aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-07-13/changes
diff options
context:
space:
mode:
Diffstat (limited to 'kevlar/2026-07-13/changes')
-rw-r--r--kevlar/2026-07-13/changes/anomalies.csv12
-rw-r--r--kevlar/2026-07-13/changes/diff-vs-prior-week.csv36
2 files changed, 48 insertions, 0 deletions
diff --git a/kevlar/2026-07-13/changes/anomalies.csv b/kevlar/2026-07-13/changes/anomalies.csv
new file mode 100644
index 0000000..111ae87
--- /dev/null
+++ b/kevlar/2026-07-13/changes/anomalies.csv
@@ -0,0 +1,12 @@
+anomaly_id,severity,asn,asn_org,description,indicator,evidence,action_recommended
+ANOM-001,CRITICAL,AS198953,Proton66 OOO,Multi-protocol bruteforce expansion,RDP+SSH+Telnet+FTP bruteforcing from single IP,176.120.22.240 GreyNoise malicious 429 events on ports 4000/1723/143/8080/111,Block IP range 176.120.22.0/24 and monitor for credential stuffing tools
+ANOM-002,CRITICAL,AS200593,Prospero Ooo,Massive scan surge from single IP,3890 events from single IP on diverse high ports,91.202.233.79 targeting ports 43128/12063/49326/19168/13230 all on 2026-07-10,Block 91.202.233.79 and investigate AS200593 for compromised infrastructure
+ANOM-003,HIGH,AS51396,Pfcloud UG,Coordinated scan cluster with synchronized timing,Three IPs with identical start/stop timestamps,204.76.203.78/79/80 all started 2026-07-11T03:24:10 stopped 2026-07-11T13:26:10,Block 204.76.203.0/24 and flag for coordinated scanning infrastructure
+ANOM-004,HIGH,AS211720,Datashield Inc.,Exchange /ews/ reconnaissance,Targeted Exchange endpoint probing,185.231.33.46 HTTP HEAD /ews/ with JA4 t13i1813h1 and JA3 60eb467937ec,Monitor Exchange servers for /ews/ access from Seychelles IPs and block 185.231.33.46
+ANOM-005,HIGH,AS400992,ZhouyiSat Communications,.env file scanning,Credentials exfiltration attempt via /.env,185.228.72.109 HTTP GET /.env with JA4 t13i1711h1 and self-signed cert WIN-8FIH4EGN4AL,Block 185.228.72.109 and alert on any /.env access attempts from US-hosted ZhouyiSat IPs
+ANOM-006,HIGH,AS14956,RouterHosting LLC,Multi-vulnerability scanner,Single IP scanning for multiple CVE exploit paths,216.126.239.17 GreyNoise suspicious scanning Wordpress/CrushFTP/Ivanti/OWA,Block 216.126.239.17 and monitor for follow-on exploitation attempts
+ANOM-007,MEDIUM,AS200651,FlokiNET ehf,Tor exit node performing active scanning,Tor exit node scanning HTTP/SSH ports,185.100.87.136 Tor 0.4.9.11 port 9001 scanning ports 80/443/444/8080/22,Rate-limit or block 185.100.87.136 and monitor Tor exit node abuse
+ANOM-008,MEDIUM,AS214940,Kprohost LLC,User agent rotation suggesting evasion,20 distinct browser UAs from 3 IPs in same /24,77.83.39.197/119/94 cycling UAs across port 443,Flag UA rotation pattern and block 77.83.39.0/24 for HTTPS scanning
+ANOM-009,MEDIUM,AS51396,Pfcloud UG,GreyNoise malicious IP in Pfcloud range,RDP crawler and bruteforcer,176.65.148.25 GreyNoise malicious OpenSSH 9.2p1 port 22,Block 176.65.148.25 and audit 176.65.148.0/24 for additional malicious infrastructure
+ANOM-010,LOW,AS57043,Hostkey B.v.,New ASN appearance in honeypots,First observed activity from Hostkey,151.243.173.235 SSH scanning port 22 from NL,Monitor for recurring activity from AS57043
+ANOM-011,LOW,AS138915,KAOPU-HK,High Sponge volume no Honeylabs match,10000 Sponge sessions but 0 Honeylabs events,NTP/123 traffic only in Sponge data,Monitor for protocol shift from NTP to attack traffic
diff --git a/kevlar/2026-07-13/changes/diff-vs-prior-week.csv b/kevlar/2026-07-13/changes/diff-vs-prior-week.csv
new file mode 100644
index 0000000..45bf9bc
--- /dev/null
+++ b/kevlar/2026-07-13/changes/diff-vs-prior-week.csv
@@ -0,0 +1,36 @@
+metric,asn,asn_org,prior_value,current_value,delta,delta_pct,category,notes
+active_asns,total,,9,15,+6,+67%,expansion,"6 new ASNs active: AS57043, AS138915, AS216139, AS33993, AS216246, AS211720"
+event_volume,AS51396,Pfcloud UG,11500,10000+,-1500,-13%,decrease,"PFCLOUD volume slightly decreased but still dominant"
+event_volume,AS51852,Private Layer INC,822,1802,+980,+119%,increase,"Significant uptick in Private Layer activity"
+event_volume,AS14956,RouterHosting LLC,267,206,-61,-23%,decrease,"RouterHosting activity decreased"
+event_volume,AS214940,Kprohost LLC,45,46,+1,+2%,stable,"Kprohost stable"
+event_volume,AS198953,Proton66 OOO,35,539,+504,+1440%,surge,"Proton66 massive surge - RDP/SSH/Telnet/FTP bruteforcing"
+event_volume,AS200651,FlokiNET ehf,20,20,0,0%,stable,"FlokiNET stable"
+event_volume,AS210644,Aeza Group LLC,3,1,-2,-67%,decrease,"Aeza minimal activity"
+event_volume,AS400992,ZhouyiSat Comm,4,2,-2,-50%,decrease,"ZhouyiSat minimal"
+event_volume,AS200593,Prospero Ooo,2,3890,+3888,+194400%,surge,"Prospero massive surge - scan-only behavior"
+new_ips,AS51396,Pfcloud UG,0,3,+3,new,"New IPs: 204.76.203.78/79/80 - coordinated scan cluster"
+new_ips,AS51852,Private Layer INC,0,3,+3,new,"New IPs: 179.43.134.114, 179.43.168.58, 179.43.186.241"
+new_ips,AS14956,RouterHosting LLC,0,4,+4,new,"New IPs: 144.172.103.227, 216.126.225.168, 144.172.97.10, 167.88.165.96"
+new_ips,AS198953,Proton66 OOO,0,2,+2,new,"New IPs: 176.120.22.240, 176.120.22.147, 37.77.150.67"
+new_ips,AS200593,Prospero Ooo,0,1,+1,new,"New IP: 91.202.233.79 - 3890 events single IP"
+new_ips,AS214940,Kprohost LLC,0,2,+2,new,"New IPs: 77.83.39.119, 77.83.39.94"
+new_ips,AS57043,Hostkey B.v.,0,1,+1,new,"New IP: 151.243.173.235 - SSH scanning"
+new_ips,AS216139,Iron Hosting Centre,0,1,+1,new,"New IP: 178.208.88.28 - SSH scanning"
+new_ips,AS211720,Datashield Inc.,0,1,+1,new,"New IP: 185.231.33.46 - Exchange /ews/ recon"
+new_asns,AS57043,Hostkey B.v.,0,1,+1,new,"First observation in Honeylabs"
+new_asns,AS138915,KAOPU-HK,0,0,0,0,"Sponge only - NTP/123 traffic, no Honeylabs"
+new_asns,AS216139,Iron Hosting Centre,0,1,+1,new,"First observation in Honeylabs"
+new_asns,AS33993,TOV Aktor,0,0,0,0,"Sponge only - 2 sessions"
+new_asns,AS216246,Qwins-LTD,0,0,0,0,"Sponge only - 93 sessions"
+new_asns,AS211720,Datashield Inc.,0,1,+1,new,"First observation - Exchange recon"
+new_attack_pattern,AS51396,Pfcloud UG,none,coordinated-scan-cluster,new,new,"Three IPs (204.76.203.78/79/80) with identical start/stop times"
+new_attack_pattern,AS198953,Proton66 OOO,rdp-only,multi-protocol-bruteforce,new,new,"Expanded from RDP-only to SSH+Telnet+FTP bruteforcing"
+new_attack_pattern,AS200593,Prospero Ooo,minimal,massive-port-scan,new,new,"Single IP generating 3890 events on diverse high ports"
+new_attack_pattern,AS211720,Datashield Inc.,none,exchange-ews-recon,new,new,"Exchange /ews/ endpoint reconnaissance"
+new_attack_pattern,AS400992,ZhouyiSat Comm,none,env-file-scanning,new,new,"/.env file probing via HTTPS"
+new_fingerprint,AS400992,ZhouyiSat,none,ja4-t13i1711h1,new,new,"TLS 1.3 fingerprint for .env scanning"
+new_fingerprint,AS200651,FlokiNET,none,ja4-t13i1909h2,new,new,"TLS 1.3 fingerprint for transparentpix.gif probing"
+new_fingerprint,AS211720,Datashield,none,ja4-t13i1813h1,new,new,"TLS 1.3 fingerprint for Exchange /ews/ recon"
+new_fingerprint,AS57043,Hostkey,none,hassh-f555226d,new,new,"HASSH for libssh_0.9.6 SSH scanning"
+new_fingerprint,AS200651,FlokiNET,none,hassh-e54ef3ec,new,new,"HASSH for OpenSSH_10.1 (Tor exit node)"