RDP honeypot/WIN-SRV01/2026-08-20 to 08-26 UTC

RDP attack telemetry

Every authentication attempt against one internet-facing honeypot over six days, with the password each one carried recovered where cracking succeeded.

Attempts
Passwords recovered
Source IPs
Usernames tried
Distinct passwords
Peak hour

Attempts per hour

117 hourly buckets across the capture window
Traffic runs at a low baseline for three days, then steps up by an order of magnitude on 23–24 August. That is a new operator arriving, not the existing ones speeding up.

Hour of day

All six days aggregated, UTC
A real diurnal cycle: 22:00–04:00 UTC carries 20× the traffic of 06:00–14:00. Earlier captures on this host were flat around the clock — this population is not.

Campaign shape

Each dot is one source IP — attempts against usernames tried (log scales)
Bottom-right is a grinder — thousands of guesses at one account. Top-left is an enumerator — few guesses across many accounts. The gap between them is why one blocklist never covers both.

Busiest sources

Top 15 of source addresses
Source IPAttemptsUsers

Most-targeted accounts

Top 12 of usernames
UsernameAttempts

Most-guessed passwords

Recovered cleartext, ranked by how many separate attempts carried it
PasswordAttemptsPasswordAttempts

Reading these numbers. Each attempt is one credential guess captured at the NLA/CredSSP stage, so the password is recovered by cracking the NetNTLMv2 response rather than read directly. Roughly 91% resolved; the rest are shown as attempts without a password rather than dropped. Times are the honeypot’s own clock in UTC.

Hash cracking crew
@0xTib3rius @apuleston @akses_0x00 @SwiftSecur1 @d1wn

Thanks for helping crack the hashes.

Created by @UK_Daniel_Card
The honeypot mission continues.