← Back to feed

AS4837 CHINA UNICOM China169 Backbone

ASN Active medium
Why this campaign was detected
16 IPs from the same network (CHINA UNICOM China169 Backbone, AS4837) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS4837 · CHINA UNICOM China169 Backbone
Subnet
Country
🇨🇳 CN
Cloud Provider
Member Count
16 IPs
Below average
Total Events
940
Below average by volume
Started / Ended
2026-02-16 18:41 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
125.39.93.73 scanner 60% 1x OSINT 92 2 ssh:bruteforce 2026-05-09 02:28 evidence →
221.213.129.46 credential_harvester 58% 1x OSINT 283 2 ssh:bruteforce 2026-05-07 03:42 evidence →
110.53.68.28 scanner 52% 1x OSINT 44 2 ssh:bruteforce 2026-05-05 17:54 evidence →
112.132.249.164 credential_harvester 51% 1x OSINT 51 2 ssh:bruteforce 164.249.132.112.adsl-pool.ah.cnuninet.net 2026-05-05 05:34 evidence →
61.240.156.16 scanner 51% 138 2 ssh:bruteforce 2026-05-06 21:01 evidence →
113.194.203.31 scanner 48% 1x OSINT 73 1 ssh:bruteforce 2026-05-08 04:29 evidence →
122.114.69.235 scanner 48% 1x OSINT 28 2 ssh:bruteforce 2026-05-09 08:01 evidence →
101.206.107.245 credential_harvester 47% 1x OSINT 73 2 ssh:bruteforce 2026-05-09 13:17 evidence →
60.219.113.54 scanner 39% 25 2 ssh:bruteforce 2026-05-07 10:47 evidence →
221.10.21.25 scanner 38% 1x OSINT 25 2 ssh:bruteforce 2026-05-05 11:13 evidence →
153.101.132.65 credential_probe 35% 1x OSINT 46 2 ssh:bruteforce 2026-05-08 19:11 evidence →
58.240.17.66 scanner 33% 1x OSINT 29 2 ssh:bruteforce 2026-05-06 18:03 evidence →
123.234.3.106 scanner 32% 12 1 ssh:bruteforce 2026-05-09 01:17 evidence →
124.164.251.88 scanner 28% 2x OSINT 13 1 ssh:bruteforce 2026-05-08 00:52 evidence →
221.195.232.14 scanner 16% 6 1 ssh:bruteforce 2026-05-07 03:55 evidence →
123.13.41.128 scanner 15% 2 1 ssh:bruteforce 2026-05-06 23:31 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds