aboutsummaryrefslogtreecommitdiff
path: root/2026
diff options
context:
space:
mode:
authorhrbrmstr <bob@rud.is>2026-06-09 20:44:52 -0400
committerhrbrmstr <bob@rud.is>2026-06-09 20:44:52 -0400
commitbd417023bfb20a65052611064b6df9e6bf9ad597 (patch)
tree37103a3de59cb098eb971c2db22001ee8882f7c6 /2026
parentd7a9bac5ba6b053f46ecd5685b60c2ffd89ea528 (diff)
add: asn-report
Diffstat (limited to '2026')
-rw-r--r--2026/asn215540-report/README.md311
-rw-r--r--2026/asn215540-report/censys-cli-queries.md54
-rw-r--r--2026/asn215540-report/companions-tier1.md55
-rw-r--r--2026/asn215540-report/companions-tier2-same24.md231
-rw-r--r--2026/asn215540-report/companions-tier3-by-block.md51
-rw-r--r--2026/asn215540-report/honeylabs-data.md89
6 files changed, 791 insertions, 0 deletions
diff --git a/2026/asn215540-report/README.md b/2026/asn215540-report/README.md
new file mode 100644
index 0000000..1f0396c
--- /dev/null
+++ b/2026/asn215540-report/README.md
@@ -0,0 +1,311 @@
+# ASN 215540 (GCS-AS) -- Comprehensive Intelligence Report
+
+**Date**: 2026-06-09
+**Data Sources**: Censys (host search, host view), Honeylabs (IOC, ASN enrichment, top attackers, attack timeline)
+**Scope**: Three target IPs (92.118.112.230, 89.185.80.144, 89.185.80.183) mapped to their full ASN infrastructure
+
+---
+
+## 1. Executive Summary
+
+The three target IPs belong to ASN 215540, operated by **GLOBAL CONNECTIVITY SOLUTIONS LLP** (GCS-AS), a UK-registered shell company with Russian management (RIPE admin Evgenii M., Russian address on file). This ASN is a **large-scale proxy/VPN exit node hosting operation** with 1,000+ IPs across 22+ IP blocks in 13+ countries.
+
+Key characteristics: massive SSH server farm (387 hosts sharing the exact build/fingerprint of the targets), geographic diversity (US, DE, PL, LT, AM, TR, NL, DK, GB, HK, AL, CH, BR), mixed infrastructure (SOCKS5 proxy, credential harvesting panel, Caddy HTTP servers, nginx), and consistent scanning/probing behavior flagged by GreyNoise.
+
+---
+
+## 2. Target IP Analysis
+
+### 2.1 Target IPs
+
+| IP | Block | Location | SSH Build | HASSH | PTR | GreyNoise |
+|---|---|---|---|---|---|---|
+| 92.118.112.230 | 92.118.112.0/24 | Atlanta, US | 9.6p1 Ubuntu-3ubuntu13.16 | e42184b0... | 157279.ip-ptr.tech | Suspicious |
+| 89.185.80.144 | 89.185.80.0/24 | Phoenix, US | 9.6p1 Ubuntu-3ubuntu13.16 | e42184b0... | 157279.ip-ptr.tech | Suspicious |
+| 89.185.80.183 | 89.185.80.0/24 | Phoenix, US | 9.6p1 Ubuntu-3ubuntu13.16 | e42184b0... | 157279.ip-ptr.tech | Suspicious |
+
+### 2.2 GreyNoise Classification (All Three)
+
+All classified as **suspicious** with identical tags:
+
+- Web Crawler, TLS/SSL Crawler
+- Carries HTTP Referer
+- Generic Login Attempt
+- Palo Alto Networks PAN-OS CVE-2020-2034 Crawler
+- F5 BIG-IP Crawler
+- Generic SQL Commands in Request
+- Generic Sensitive File Access Attempt (.183 only)
+- Generic Path Traversal Attempt (.183 only)
+- Generic Suspicious Linux Command in Request (.144, .183)
+
+### 2.3 Censys Reputation
+
+All three rated **"benign"** by Censys reputation model (v0.1.0) -- likely because they only expose SSH:22 and do not host malicious web content.
+
+### 2.4 CVE Exposure
+
+All run OpenSSH 9.6p1, exposing them to:
+
+- CVE-2024-6387 (regreSSHion) -- CVSS 8.1, EPSS 0.658 (98.5th percentile)
+- CVE-2025-26465 -- CVSS 6.8, EPSS 0.617 (98.4th percentile)
+- CVE-2025-26466 -- CVSS 5.9, EPSS 0.624 (98.4th percentile)
+- CVE-2025-32728 -- CVSS 4.3
+- CVE-2026-35385-35388, 35414 -- various recent CVEs
+
+---
+
+## 3. Provider Profile
+
+### 3.1 Registration Details
+
+| Field | Value |
+|---|---|
+| ASN | 215540 |
+| Legal Name | GLOBAL CONNECTIVITY SOLUTIONS LLP |
+| Also Known As | GLOBAL INTERNET SOLUTIONS LLC |
+| RIPE Handle | ORG-GCSL7-RIPE |
+| RIPE Admin | Evgenii M. (admin@gir.network) |
+| Abuse Contacts | abuse@globconnex.com, abuse@gir.network |
+| UK Address | Suite 310, 21 Hill Street, Haverfordwest, Pembrokeshire, SA61 1QQ |
+| Russian Address | Vn.Ter.G. Gagarinsky Municipal District, Mayachnaya St., 13. |
+| WHOIS Created | Various blocks 2021-2025 |
+
+### 3.2 IP Blocks (23 total)
+
+| Prefix | Location | WHOIS Created |
+|---|---|---|
+| 45.89.60.0/24 | Tirana, AL | -- |
+| 62.60.232.0/24 | Hong Kong, HK | -- |
+| 77.83.246.0/24 | Warsaw, PL | -- |
+| 78.153.131.0/24 | Siauliai, LT | -- |
+| 78.153.155.0/24 | Atlanta, US | -- |
+| 81.17.159.0/24 | Copenhagen, DK | -- |
+| 81.177.215.0/24 | Istanbul, TR | -- |
+| 85.234.100.0/24 | Frankfurt, DE | -- |
+| 87.120.219.0/24 | London, GB | -- |
+| 87.120.222.0/24 | Zurich, CH | -- |
+| 87.121.47.0/24 | Tsovasar, AM | 2025-07-03 |
+| 89.185.80.0/24 | Phoenix, US | 2024-06-28 |
+| 89.185.81.0/24 | Sandefjord, NO | 2024-06-28 |
+| 92.118.112.0/24 | Atlanta, US | 2021-12-24 |
+| 109.172.55.0/24 | Paris, FR | 2025-04-23 |
+| 141.98.234.0/24 | Hong Kong, HK | -- |
+| 145.249.115.0/24 | Amsterdam, NL | -- |
+| 147.45.50.0/24 | Kerkrade, NL | 2024-02-20 |
+| 147.45.60.0/24 | Atlanta, US | 2024-02-22 |
+| 147.45.86.0/24 | -- | -- |
+| 147.45.116.0/24 | Sao Paulo, BR | -- |
+| 147.45.204.0/24 | Kerkrade, NL | -- |
+| 147.45.217.0/24 | Siauliai, LT | -- |
+| 153.80.242.0/24 | Frankfurt, DE | -- |
+| 170.168.136.0/22 | -- | -- |
+| 178.17.53.0/24 | Helsinki, FI | 2025-08-07 |
+| 178.17.58.0/24 | Frankfurt, DE | -- |
+| 178.130.46.0/24 | Kerkrade, NL | 2025-04-23 |
+| 178.130.47.0/24 | Phoenix, US | -- |
+| 185.39.204.0/24 | Istanbul, TR | -- |
+| 185.75.132.0/24 | -- | -- |
+| 185.100.159.0/24 | Frankfurt, DE | -- |
+| 185.161.251.0/24 | Frankfurt, DE | -- |
+| 185.214.74.0/24 | Kerkrade, NL | 2021-11-24 |
+| 188.130.196.0/22 | -- | -- |
+| 193.39.208.0/24 | Kerkrade, NL | -- |
+| 193.233.74.0/24 | Frankfurt, DE | -- |
+| 2a05:541:121::/48 | IPv6 | -- |
+
+---
+
+## 4. Signature-Based Companion Analysis
+
+### 4.1 Signature Set from Target IPs
+
+| Signature | Value | Coverage |
+|---|---|---|
+| ASN | 215540 | 1,000+ hosts |
+| SSH Build | OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 | 387 hosts |
+| HASSH | e42184b06d45385a906f0803d04c83da | 387 hosts |
+| PTR | 157279.ip-ptr.tech | 4 hosts |
+| PTR Domain | *.ip-ptr.tech | ~168 hosts |
+| JA4t Scan | 65160_2-4-8-1-3_1460_7_1-2-4-8-16 | All 3 originals |
+| GreyNoise Tags | Login Scanner, PAN-OS, F5, SQLi | 3 originals + 1 companion |
+
+### 4.2 Tier 1: Exact Signature Twins (4 hosts)
+
+These share PTR `157279.ip-ptr.tech`, identical SSH build, identical HASSH:
+
+| IP | Block | Location | GreyNoise |
+|---|---|---|---|
+| 92.118.112.230 | 92.118.112.0/24 | Atlanta, US | Suspicious |
+| 89.185.80.144 | 89.185.80.0/24 | Phoenix, US | Suspicious |
+| 89.185.80.183 | 89.185.80.0/24 | Phoenix, US | Suspicious |
+| **147.45.60.25** | 147.45.60.0/24 | Atlanta, US | Suspicious (same tags) + domain `zubat.org` |
+
+### 4.3 Tier 2: Same /24 + Same Build
+
+**92.118.112.0/24** -- 103 hosts with matching SSH build
+**89.185.80.0/24** -- 97 hosts with matching SSH build
+
+Complete listings in `companions-tier2.md`.
