← Back to feed
AS26599 TELEFONICA BRASIL S.A
ASN Ended mediumWhy this campaign was detected
5 IPs from the same network (TELEFONICA BRASIL S.A, AS26599) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS26599 · TELEFONICA BRASIL S.A
Subnet
—
Country
🇧🇷 BR
Cloud Provider
—
Member Count
5 IPs
Below average
Total Events
64
Below average by volume
Started / Ended
2026-02-22 20:31 — 2026-04-22 02:52
Attack Types
MITRE ATT&CK Techniques
Member Actors
| IP Address | Behavior | Confidence | Flags | Events | Agents | Attack Types | Hostname | Last Seen | |
|---|---|---|---|---|---|---|---|---|---|
| 177.172.4.218 | malware_dropper | 36% | 23 | 1 | ssh:bruteforce | 177-172-4-218.user.vivozap.com.br | 2026-02-28 08:00 | evidence → | |
| 177.174.95.245 | credential_harvester | 33% | 41 | 1 | ssh:bruteforce | 177-174-95-245.user.vivozap.com.br | 2026-03-16 02:47 | evidence → | |
| 177.174.106.155 | proxy_abuser | 31% | 11 | 1 | ssh:bruteforce | 177-174-106-155.user.vivozap.com.br | 2026-03-01 12:41 | evidence → | |
| 177.174.0.3 | credential_probe | 19% | 1x OSINT | 26 | 1 | ssh:bruteforce | 177-174-0-3.user.vivozap.com.br | 2026-03-16 02:42 | evidence → |
| 177.174.105.113 | credential_probe | 13% | 20 | 1 | ssh:bruteforce | 177-174-105-113.user.vivozap.com.br | 2026-03-06 12:19 | evidence → |
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds