AS398722 — CENSYS-ARIN-03
Attacker network profile
Observed by OffSeq honeypot sensors · last 30 days · last seen 15 hours ago · first observed 2026-08-19 (28 days ago)
3,042
Attacks
173
Distinct source IPs
Attacks from this network most often target T1595 Active Scanning.
OffSeq honeypot sensors recorded 3,042 attacks from 173 distinct hosts within AS398722in the last 30 days. Source addresses are aggregated to /16 networks — Mirage never publishes an individual attacker IP.
Techniques
- T1595 Active Scanning967
- T1190 Exploit Public-Facing Application827
- T1110 Brute Force564
- T1046 Network Service Discovery380
- T1595.002 Vulnerability Scanning156
- T1498.002 Reflection Amplification60
- T0846 T084638
- T1187 Forced Authentication13
- T1040 Network Sniffing12
- T1105 Ingress Tool Transfer8
- T1210 Exploitation of Remote Services8
- T1021.005 VNC4
Top countries
- United States2,968
- Hong Kong74