Attack traffic from India
Honeypot telemetry for sources geolocated to India
Observed by OffSeq honeypot sensors · last 30 days · last seen 4 minutes ago · first observed 2026-08-03 (30 days ago)
138,658
Attacks
1,274
Distinct source IPs
1
KEV exploit hits
Attack traffic is led by WEBWERKS-AS-IN Web Werks India Pvt. Ltd..
OffSeq honeypot sensors recorded 138,658 attacks from 1,274 distinct hosts geolocated to Indiain the last 30 days. Source addresses are aggregated to /16 networks — Mirage never publishes an individual attacker IP.
Techniques
- T1110 Brute Force100,482
- T1021.005 VNC17,445
- T1187 Forced Authentication4,932
- T1210 Exploitation of Remote Services2,678
- T1595 Active Scanning2,462
- T1657 Financial Theft1,916
- T1190 Exploit Public-Facing Application1,775
- T1595.002 Vulnerability Scanning719
- T1059 Command and Scripting Interpreter404
- T1046 Network Service Discovery298
- T1552 Unsecured Credentials272
- T1090 Proxy34
Top networks (ASNs)
- WEBWERKS-AS-IN Web Werks India Pvt. Ltd.11,383
- SKYNTPL-AS-AP Skylink Fibernet Private Limited3,141
- ZYETELECOM-IN ZYE TELECOM PVT LTD3,070
- DigitalOcean, LLC2,101
- CYBERZONEHUB1,887
- GATIK-AS-IN Gatik Business Solutions1,727
- AMAZON-021,652
- PDPL-AS-AP PI DATA CENTERS PRIVATE LIMITED1,618
- HOSTZOP-AS-IN HOSTZOP CLOUD SERVICES PRIVATE LIM1,353
- SOLORDP-AS-AP SoloRDP1,230
- Microsoft Corporation1,179
- AIRTELBROADBAND-AS-AP Bharti Airtel Ltd., Teleme926