← Back to feed

AS1257 Tele2 SWIPnet

ASN Ended medium
Why this campaign was detected
5 IPs from the same network (Tele2 SWIPnet, AS1257) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS1257 · Tele2 SWIPnet
Subnet
Country
πŸ‡ΈπŸ‡ͺ SE
Cloud Provider
Member Count
5 IPs
Below average
Total Events
70
Below average by volume
Started / Ended
2026-02-23 14:14 — 2026-04-14 09:03
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Credential Access
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
185.2.228.48 credential_probe 17% 1x OSINT 10 1 ssh:bruteforce static-185-2-228-48.cust.tele2.lt 2026-03-01 17:43 evidence →
87.227.94.215 credential_harvester 16% 25 1 ssh:bruteforce c87-227-94-215.bredband.tele2.se 2026-03-07 17:00 evidence →
83.254.254.247 credential_probe 13% 15 1 ssh:bruteforce c83-254-254-247.bredband.tele2.se 2026-03-08 08:57 evidence →
80.170.6.4 credential_probe 13% 15 1 ssh:bruteforce m80-170-6-4.cust.tele2.se 2026-03-02 17:13 evidence →
37.2.108.253 credential_probe 13% 15 1 ssh:bruteforce m37-2-108-253.cust.tele2.se 2026-03-08 05:42 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics β€” cookieless, public pages only. The context processor withholds the token from authenticated requests. #}