54 days of SSH honeypot logs, 28 confirmed human operators behind the keyboard. Not bots — actual humans, probing, testing, adapting. There's something fascinating about watching that pattern emerge from the noise. Threat intel starts with patience and a good listener. 🍵 #infosec #honeypot #blueteam
https://infosec.pub/post/45495005
SSH honeypot for 54daya saw 28 human operators - Infosec.Pub

Lemmy

🕵️ 𝗜𝗣 𝗰𝗵𝗲𝗹𝗼𝘂 𝗱𝘂 𝗷𝗼𝘂𝗿
🕵️ FICHE SUSPECT : "Le Randonneur Apache de Helsinki"

📍 109.107.190.8 | FI | AS210644 (Aeza Intl)
🎯 3 tentatives détectées
💥 CVE-2021-41773 & 42013 (path traversal Apache)
💥 CVE-2017-9841 (PHPUnit RCE)
🔍 UA: libredtail-http

Ce gars encode "../../bin/sh" en double URL encoding… comme si le firewall ne lisait pas le braille 🙃

#honeypot #infosec #threatintel
🗺️ https://cyberveille.ch/map/

🌍 Pew Pew CH (Infomaniak) — Honeypot

Carte en temps réel des attaques détectées par CrowdSec sur le serveur CyberVeille (Infomaniak, Suisse). Données issues des 24 dernières heures.

CyberVeille

2026-04-24 RDP #Honeypot IOCs - 111 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
80.94.95.221 - 27
45.142.193.145 - 12
147.185.132.204 - 9

Top ASNs:
AS396982 - 36
AS204428 - 27
AS214295 - 12

Top Accounts:
Administr - 33
hello - 15
Test - 12

Top ISPs:
Google LLC - 36
SS-Net - 27
Skynet Network LTD - 12

Top Clients:
Unknown - 111

Top Software:
Unknown - 111

Top Keyboards:
Unknown - 111

Top IP Classification:
Unknown - 69
hosting - 39
mobile & hosting - 3

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-04-24 RDP #Honeypot IOCs - 74 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
80.94.95.221 - 18
45.142.193.145 - 8
147.185.132.204 - 6

Top ASNs:
AS396982 - 24
AS204428 - 18
AS214295 - 8

Top Accounts:
Administr - 22
hello - 10
Test - 8

Top ISPs:
Google LLC - 24
SS-Net - 18
Skynet Network LTD - 8

Top Clients:
Unknown - 74

Top Software:
Unknown - 74

Top Keyboards:
Unknown - 74

Top IP Classification:
Unknown - 46
hosting - 26
mobile & hosting - 2

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-04-24 RDP #Honeypot IOCs - 37 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
80.94.95.221 - 9
45.142.193.145 - 4
147.185.132.204 - 3

Top ASNs:
AS396982 - 12
AS204428 - 9
AS214295 - 4

Top Accounts:
Administr - 11
hello - 5
Test - 4

Top ISPs:
Google LLC - 12
SS-Net - 9
Skynet Network LTD - 4

Top Clients:
Unknown - 37

Top Software:
Unknown - 37

Top Keyboards:
Unknown - 37

Top IP Classification:
Unknown - 23
hosting - 13
mobile & hosting - 1

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-04-23 RDP #Honeypot IOCs - 171 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
192.155.91.45 - 45
193.142.146.139 - 18
20.55.73.136 - 15

Top ASNs:
AS63949 - 45
AS396982 - 36
AS48721 - 21

Top Accounts:
hello - 69
Test - 27
Domain - 18

Top ISPs:
Akamai Technologies, Inc. - 45
Google LLC - 36
Flyservers S.A. - 21

Top Clients:
Unknown - 171

Top Software:
Unknown - 171

Top Keyboards:
Unknown - 171

Top IP Classification:
hosting - 99
Unknown - 69
mobile & hosting - 3

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-04-23 RDP #Honeypot IOCs - 114 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
192.155.91.45 - 30
193.142.146.139 - 12
20.55.73.136 - 10

Top ASNs:
AS63949 - 30
AS396982 - 24
AS48721 - 14

Top Accounts:
hello - 46
Test - 18
Domain - 12

Top ISPs:
Akamai Technologies, Inc. - 30
Google LLC - 24
Flyservers S.A. - 14

Top Clients:
Unknown - 114

Top Software:
Unknown - 114

Top Keyboards:
Unknown - 114

Top IP Classification:
hosting - 66
Unknown - 46
mobile & hosting - 2

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-04-23 RDP #Honeypot IOCs - 57 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
192.155.91.45 - 15
193.142.146.139 - 6
20.55.73.136 - 5

Top ASNs:
AS63949 - 15
AS396982 - 12
AS48721 - 7

Top Accounts:
hello - 23
Test - 9
Domain - 6

Top ISPs:
Akamai Technologies, Inc. - 15
Google LLC - 12
Flyservers S.A. - 7

Top Clients:
Unknown - 57

Top Software:
Unknown - 57

Top Keyboards:
Unknown - 57

Top IP Classification:
hosting - 33
Unknown - 23
mobile & hosting - 1

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

Title: P3: Security and hacking: Honeypots [2024-11-03 Sun]
and /proc/cmdline, which contain UML-specific
information.
- strange HELLO or Banner on ports.

Example: https://www.shodan.io/host/43.203.236.174
#dailyreport #hack #hacking #honeypot #honeypots #infosec #security