Mmastodon TechnologyCybersecurity first seen 2 h ago, last 2 h ago, peak #7
RDP honeypot data exposes top attacking IP addresses
Original: 2026-10-01 RDP # Honeypot IOCs - 183 scans Thread with top 3 features in each category and links to the full dataset # D
A cybersecurity researcher has published indicators of compromise drawn from an RDP honeypot, covering 183 scans recorded on 1 October 2026. The dataset lists the most active source IPs, including 94.26.68.55 with 60 hits, top hosting networks such as AS201814 and AS14061, and commonly targeted accounts like 'hello'. Full data and category breakdowns are shared for defenders to block or investigate.
Why now: Security teams monitor fresh honeypot IOCs to block active RDP scanning infrastructure.
94.26.68.55AS201814AS14061RDP honeypot
Evidence
- 2026-10-01 RDP # Honeypot IOCs - 183 scans Thread with top 3 features in each category and links to the full dataset # DFIR # InfoSec Top IPs: 94.26.68.55 - 60 165.22.190.202 - 27 80.66.83.43 - 18 Top ASNs: AS201814 - 60 AS396982 - 36 AS14061 - 30 Top Accounts: hello - 93… · rdpsnitch@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/670960