+
+### 4.4 Tier 3: Same Build Across Entire ASN
+
+**387 hosts total** with HASSH `e42184b06d45385a906f0803d04c83da` by country:
+
+| Country | Hosts | Key Blocks |
+|---|---|---|
+| Germany | 145 | 185.100.159.0/24, 193.233.74.0/24, 178.17.58.0/24, 153.80.242.0/24 |
+| United States | 58 | 78.153.155.0/24, 92.118.112.0/24, 178.130.47.0/24 |
+| Lithuania | 58 | 147.45.217.0/24, 78.153.131.0/24 |
+| Poland | 52 | 77.83.246.0/24 |
+| Armenia | 43 | 87.121.47.0/24 |
+| Turkey | 42 | 185.39.204.0/24, 81.177.215.0/24 |
+| Netherlands | 28 | 193.39.208.0/24, 147.45.204.0/24 |
+| Denmark | 26 | 81.17.159.0/24 |
+| United Kingdom | 25 | 87.120.219.0/24 |
+| Hong Kong | 17 | 62.60.232.0/24 |
+| Albania | 4 | 45.89.60.0/24 |
+| Brazil | 1 | 147.45.116.0/24 |
+| Switzerland | 1 | 87.120.222.0/24 |
+
+---
+
+## 5. Special-Purpose Infrastructure in ASN 215540
+
+### 5.1 Proxy/Tunneling Services
+
+| IP | Block | Service | Details |
+|---|---|---|---|
+| 178.130.46.2 | 178.130.46.0/24 | SOCKS5 :1080 | Username/password auth. Domains: games-oracle.ru, 7neth.solonettochka.ru |
+| 185.100.159.193 | 185.100.159.0/24 | Tunneling | PTR: de05.tunnely.ru |
+
+### 5.2 Credential Harvesting / Admin Panels
+
+| IP | Block | Service | Notes |
+|---|---|---|---|
+| 147.45.50.108 | 147.45.50.0/24 | Gunicorn :8080 | **GreyNoise: MALICIOUS**. Admin Login page (username + password + TOTP). Tags: SSH bruteforcer, path traversal, ThinkPHP RCE, PHP CVE-2024-4577, Docker scanner, Telnet, IoT |
+| 147.45.50.147 | 147.45.50.0/24 | -- | Active in honeypot (48 events) |
+| 147.45.50.171 | 147.45.50.0/24 | -- | Active in honeypot (47 events) |
+
+### 5.3 Web Servers
+
+| IP | Block | Service | Details |
+|---|---|---|---|
+| 92.118.112.178 | 92.118.112.0/24 | Caddy HTTP | Ports 1337, 9091, 10095. JSON error responses |
+| 185.214.74.251 | 185.214.74.0/24 | nginx :80,443 | Domain: dnau-getfkdwhocares123.xyz |
+| 147.45.60.22 | 147.45.60.0/24 | HTTPS :2096 | Let's Encrypt cert, 404 |
+| 87.121.47.94 | 87.121.47.0/24 | HTTPS :443, :2096, :55421 | Sectigo cert (github.com CN -- likely spoofed), Let's Encrypt (igorarmsrv.duckdns.org) |
+
+### 5.4 Notable PTR Artifacts
+
+| PTR | Block | Implication |
+|---|---|---|
+| fbi.com | 77.83.246.0/24, 89.185.80.0/24, 147.45.49.0/24 | Fake PTR (trolling/masquerading) |
+| ya.ru | 77.83.246.0/24 | Masquerading as Yandex |
+| *.4server.su | Various | Russian hosting infrastructure domains |
+| *.my-server.app | Various | Infra domain (usa1-pho-monitor, lt1-cloned, etc.) |
+| *.servera.info | Various | Infra domain |
+| *.itg.top | 92.118.112.0/24 | us.itg.top |
+| *.tunnely.ru | 185.100.159.0/24 | Tunneling service |
+| *.4host.su | 92.118.112.0/24 | Infra domain |
+
+---
+
+## 6. Honeylabs Telemetry
+
+### 6.1 ASN 215540 in Honeypot (30 days: May 9 - Jun 9)
+
+| Metric | Value |
+|---|---|
+| Total Events | 724 |
+| Unique IPs | 21 |
+| First Seen | 2026-05-09 |
+| Last Seen | 2026-06-09 |
+| Source Countries | FI, NL, NO, FR, US |
+
+### 6.2 Top Attacking IPs from ASN 215540 (30 days)
+
+| IP | Events | Block | Location | Service |
+|---|---|---|---|---|
+| 178.17.53.215 | 278 | 178.17.53.0/24 | Helsinki, FI | SSH (different build) |
+| 89.185.81.112 | 95 | 89.185.81.0/24 | Sandefjord, NO | No visible services |
+| 5.253.59.171 | 48 | -- | -- | -- |
+| 147.45.50.147 | 48 | 147.45.50.0/24 | Kerkrade, NL | Same block as admin panel |
+| 147.45.50.171 | 47 | 147.45.50.0/24 | Kerkrade, NL | Same block as admin panel |
+| 147.45.50.108 | 47 | 147.45.50.0/24 | Kerkrade, NL | **GreyNoise MALICIOUS** admin panel |
+| 194.87.216.198 | 46 | 194.87.216.0/24 | Kerkrade, NL | No visible services |
+| 109.172.55.64 | 46 | 109.172.55.0/24 | Paris, FR | SSH (same build as targets) |
+| 78.153.155.71 | 18 | 78.153.155.0/24 | Atlanta, US | Same block as target build hosts |
+| 178.130.47.195 | 17 | 178.130.47.0/24 | Phoenix, US | Same block as target build hosts |
+
+### 6.3 Top Targeted Ports (ASN 215540, 30 days)
+
+| Port | Service | Notes |
+|---|---|---|
+| 80 | HTTP | Most targeted |
+| 443 | HTTPS | |
+| 22 | SSH | Self-referential (SSH farm scanning SSH) |
+| 2087 | cPanel | |
+| 2375 | Docker | Unsecured Docker API scanning |
+| 2086 | cPanel | |
+| 5002 | -- | |
+| 2222 | SSH alt | |
+| 2443 | HTTPS alt | |
+| 18789 | -- | |
+
+### 6.4 Broader Honeypot Context (90 days: Mar 11 - Jun 9)
+
+- ASN 215540 had **1,973 events** from **58 unique IPs** (90-day window)
+- Peak activity source countries: NL > FI > US > RU > NO
+- Top ports hit: 443, 80, 1723 (PPTP), 2087, 22, 2375, 2222, 2086, 8443, 25565 (Minecraft)
+
+---
+
+## 7. Infrastructure Domains & Ownership Chain
+
+### 7.1 Domain Infrastructure
+
+| Domain | IP | Use |
+|---|---|---|
+| zubat.org | 147.45.60.25 | Companion to target IPs |
+| dnau-getfkdwhocares123.xyz | 185.214.74.251 | Trolling domain |
+| games-oracle.ru | 178.130.46.2 | SOCKS proxy domain |
+| 7neth.solonettochka.ru | 178.130.46.2 | SOCKS proxy domain |
+| igorarmsrv.duckdns.org | 87.121.47.94 | Let's Encrypt cert |
+| nl1fast.netgo.su | 185.214.74.251 | -- |
+| various .4server.su | Multiple | Russian hosting infra |
+| various .my-server.app | Multiple | Infra monitoring |
+| various .servera.info | Multiple | Infra |
+| tunnely.ru | 185.100.159.193 | Tunneling service |
+
+### 7.2 PTR Infrastructure
+
+The PTR pattern `*.ip-ptr.tech` is the dominant reverse DNS infrastructure across the ASN, used by ~168 of the 387 same-build hosts. Individual numeric IDs (e.g. `157279`, `148100`, `118799`) appear to be customer/session identifiers.
