Attack traffic from Philippines
Honeypot telemetry for sources geolocated to Philippines
Observed by OffSeq honeypot sensors · last 30 days · last seen 2 hours ago · first observed 2026-08-03 (30 days ago)
17,950
Attacks
137
Distinct source IPs
Attack traffic is led by IPG-AS-AP Philippine Long Distance Telephone Com.
OffSeq honeypot sensors recorded 17,950 attacks from 137 distinct hosts geolocated to Philippinesin the last 30 days. Source addresses are aggregated to /16 networks — Mirage never publishes an individual attacker IP.
Techniques
- T1110 Brute Force13,287
- T1187 Forced Authentication2,170
- T1210 Exploitation of Remote Services1,093
- T1021.005 VNC893
- T1190 Exploit Public-Facing Application141
- T1595 Active Scanning97
- T1046 Network Service Discovery81
- T1595.002 Vulnerability Scanning52
- T1059 Command and Scripting Interpreter29
- T1078 Valid Accounts7
- T1552.001 Credentials In Files2
- T1040 Network Sniffing2
Top networks (ASNs)
- IPG-AS-AP Philippine Long Distance Telephone Com3,835
- GLOBE-TELECOM-AS Globe Telecoms1,155
- SOURCETELECOMS-AS-AP Source Telecoms Inc.820
- GHOSTYNETWORKS480
- GLOBE-MOBILE-5TH-GEN-AS Globe Telecom Inc.81
- CONVERGE-AS Converge ICT Solutions Inc.68
- UCLOUD-HK-AS-AP UCLOUD INFORMATION TECHNOLOGY HK56
- INFINIVAN-AS-AP Infinivan Incorporated5
- MIS-AS-AP MCBROAD IT SOLUTIONS3
- RADIUSTELECOMS-AS-AP RADIUS TELECOMS, INC.1
- TIM-GNS-AS-AP Total Information Management Corpo1
- ETPI-IDS-AS-AP Eastern Telecoms Phils., Inc.1