← Back to feed
Location
🇺🇸 US
ASN
AS398324 · Censys, Inc.
Cloud Provider
—
Total Events
5
Below average by volume
Agent Count
2
First / Last Seen
2026-05-16 07:53 — 2026-05-20 21:39
Attack Types
MITRE ATT&CK Techniques
Initial Access
Discovery
External Corroboration
DShield Top Attackers
dshield:top_attacker
Campaigns
Subnet 66.132.195.0/24
SUBNET
Active
high
🇺🇸 US
18 IPs
89 events
http:scanssh:bruteforce
2026-03-23 — ongoing · 18 IPs from the same /24 subnet (66.132.195.0/24) were observed attacking our sensors within the same time window. …
Multi-Agent Scan
SCAN
Active
medium
76 IPs
410011 events
2026-03-09 — ongoing · 76 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
53 IPs
30547 events
2026-03-09 — ongoing · 53 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
77 IPs
410111 events
2026-03-09 — ongoing · 77 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
145 IPs
422805 events
2026-03-09 — ongoing · 145 IPs independently targeted the same honeypot sensors within a 24-hour window. Hosted on DO. Scanning the same …
Session Forensics
Sessions
2
Avg Depth Score
0.2
Commands Executed
0
Files Downloaded
0
Fingerprints
HASSH
SSH Client
Evidence Timeline
Web Probe
a111cfafe68961c0
25%
Loading events...
Non-Session Events
| Timestamp | Port | Proto | Event | Source | Location |
|---|---|---|---|---|---|
| 2026-05-16 07:53:14 | :80 | http | HTTP GET request | opencanary | ewr |