← Back to feed
AS401701 cognetcloud INC
ASN Ended mediumWhy this campaign was detected
6 IPs from the same network (cognetcloud INC, AS401701) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS401701 · cognetcloud INC
Subnet
—
Country
🇭🇰 HK
Cloud Provider
—
Member Count
6 IPs
Below average
Total Events
425
Below average by volume
Started / Ended
2026-03-17 23:35 — 2026-06-01 03:57
Attack Types
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Command and Control
Member Actors
| IP Address | Behavior | Confidence | Flags | Events | Agents | Attack Types | Hostname | Last Seen | |
|---|---|---|---|---|---|---|---|---|---|
| 45.207.221.76 | credential_harvester | 50% | DROP | 500 | 2 | ssh:bruteforce | — | 2026-04-13 06:16 | evidence → |
| 103.52.152.101 | credential_harvester | 50% | DROP | 436 | 2 | ssh:bruteforce | — | 2026-04-25 03:48 | evidence → |
| 154.222.24.142 | credential_harvester | 47% | DROP | 93 | 2 | ssh:bruteforce | — | 2026-03-26 13:56 | evidence → |
| 156.233.226.182 | scanner | 22% | DROP | 10 | 1 | ssh:bruteforce | — | 2026-03-20 03:36 | evidence → |
| 38.76.218.72 | credential_probe | 14% | DROP | 40 | 1 | ssh:bruteforce | — | 2026-03-26 01:00 | evidence → |
| 82.158.224.77 | credential_probe | 13% | DROP | 15 | 1 | ssh:bruteforce | — | 2026-03-21 04:46 | evidence → |
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds