← Back to feed

AS150436 Byteplus Pte. Ltd.

ASN Active medium
Why this campaign was detected
9 IPs from the same network (Byteplus Pte. Ltd., AS150436) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS150436 · Byteplus Pte. Ltd.
Subnet
Country
πŸ‡ΈπŸ‡¬ SG
Cloud Provider
Member Count
9 IPs
Below average
Total Events
3742
Below average by volume
Started / Ended
2026-02-18 08:37 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
163.7.3.26 credential_harvester 81% 2x OSINT 390 3 ssh:bruteforce β€” 2026-05-09 01:04 evidence →
45.78.206.111 credential_harvester 78% 1x OSINT 565 3 ssh:bruteforce β€” 2026-05-09 01:07 evidence →
45.78.194.186 credential_harvester 77% 1x OSINT 687 3 ssh:bruteforce β€” 2026-05-08 16:03 evidence →
150.5.169.176 credential_harvester 77% 1x OSINT 818 3 ssh:bruteforce β€” 2026-05-08 07:13 evidence →
163.7.6.74 credential_harvester 73% 1x OSINT 313 3 ssh:bruteforce β€” 2026-05-06 22:41 evidence →
163.7.1.218 credential_harvester 64% 2x OSINT 227 2 ssh:bruteforce β€” 2026-05-08 10:56 evidence →
45.78.207.244 credential_harvester 60% 1x OSINT 229 2 ssh:bruteforce β€” 2026-05-08 14:42 evidence →
45.78.204.246 credential_harvester 60% 2x OSINT 490 2 ssh:bruteforce β€” 2026-05-05 17:16 evidence →
101.47.159.50 opportunistic_bruter 39% 23 1 ssh:bruteforce β€” 2026-05-06 20:33 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds