← Back to feed

Subnet 69.5.169.0/24

SUBNET Active high
Why this campaign was detected
17 IPs from the same /24 subnet (69.5.169.0/24) were observed attacking our sensors within the same time window. All belong to Hydra Communications Ltd (AS25369). Concentrated activity from adjacent IPs is a strong indicator of a single operator or coordinated botnet.
Primary ASN
AS25369 · Hydra Communications Ltd
Subnet
69.5.169.0/24
Country
🇩🇪 DE
Cloud Provider
Member Count
17 IPs
Below average
Total Events
73
Below average by volume
Started / Ended
2026-05-13 12:51 — ongoing
Attack Types
http:scan ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
69.5.169.75 scanner 54% 2x OSINT 7 2 http:scanssh:bruteforce 2026-09-01 12:30 evidence →
69.5.169.87 scanner 53% 2x OSINT 5 2 http:scanssh:bruteforce 2026-09-01 12:30 evidence →
69.5.169.52 scanner 42% 1x OSINT 10 2 http:scanssh:bruteforce 2026-08-27 22:23 evidence →
69.5.169.81 web_probe 33% 1x OSINT 1 1 http:scan 2026-08-31 10:39 evidence →
69.5.169.100 scanner 33% 1x OSINT 4 1 ssh:bruteforce 2026-08-31 13:08 evidence →
69.5.169.3 web_probe 28% 1x OSINT 5 1 http:scanssh:bruteforce 2026-08-25 23:26 evidence →
69.5.169.125 scanner 28% 1x OSINT 4 1 ssh:bruteforce 2026-08-31 03:28 evidence →
69.5.169.118 scanner 28% 2x OSINT 2 1 ssh:bruteforce 2026-08-31 08:21 evidence →
69.5.169.208 scanner 27% 12 1 http:scanssh:bruteforce 2026-08-27 00:41 evidence →
69.5.169.95 web_probe 26% 2x OSINT 1 1 http:scan 2026-08-28 06:06 evidence →
69.5.169.42 web_probe 25% 2x OSINT 2 1 http:scan 2026-08-27 00:37 evidence →
69.5.169.117 web_probe 24% 5 1 http:scanssh:bruteforce 2026-08-25 23:26 evidence →
69.5.169.62 web_probe 23% 1x OSINT 1 1 http:scan 2026-08-28 06:06 evidence →
69.5.169.37 scanner 22% 2x OSINT 8 1 ssh:bruteforce 2026-08-26 03:34 evidence →
69.5.169.56 web_probe 20% 1x OSINT 1 1 http:scan 2026-08-27 00:37 evidence →
69.5.169.86 web_probe 18% 1x OSINT 1 1 http:scan 2026-08-25 23:38 evidence →
69.5.169.31 scanner 15% 4 1 ssh:bruteforce 2026-08-27 00:42 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}