← Back to feed

AS54994 Meteverse Limited.

ASN Active medium
Why this campaign was detected
5 IPs from the same network (Meteverse Limited., AS54994) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS54994 · Meteverse Limited.
Subnet
Country
🇰🇷 KR
Cloud Provider
Member Count
5 IPs
Below average
Total Events
876
Below average by volume
Started / Ended
2026-05-24 20:26 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
101.79.165.43 credential_harvester 75% 2x OSINT 2027 3 ssh:bruteforce 2026-09-08 19:37 evidence →
114.111.53.214 credential_harvester 74% 1x OSINT 924 3 ssh:bruteforce 2026-09-10 03:48 evidence →
114.111.54.189 credential_harvester 71% 1x OSINT 1132 3 ssh:bruteforce 2026-08-03 02:21 evidence →
138.113.23.170 credential_harvester 66% 765 3 ssh:bruteforce 2026-06-15 13:12 evidence →
174.35.25.177 credential_harvester 43% 1004 1 ssh:bruteforce 2026-07-02 10:25 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}