← Back to feed

Subnet 216.180.246.0/24

SUBNET Active high
Why this campaign was detected
12 IPs from the same /24 subnet (216.180.246.0/24) were observed attacking our sensors within the same time window. All belong to Google LLC (AS396982). Concentrated activity from adjacent IPs is a strong indicator of a single operator or coordinated botnet.
Primary ASN
AS396982 · Google LLC
Subnet
216.180.246.0/24
Country
πŸ‡ΊπŸ‡Έ US
Cloud Provider
Member Count
12 IPs
Below average
Total Events
20
Below average by volume
Started / Ended
2026-02-20 23:07 — ongoing
Attack Types
http:scan ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
216.180.246.75 scanner 36% 6 1 http:scanssh:bruteforce β€” 2026-06-03 08:49 evidence →
216.180.246.74 web_probe 35% 2 2 http:scan β€” 2026-06-03 12:30 evidence →
216.180.246.68 web_probe 35% 2 2 http:scan β€” 2026-06-03 05:59 evidence →
216.180.246.224 web_probe 30% 2 2 http:scan β€” 2026-05-31 20:23 evidence →
216.180.246.237 web_probe 25% 1 1 http:scan β€” 2026-06-01 14:57 evidence →
216.180.246.249 web_probe 25% 1 1 http:scan β€” 2026-06-03 04:07 evidence →
216.180.246.156 web_probe 16% 1 1 http:scan β€” 2026-05-29 10:31 evidence →
216.180.246.240 web_probe 16% 1 1 http:scan β€” 2026-05-29 04:53 evidence →
216.180.246.79 web_probe 15% 1 1 http:scan β€” 2026-05-28 13:10 evidence →
216.180.246.45 web_probe 15% 1 1 http:scan β€” 2026-05-28 13:02 evidence →
216.180.246.193 web_probe 14% 1 1 http:scan β€” 2026-05-28 08:46 evidence →
216.180.246.115 web_probe 14% 1 1 http:scan β€” 2026-05-28 03:58 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds