Mmastodon TechnologyCybersecurity first seen 13 h ago, last 13 h ago, peak #12
RDP honeypot logs 438 scans, indicators published
Original: 2026-10-02 RDP # Honeypot IOCs - 438 scans Thread with top 3 features in each category and links to the full dataset # D
A security researcher published indicators of compromise from an RDP honeypot after logging 438 scans on 2 October 2026. The dataset highlights the most active source IP, 94.26.68.55 with 219 hits, the top networks including AS201814, and commonly attempted usernames such as 'hello'. Full data and per-category breakdowns were shared so defenders can block the listed addresses and monitor related activity.
Why now: Cybersecurity practitioners are sharing fresh indicators of compromise to help defenders block active RDP scanning sources.
RDP honeypot94.26.68.55AS201814Infosec.ExchangeDFIR community
Evidence
- 2026-10-02 RDP # Honeypot IOCs - 438 scans Thread with top 3 features in each category and links to the full dataset # DFIR # InfoSec Top IPs: 94.26.68.55 - 219 71.6.134.234 - 30 82.85.225.167 - 12 Top ASNs: AS201814 - 219 AS10439 - 30 AS396982 - 27 Top Accounts: hello - 225… · rdpsnitch@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/799955