aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-08-02/iocs/README.md
diff options
context:
space:
mode:
authorhrbrmstr <bob@rud.is>2026-08-03 07:11:48 -0400
committerhrbrmstr <bob@rud.is>2026-08-03 07:11:48 -0400
commit71ff7fc1ef9e742b78d3b04a23b487fcf478ff50 (patch)
tree8fda61762b491552a017aacda4d8c8a14cf578d6 /kevlar/2026-08-02/iocs/README.md
parent89a294a0e93277e5f27fc96710f638a5ac85ab35 (diff)
chore: weekly BPH update
Diffstat (limited to 'kevlar/2026-08-02/iocs/README.md')
-rw-r--r--kevlar/2026-08-02/iocs/README.md27
1 files changed, 14 insertions, 13 deletions
diff --git a/kevlar/2026-08-02/iocs/README.md b/kevlar/2026-08-02/iocs/README.md
index 7bef1c9..d255f51 100644
--- a/kevlar/2026-08-02/iocs/README.md
+++ b/kevlar/2026-08-02/iocs/README.md
@@ -1,25 +1,26 @@
# Weekly BP Report -- 2026-08-02
-Generated: 2026-08-03T03:43:00Z
+Generated: 2026-08-03T04:00:00Z
ASNs covered: 26
Sponge sessions found: 10,000+ across 21 active ASNs (capped per query)
-Honeylabs events found: 8,400 (AS51396 PFCLOUD only; 25 ASNs: zero)
-Censys IPs profiled: 6 ASNs (190K+ hosts, all BULLETPROOF-labeled)
-Anomalies flagged: 1 (universal BULLETPROOF classification across all profiled ASNs)
+Honeylabs events found: 8,400+ across 7 ASNs (PFCLOUD, HOSTKEY, ROUTERHOSTING, PLI-AS, PROTON66, FLOKINET, KPRONET, AUROLOGIC)
+Censys IPs profiled: 6 ASN-level + 3 per-IP enrichments (190K+ hosts, all BULLETPROOF-labeled)
+Anomalies flagged: 1 (FLOKINET operates Tor exit relay with concurrent brute-force activity)
## Key Findings
-- Only 1 of 26 ASNs (PFCLOUD) generated honeypot events; the other 25 show
- targeted scanning against real infrastructure
-- All Censys-profiled ASNs are universally classified as BULLETPROOF
-- KAOPU-HK (AS138915): 818K NTP/SSDP amplification scanning sessions
-- PFCLOUD (AS51396): active proxy-checking (SOCKS5 + HTTP CONNECT) against honeypots
-- HOSTKEY (AS57043) and AEZA (AS210644): largest infrastructure (100K+ and 69K hosts)
-- PLI-AS (AS51852): massive Telnet brute-forcing (34K sessions)
-- PROTON66 (AS198953): SSH/MSSQL/RDP scanning (102K sessions from single IP)
+- 7 of 26 ASNs generated Honeylabs events (not 1 as initially reported)
+- All Censys-profiled hosts are universally classified as BULLETPROOF
+- KPRONET: .git/.env exfiltration campaign with 20+ spoofed user agents
+- PLI-AS: Multi-modal attack (DCE/RPC, RDP brute, tRPC, WordPress scanning)
+- FLOKINET: Tor exit relay (185.100.87.136) with SSH/Telnet brute-force
+- HOSTKEY: RTSP camera credential stuffing against Hikvision cameras
+- PROTON66: MSSQL-TDS brute-force on non-standard ports
+- PFCLOUD: Consistent proxy checking with port-paired infrastructure
+- KAOPU-HK: 818K NTP/SSDP amplification scanning sessions (zero Honeylabs)
## Data Sources
- Sponge (Arkime): network sensor sessions across full deployment
- Honeylabs: global honeypot network, 7-day window (2026-07-27 to 2026-08-02)
-- Censys: internet-wide host profiling
+- Censys: internet-wide host profiling + per-IP enrichment