← Back to feed

AS38365 Beijing Baidu Netcom Science and Technology Co., Ltd.

ASN Active medium
Why this campaign was detected
36 IPs from the same network (Beijing Baidu Netcom Science and Technology Co., Ltd., AS38365) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS38365 · Beijing Baidu Netcom Science and Technology Co., Ltd.
Subnet
Country
🇨🇳 CN
Cloud Provider
Member Count
36 IPs
Below average
Total Events
2246
Below average by volume
Started / Ended
2026-02-18 13:36 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
180.76.202.69 credential_harvester 74% 1x OSINT 188 3 ssh:bruteforce 2026-05-08 07:31 evidence →
180.76.236.214 scanner 62% 1x OSINT 179 2 ssh:bruteforce 2026-05-09 22:12 evidence →
180.76.98.164 scanner 61% 1x OSINT 318 2 ssh:bruteforce 2026-05-08 19:53 evidence →
106.13.37.197 scanner 60% 1x OSINT 170 2 ssh:bruteforce 2026-05-08 23:48 evidence →
120.48.77.176 scanner 60% 1x OSINT 127 2 ssh:bruteforce 2026-05-08 23:21 evidence →
120.48.135.189 scanner 57% 1x OSINT 60 2 ssh:bruteforce 2026-05-07 21:58 evidence →
106.13.114.161 scanner 57% 1x OSINT 61 2 ssh:bruteforce 2026-05-07 21:14 evidence →
182.61.148.217 scanner 55% 1x OSINT 37 2 ssh:bruteforce 2026-05-07 18:08 evidence →
180.76.176.249 credential_harvester 55% 1x OSINT 185 2 ssh:bruteforce 2026-05-06 02:26 evidence →
106.13.100.52 scanner 54% 108 2 ssh:bruteforce 2026-05-08 10:22 evidence →
120.48.168.33 scanner 53% 1x OSINT 25 2 ssh:bruteforce 2026-05-06 14:39 evidence →
120.48.34.72 credential_harvester 53% 1x OSINT 80 2 ssh:bruteforce 2026-05-05 11:55 evidence →
120.48.106.205 scanner 52% 70 2 ssh:bruteforce 2026-05-07 22:48 evidence →
106.12.241.195 credential_probe 51% 2x OSINT 43 3 ssh:bruteforce 2026-05-07 10:18 evidence →
120.48.28.60 scanner 50% 1x OSINT 68 1 ssh:bruteforce 2026-05-09 07:01 evidence →
106.13.96.57 scanner 48% 1x OSINT 115 1 ssh:bruteforce 2026-05-07 14:49 evidence →
106.12.18.199 credential_harvester 48% 1x OSINT 12 1 ssh:bruteforce 2026-05-09 15:51 evidence →
106.12.86.145 scanner 43% 1x OSINT 19 2 ssh:bruteforce 2026-05-08 04:09 evidence →
180.76.226.129 scanner 41% 20 2 ssh:bruteforce 2026-05-08 07:23 evidence →
180.76.104.44 scanner 38% 1x OSINT 51 2 ssh:bruteforce 2026-05-08 19:11 evidence →
120.48.42.17 scanner 38% 1x OSINT 115 2 ssh:bruteforce 2026-05-07 21:15 evidence →
106.12.15.118 reconnaissance 37% 20 2 ssh:bruteforce 2026-05-06 13:06 evidence →
106.13.107.66 opportunistic_bruter 35% 1x OSINT 16 1 ssh:bruteforce 2026-05-07 13:18 evidence →
180.76.96.235 credential_probe 32% 1x OSINT 19 2 ssh:bruteforce 2026-05-07 23:25 evidence →
106.13.95.100 reconnaissance 32% 10 1 ssh:bruteforce 2026-05-09 04:08 evidence →
120.48.54.170 credential_probe 31% 51 2 ssh:bruteforce 2026-05-09 03:21 evidence →
106.12.56.73 opportunistic_bruter 31% 1x OSINT 6 1 ssh:bruteforce 2026-05-07 13:54 evidence →
106.13.165.101 scanner 29% 2x OSINT 30 1 ssh:bruteforce 2026-05-07 03:40 evidence →
120.48.82.124 opportunistic_bruter 27% 1x OSINT 6 1 ssh:bruteforce 2026-05-05 15:50 evidence →
120.48.55.8 opportunistic_bruter 26% 6 1 ssh:bruteforce 2026-05-07 19:43 evidence →
106.13.178.166 scanner 26% 2x OSINT 6 1 ssh:bruteforce 2026-05-07 17:52 evidence →
180.76.103.111 scanner 24% 1x OSINT 4 1 ssh:bruteforce 2026-05-09 05:50 evidence →
180.76.102.139 opportunistic_bruter 22% 7 1 ssh:bruteforce 2026-05-05 06:27 evidence →
120.48.134.186 scanner 20% 1x OSINT 2 1 ssh:bruteforce 2026-05-07 09:43 evidence →
180.76.243.197 scanner 20% 1x OSINT 8 1 ssh:bruteforce 2026-05-06 03:58 evidence →
120.48.71.252 scanner 16% 4 1 ssh:bruteforce 2026-05-07 09:25 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds