diff options
| author | hrbrmstr <bob@rud.is> | 2026-07-13 07:27:00 -0400 |
|---|---|---|
| committer | hrbrmstr <bob@rud.is> | 2026-07-13 07:27:00 -0400 |
| commit | a47b685eac21aeedad5c4ab5df5c67a1df905486 (patch) | |
| tree | 132867a1f6cef28c38f4bc43107a0cc6156226be /kevlar/2026-07-13/changes/anomalies.csv | |
| parent | 083a60f55cfc8b33735117feb6df6904342818b5 (diff) | |
chore: weekly asn update
Diffstat (limited to 'kevlar/2026-07-13/changes/anomalies.csv')
| -rw-r--r-- | kevlar/2026-07-13/changes/anomalies.csv | 12 |
1 files changed, 12 insertions, 0 deletions
diff --git a/kevlar/2026-07-13/changes/anomalies.csv b/kevlar/2026-07-13/changes/anomalies.csv new file mode 100644 index 0000000..111ae87 --- /dev/null +++ b/kevlar/2026-07-13/changes/anomalies.csv @@ -0,0 +1,12 @@ +anomaly_id,severity,asn,asn_org,description,indicator,evidence,action_recommended +ANOM-001,CRITICAL,AS198953,Proton66 OOO,Multi-protocol bruteforce expansion,RDP+SSH+Telnet+FTP bruteforcing from single IP,176.120.22.240 GreyNoise malicious 429 events on ports 4000/1723/143/8080/111,Block IP range 176.120.22.0/24 and monitor for credential stuffing tools +ANOM-002,CRITICAL,AS200593,Prospero Ooo,Massive scan surge from single IP,3890 events from single IP on diverse high ports,91.202.233.79 targeting ports 43128/12063/49326/19168/13230 all on 2026-07-10,Block 91.202.233.79 and investigate AS200593 for compromised infrastructure +ANOM-003,HIGH,AS51396,Pfcloud UG,Coordinated scan cluster with synchronized timing,Three IPs with identical start/stop timestamps,204.76.203.78/79/80 all started 2026-07-11T03:24:10 stopped 2026-07-11T13:26:10,Block 204.76.203.0/24 and flag for coordinated scanning infrastructure +ANOM-004,HIGH,AS211720,Datashield Inc.,Exchange /ews/ reconnaissance,Targeted Exchange endpoint probing,185.231.33.46 HTTP HEAD /ews/ with JA4 t13i1813h1 and JA3 60eb467937ec,Monitor Exchange servers for /ews/ access from Seychelles IPs and block 185.231.33.46 +ANOM-005,HIGH,AS400992,ZhouyiSat Communications,.env file scanning,Credentials exfiltration attempt via /.env,185.228.72.109 HTTP GET /.env with JA4 t13i1711h1 and self-signed cert WIN-8FIH4EGN4AL,Block 185.228.72.109 and alert on any /.env access attempts from US-hosted ZhouyiSat IPs +ANOM-006,HIGH,AS14956,RouterHosting LLC,Multi-vulnerability scanner,Single IP scanning for multiple CVE exploit paths,216.126.239.17 GreyNoise suspicious scanning Wordpress/CrushFTP/Ivanti/OWA,Block 216.126.239.17 and monitor for follow-on exploitation attempts +ANOM-007,MEDIUM,AS200651,FlokiNET ehf,Tor exit node performing active scanning,Tor exit node scanning HTTP/SSH ports,185.100.87.136 Tor 0.4.9.11 port 9001 scanning ports 80/443/444/8080/22,Rate-limit or block 185.100.87.136 and monitor Tor exit node abuse +ANOM-008,MEDIUM,AS214940,Kprohost LLC,User agent rotation suggesting evasion,20 distinct browser UAs from 3 IPs in same /24,77.83.39.197/119/94 cycling UAs across port 443,Flag UA rotation pattern and block 77.83.39.0/24 for HTTPS scanning +ANOM-009,MEDIUM,AS51396,Pfcloud UG,GreyNoise malicious IP in Pfcloud range,RDP crawler and bruteforcer,176.65.148.25 GreyNoise malicious OpenSSH 9.2p1 port 22,Block 176.65.148.25 and audit 176.65.148.0/24 for additional malicious infrastructure +ANOM-010,LOW,AS57043,Hostkey B.v.,New ASN appearance in honeypots,First observed activity from Hostkey,151.243.173.235 SSH scanning port 22 from NL,Monitor for recurring activity from AS57043 +ANOM-011,LOW,AS138915,KAOPU-HK,High Sponge volume no Honeylabs match,10000 Sponge sessions but 0 Honeylabs events,NTP/123 traffic only in Sponge data,Monitor for protocol shift from NTP to attack traffic |