+
+---
+
+## 8. Conclusions
+
+1. **ASN 215540 is a large-scale proxy/VPN exit node service**, not a traditional bulletproof hoster. The SSH server farm (387 hosts with identical software, unique host keys) is consistent with a proxy rotation service where each customer gets an ephemeral SSH listener.
+
+2. **The three target IPs are nodes in this proxy farm**, indistinguishable from 384+ other hosts running identical software. The shared PTR `157279.ip-ptr.tech` across the 3 originals plus `147.45.60.25` suggests these 4 are a specific deployment batch or customer allocation.
+
+3. **The infrastructure is globally distributed** across 13+ countries with concentration in Germany (Frankfurt), US (Atlanta/Phoenix), Poland (Warsaw), and Lithuania (Siauliai).
+
+4. **Notable criminal infrastructure in the same ASN** includes: a credential harvesting panel with TOTP support (147.45.50.108), a SOCKS5 proxy (178.130.46.2), and multiple hosts flagged by GreyNoise for login scanning, vulnerability exploitation, and path traversal.
+
+5. **The provider has a Russian nexus** despite UK registration: Russian physical address, Russian RIPE admin (Evgenii M.), Russian infrastructure domains (.4server.su, .4host.su, .tunnely.ru), and Russian-language PTR entries.
+
+---
+
+## 9. File Index
+
+| File | Contents |
+|---|---|
+| README.md | This report |
+| companions-tier1.md | 4 exact signature twins (same PTR + same build) |
+| companions-tier2-same24.md | Hosts in same /24 blocks with same build |
+| companions-tier2-same24-92.118.112.md | Full listing for 92.118.112.0/24 same-build hosts |
+| companions-tier2-same24-89.185.80.md | Full listing for 89.185.80.0/24 same-build hosts |
+| companions-tier3-by-block.md | All 387 hosts by block |
+| honeylabs-data.md | Raw honeylabs telemetry extracts |
+| censys-cli-queries.md | Censys CLI queries used |
diff --git a/2026/asn215540-report/censys-cli-queries.md b/2026/asn215540-report/censys-cli-queries.md
new file mode 100644
index 0000000..63fa51d
--- /dev/null
+++ b/2026/asn215540-report/censys-cli-queries.md
@@ -0,0 +1,54 @@
+# Censys CLI Queries Used
+
+## Prerequisites
+
+The Censys API tools (`search_hosts`, `aggregate`) were non-functional for this dataset. All host search queries were run via the Censys CLI with `--streaming` NDJSON output.
+
+## Queries
+
+### Find all hosts in ASN 215540
+```bash
+censys search --quiet --streaming --max-pages 10 --page-size 100 \
+ "host.autonomous_system.asn=215540"
+```
+
+### Find hosts by HASSH fingerprint within ASN
+```bash
+censys search --quiet --streaming --max-pages 5 --page-size 100 \
+ "host.autonomous_system.asn=215540 AND host.services.ssh.hassh_fingerprint=e42184b06d45385a906f0803d04c83da"
+```
+
+### Find hosts by exact SSH banner within ASN
+```bash
+censys search --quiet --streaming --max-pages 5 --page-size 100 \
+ 'host.autonomous_system.asn=215540 AND host.services.ssh.endpoint_id.raw="SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16"'
+```
+
+### Find hosts in specific /24 block
+```bash
+censys search --quiet --streaming --max-pages 3 --page-size 100 \
+ 'host.ip: "92.118.112.0/24"'
+```
+
+### Find hosts by PTR pattern
+```bash
+censys search --quiet --streaming --max-pages 5 --page-size 100 \
+ 'host.dns.reverse_dns.names: "157279.ip-ptr.tech"'
+```
+
+## Field Extraction (jq)
+
+### Extract IP, location, PTR (TSV)
+```bash
+jq -r '.host | [.ip, .location.city // "?", .location.country_code // "?", .dns.reverse_dns.names[0] // "no-ptr"] | @tsv'
+```
+
+### Extract SSH build info
+```bash
+jq -r '.host.services[]? | select(.protocol=="SSH") | .ssh.endpoint_id.raw // empty'
+```
+
+### Summary counts by IP block
+```bash
+jq -r '.host.autonomous_system.bgp_prefix' | sort | uniq -c | sort -rn
+```
diff --git a/2026/asn215540-report/companions-tier1.md b/2026/asn215540-report/companions-tier1.md
new file mode 100644
index 0000000..4a943ea
--- /dev/null
+++ b/2026/asn215540-report/companions-tier1.md
@@ -0,0 +1,55 @@
+# Tier 1 Companions: Exact Signature Twins
+
+These 4 hosts share the complete signature set: same PTR `157279.ip-ptr.tech`, same SSH build `OpenSSH_9.6p1 Ubuntu-3ubuntu13.16`, same HASSH `e42184b06d45385a906f0803d04c83da`, same JA4t scan, same Censys exposure labels.
