← Back to feed
AS1257 Tele2 SWIPnet
ASN Ended mediumWhy this campaign was detected
5 IPs from the same network (Tele2 SWIPnet, AS1257) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS1257 · Tele2 SWIPnet
Subnet
—
Country
πΈπͺ SE
Cloud Provider
—
Member Count
5 IPs
Below average
Total Events
70
Below average by volume
Started / Ended
2026-02-23 14:14 — 2026-04-14 09:03
Attack Types
MITRE ATT&CK Techniques
Member Actors
| IP Address | Behavior | Confidence | Flags | Events | Agents | Attack Types | Hostname | Last Seen | |
|---|---|---|---|---|---|---|---|---|---|
| 185.2.228.48 | credential_probe | 17% | 1x OSINT | 10 | 1 | ssh:bruteforce | static-185-2-228-48.cust.tele2.lt | 2026-03-01 17:43 | evidence → |
| 87.227.94.215 | credential_harvester | 16% | 25 | 1 | ssh:bruteforce | c87-227-94-215.bredband.tele2.se | 2026-03-07 17:00 | evidence → | |
| 83.254.254.247 | credential_probe | 13% | 15 | 1 | ssh:bruteforce | c83-254-254-247.bredband.tele2.se | 2026-03-08 08:57 | evidence → | |
| 80.170.6.4 | credential_probe | 13% | 15 | 1 | ssh:bruteforce | m80-170-6-4.cust.tele2.se | 2026-03-02 17:13 | evidence → | |
| 37.2.108.253 | credential_probe | 13% | 15 | 1 | ssh:bruteforce | m37-2-108-253.cust.tele2.se | 2026-03-08 05:42 | evidence → |
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds