AS48090 — DMZHOST
Attacker network profile
Observed by OffSeq honeypot sensors · last 30 days · last seen 12 minutes ago · first observed 2026-08-10 (30 days ago)
65,456
Attacks
95
Distinct source IPs
1
KEV exploit hits
Attacks from this network most often target T1595 Active Scanning.
OffSeq honeypot sensors recorded 65,456 attacks from 95 distinct hosts within AS48090in the last 30 days. Source addresses are aggregated to /16 networks — Mirage never publishes an individual attacker IP.
Techniques
- T1595 Active Scanning31,154
- T1110 Brute Force11,976
- T1190 Exploit Public-Facing Application7,859
- T1552 Unsecured Credentials7,659
- T1595.002 Vulnerability Scanning2,845
- T1552.001 Credentials In Files898
- T1059 Command and Scripting Interpreter499
- T1046 Network Service Discovery177
- T1592 Gather Victim Host Information174
- T1090 Proxy6
- T0846 T08461
- T1021.005 VNC1
Top countries
- The Netherlands52,582
- Germany8,823
- Bulgaria2,281
- North Korea783
- United States383
- Iceland308
- Iran240
- United Kingdom48
- Andorra8