← Back to feed

AS3269 TIM

ASN Active medium
Why this campaign was detected
5 IPs from the same network (TIM, AS3269) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS3269 · TIM
Subnet
Country
🇮🇹 IT
Cloud Provider
Member Count
5 IPs
Below average
Total Events
588
Below average by volume
Started / Ended
2026-03-01 04:59 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Execution
Credential Access
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
79.36.191.212 credential_harvester 78% 1x OSINT 933 3 ssh:bruteforce 2026-05-28 16:33 evidence →
95.250.241.71 opportunistic_bruter 42% 1x OSINT 46 1 ssh:bruteforce 2026-05-21 21:05 evidence →
95.239.229.172 interactive_operator 34% 34 1 ssh:bruteforce 2026-05-18 15:33 evidence →
79.40.191.81 credential_probe 12% 10 1 ssh:bruteforce 2026-05-20 10:40 evidence →
87.1.208.75 credential_probe 12% 10 1 ssh:bruteforce 2026-05-25 00:38 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds