← Back to feed
AS58466 CHINANET Guangdong province network
ASN Active mediumWhy this campaign was detected
5 IPs from the same network (CHINANET Guangdong province network, AS58466) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS58466 · CHINANET Guangdong province network
Subnet
—
Country
🇨🇳 CN
Cloud Provider
—
Member Count
5 IPs
Below average
Total Events
200
Below average by volume
Started / Ended
2026-02-28 01:53 — ongoing
Attack Types
MITRE ATT&CK Techniques
Initial Access
Command and Control
Member Actors
| IP Address | Behavior | Confidence | Flags | Events | Agents | Attack Types | Hostname | Last Seen | |
|---|---|---|---|---|---|---|---|---|---|
| 106.75.153.103 | credential_harvester | 72% | 2x OSINT | 182 | 3 | ssh:bruteforce | — | 2026-08-13 23:47 | evidence → |
| 106.75.184.142 | mysql_bruter | 44% | 6 | 3 | mysql:bruteforce | — | 2026-08-29 01:19 | evidence → | |
| 106.75.156.189 | mysql_probe | 25% | 1x OSINT | 4 | 2 | mysql:bruteforce | — | 2026-08-12 23:24 | evidence → |
| 106.75.189.197 | mysql_bruter | 23% | 5 | 2 | mysql:bruteforce | — | 2026-08-12 23:03 | evidence → | |
| 106.75.188.200 | mysql_bruter | 23% | 5 | 2 | mysql:bruteforce | — | 2026-08-18 22:49 | evidence → |
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds