Attack traffic from United States
Honeypot telemetry for sources geolocated to United States
Observed by OffSeq honeypot sensors · last 30 days · last seen 12 minutes ago · first observed 2026-08-02 (30 days ago)
2,900,279
Attacks
16,076
Distinct source IPs
52
KEV exploit hits
Attack traffic is led by RELIABLESITE, most often targeting CVE-2021-26855.
OffSeq honeypot sensors recorded 2,900,279 attacks from 16,076 distinct hosts geolocated to United Statesin the last 30 days. Source addresses are aggregated to /16 networks — Mirage never publishes an individual attacker IP.
CVEs targeted
- CVE-2021-26855267
- CVE-2024-4577171
- CVE-2017-9841154
Techniques
- T1110 Brute Force1,363,389
- T1657 Financial Theft529,446
- T1105 Ingress Tool Transfer324,981
- T1021.005 VNC252,618
- T1190 Exploit Public-Facing Application124,327
- T1595 Active Scanning97,459
- T1046 Network Service Discovery31,564
- T1059 Command and Scripting Interpreter26,271
- T1595.002 Vulnerability Scanning24,480
- T1552 Unsecured Credentials12,674
- T1498.002 Reflection Amplification4,714
- T0846 T08462,041
Top networks (ASNs)
- RELIABLESITE132,404
- Latitude.sh LTDA76,170
- SHIFT-HOSTING-LLC74,415
- COGENT-17472,632
- CONTABO59,909
- LATITUDE-SH50,769
- AS-COLOCROSSING44,645
- GOOGLE-CLOUD-PLATFORM36,203
- ROUTERHOSTING27,557
- MICROSOFT-CORP-MSN-AS-BLOCK27,389
- DIGITALOCEAN-ASN24,217
- PONYNET22,820