Adventures of an RDP Honeypot – Part Two: Know Your Enemy
ID: e434403f-af05-5ed8-ba4f-e5556144c236
STIX ID: report--e434403f-af05-5ed8-ba4f-e5556144c236
Feed Name: TrustedSec blog
This report describes a 9.5-day RDP honeypot that recorded over 58,000 authentication attempts and 46 successful logins; attackers deployed Rapid Ransomware (encrypting files and disabling recovery), and later intruders modified RDP to allow persistence, added hidden administrative accounts, created scheduled tasks, and adjusted firewall rules—demonstrating how quickly exposed RDP can lead to ransomware and sustained compromise and including multiple MD5 indicators and procedural details.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
