← Back to feed

AS32475 Internap Holding LLC

ASN Active medium
Why this campaign was detected
10 IPs from the same network (Internap Holding LLC, AS32475) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS32475 · Internap Holding LLC
Subnet
Country
πŸ‡ΊπŸ‡Έ US
Cloud Provider
Member Count
10 IPs
Below average
Total Events
210
Below average by volume
Started / Ended
2026-05-02 23:14 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Credential Access
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
184.154.153.131 credential_harvester 42% 28 2 ssh:bruteforce β€” 2026-05-05 03:15 evidence →
173.236.16.74 credential_harvester 40% 42 2 ssh:bruteforce β€” 2026-05-03 18:02 evidence →
184.154.156.13 credential_harvester 39% 28 2 ssh:bruteforce β€” 2026-05-03 14:28 evidence →
108.178.7.34 credential_harvester 39% 28 2 ssh:bruteforce β€” 2026-05-03 05:18 evidence →
69.175.92.29 credential_harvester 34% 1x OSINT 14 1 ssh:bruteforce β€” 2026-05-03 16:15 evidence →
184.154.78.51 credential_harvester 33% 1x OSINT 14 1 ssh:bruteforce β€” 2026-05-03 06:16 evidence →
184.154.78.61 credential_harvester 29% 14 1 ssh:bruteforce β€” 2026-05-03 17:02 evidence →
107.6.164.240 credential_harvester 29% 14 1 ssh:bruteforce β€” 2026-05-03 12:31 evidence →
65.60.5.244 credential_harvester 29% 14 1 ssh:bruteforce β€” 2026-05-03 11:33 evidence →
96.127.172.218 credential_harvester 29% 14 1 ssh:bruteforce β€” 2026-05-03 07:55 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds