← Back to feed

AS3216 PVimpelCom

ASN Ended medium
Why this campaign was detected
5 IPs from the same network (PVimpelCom, AS3216) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS3216 · PVimpelCom
Subnet
Country
🇷🇺 RU
Cloud Provider
Member Count
5 IPs
Below average
Total Events
379
Below average by volume
Started / Ended
2026-02-23 20:55 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
81.211.72.167 credential_harvester 75% 2x OSINT 4937 3 ssh:bruteforce 2026-09-02 14:06 evidence →
81.211.88.66 credential_harvester 48% 150 2 ssh:bruteforce ns1.ime.ru 2026-03-25 20:59 evidence →
195.190.104.66 scanner 26% 36 2 ssh:bruteforce spb-195-190-104-66.sovintel.ru 2026-03-12 13:26 evidence →
195.218.159.123 credential_harvester 16% 27 1 ssh:bruteforce 2026-03-05 00:39 evidence →
195.190.126.122 credential_probe 12% 12 1 ssh:bruteforce 122-126-190-195.static.sovintel.ru 2026-03-06 05:24 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}