← Back to feed
AS36352 HostPapa
ASN Active mediumWhy this campaign was detected
6 IPs from the same network (HostPapa, AS36352) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS36352 · HostPapa
Subnet
—
Country
πΊπΈ US
Cloud Provider
—
Member Count
6 IPs
Below average
Total Events
3798
Below average by volume
Started / Ended
2026-02-19 17:38 — ongoing
Attack Types
MITRE ATT&CK Techniques
Initial Access
Command and Control
Member Actors
| IP Address | Behavior | Confidence | Flags | Events | Agents | Attack Types | Hostname | Last Seen | |
|---|---|---|---|---|---|---|---|---|---|
| 192.210.192.220 | credential_harvester | 61% | 1x OSINT | 1326 | 2 | ssh:bruteforce | β | 2026-08-28 06:09 | evidence → |
| 23.95.193.99 | credential_harvester | 58% | 2x OSINT | 628 | 1 | ssh:bruteforce | β | 2026-08-29 23:53 | evidence → |
| 107.174.137.235 | credential_harvester | 56% | 2x OSINT | 1369 | 1 | ssh:bruteforce | β | 2026-08-28 03:18 | evidence → |
| 107.174.159.19 | credential_harvester | 54% | 2x OSINT | 448 | 1 | ssh:bruteforce | β | 2026-08-27 16:58 | evidence → |
| 167.160.189.163 | malware_dropper | 49% | 1x OSINT | 23 | 1 | ssh:bruteforce | β | 2026-08-29 23:50 | evidence → |
| 66.63.163.134 | scanner | 16% | 4 | 1 | ssh:bruteforce | β | 2026-08-27 11:04 | evidence → |
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds