← Back to feed

AS24544 Overcasts Limited

ASN Ended medium
Why this campaign was detected
5 IPs from the same network (Overcasts Limited, AS24544) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS24544 · Overcasts Limited
Subnet
Country
🇭🇰 HK
Cloud Provider
Member Count
5 IPs
Below average
Total Events
2316
Below average by volume
Started / Ended
2026-02-23 08:28 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
45.116.78.92 credential_harvester 71% DROP1x OSINT 1525 3 ssh:bruteforce 2026-08-27 08:41 evidence →
103.243.26.174 credential_harvester 67% DROP 1733 3 ssh:bruteforce 2026-08-05 09:47 evidence →
103.243.24.124 credential_harvester 66% DROP 661 3 ssh:bruteforce 2026-05-31 22:01 evidence →
45.116.79.184 credential_harvester 51% DROP 641 2 ssh:bruteforce 2026-04-19 13:57 evidence →
185.216.119.134 credential_harvester 49% DROP 220 2 ssh:bruteforce 2026-05-18 02:34 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}