← Back to feed

AS13489 UNE EPM TELECOMUNICACIONES S.A.

ASN Ended medium
Why this campaign was detected
5 IPs from the same network (UNE EPM TELECOMUNICACIONES S.A., AS13489) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS13489 · UNE EPM TELECOMUNICACIONES S.A.
Subnet
Country
🇨🇴 CO
Cloud Provider
Member Count
5 IPs
Below average
Total Events
2574
Below average by volume
Started / Ended
2026-02-25 17:50 — ongoing
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
201.184.50.251 credential_harvester 75% 2x OSINT 2537 3 ssh:bruteforce static-adsl201-184-50-251.une.net.co 2026-08-19 00:45 evidence →
190.249.168.85 scanner 22% 8 2 ssh:bruteforce 2026-08-20 17:50 evidence →
181.129.31.42 credential_probe 18% 1x OSINT 21 1 ssh:bruteforce adsl-181-129-31-42.une.net.co 2026-08-16 01:03 evidence →
181.68.11.98 scanner 12% 4 1 ssh:bruteforce 2026-08-18 04:22 evidence →
181.139.151.176 scanner 12% 4 1 ssh:bruteforce 2026-08-16 11:28 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}