← Back to feed

AS134768 CHINANET SHAANXI province Cloud Base network

ASN Active medium
Why this campaign was detected
5 IPs from the same network (CHINANET SHAANXI province Cloud Base network, AS134768) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS134768 · CHINANET SHAANXI province Cloud Base network
Subnet
Country
🇨🇳 CN
Cloud Provider
Member Count
5 IPs
Below average
Total Events
1273
Below average by volume
Started / Ended
2026-02-20 07:55 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
117.34.85.168 scanner 70% 1x OSINT 202 3 ssh:bruteforce 2026-09-09 15:44 evidence →
36.41.173.197 credential_harvester 65% 509 3 ssh:bruteforce 2026-08-22 23:04 evidence →
113.141.171.139 scanner 55% 1x OSINT 369 2 ssh:bruteforce 2026-08-24 02:15 evidence →
117.34.125.173 scanner 54% 1x OSINT 210 2 ssh:bruteforce 2026-09-02 22:44 evidence →
113.137.40.250 scanner 53% 1x OSINT 158 2 ssh:bruteforce 2026-08-22 01:03 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}