Mmastodon TechnologyCybersecurity first seen 14 h ago, last 13 h ago, peak #7
RDP honeypot logs 184 scans, shares indicator data
Original: 2026-10-03 RDP # Honeypot IOCs - 184 scans Thread with top 3 features in each category and links to the full dataset # D
A cybersecurity researcher has published indicators of compromise from an RDP honeypot covering 184 scans recorded on 3 October 2026. The dataset highlights the most active source IPs, led by 94.26.68.55 and 94.26.68.54 with 26 scans each, top hosting networks AS201814, AS396982 and AS151734, and the most attempted usernames, including 'hello' with 80 attempts. Full data has been released for defenders to block.
Why now: Security teams monitor shared honeypot IOCs to block active RDP scanning infrastructure.
rdpsnitch94.26.68.55AS201814RDP honeypotInfosec.Exchange
Rank over time, top of the chart is #1. 2 snapshots from 14 h ago to 13 h ago.
Evidence
- 2026-10-03 RDP # Honeypot IOCs - 184 scans Thread with top 3 features in each category and links to the full dataset # DFIR # InfoSec Top IPs: 94.26.68.55 - 26 94.26.68.54 - 26 103.180.212.8 - 20 Top ASNs: AS201814 - 56 AS396982 - 32 AS151734 - 20 Top Accounts: hello - 80… · rdpsnitch@infosec.exchange · 3
API: https://socialmediatrends-api.osmike.com/v1/trends/921817