+
+## Host Details
+
+### 92.118.112.230 (Original Target)
+
+- Block: 92.118.112.0/24
+- Location: Atlanta, Georgia, US
+- ASN: 215540 (GLOBAL CONNECTIVITY SOLUTIONS LLP)
+- PTR: 157279.ip-ptr.tech
+- SSH: OpenSSH_9.6p1 Ubuntu-3ubuntu13.16
+- HASSH: e42184b06d45385a906f0803d04c83da
+- GreyNoise: Suspicious -- Login Scanner, PAN-OS CVE-2020-2034 Crawler, F5 BIG-IP Crawler, SQLi
+- Censys Reputation: benign (model v0.1.0)
+- WHOIS Created: 2021-12-24
+
+### 89.185.80.144 (Original Target)
+
+- Block: 89.185.80.0/24
+- Location: Phoenix, Arizona, US
+- ASN: 215540 (GLOBAL CONNECTIVITY SOLUTIONS LLP)
+- PTR: 157279.ip-ptr.tech
+- SSH: OpenSSH_9.6p1 Ubuntu-3ubuntu13.16
+- HASSH: e42184b06d45385a906f0803d04c83da
+- GreyNoise: Suspicious -- same tags plus Suspicious Linux Command
+- Censys Reputation: benign
+- WHOIS Created: 2024-06-28
+
+### 89.185.80.183 (Original Target)
+
+- Block: 89.185.80.0/24
+- Location: Phoenix, Arizona, US
+- ASN: 215540 (GLOBAL CONNECTIVITY SOLUTIONS LLP)
+- PTR: 157279.ip-ptr.tech
+- SSH: OpenSSH_9.6p1 Ubuntu-3ubuntu13.16
+- HASSH: e42184b06d45385a906f0803d04c83da
+- GreyNoise: Suspicious -- same tags plus Path Traversal + Sensitive File Access
+- Censys Reputation: benign
+- WHOIS Created: 2024-06-28
+
+### 147.45.60.25 (Best New Companion)
+
+- Block: 147.45.60.0/24
+- Location: Atlanta, Georgia, US
+- ASN: 215540 (GLOBAL CONNECTIVITY SOLUTIONS LLP)
+- PTR: 157279.ip-ptr.tech
+- SSH: OpenSSH_9.6p1 Ubuntu-3ubuntu13.16
+- HASSH: e42184b06d45385a906f0803d04c83da
+- ECDSA Key: a05bfd9d42162150bf91193773642fed509bf8155de96fb468baccd693cce208
+- Forward DNS: zubat.org
+- GreyNoise: **Suspicious** -- exact same tag set (Login Scanner, PAN-OS, F5, SQLi, Sensitive File Access, Suspicious Linux Command)
+- Censys Reputation: benign
+- WHOIS Created: 2024-02-22
diff --git a/2026/asn215540-report/companions-tier2-same24.md b/2026/asn215540-report/companions-tier2-same24.md
new file mode 100644
index 0000000..19a0e9d
--- /dev/null
+++ b/2026/asn215540-report/companions-tier2-same24.md
@@ -0,0 +1,231 @@
+# Tier 2 Companions: Same /24 + Same SSH Build
+
+These hosts are in the same /24 blocks as the target IPs and run the identical SSH build (`OpenSSH_9.6p1 Ubuntu-3ubuntu13.16`, HASSH `e42184b06d45385a906f0803d04c83da`). They are immediate network neighbors with identical software -- likely part of the same customer pool.
+
+## 92.118.112.0/24 (Atlanta, US)
+
+### Hosts with Matching Build
+
+92.118.112.3 PTR: 157532.ip-ptr.tech
+92.118.112.10 PTR: 147768.ip-ptr.tech
+92.118.112.13 PTR: 157611.ip-ptr.tech
+92.118.112.15 PTR: none
+92.118.112.17 PTR: 163409.ip-ptr.tech
+92.118.112.21 PTR: none
+92.118.112.25 PTR: none
+92.118.112.27 PTR: none
+92.118.112.30 PTR: none
+92.118.112.32 PTR: 23052.ip-ptr.tech
+92.118.112.33 PTR: none
+92.118.112.34 PTR: none
+92.118.112.37 PTR: 156336.ip-ptr.tech
+92.118.112.38 PTR: 156860.ip-ptr.tech
+92.118.112.39 PTR: 163463.ip-ptr.tech
+92.118.112.40 PTR: 153649.ip-ptr.tech
+92.118.112.41 PTR: 153678.ip-ptr.tech
+92.118.112.43 PTR: none
+92.118.112.46 PTR: 155379.ip-ptr.tech
+92.118.112.47 PTR: 47390.pilot
+92.118.112.49 PTR: none
+92.118.112.50 PTR: 158024.ip-ptr.tech
+92.118.112.51 PTR: none
+92.118.112.53 PTR: 163516.ip-ptr.tech
+92.118.112.58 PTR: none
+92.118.112.59 PTR: 151446.ip-ptr.tech
+92.118.112.61 PTR: none
+92.118.112.62 PTR: 149428.ip-ptr.tech
+92.118.112.63 PTR: none
+92.118.112.66 PTR: 162034.ip-ptr.tech
