#cybersec

PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **talus-foundatlon[.]xyz**
🔍 Analysis at: urlscan.io/result/019add13-8ee

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **alert[.]casino6868[.]xyz**
🔍 Analysis at: urlscan.io/result/019adc85-617

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **defire-solutions[.]pages[.]dev**
🔍 Analysis at: urlscan.io/result/019adc85-7ad

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **ahaoinn[.]com**
🔍 Analysis at: urlscan.io/result/019adc85-497

PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **blueboatpresidoo[.]pages[.]dev**
🔍 Analysis at: urlscan.io/result/019adc84-698

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **token-pocket[.]pages[.]dev**
🔍 Analysis at: urlscan.io/result/019adc84-8ac

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **dnzdfg8[.]pages[.]dev**
🔍 Analysis at: urlscan.io/result/019adc83-3cd

PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **mail[.]google[.]oscarmar[.]com**
🔍 Analysis at: urlscan.io/result/019adc70-464

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **ftnxboost[.]icu**
🔍 Analysis at: urlscan.io/result/019adc70-0ce

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **distribution-mon[.]xyz**
🔍 Analysis at: urlscan.io/result/019adc6f-985

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **kntara[.]click**
🔍 Analysis at: urlscan.io/result/019adc6f-144

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **oklvld[.]pl[.]ua**
🔍 Analysis at: urlscan.io/result/019adc6e-552

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **bullishdegen[.]pro**
🔍 Analysis at: urlscan.io/result/019adc6e-43c

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **omnera-tge[.]xyz**
🔍 Analysis at: urlscan.io/result/019adc6e-1a3

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **trezor-suite-feq-us[.]typedream[.]app**
🔍 Analysis at: urlscan.io/result/019adc6d-bac

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **oeze5y57b26xn8zk[.]umso[.]co**
🔍 Analysis at: urlscan.io/result/019adc6d-845

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **bitbboob[.]com**
🔍 Analysis at: urlscan.io/result/019adc6c-f76

Screenshot of phishing site
PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **scst[.]booksvala[.]in**
🔍 Analysis at: urlscan.io/result/019adc6b-f9e

2025-12-02

2025-12-01 RDP #Honeypot IOCs - 1980 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
134.199.198.215 - 1824
103.126.161.152 - 27
80.64.19.158 - 18

Top ASNs:
AS14061 - 1833
AS396982 - 36
AS135959 - 27

Top Accounts:
hello - 1881
Test - 33
Administr - 15

Top ISPs:
DigitalOcean, LLC - 1833
Google LLC - 36
Onebim Vietnam Limited Company - 27

Top Clients:
Unknown - 1980

Top Software:
Unknown - 1980

Top Keyboards:
Unknown - 1980

Top IP Classification:
hosting - 1881
Unknown - 93
hosting & proxy - 3

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

PhishDestroy Alertphishdestroy
2025-12-02

🚨 PHISHING DETECTED 🚨

🔗 Suspicious URL: **ai-trade[.]live**
🔍 Analysis at: urlscan.io/result/019adc6b-a1b

Screenshot of phishing site

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst