← Back to feed

AS134756 CHINANET Nanjing Jishan IDC network

ASN Ended medium
Why this campaign was detected
5 IPs from the same network (CHINANET Nanjing Jishan IDC network, AS134756) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS134756 · CHINANET Nanjing Jishan IDC network
Subnet
Country
🇨🇳 CN
Cloud Provider
Member Count
5 IPs
Below average
Total Events
780
Below average by volume
Started / Ended
2026-02-23 11:15 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
121.229.202.143 scanner 42% 1x OSINT 57 1 ssh:bruteforce 2026-08-11 01:06 evidence →
117.89.254.46 scanner 31% 1x OSINT 33 1 ssh:bruteforce 2026-08-14 16:04 evidence →
121.229.98.52 reconnaissance 25% 10 1 ssh:bruteforce 2026-08-14 22:58 evidence →
220.154.131.135 scanner 21% 2x OSINT 8 1 ssh:bruteforce 2026-08-12 12:28 evidence →
121.229.210.188 scanner 21% 696 1 ssh:bruteforce 2026-08-17 05:06 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}