← Back to feed

AS41668 JSC ER-Telecom Holding

ASN Ended medium
Why this campaign was detected
5 IPs from the same network (JSC ER-Telecom Holding, AS41668) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS41668 · JSC ER-Telecom Holding
Subnet
Country
🇷🇺 RU
Cloud Provider
Member Count
5 IPs
Below average
Total Events
47
Below average by volume
Started / Ended
2026-02-26 00:13 — 2026-04-26 01:01
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Credential Access
Discovery
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
94.180.250.11 credential_harvester 63% 143 3 ssh:bruteforce 94x180x250x11.static-business.kzn.ertelecom.ru 2026-07-05 18:32 evidence →
94.180.223.124 scanner 22% 10 2 ssh:bruteforce 2026-03-20 00:53 evidence →
92.255.196.185 credential_probe 18% 1x OSINT 19 1 ssh:bruteforce 92x255x196x185.static-customer.kzn.ertelecom.ru 2026-03-08 06:13 evidence →
94.180.220.228 credential_probe 13% 22 1 ssh:bruteforce dynamicip-94-180-220-228.pppoe.kzn.ertelecom.ru 2026-03-06 09:35 evidence →
94.180.229.67 scanner 11% 2 1 ssh:bruteforce 2026-03-02 20:55 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}