← Back to feed

AS200019 Alexhost Srl

ASN Active medium
Why this campaign was detected
6 IPs from the same network (Alexhost Srl, AS200019) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS200019 · Alexhost Srl
Subnet
Country
🇲🇩 MD
Cloud Provider
Member Count
6 IPs
Below average
Total Events
196
Below average by volume
Started / Ended
2026-05-05 04:49 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Credential Access
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
91.208.197.64 credential_harvester 35% 88 2 ssh:bruteforce 2026-05-12 17:02 evidence →
85.121.4.10 credential_harvester 31% 34 2 ssh:bruteforce 2026-05-11 01:14 evidence →
217.156.64.228 credential_harvester 27% 1x OSINT 20 1 ssh:bruteforce 2026-05-12 02:58 evidence →
91.229.239.210 credential_harvester 25% 14 1 ssh:bruteforce 2026-05-13 11:25 evidence →
85.120.81.241 credential_harvester 22% 6 1 ssh:bruteforce 2026-05-12 19:38 evidence →
45.150.111.52 credential_probe 15% 6 1 ssh:bruteforce 2026-05-12 22:26 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds