2026-04-25 RDP #Honeypot IOCs - 132 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
103.149.252.223 - 30
162.216.149.210 - 12
45.227.254.155 - 12

Top ASNs:
AS396982 - 30
AS135918 - 30
AS63949 - 15

Top Accounts:
hello - 33
Test - 30
Administr - 24

Top ISPs:
Google LLC - 30
AI-SOL - 30
Akamai Technologies, Inc. - 15

Top Clients:
Unknown - 132

Top Software:
Unknown - 132

Top Keyboards:
Unknown - 132

Top IP Classification:
Unknown - 81
hosting - 45
hosting & proxy - 6

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-04-25 RDP #Honeypot IOCs - 88 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
103.149.252.223 - 20
162.216.149.210 - 8
45.227.254.155 - 8

Top ASNs:
AS396982 - 20
AS135918 - 20
AS63949 - 10

Top Accounts:
hello - 22
Test - 20
Administr - 16

Top ISPs:
Google LLC - 20
AI-SOL - 20
Akamai Technologies, Inc. - 10

Top Clients:
Unknown - 88

Top Software:
Unknown - 88

Top Keyboards:
Unknown - 88

Top IP Classification:
Unknown - 54
hosting - 30
hosting & proxy - 4

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-04-25 RDP #Honeypot IOCs - 44 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
103.149.252.223 - 10
162.216.149.210 - 4
45.227.254.155 - 4

Top ASNs:
AS396982 - 10
AS135918 - 10
AS63949 - 5

Top Accounts:
hello - 11
Test - 10
Administr - 8

Top ISPs:
Google LLC - 10
AI-SOL - 10
Akamai Technologies, Inc. - 5

Top Clients:
Unknown - 44

Top Software:
Unknown - 44

Top Keyboards:
Unknown - 44

Top IP Classification:
Unknown - 27
hosting - 15
hosting & proxy - 2

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

54 days of SSH honeypot logs, 28 confirmed human operators behind the keyboard. Not bots — actual humans, probing, testing, adapting. There's something fascinating about watching that pattern emerge from the noise. Threat intel starts with patience and a good listener. 🍵 #infosec #honeypot #blueteam
https://infosec.pub/post/45495005
SSH honeypot for 54daya saw 28 human operators - Infosec.Pub

Lemmy

🕵️ 𝗜𝗣 𝗰𝗵𝗲𝗹𝗼𝘂 𝗱𝘂 𝗷𝗼𝘂𝗿
🕵️ FICHE SUSPECT : "Le Randonneur Apache de Helsinki"

📍 109.107.190.8 | FI | AS210644 (Aeza Intl)
🎯 3 tentatives détectées
💥 CVE-2021-41773 & 42013 (path traversal Apache)
💥 CVE-2017-9841 (PHPUnit RCE)
🔍 UA: libredtail-http

Ce gars encode "../../bin/sh" en double URL encoding… comme si le firewall ne lisait pas le braille 🙃

#honeypot #infosec #threatintel
🗺️ https://cyberveille.ch/map/

🌍 Pew Pew CH (Infomaniak) — Honeypot

Carte en temps réel des attaques détectées par CrowdSec sur le serveur CyberVeille (Infomaniak, Suisse). Données issues des 24 dernières heures.

CyberVeille

2026-04-24 RDP #Honeypot IOCs - 111 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
80.94.95.221 - 27
45.142.193.145 - 12
147.185.132.204 - 9

Top ASNs:
AS396982 - 36
AS204428 - 27
AS214295 - 12

Top Accounts:
Administr - 33
hello - 15
Test - 12

Top ISPs:
Google LLC - 36
SS-Net - 27
Skynet Network LTD - 12

Top Clients:
Unknown - 111

Top Software:
Unknown - 111

Top Keyboards:
Unknown - 111

Top IP Classification:
Unknown - 69
hosting - 39
mobile & hosting - 3

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-04-24 RDP #Honeypot IOCs - 74 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
80.94.95.221 - 18
45.142.193.145 - 8
147.185.132.204 - 6

Top ASNs:
AS396982 - 24
AS204428 - 18
AS214295 - 8

Top Accounts:
Administr - 22
hello - 10
Test - 8

Top ISPs:
Google LLC - 24
SS-Net - 18
Skynet Network LTD - 8

Top Clients:
Unknown - 74

Top Software:
Unknown - 74

Top Keyboards:
Unknown - 74

Top IP Classification:
Unknown - 46
hosting - 26
mobile & hosting - 2

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-04-24 RDP #Honeypot IOCs - 37 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
80.94.95.221 - 9
45.142.193.145 - 4
147.185.132.204 - 3

Top ASNs:
AS396982 - 12
AS204428 - 9
AS214295 - 4

Top Accounts:
Administr - 11
hello - 5
Test - 4

Top ISPs:
Google LLC - 12
SS-Net - 9
Skynet Network LTD - 4

Top Clients:
Unknown - 37

Top Software:
Unknown - 37

Top Keyboards:
Unknown - 37

Top IP Classification:
Unknown - 23
hosting - 13
mobile & hosting - 1

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-04-23 RDP #Honeypot IOCs - 171 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
192.155.91.45 - 45
193.142.146.139 - 18
20.55.73.136 - 15

Top ASNs:
AS63949 - 45
AS396982 - 36
AS48721 - 21

Top Accounts:
hello - 69
Test - 27
Domain - 18

Top ISPs:
Akamai Technologies, Inc. - 45
Google LLC - 36
Flyservers S.A. - 21

Top Clients:
Unknown - 171

Top Software:
Unknown - 171

Top Keyboards:
Unknown - 171

Top IP Classification:
hosting - 99
Unknown - 69
mobile & hosting - 3

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security