← Back to feed
AS38365 Beijing Baidu Netcom Science and Technology Co., Ltd.
ASN Active mediumWhy this campaign was detected
36 IPs from the same network (Beijing Baidu Netcom Science and Technology Co., Ltd., AS38365) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS38365 · Beijing Baidu Netcom Science and Technology Co., Ltd.
Subnet
—
Country
🇨🇳 CN
Cloud Provider
—
Member Count
36 IPs
Below average
Total Events
2246
Below average by volume
Started / Ended
2026-02-18 13:36 — ongoing
Attack Types
MITRE ATT&CK Techniques
Initial Access
Command and Control
Member Actors
| IP Address | Behavior | Confidence | Flags | Events | Agents | Attack Types | Hostname | Last Seen | |
|---|---|---|---|---|---|---|---|---|---|
| 180.76.202.69 | credential_harvester | 74% | 1x OSINT | 188 | 3 | ssh:bruteforce | — | 2026-05-08 07:31 | evidence → |
| 180.76.236.214 | scanner | 62% | 1x OSINT | 179 | 2 | ssh:bruteforce | — | 2026-05-09 22:12 | evidence → |
| 180.76.98.164 | scanner | 61% | 1x OSINT | 318 | 2 | ssh:bruteforce | — | 2026-05-08 19:53 | evidence → |
| 106.13.37.197 | scanner | 60% | 1x OSINT | 170 | 2 | ssh:bruteforce | — | 2026-05-08 23:48 | evidence → |
| 120.48.77.176 | scanner | 60% | 1x OSINT | 127 | 2 | ssh:bruteforce | — | 2026-05-08 23:21 | evidence → |
| 120.48.135.189 | scanner | 57% | 1x OSINT | 60 | 2 | ssh:bruteforce | — | 2026-05-07 21:58 | evidence → |
| 106.13.114.161 | scanner | 57% | 1x OSINT | 61 | 2 | ssh:bruteforce | — | 2026-05-07 21:14 | evidence → |
| 182.61.148.217 | scanner | 55% | 1x OSINT | 37 | 2 | ssh:bruteforce | — | 2026-05-07 18:08 | evidence → |
| 180.76.176.249 | credential_harvester | 55% | 1x OSINT | 185 | 2 | ssh:bruteforce | — | 2026-05-06 02:26 | evidence → |
| 106.13.100.52 | scanner | 54% | 108 | 2 | ssh:bruteforce | — | 2026-05-08 10:22 | evidence → | |
| 120.48.168.33 | scanner | 53% | 1x OSINT | 25 | 2 | ssh:bruteforce | — | 2026-05-06 14:39 | evidence → |
| 120.48.34.72 | credential_harvester | 53% | 1x OSINT | 80 | 2 | ssh:bruteforce | — | 2026-05-05 11:55 | evidence → |
| 120.48.106.205 | scanner | 52% | 70 | 2 | ssh:bruteforce | — | 2026-05-07 22:48 | evidence → | |
| 106.12.241.195 | credential_probe | 51% | 2x OSINT | 43 | 3 | ssh:bruteforce | — | 2026-05-07 10:18 | evidence → |
| 120.48.28.60 | scanner | 50% | 1x OSINT | 68 | 1 | ssh:bruteforce | — | 2026-05-09 07:01 | evidence → |
| 106.13.96.57 | scanner | 48% | 1x OSINT | 115 | 1 | ssh:bruteforce | — | 2026-05-07 14:49 | evidence → |
| 106.12.18.199 | credential_harvester | 48% | 1x OSINT | 12 | 1 | ssh:bruteforce | — | 2026-05-09 15:51 | evidence → |
| 106.12.86.145 | scanner | 43% | 1x OSINT | 19 | 2 | ssh:bruteforce | — | 2026-05-08 04:09 | evidence → |
| 180.76.226.129 | scanner | 41% | 20 | 2 | ssh:bruteforce | — | 2026-05-08 07:23 | evidence → | |
| 180.76.104.44 | scanner | 38% | 1x OSINT | 51 | 2 | ssh:bruteforce | — | 2026-05-08 19:11 | evidence → |
| 120.48.42.17 | scanner | 38% | 1x OSINT | 115 | 2 | ssh:bruteforce | — | 2026-05-07 21:15 | evidence → |
| 106.12.15.118 | reconnaissance | 37% | 20 | 2 | ssh:bruteforce | — | 2026-05-06 13:06 | evidence → | |
| 106.13.107.66 | opportunistic_bruter | 35% | 1x OSINT | 16 | 1 | ssh:bruteforce | — | 2026-05-07 13:18 | evidence → |
| 180.76.96.235 | credential_probe | 32% | 1x OSINT | 19 | 2 | ssh:bruteforce | — | 2026-05-07 23:25 | evidence → |
| 106.13.95.100 | reconnaissance | 32% | 10 | 1 | ssh:bruteforce | — | 2026-05-09 04:08 | evidence → | |
| 120.48.54.170 | credential_probe | 31% | 51 | 2 | ssh:bruteforce | — | 2026-05-09 03:21 | evidence → | |
| 106.12.56.73 | opportunistic_bruter | 31% | 1x OSINT | 6 | 1 | ssh:bruteforce | — | 2026-05-07 13:54 | evidence → |
| 106.13.165.101 | scanner | 29% | 2x OSINT | 30 | 1 | ssh:bruteforce | — | 2026-05-07 03:40 | evidence → |
| 120.48.82.124 | opportunistic_bruter | 27% | 1x OSINT | 6 | 1 | ssh:bruteforce | — | 2026-05-05 15:50 | evidence → |
| 120.48.55.8 | opportunistic_bruter | 26% | 6 | 1 | ssh:bruteforce | — | 2026-05-07 19:43 | evidence → | |
| 106.13.178.166 | scanner | 26% | 2x OSINT | 6 | 1 | ssh:bruteforce | — | 2026-05-07 17:52 | evidence → |
| 180.76.103.111 | scanner | 24% | 1x OSINT | 4 | 1 | ssh:bruteforce | — | 2026-05-09 05:50 | evidence → |
| 180.76.102.139 | opportunistic_bruter | 22% | 7 | 1 | ssh:bruteforce | — | 2026-05-05 06:27 | evidence → | |
| 120.48.134.186 | scanner | 20% | 1x OSINT | 2 | 1 | ssh:bruteforce | — | 2026-05-07 09:43 | evidence → |
| 180.76.243.197 | scanner | 20% | 1x OSINT | 8 | 1 | ssh:bruteforce | — | 2026-05-06 03:58 | evidence → |
| 120.48.71.252 | scanner | 16% | 4 | 1 | ssh:bruteforce | — | 2026-05-07 09:25 | evidence → |
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds