← Back to feed
AS852 TELUS Communications
ASN Ended mediumWhy this campaign was detected
5 IPs from the same network (TELUS Communications, AS852) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS852 · TELUS Communications
Subnet
—
Country
🇨🇦 CA
Cloud Provider
—
Member Count
5 IPs
Below average
Total Events
94
Below average by volume
Started / Ended
2026-02-23 03:20 — 2026-04-16 21:18
Attack Types
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Discovery
Command and Control
Member Actors
| IP Address | Behavior | Confidence | Flags | Events | Agents | Attack Types | Hostname | Last Seen | |
|---|---|---|---|---|---|---|---|---|---|
| 108.173.137.12 | credential_harvester | 38% | 96 | 1 | ssh:bruteforce | d108-173-137-12.abhsia.telus.net | 2026-03-10 21:12 | evidence → | |
| 207.219.221.101 | credential_probe | 18% | 1x OSINT | 20 | 1 | ssh:bruteforce | — | 2026-03-05 21:56 | evidence → |
| 96.1.40.151 | credential_probe | 18% | 1x OSINT | 15 | 1 | ssh:bruteforce | 96-1-40-151-staticipeast.wireless.telus.com | 2026-03-06 14:22 | evidence → |
| 207.219.221.53 | credential_probe | 14% | 26 | 1 | ssh:bruteforce | — | 2026-03-08 18:20 | evidence → | |
| 104.157.40.219 | credential_probe | 12% | 10 | 1 | ssh:bruteforce | — | 2026-03-04 15:22 | evidence → |
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds