diff options
| author | hrbrmstr <bob@rud.is> | 2026-08-03 07:11:48 -0400 |
|---|---|---|
| committer | hrbrmstr <bob@rud.is> | 2026-08-03 07:11:48 -0400 |
| commit | 71ff7fc1ef9e742b78d3b04a23b487fcf478ff50 (patch) | |
| tree | 8fda61762b491552a017aacda4d8c8a14cf578d6 /kevlar/2026-08-02/iocs | |
| parent | 89a294a0e93277e5f27fc96710f638a5ac85ab35 (diff) | |
chore: weekly BPH update
Diffstat (limited to 'kevlar/2026-08-02/iocs')
| -rw-r--r-- | kevlar/2026-08-02/iocs/README.md | 27 | ||||
| -rw-r--r-- | kevlar/2026-08-02/iocs/all-observed-ips.txt | 29 | ||||
| -rw-r--r-- | kevlar/2026-08-02/iocs/c2-paths.txt | 37 | ||||
| -rw-r--r-- | kevlar/2026-08-02/iocs/fingerprints.txt | 21 |
4 files changed, 81 insertions, 33 deletions
diff --git a/kevlar/2026-08-02/iocs/README.md b/kevlar/2026-08-02/iocs/README.md index 7bef1c9..d255f51 100644 --- a/kevlar/2026-08-02/iocs/README.md +++ b/kevlar/2026-08-02/iocs/README.md @@ -1,25 +1,26 @@ # Weekly BP Report -- 2026-08-02 -Generated: 2026-08-03T03:43:00Z +Generated: 2026-08-03T04:00:00Z ASNs covered: 26 Sponge sessions found: 10,000+ across 21 active ASNs (capped per query) -Honeylabs events found: 8,400 (AS51396 PFCLOUD only; 25 ASNs: zero) -Censys IPs profiled: 6 ASNs (190K+ hosts, all BULLETPROOF-labeled) -Anomalies flagged: 1 (universal BULLETPROOF classification across all profiled ASNs) +Honeylabs events found: 8,400+ across 7 ASNs (PFCLOUD, HOSTKEY, ROUTERHOSTING, PLI-AS, PROTON66, FLOKINET, KPRONET, AUROLOGIC) +Censys IPs profiled: 6 ASN-level + 3 per-IP enrichments (190K+ hosts, all BULLETPROOF-labeled) +Anomalies flagged: 1 (FLOKINET operates Tor exit relay with concurrent brute-force activity) ## Key Findings -- Only 1 of 26 ASNs (PFCLOUD) generated honeypot events; the other 25 show - targeted scanning against real infrastructure -- All Censys-profiled ASNs are universally classified as BULLETPROOF -- KAOPU-HK (AS138915): 818K NTP/SSDP amplification scanning sessions -- PFCLOUD (AS51396): active proxy-checking (SOCKS5 + HTTP CONNECT) against honeypots -- HOSTKEY (AS57043) and AEZA (AS210644): largest infrastructure (100K+ and 69K hosts) -- PLI-AS (AS51852): massive Telnet brute-forcing (34K sessions) -- PROTON66 (AS198953): SSH/MSSQL/RDP scanning (102K sessions from single IP) +- 7 of 26 ASNs generated Honeylabs events (not 1 as initially reported) +- All Censys-profiled hosts are universally classified as BULLETPROOF +- KPRONET: .git/.env exfiltration campaign with 20+ spoofed user agents +- PLI-AS: Multi-modal attack (DCE/RPC, RDP brute, tRPC, WordPress scanning) +- FLOKINET: Tor exit relay (185.100.87.136) with SSH/Telnet brute-force +- HOSTKEY: RTSP camera credential stuffing against Hikvision cameras +- PROTON66: MSSQL-TDS brute-force on non-standard ports +- PFCLOUD: Consistent proxy checking with port-paired infrastructure +- KAOPU-HK: 818K NTP/SSDP amplification scanning sessions (zero Honeylabs) ## Data Sources - Sponge (Arkime): network sensor sessions across full deployment - Honeylabs: global honeypot network, 7-day window (2026-07-27 to 2026-08-02) -- Censys: internet-wide host profiling +- Censys: internet-wide host profiling + per-IP enrichment diff --git a/kevlar/2026-08-02/iocs/all-observed-ips.txt b/kevlar/2026-08-02/iocs/all-observed-ips.txt index 964b94f..640acbd 100644 --- a/kevlar/2026-08-02/iocs/all-observed-ips.txt +++ b/kevlar/2026-08-02/iocs/all-observed-ips.txt @@ -155,3 +155,32 @@ # AS58854 - KAOPY (Kaopu Cloud) 103.236.255.202 +# === IPs from Honeylabs events === +# AS57043 - HOSTKEY (RTSP camera brute-forcing) +163.5.29.40 + +# AS14956 - ROUTERHOSTING (binary protocol + TLS browser) +144.172.100.235 +167.88.168.121 + +# AS51852 - PLI-AS (DCE/RPC, RDP, tRPC, WordPress) +81.17.28.130 +179.43.186.199 +179.43.150.26 +179.43.158.246 + +# AS198953 - PROTON66 (MSSQL brute-force) +176.120.22.61 + +# AS200651 - FLOKINET (SSH/Telnet brute, Tor exit relay) +185.100.87.136 +185.246.188.74 +185.246.190.66 + +# AS30823 - AUROLOGIC (SIP scanning) +216.126.229.131 + +# AS214940 - KPRONET (.git/.env exfiltration) +77.83.39.94 +77.83.39.6 +77.83.39.24 diff --git a/kevlar/2026-08-02/iocs/c2-paths.txt b/kevlar/2026-08-02/iocs/c2-paths.txt index 2b9aae3..0432430 100644 --- a/kevlar/2026-08-02/iocs/c2-paths.txt +++ b/kevlar/2026-08-02/iocs/c2-paths.txt @@ -1,15 +1,22 @@ -# HTTP URL Paths Observed (from prior week Honeylabs data) - -/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php -- PHPUnit RCE probe -/dana-na/auth/url_default/welcome.cgi -- Pulse Secure VPN enumeration -/global-protect/login.esp -- Palo Alto GlobalProtect enumeration -/sslvpnLogin.html -- SSL VPN portal enumeration -/guacamole/ -- Apache Guacamole RDP gateway probing -/remote/login -- Generic remote access login probe -/auth/login -- Authentication endpoint probing -/login -- Login page enumeration - -# Note: No URL paths were observed in Honeylabs events from monitored ASNs -# this week. All non-PFCLOUD ASNs registered zero honeypot events. -# PFCLOUD Honeylabs events were proxy-checking (HTTP CONNECT tunnels, SOCKS5) -# rather than HTTP path-based exploitation. +# C2 and Exploitation Paths Observed + +# PLI-AS (AS51852) +/api/trpc/setup.setup -- tRPC setup endpoint targeting, POST with JSON body, port 3000 +/wp-login.php -- WordPress credential enumeration, TLS, Go-http-client/1.1 + +# HOSTKEY (AS57043) +/ISAPI/Streaming/channels/10101 -- Hikvision camera streaming, RTSP DESCRIBE, Basic auth credential stuffing +/Streaming/Channels/10201 -- Hikvision camera streaming (alternate path) + +# KPRONET (AS214940) +/.git/HEAD -- Git repository discovery, secret harvesting +/.git/index -- Git index file enumeration +/.git/config -- Git remote configuration extraction +/.env -- Environment file exfiltration (database creds, API keys, secrets) + +# From prior week, still relevant: +/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php -- PHPUnit RCE +/dana-na/auth/url_default/welcome.cgi -- Pulse Secure VPN +/global-protect/login.esp -- Palo Alto GlobalProtect +/sslvpnLogin.html -- SSL VPN portal enumeration +/guacamole/ -- Apache Guacamole RDP gateway probing diff --git a/kevlar/2026-08-02/iocs/fingerprints.txt b/kevlar/2026-08-02/iocs/fingerprints.txt index bd25290..264c0b2 100644 --- a/kevlar/2026-08-02/iocs/fingerprints.txt +++ b/kevlar/2026-08-02/iocs/fingerprints.txt @@ -1,8 +1,19 @@ +# JA4 TLS Fingerprints + +t13i190800_9dc949149365_97f8aa674fd9 -- KPRONET .env exfiltration campaign, 77.83.39.x, Ukraine +t13i251000_b78ed14e2fd0_ab7e3b40a677 -- KPRONET .git/HEAD scanning, 77.83.39.94, Ukraine +t13i190900_9dc949149365_e7c285222651 -- PLI-AS WordPress login scan, 179.43.158.246, Switzerland +t13i1310h1_f57a46bbacb6_e7c285222651 -- ROUTERHOSTING TLS Firefox browser, 167.88.168.121, US + # JA4H HTTP Fingerprints -ge11nn0400_9c3956fad5da -- PFCLOUD Go-http-client/1.1 proxy checker, 204.76.203.78-80 -ge11nn0400_88d30a62b7ad -- PFCLOUD zgrab/0.x web scanner, 176.65.149.236 +ge11nn0500_9af7e0472034 -- KPRONET .env/.git exfiltration (detects despite 20+ UA rotations), 77.83.39.x +po11nr09en_94d98df401ed -- PLI-AS tRPC setup endpoint attack, 179.43.150.26 +ge11nn0400_9c3956fad5da -- PFCLOUD Go-http-client/1.1 proxy checker, 204.76.203.78-80 +ge11nn0400_88d30a62b7ad -- PFCLOUD zgrab/0.x web scanner, 176.65.149.236 +ge11nn0300_0db47b7d240d -- PLI-AS Go-http-client/1.1 wordpress scanner, 179.43.158.246 + +# HASSH SSH Fingerprints -# Note: No JA4 TLS or HASSH SSH fingerprints were observed in Honeylabs events -# from monitored ASNs this week. All non-PFCLOUD ASNs registered zero honeypot -# events in the 2026-07-27 to 2026-08-02 observation window. +e54ef3ec27fe1fea7ab64d3fa05359fd -- FLOKINET OpenSSH 10.1 SSH brute client, 185.100.87.136 +b1bff636ebbdbaa9dd2ad97fd173c956 -- FLOKINET Tor relay OpenSSH 9.9, 185.100.87.136:7288 |
