← Back to feed

AS45102 Alibaba US Technology Co., Ltd.

ASN Active medium
Why this campaign was detected
18 IPs from the same network (Alibaba US Technology Co., Ltd., AS45102) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS45102 · Alibaba US Technology Co., Ltd.
Subnet
Country
🇭🇰 HK
Cloud Provider
Member Count
18 IPs
Below average
Total Events
1665
Below average by volume
Started / Ended
2026-02-28 21:04 — ongoing
Attack Types
http:scan mysql:bruteforce ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Execution
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
8.217.232.214 scanner 63% 1x OSINT 233 3 ssh:bruteforce 2026-08-27 13:47 evidence →
8.222.128.242 scanner 61% 2x OSINT 58 3 mysql:bruteforcessh:bruteforce 2026-08-27 08:41 evidence →
8.222.181.172 scanner 57% 1x OSINT 57 3 mysql:bruteforcessh:bruteforce 2026-08-27 01:57 evidence →
8.221.139.48 scanner 56% 1x OSINT 59 3 mysql:bruteforcessh:bruteforce 2026-08-26 10:35 evidence →
8.221.136.6 scanner 55% 55 3 mysql:bruteforcessh:bruteforce 2026-08-28 10:04 evidence →
8.210.214.44 scanner 55% 81 3 ssh:bruteforce 2026-08-26 19:29 evidence →
47.84.48.99 opportunistic_bruter 48% 23 1 ssh:bruteforce 2026-08-30 14:08 evidence →
8.217.68.84 credential_harvester 46% 1x OSINT 1026 1 ssh:bruteforce 2026-08-29 23:59 evidence →
47.243.252.177 interactive_operator 44% 13 1 ssh:bruteforce 2026-08-31 09:01 evidence →
47.251.116.61 web_probe 43% 1x OSINT 2 2 http:scanmysql:bruteforce 2026-08-29 16:09 evidence →
8.220.135.32 malware_dropper 43% 23 1 ssh:bruteforce 2026-08-29 03:24 evidence →
8.208.9.170 scanner 43% 6 3 ssh:bruteforce 2026-08-28 18:27 evidence →
198.11.177.243 web_probe 37% 9 2 http:scan 2026-09-01 01:47 evidence →
47.77.214.63 web_probe 32% 1x OSINT 2 2 http:scan 2026-08-28 01:30 evidence →
8.222.211.75 scanner 26% 4 2 ssh:bruteforce 2026-08-28 01:37 evidence →
47.88.86.63 web_probe 25% 2 2 http:scan 2026-08-26 11:36 evidence →
47.239.18.157 scanner 24% 2 1 ssh:bruteforce 2026-08-31 17:12 evidence →
47.251.90.48 web_probe 20% 10 1 http:scan 2026-08-27 10:10 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}