Attack traffic from Mexico
Honeypot telemetry for sources geolocated to Mexico
Observed by OffSeq honeypot sensors · last 30 days · last seen 44 minutes ago · first observed 2026-08-03 (30 days ago)
40,157
Attacks
288
Distinct source IPs
3
KEV exploit hits
Attack traffic is led by Microsoft Singapore Pte. Ltd..
OffSeq honeypot sensors recorded 40,157 attacks from 288 distinct hosts geolocated to Mexicoin the last 30 days. Source addresses are aggregated to /16 networks — Mirage never publishes an individual attacker IP.
Techniques
- T1110 Brute Force25,714
- T1595 Active Scanning10,671
- T1187 Forced Authentication1,492
- T1210 Exploitation of Remote Services876
- T1190 Exploit Public-Facing Application699
- T1505.003 Web Shell129
- T1505 Server Software Component91
- T1592 Gather Victim Host Information57
- T1021.005 VNC43
- T1595.002 Vulnerability Scanning31
- T1059 Command and Scripting Interpreter7
- T1657 Financial Theft5
Top networks (ASNs)
- Microsoft Singapore Pte. Ltd.12,887
- UNINET12,558
- TOTAL PLAY TELECOMUNICACIONES SA DE CV3,111
- ORACLE-BMC-31898103
- TOTAL PLAY TELECOMUNICACIONES SA DE CV31
- WHG Hosting Services Ltd23
- Mega Cable, S.A. de C.V.9
- Alestra, S. de R.L. de C.V.6
- TRANSTELCO-INC6
- AS-HOSTINGER5
- Television Internacional, S.A. de C.V.4
- SPACEX-STARLINK4