← Back to feed

AS401701 cognetcloud INC

ASN Ended medium
Why this campaign was detected
6 IPs from the same network (cognetcloud INC, AS401701) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS401701 · cognetcloud INC
Subnet
Country
🇭🇰 HK
Cloud Provider
Member Count
6 IPs
Below average
Total Events
425
Below average by volume
Started / Ended
2026-03-17 23:35 — 2026-06-01 03:57
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
45.207.221.76 credential_harvester 50% DROP 500 2 ssh:bruteforce 2026-04-13 06:16 evidence →
103.52.152.101 credential_harvester 50% DROP 436 2 ssh:bruteforce 2026-04-25 03:48 evidence →
154.222.24.142 credential_harvester 47% DROP 93 2 ssh:bruteforce 2026-03-26 13:56 evidence →
156.233.226.182 scanner 22% DROP 10 1 ssh:bruteforce 2026-03-20 03:36 evidence →
38.76.218.72 credential_probe 14% DROP 40 1 ssh:bruteforce 2026-03-26 01:00 evidence →
82.158.224.77 credential_probe 13% DROP 15 1 ssh:bruteforce 2026-03-21 04:46 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}