+92.118.112.67 PTR: none
+92.118.112.69 PTR: none
+92.118.112.71 PTR: none
+92.118.112.78 PTR: 131817.ip-ptr.tech
+92.118.112.81 PTR: none
+92.118.112.84 PTR: none
+92.118.112.90 PTR: 159494.ip-ptr.tech
+92.118.112.93 PTR: none
+92.118.112.95 PTR: embrokvn.usa1
+92.118.112.96 PTR: none
+92.118.112.99 PTR: 145783.ip-ptr.tech
+92.118.112.103 PTR: 164732.ip-ptr.tech
+92.118.112.104 PTR: none
+92.118.112.105 PTR: 153837.ip-ptr.tech
+92.118.112.108 PTR: none
+92.118.112.109 PTR: none
+92.118.112.111 PTR: none
+92.118.112.112 PTR: none
+92.118.112.113 PTR: 154097.ip-ptr.tech
+92.118.112.117 PTR: none
+92.118.112.118 PTR: none
+92.118.112.123 PTR: none
+92.118.112.124 PTR: none
+92.118.112.125 PTR: none
+92.118.112.126 PTR: 149501.ip-ptr.tech
+92.118.112.129 PTR: none
+92.118.112.132 PTR: 158322.ip-ptr.tech
+92.118.112.136 PTR: 160654.ip-ptr.tech
+92.118.112.139 PTR: pendosofff.ip-ptr.tech
+92.118.112.144 PTR: none
+92.118.112.147 PTR: 157935.ip-ptr.tech
+92.118.112.154 PTR: none
+92.118.112.157 PTR: 158308.ip-ptr.tech
+92.118.112.158 PTR: none
+92.118.112.160 PTR: none
+92.118.112.161 PTR: none
+92.118.112.163 PTR: 149262.ip-ptr.tech
+92.118.112.164 PTR: 149588.ip-ptr.tech
+92.118.112.166 PTR: none
+92.118.112.167 PTR: 149521.ip-ptr.tech
+92.118.112.168 PTR: 134722.ip-ptr.tech
+92.118.112.170 PTR: us.itg.top
+92.118.112.171 PTR: none
+92.118.112.173 PTR: none
+92.118.112.174 PTR: 122851.ip-ptr.tech
+92.118.112.178 PTR: 148100.ip-ptr.tech (Caddy HTTP on 1337/9091/10095)
+92.118.112.182 PTR: 45865.ip-ptr.tech
+92.118.112.190 PTR: none
+92.118.112.191 PTR: none
+92.118.112.192 PTR: 145337.ip-ptr.tech
+92.118.112.194 PTR: none
+92.118.112.195 PTR: none
+92.118.112.199 PTR: 145803.ip-ptr.tech
+92.118.112.201 PTR: none
+92.118.112.202 PTR: 158159.ip-ptr.tech
+92.118.112.204 PTR: 161382.ip-ptr.tech
+92.118.112.206 PTR: 158596.ip-ptr.tech
+92.118.112.209 PTR: 152590.ip-ptr.tech
+92.118.112.210 PTR: 149355.ip-ptr.tech
+92.118.112.212 PTR: 152279.ip-ptr.tech
+92.118.112.214 PTR: 147080.ip-ptr.tech
+92.118.112.215 PTR: none
+92.118.112.217 PTR: none
+92.118.112.222 PTR: 146703.ip-ptr.tech
+92.118.112.224 PTR: 165081.ip-ptr.tech
+92.118.112.225 PTR: 39423.ip-ptr.tech
+92.118.112.229 PTR: none
+92.118.112.230 PTR: 157279.ip-ptr.tech (ORIGINAL)
+92.118.112.231 PTR: 37401.ip-ptr.tech
+92.118.112.235 PTR: none
+92.118.112.236 PTR: none (9.6p1 Ubuntu-3ubuntu13.14)
+92.118.112.238 PTR: 154242.ip-ptr.tech
+92.118.112.243 PTR: none
+92.118.112.251 PTR: 151080.ip-ptr.tech
+92.118.112.252 PTR: none
+92.118.112.253 PTR: none
+
+**Total in 92.118.112.0/24 with matching build: ~103 hosts**
+
+## 89.185.80.0/24 (Phoenix, US)
+
+### Hosts with Matching Build
+
+89.185.80.3 PTR: none
+89.185.80.4 PTR: 165219.ip-ptr.tech
+89.185.80.5 PTR: none
+89.185.80.7 PTR: 49905.ip-ptr.tech
+89.185.80.11 PTR: none
+89.185.80.14 PTR: 163430.ip-ptr.tech
+89.185.80.15 PTR: 38472.ip-ptr.tech
+89.185.80.19 PTR: 133733.ip-ptr.tech
+89.185.80.25 PTR: 163364.ip-ptr.tech
+89.185.80.27 PTR: 158506.ip-ptr.tech
+89.185.80.28 PTR: 164349.ip-ptr.tech
+89.185.80.29 PTR: 131751.ip-ptr.tech (9.6p1 Ubuntu-3ubuntu13.15)
+89.185.80.40 PTR: 5306-1.ip-ptr.tech
+89.185.80.41 PTR: 5306-2.ip-ptr.tech
+89.185.80.43 PTR: usa-krasava.net
+89.185.80.44 PTR: 146929.ip-ptr.tech
+89.185.80.46 PTR: none
+89.185.80.47 PTR: none
+89.185.80.49 PTR: 160579.ip-ptr.tech
+89.185.80.50 PTR: 44447.ip-ptr.tech
+89.185.80.51 PTR: 137178.ip-ptr.tech
