Attack traffic from Saudi Arabia
Honeypot telemetry for sources geolocated to Saudi Arabia
Observed by OffSeq honeypot sensors · last 30 days · last seen 17 hours ago · first observed 2026-08-03 (29 days ago)
3,977
Attacks
75
Distinct source IPs
Attack traffic is led by SAUDINETSTC-AS.
OffSeq honeypot sensors recorded 3,977 attacks from 75 distinct hosts geolocated to Saudi Arabiain the last 30 days. Source addresses are aggregated to /16 networks — Mirage never publishes an individual attacker IP.
Techniques
- T1110 Brute Force3,716
- T1190 Exploit Public-Facing Application103
- T1210 Exploitation of Remote Services49
- T1059 Command and Scripting Interpreter42
- T1595 Active Scanning10
- T1187 Forced Authentication9
- T1078 Valid Accounts5
- T1105 Ingress Tool Transfer4
- T1595.002 Vulnerability Scanning3
- T1046 Network Service Discovery3