← Back to feed

AS24940 Hetzner Online GmbH

ASN Active medium
Why this campaign was detected
11 IPs from the same network (Hetzner Online GmbH, AS24940) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS24940 · Hetzner Online GmbH
Subnet
Country
🇩🇪 DE
Cloud Provider
Member Count
11 IPs
Below average
Total Events
741
Below average by volume
Started / Ended
2026-02-18 14:23 — 2026-04-11 14:19
Attack Types
http:scan ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
91.107.158.47 credential_harvester 50% 1x OSINT 556 1 ssh:bruteforce 2026-08-27 13:07 evidence →
204.168.250.82 opportunistic_bruter 42% 23 1 ssh:bruteforce 2026-08-28 17:49 evidence →
95.216.150.147 malware_dropper 38% 23 1 ssh:bruteforce 2026-08-26 13:21 evidence →
195.201.101.202 reconnaissance 34% 37 1 ssh:bruteforce 2026-08-29 07:59 evidence →
23.88.51.118 reconnaissance 34% 1x OSINT 16 1 ssh:bruteforce 2026-08-27 10:08 evidence →
178.63.251.94 credential_probe 26% 1x OSINT 26 1 ssh:bruteforce 2026-08-29 11:16 evidence →
195.201.40.19 credential_probe 25% 1x OSINT 21 1 ssh:bruteforce 2026-08-29 07:57 evidence →
65.108.235.95 web_probe 22% 3 1 http:scan 2026-08-29 12:59 evidence →
65.108.235.106 web_probe 21% 2 1 http:scan 2026-08-29 13:00 evidence →
178.105.183.10 web_probe 21% 16 1 http:scan 2026-08-27 15:33 evidence →
116.203.47.59 credential_probe 20% 18 1 ssh:bruteforce 2026-08-29 11:05 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}