← Back to feed

AS202412 Omegatech LTD

ASN Ended medium
Why this campaign was detected
5 IPs from the same network (Omegatech LTD, AS202412) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS202412 · Omegatech LTD
Subnet
Country
πŸ‡ΊπŸ‡Έ US
Cloud Provider
Member Count
5 IPs
Below average
Total Events
6680
Below average by volume
Started / Ended
2026-02-18 05:40 — 2026-05-11 20:51
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Execution
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
91.92.243.116 credential_harvester 49% DROP 2596 2 ssh:bruteforce β€” 2026-04-02 11:49 evidence →
91.92.240.199 credential_harvester 49% DROP 1455 2 ssh:bruteforce β€” 2026-03-31 02:49 evidence →
91.92.243.49 credential_harvester 44% DROP 122 2 ssh:bruteforce β€” 2026-04-04 20:48 evidence →
158.94.208.44 credential_harvester 38% DROP 401 1 ssh:bruteforce β€” 2026-04-01 01:26 evidence →
158.94.209.131 credential_harvester 33% DROP 2203 1 ssh:bruteforce β€” 2026-04-03 12:33 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds