← Back to feed

AS4808 China Unicom Beijing Province Network

ASN Active medium
Why this campaign was detected
8 IPs from the same network (China Unicom Beijing Province Network, AS4808) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS4808 · China Unicom Beijing Province Network
Subnet
Country
🇨🇳 CN
Cloud Provider
Member Count
8 IPs
Below average
Total Events
558
Below average by volume
Started / Ended
2026-02-19 11:36 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
117.50.70.169 scanner 55% 2x OSINT 78 2 ssh:bruteforce 2026-07-15 14:38 evidence →
220.243.133.81 scanner 55% 1x OSINT 132 2 ssh:bruteforce 2026-08-26 11:30 evidence →
117.50.178.180 malware_dropper 48% 1x OSINT 18 1 ssh:bruteforce 2026-08-29 15:47 evidence →
203.212.9.221 scanner 46% 1x OSINT 318 1 ssh:bruteforce 2026-08-25 19:29 evidence →
111.192.80.111 scanner 28% 1x OSINT 2 1 ssh:bruteforce 2026-08-31 14:59 evidence →
125.34.226.88 scanner 22% 1x OSINT 4 1 ssh:bruteforce 2026-08-28 03:18 evidence →
221.216.37.140 scanner 18% 2 1 ssh:bruteforce 2026-08-29 03:19 evidence →
61.148.244.207 scanner 12% 2 1 ssh:bruteforce 2026-08-25 18:33 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}