← Back to feed

AS8359 MTS PJSC

ASN Ended medium
Why this campaign was detected
5 IPs from the same network (MTS PJSC, AS8359) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS8359 · MTS PJSC
Subnet
Country
🇷🇺 RU
Cloud Provider
Member Count
5 IPs
Below average
Total Events
174
Below average by volume
Started / Ended
2026-02-26 03:37 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
81.23.173.32 credential_harvester 75% 2x OSINT 1856 3 ssh:bruteforce 81-23-173-32.zgtk.ru 2026-08-11 00:15 evidence →
176.118.13.206 scanner 15% 11 1 ssh:bruteforce 2026-03-08 13:55 evidence →
213.87.245.200 credential_probe 13% 15 1 ssh:bruteforce P213-87-245-200.ural.mts.ru 2026-03-08 06:56 evidence →
213.87.53.167 scanner 12% 4 1 ssh:bruteforce 167.53.static-ip.mts.ru 2026-03-04 17:28 evidence →
213.87.53.189 scanner 11% 2 1 ssh:bruteforce 2026-03-08 00:26 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}