← Back to feed

AS56041 China Mobile communications corporation

ASN Ended medium
Why this campaign was detected
5 IPs from the same network (China Mobile communications corporation, AS56041) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS56041 · China Mobile communications corporation
Subnet
Country
🇨🇳 CN
Cloud Provider
Member Count
5 IPs
Below average
Total Events
456
Below average by volume
Started / Ended
2026-02-18 13:37 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
39.174.42.18 scanner 68% 157 3 ssh:bruteforce 2026-08-21 19:24 evidence →
36.138.134.121 scanner 54% 1x OSINT 248 2 ssh:bruteforce 2026-08-19 09:44 evidence →
183.247.202.167 scanner 39% 16 2 ssh:bruteforce 2026-08-18 10:30 evidence →
117.149.196.217 reconnaissance 39% 1x OSINT 15 2 ssh:bruteforce 2026-08-22 22:40 evidence →
117.149.196.215 scanner 35% 20 2 ssh:bruteforce 2026-08-17 15:24 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}