+89.185.80.53 PTR: 56648.ip-ptr.tech
+89.185.80.57 PTR: 114148.ip-ptr.tech
+89.185.80.65 PTR: 154023.ip-ptr.tech
+89.185.80.68 PTR: none
+89.185.80.69 PTR: none
+89.185.80.74 PTR: 134903.ip-ptr.tech
+89.185.80.78 PTR: none
+89.185.80.79 PTR: 135557.ip-ptr.tech
+89.185.80.80 PTR: 155185.ip-ptr.tech
+89.185.80.81 PTR: none
+89.185.80.83 PTR: 148687.ip-ptr.tech
+89.185.80.85 PTR: 135502.ip-ptr.tech
+89.185.80.86 PTR: 153743.ip-ptr.tech
+89.185.80.88 PTR: 157099.ip-ptr.tech
+89.185.80.90 PTR: 119100.ip-ptr.tech
+89.185.80.92 PTR: none
+89.185.80.95 PTR: none
+89.185.80.99 PTR: 160768.ip-ptr.tech
+89.185.80.103 PTR: 165881.ip-ptr.tech
+89.185.80.106 PTR: 145858.ip-ptr.tech
+89.185.80.110 PTR: none
+89.185.80.112 PTR: none
+89.185.80.113 PTR: 133249.ip-ptr.tech
+89.185.80.116 PTR: 164931.ip-ptr.tech
+89.185.80.118 PTR: 155721.ip-ptr.tech
+89.185.80.119 PTR: 56648.ip-ptr.tech
+89.185.80.121 PTR: 164033.ip-ptr.tech
+89.185.80.122 PTR: none
+89.185.80.124 PTR: none
+89.185.80.126 PTR: 153514.ip-ptr.tech
+89.185.80.127 PTR: none
+89.185.80.129 PTR: none
+89.185.80.133 PTR: 56277.ip-ptr.tech
+89.185.80.135 PTR: none
+89.185.80.137 PTR: none
+89.185.80.138 PTR: none
+89.185.80.139 PTR: 145715.ip-ptr.tech
+89.185.80.141 PTR: none
+89.185.80.143 PTR: none
+89.185.80.144 PTR: 157279.ip-ptr.tech (ORIGINAL)
+89.185.80.146 PTR: 156737.ip-ptr.tech
+89.185.80.147 PTR: none
+89.185.80.148 PTR: 149288.ip-ptr.tech
+89.185.80.150 PTR: none
+89.185.80.151 PTR: 156978.ip-ptr.tech
+89.185.80.152 PTR: 291.ip-ptr.tech
+89.185.80.153 PTR: 148975.ip-ptr.tech
+89.185.80.155 PTR: none
+89.185.80.156 PTR: 3947.ip-ptr.tech
+89.185.80.159 PTR: none
+89.185.80.163 PTR: 127176.ip-ptr.tech
+89.185.80.164 PTR: none
+89.185.80.166 PTR: none
+89.185.80.169 PTR: none
+89.185.80.175 PTR: 24827.ip-ptr.tech
+89.185.80.176 PTR: none
+89.185.80.177 PTR: none
+89.185.80.179 PTR: none
+89.185.80.180 PTR: none
+89.185.80.181 PTR: 54444.ip-ptr.tech (9.6p1 Ubuntu-3ubuntu13.4)
+89.185.80.182 PTR: 158074.ip-ptr.tech
+89.185.80.183 PTR: 157279.ip-ptr.tech (ORIGINAL)
+89.185.80.184 PTR: 153517.ip-ptr.tech (9.6p1 Ubuntu-3ubuntu13.15)
+89.185.80.187 PTR: 44819-1.ip-ptr.tech
+89.185.80.189 PTR: none
+89.185.80.191 PTR: 157855.ip-ptr.tech
+89.185.80.193 PTR: none
+89.185.80.194 PTR: fbi.com
+89.185.80.195 PTR: none
+89.185.80.199 PTR: none
+89.185.80.202 PTR: 156952.ip-ptr.tech
+89.185.80.203 PTR: none
+89.185.80.213 PTR: none
+89.185.80.214 PTR: 139675.ip-ptr.tech
+89.185.80.229 PTR: v90297c060e.servera.info
+89.185.80.230 PTR: none
+89.185.80.234 PTR: 153022.ip-ptr.tech (9.6p1 Ubuntu-3ubuntu13.15)
+89.185.80.239 PTR: 143029.ip-ptr.tech
+89.185.80.240 PTR: none
+89.185.80.242 PTR: 5306-4.ip-ptr.tech
+89.185.80.243 PTR: 5306-5.ip-ptr.tech
+89.185.80.244 PTR: none
+89.185.80.245 PTR: none
+89.185.80.246 PTR: 5306-8.ip-ptr.tech
+89.185.80.247 PTR: none
+89.185.80.248 PTR: none
+89.185.80.252 PTR: 149435.ip-ptr.tech
+
+**Total in 89.185.80.0/24 with matching build: ~97 hosts**
diff --git a/2026/asn215540-report/companions-tier3-by-block.md b/2026/asn215540-report/companions-tier3-by-block.md
new file mode 100644
index 0000000..c20f3f4
--- /dev/null
+++ b/2026/asn215540-report/companions-tier3-by-block.md
@@ -0,0 +1,51 @@
+# Tier 3 Companions: Same HASSH Across ASN
+
+All 387 hosts matching HASSH `e42184b06d45385a906f0803d04c83da` (OpenSSH_9.6p1 Ubuntu-3ubuntu13.16) within ASN 215540, grouped by IP block.
