← Back to feed

AS7552 Viettel Group

ASN Active medium
Why this campaign was detected
18 IPs from the same network (Viettel Group, AS7552) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS7552 · Viettel Group
Subnet
Country
🇻🇳 VN
Cloud Provider
Member Count
18 IPs
Below average
Total Events
3752
Below average by volume
Started / Ended
2026-02-16 19:38 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
171.244.37.103 credential_harvester 75% 1x OSINT 675 3 ssh:bruteforce 2026-05-07 01:40 evidence →
171.244.141.86 credential_harvester 63% 1x OSINT 931 2 ssh:bruteforce 2026-05-08 12:56 evidence →
117.6.44.221 credential_harvester 61% 1x OSINT 1024 2 ssh:bruteforce 2026-05-07 08:01 evidence →
27.79.44.185 credential_harvester 54% 210 2 ssh:bruteforce 2026-05-09 12:29 evidence →
27.79.0.66 credential_harvester 51% 1x OSINT 58 1 ssh:bruteforce 2026-05-11 17:06 evidence →
171.243.150.94 credential_harvester 44% 168 1 ssh:bruteforce 2026-05-09 10:26 evidence →
27.79.2.106 credential_harvester 42% 205 1 ssh:bruteforce 2026-05-08 01:55 evidence →
27.79.5.2 credential_harvester 41% 100 1 ssh:bruteforce 2026-05-08 01:42 evidence →
171.231.199.189 credential_harvester 40% 147 1 ssh:bruteforce 2026-05-07 07:56 evidence →
27.79.45.243 credential_harvester 36% 66 1 ssh:bruteforce 2026-05-06 00:24 evidence →
171.243.149.169 proxy_abuser 35% 8 1 ssh:bruteforce 2026-05-07 09:28 evidence →
27.79.40.45 proxy_abuser 34% 8 1 ssh:bruteforce 2026-05-06 17:36 evidence →
27.79.7.22 credential_probe 32% 1x OSINT 36 1 ssh:bruteforce 2026-05-11 16:26 evidence →
27.79.41.151 credential_probe 31% 1x OSINT 24 1 ssh:bruteforce 2026-05-11 16:31 evidence →
27.79.3.146 credential_probe 31% 1x OSINT 23 1 ssh:bruteforce 2026-05-11 17:02 evidence →
27.79.45.168 credential_harvester 21% 39 1 ssh:bruteforce 2026-05-07 07:31 evidence →
116.99.50.13 credential_probe 20% 1x OSINT 15 1 ssh:bruteforce 2026-05-06 04:35 evidence →
171.243.149.36 credential_probe 17% 15 1 ssh:bruteforce 2026-05-07 09:31 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds