← Back to feed

Subnet 153.75.82.0/24

SUBNET Active high
Why this campaign was detected
12 IPs from the same /24 subnet (153.75.82.0/24) were observed attacking our sensors within the same time window. All belong to RouterHosting LLC (AS14956). Concentrated activity from adjacent IPs is a strong indicator of a single operator or coordinated botnet.
Primary ASN
AS14956 · RouterHosting LLC
Subnet
153.75.82.0/24
Country
πŸ‡ΊπŸ‡Έ US
Cloud Provider
Member Count
12 IPs
Below average
Total Events
1145
Below average by volume
Started / Ended
2026-08-17 22:02 — ongoing
Attack Types
ftp:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Credential Access
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
153.75.82.223 ftp_bruter 58% 403 3 ftp:bruteforce β€” 2026-09-01 11:34 evidence →
153.75.82.216 ftp_bruter 45% 134 3 ftp:bruteforce β€” 2026-08-26 18:25 evidence →
153.75.82.123 ftp_bruter 33% 196 1 ftp:bruteforce β€” 2026-09-01 11:46 evidence →
153.75.82.162 ftp_bruter 30% 89 2 ftp:bruteforce β€” 2026-08-26 21:32 evidence →
153.75.82.185 ftp_bruter 28% 51 2 ftp:bruteforce β€” 2026-08-26 15:17 evidence →
153.75.82.135 ftp_bruter 27% 14 2 ftp:bruteforce β€” 2026-08-26 20:16 evidence →
153.75.82.182 ftp_bruter 26% 38 2 ftp:bruteforce β€” 2026-08-25 19:36 evidence →
153.75.82.171 ftp_bruter 25% 5 2 ftp:bruteforce β€” 2026-08-26 21:22 evidence →
153.75.82.158 ftp_bruter 22% 188 1 ftp:bruteforce β€” 2026-08-26 21:13 evidence →
153.75.82.191 ftp_bruter 18% 19 1 ftp:bruteforce β€” 2026-08-26 19:19 evidence →
153.75.82.149 ftp_bruter 15% 10 1 ftp:bruteforce β€” 2026-08-25 16:24 evidence →
153.75.82.240 ftp_probe 12% 1 1 ftp:bruteforce β€” 2026-08-26 21:12 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics β€” cookieless, public pages only. The context processor withholds the token from authenticated requests. #}