← Back to feed

AS12479 Orange Espagne SA

ASN Ended medium
Why this campaign was detected
5 IPs from the same network (Orange Espagne SA, AS12479) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS12479 · Orange Espagne SA
Subnet
Country
🇪🇸 ES
Cloud Provider
Member Count
5 IPs
Below average
Total Events
255
Below average by volume
Started / Ended
2026-02-22 17:42 — 2026-04-29 15:46
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
92.191.96.115 credential_harvester 49% 187 2 ssh:bruteforce 115.96.191.92.dynamic.jazztel.es 2026-03-13 01:45 evidence →
62.14.96.56 credential_harvester 49% 177 2 ssh:bruteforce 56.96.14.62.static.jazztel.es 2026-03-23 15:45 evidence →
90.160.139.163 credential_harvester 33% 36 1 ssh:bruteforce 163.pool90-160-139.dynamic.orange.es 2026-03-07 20:39 evidence →
90.161.217.228 credential_probe 13% 21 1 ssh:bruteforce 2026-03-21 01:36 evidence →
90.160.135.217 scanner 12% 4 1 ssh:bruteforce 2026-03-04 17:55 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}