← Back to feed

AS852 TELUS Communications

ASN Ended medium
Why this campaign was detected
5 IPs from the same network (TELUS Communications, AS852) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS852 · TELUS Communications
Subnet
Country
🇨🇦 CA
Cloud Provider
Member Count
5 IPs
Below average
Total Events
94
Below average by volume
Started / Ended
2026-02-23 03:20 — 2026-04-16 21:18
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
108.173.137.12 credential_harvester 38% 96 1 ssh:bruteforce d108-173-137-12.abhsia.telus.net 2026-03-10 21:12 evidence →
207.219.221.101 credential_probe 18% 1x OSINT 20 1 ssh:bruteforce 2026-03-05 21:56 evidence →
96.1.40.151 credential_probe 18% 1x OSINT 15 1 ssh:bruteforce 96-1-40-151-staticipeast.wireless.telus.com 2026-03-06 14:22 evidence →
207.219.221.53 credential_probe 14% 26 1 ssh:bruteforce 2026-03-08 18:20 evidence →
104.157.40.219 credential_probe 12% 10 1 ssh:bruteforce 2026-03-04 15:22 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}