+
+## Distribution Summary
+
+| Block | Location | Count |
+|---|---|---|
+| 185.100.159.0/24 | Frankfurt, DE | 60 |
+| 77.83.246.0/24 | Warsaw, PL | 52 |
+| 193.233.74.0/24 | Frankfurt, DE | 49 |
+| 78.153.155.0/24 | Atlanta, US | 46 |
+| 87.121.47.0/24 | Tsovasar, AM | 43 |
+| 185.39.204.0/24 | Istanbul, TR | 41 |
+| 147.45.217.0/24 | Siauliai, LT | 39 |
+| 178.17.58.0/24 | Frankfurt, DE | 27 |
+| 81.17.159.0/24 | Copenhagen, DK | 26 |
+| 193.39.208.0/24 | Kerkrade, NL | 26 |
+| 87.120.219.0/24 | London, GB | 25 |
+| 78.153.131.0/24 | Siauliai, LT | 19 |
+| 62.60.232.0/24 | Hong Kong, HK | 17 |
+| 178.130.47.0/24 | Phoenix, US | 12 |
+| 185.161.251.0/24 | Frankfurt, DE | 5 |
+| 45.89.60.0/24 | Tirana, AL | 4 |
+| 153.80.242.0/24 | Frankfurt, DE | 4 |
+| 147.45.204.0/24 | Kerkrade, NL | 2 |
+| 147.45.116.0/24 | Sao Paulo, BR | 1 |
+| 81.177.215.0/24 | Istanbul, TR | 1 |
+| 87.120.222.0/24 | Zurich, CH | 1 |
+| 92.118.112.0/24 | Atlanta, US | ~103 (see tier2) |
+| 89.185.80.0/24 | Phoenix, US | ~97 (see tier2) |
+
+**Total: 387 hosts**
+
+## Country Totals
+
+| Country | Count |
+|---|---|
+| Germany | 145 |
+| United States | 58 |
+| Lithuania | 58 |
+| Poland | 52 |
+| Armenia | 43 |
+| Turkey | 42 |
+| Netherlands | 28 |
+| Denmark | 26 |
+| United Kingdom | 25 |
+| Hong Kong | 17 |
+| Albania | 4 |
+| Brazil | 1 |
+| Switzerland | 1 |
diff --git a/2026/asn215540-report/honeylabs-data.md b/2026/asn215540-report/honeylabs-data.md
new file mode 100644
index 0000000..2c6f520
--- /dev/null
+++ b/2026/asn215540-report/honeylabs-data.md
@@ -0,0 +1,89 @@
+# Honeylabs Telemetry Data
+
+## ASN 215540 Enrichment (30 days: May 9 - Jun 9)
+
+- Total events: 724
+- Unique source IPs: 21
+- First seen: 2026-05-09T08:51:23
+- Last seen: 2026-06-09T10:48:20
+
+### Top Ports Targeted
+
+80, 443, 22, 2087, 2375, 2086, 5002, 2222, 2443, 18789
+
+### Source Countries
+
+FI (Finland), NL (Netherlands), NO (Norway), FR (France), US (United States)
+
+### Top Source IPs
+
+178.17.53.215 (278 events)
+89.185.81.112 (95 events)
+5.253.59.171 (48 events)
+147.45.50.147 (48 events)
+147.45.50.171 (47 events)
+147.45.50.108 (47 events) -- GreyNoise MALICIOUS admin panel
+194.87.216.198 (46 events)
+109.172.55.64 (46 events) -- Same SSH build as target IPs
+78.153.155.71 (18 events)
+178.130.47.195 (17 events)
+
+## ASN 215540 Enrichment (90 days: Mar 11 - Jun 9)
+
+- Total events: 1,973
+- Unique source IPs: 58
+- Top ports: 443, 80, 1723, 2087, 22, 2375, 2222, 2086, 8443, 25565
+- Source countries: NL, FI, US, RU, NO
+
+## IOC Lookups on Target IPs
+
+All three target IPs (92.118.112.230, 89.185.80.144, 89.185.80.183):
+
+- **Total events: 0** (not observed in honeypot data)
+- No activity in the retained window on any port/protocol monitored
+
+## Global Attack Timeline (30 days: May 9 - Jun 9)
+
+```
+Date Events Unique Sources
+2026-05-09 182,677 9,664
+2026-05-10 208,198 9,527
+2026-05-11 117,326 9,952
+2026-05-12 147,346 10,068
+2026-05-13 126,539 9,508
+2026-05-14 154,697 9,481
+2026-05-15 138,283 9,065
+2026-05-16 123,784 8,310
+2026-05-17 96,388 7,553
+2026-05-18 232,171 7,736
+2026-05-19 134,117 8,076
+2026-05-20 109,114 7,627
+2026-05-21 156,160 7,983
+2026-05-22 92,009 7,585
+2026-05-23 89,882 7,160
+2026-05-24 113,648 7,130
+2026-05-25 110,080 7,583
+2026-05-26 206,768 7,733
+2026-05-27 93,606 7,477
+2026-05-28 177,479 8,148
+2026-05-29 127,072 8,751
+2026-05-30 191,029 8,314
+2026-05-31 201,908 8,266
+2026-06-01 119,234 8,710
+2026-06-02 166,775 9,009
+2026-06-03 147,398 9,263
+2026-06-04 135,744 9,221
+2026-06-05 127,141 8,591
+2026-06-06 122,880 7,649
+2026-06-07 119,033 7,100
+2026-06-08 170,475 7,787
+2026-06-09 168,843 7,652
+```
+
+## Top ASNs by Event Count (90 days)
+
+1. ASN 14061 (DigitalOcean): 1,494,911 events, 13,120 unique IPs
+2. ASN 396982 (Google LLC): 1,058,293 events, 5,715 IPs
+3. ASN 135377 (UCLOUD HK): 732,199 events, 850 IPs
+4. ASN 398705 (Censys Inc): 545,368 events, 16 IPs
+5. ASN 202425 (IP Volume inc): 530,594 events, 65 IPs -- same provider type as 215540