← Back to feed

AS36352 HostPapa

ASN Active medium
Why this campaign was detected
6 IPs from the same network (HostPapa, AS36352) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS36352 · HostPapa
Subnet
Country
πŸ‡ΊπŸ‡Έ US
Cloud Provider
Member Count
6 IPs
Below average
Total Events
3798
Below average by volume
Started / Ended
2026-02-19 17:38 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
192.210.192.220 credential_harvester 61% 1x OSINT 1326 2 ssh:bruteforce β€” 2026-08-28 06:09 evidence →
23.95.193.99 credential_harvester 58% 2x OSINT 628 1 ssh:bruteforce β€” 2026-08-29 23:53 evidence →
107.174.137.235 credential_harvester 56% 2x OSINT 1369 1 ssh:bruteforce β€” 2026-08-28 03:18 evidence →
107.174.159.19 credential_harvester 54% 2x OSINT 448 1 ssh:bruteforce β€” 2026-08-27 16:58 evidence →
167.160.189.163 malware_dropper 49% 1x OSINT 23 1 ssh:bruteforce β€” 2026-08-29 23:50 evidence →
66.63.163.134 scanner 16% 4 1 ssh:bruteforce β€” 2026-08-27 11:04 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics β€” cookieless, public pages only. The context processor withholds the token from authenticated requests. #}