35.16 - 4233
143.198.111.35 - 636
80.94.95.221 - 12

Top ASNs:
AS18403 - 4233
AS14061 - 636
AS396982 - 36

Top Accounts:
hello - 4875
Administr - 18
(empty) - 9

Top ISPs:
FPT Telecom Company - 4233
DigitalOcean, LLC - 636
Google LLC - 36

Top Clients:
Unknown - 4950

Top Software:
Unknown - 4950

Top Keyboards:
Unknown - 4950

Top IP Classification:
Unknown - 4257
hosting & proxy - 636
hosting - 51

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-03-25 RDP #Honeypot IOCs - 3300 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
183.81.35.16 - 2822
143.198.111.35 - 424
80.94.95.221 - 8

Top ASNs:
AS18403 - 2822
AS14061 - 424
AS396982 - 24

Top Accounts:
hello - 3250
Administr - 12
(empty) - 6

Top ISPs:
FPT Telecom Company - 2822
DigitalOcean, LLC - 424
Google LLC - 24

Top Clients:
Unknown - 3300

Top Software:
Unknown - 3300

Top Keyboards:
Unknown - 3300

Top IP Classification:
Unknown - 2838
hosting & proxy - 424
hosting - 34

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-03-25 RDP #Honeypot IOCs - 1650 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
183.81.35.16 - 1411
143.198.111.35 - 212
80.94.95.221 - 4

Top ASNs:
AS18403 - 1411
AS14061 - 212
AS396982 - 12

Top Accounts:
hello - 1625
Administr - 6
(empty) - 3

Top ISPs:
FPT Telecom Company - 1411
DigitalOcean, LLC - 212
Google LLC - 12

Top Clients:
Unknown - 1650

Top Software:
Unknown - 1650

Top Keyboards:
Unknown - 1650

Top IP Classification:
Unknown - 1419
hosting & proxy - 212
hosting - 17

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-03-24 RDP #Honeypot IOCs - 2202 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
183.81.35.16 - 1449
217.218.67.254 - 342
167.71.102.165 - 120

Top ASNs:
AS18403 - 1449
AS49666 - 342
AS14061 - 120

Top Accounts:
hello - 2001
Administrator - 90
142.93.8.59 - 33

Top ISPs:
FPT Telecom Company - 1449
DCI - 342
DigitalOcean, LLC - 120

Top Clients:
Unknown - 2202

Top Software:
Unknown - 2202

Top Keyboards:
Unknown - 2202

Top IP Classification:
Unknown - 1932
hosting - 183
proxy - 87

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-03-24 RDP #Honeypot IOCs - 1468 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
183.81.35.16 - 966
217.218.67.254 - 228
167.71.102.165 - 80

Top ASNs:
AS18403 - 966
AS49666 - 228
AS14061 - 80

Top Accounts:
hello - 1334
Administrator - 60
142.93.8.59 - 22

Top ISPs:
FPT Telecom Company - 966
DCI - 228
DigitalOcean, LLC - 80

Top Clients:
Unknown - 1468

Top Software:
Unknown - 1468

Top Keyboards:
Unknown - 1468

Top IP Classification:
Unknown - 1288
hosting - 122
proxy - 58

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-03-24 RDP #Honeypot IOCs - 734 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
183.81.35.16 - 483
217.218.67.254 - 114
167.71.102.165 - 40

Top ASNs:
AS18403 - 483
AS49666 - 114
AS14061 - 40

Top Accounts:
hello - 667
Administrator - 30
142.93.8.59 - 11

Top ISPs:
FPT Telecom Company - 483
DCI - 114
DigitalOcean, LLC - 40

Top Clients:
Unknown - 734

Top Software:
Unknown - 734

Top Keyboards:
Unknown - 734

Top IP Classification:
Unknown - 644
hosting - 61
proxy - 29

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-03-23 RDP #Honeypot IOCs - 462 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
103.9.207.80 - 108
137.184.100.236 - 81
217.218.67.254 - 51

Top ASNs:
AS135905 - 108
AS14061 - 96
AS49666 - 51

Top Accounts:
hello - 279
Administr - 63
142.93.8.59 - 57

Top ISPs:
SUNSOFT - 108
DigitalOcean, LLC - 96
DCI - 51

Top Clients:
Unknown - 462

Top Software:
Unknown - 462

Top Keyboards:
Unknown - 462

Top IP Classification:
Unknown - 273
hosting - 189

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-03-23 RDP #Honeypot IOCs - 308 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
103.9.207.80 - 72
137.184.100.236 - 54
217.218.67.254 - 34

Top ASNs:
AS135905 - 72
AS14061 - 64
AS49666 - 34

Top Accounts:
hello - 186
Administr - 42
142.93.8.59 - 38

Top ISPs:
SUNSOFT - 72
DigitalOcean, LLC - 64
DCI - 34

Top Clients:
Unknown - 308

Top Software:
Unknown - 308

Top Keyboards:
Unknown - 308

Top IP Classification:
Unknown - 182
hosting - 126

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-03-23 RDP #Honeypot IOCs - 154 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
103.9.207.80 - 36
137.184.100.236 - 27
217.218.67.254 - 17

Top ASNs:
AS135905 - 36
AS14061 - 32
AS49666 - 17

Top Accounts:
hello - 93
Administr - 21
142.93.8.59 - 19

Top ISPs:
SUNSOFT - 36
DigitalOcean, LLC - 32
DCI - 17

Top Clients:
Unknown - 154

Top Software:
Unknown - 154

Top Keyboards:
Unknown - 154

Top IP Classification:
Unknown - 91
hosting - 63

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

Sasha insisted we co-author this, and honestly, after the weekend she had, I didn’t have the authority to say no. 🦩

- We arrived at @bsidesroc as first-timers
- We left with a suspicious number of new friends, at least three inside jokes, and what I can only assume is the beginning of Sasha’s unofficial “Flamingo Ambassador Program.”

Sasha, for her part, would like it formally noted that:
- She achieved a 100% success rate in attracting delightful humans
- She was questioned about her honeypots approximately 47 times (conservative estimate)
- She may now have more friends in Rochester than I do

Post-conference, we migrated to Bitter Honey, which Sasha has classified as “Tequila Research HQ.”

Extensive… research… was conducted. 👍

Findings include:
- The tequila selection is both impressive and slightly dangerous
- The food is absolutely worth writing home about
- “Quick dinner” is a fictional concept when you’re surrounded by great people

Somewhere between the laughter, the stories, and the “just one more” moments, the night quietly turned into one of those you wish you could bottle. 💃

The flight home added a touch of airborne chaos, with turbulence strong enough to keep everyone seated, including the FAs. Sasha remained calm, mostly because she does not believe in gravity. 🛩️

And now it’s Monday. 🤷‍♀️

Sasha is back to monitoring global flamingo #honeypot operations.
I’m back to working on my Portugal move.

But we’re both still carrying that post-conference glow, the kind powered by community, connection, and just the right amount of tequila-fueled storytelling!!

Rochester, we’ll be back!!!