← Back to feed
AS402253 SKN Subnet & Telecom Ltd
ASN Ended mediumWhy this campaign was detected
6 IPs from the same network (SKN Subnet & Telecom Ltd, AS402253) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS402253 · SKN Subnet & Telecom Ltd
Subnet
—
Country
🇨🇭 CH
Cloud Provider
—
Member Count
6 IPs
Below average
Total Events
5739
Below average by volume
Started / Ended
2026-04-21 14:35 — 2026-09-10 04:30
Attack Types
MITRE ATT&CK Techniques
Discovery
Command and Control
Member Actors
| IP Address | Behavior | Confidence | Flags | Events | Agents | Attack Types | Hostname | Last Seen | |
|---|---|---|---|---|---|---|---|---|---|
| 209.99.189.177 | credential_harvester | 71% | DROP1x OSINT | 2022 | 3 | ssh:bruteforce | — | 2026-08-04 03:32 | evidence → |
| 209.99.185.195 | credential_harvester | 71% | DROP1x OSINT | 820 | 3 | ssh:bruteforce | — | 2026-08-03 11:45 | evidence → |
| 209.99.191.19 | credential_harvester | 67% | DROP | 2634 | 3 | ssh:bruteforce | — | 2026-07-12 09:30 | evidence → |
| 209.99.184.143 | credential_harvester | 67% | DROP | 1919 | 3 | ssh:bruteforce | — | 2026-06-29 17:16 | evidence → |
| 209.99.185.98 | scanner | 23% | DROP | 12 | 2 | ssh:bruteforce | — | 2026-06-30 10:26 | evidence → |
| 209.99.186.68 | web_probe | 15% | DROP | 4 | 1 | http:scan | — | 2026-07-04 17:43 | evidence → |
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds