← Back to feed

AS26496 GoDaddy.com, LLC

ASN Ended medium
Why this campaign was detected
5 IPs from the same network (GoDaddy.com, LLC, AS26496) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS26496 · GoDaddy.com, LLC
Subnet
Country
πŸ‡ΈπŸ‡¬ SG
Cloud Provider
Member Count
5 IPs
Below average
Total Events
2963
Below average by volume
Started / Ended
2026-03-19 08:38 — ongoing
Attack Types
mysql:bruteforce ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
97.74.87.152 credential_harvester 71% 1x OSINT 2151 3 ssh:bruteforce β€” 2026-08-03 15:09 evidence →
50.62.22.47 credential_harvester 56% 1x OSINT 1340 2 ssh:bruteforce β€” 2026-07-29 01:05 evidence →
68.178.163.185 scanner 33% 13 1 mysql:bruteforcessh:bruteforce β€” 2026-07-29 06:57 evidence →
148.66.133.23 reconnaissance 32% 1x OSINT 61 1 ssh:bruteforce β€” 2026-08-03 11:53 evidence →
97.74.83.203 scanner 13% 10 1 ssh:bruteforce β€” 2026-07-29 12:01 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics β€” cookieless, public pages only. The context processor withholds the token from authenticated requests. #}