diff options
Diffstat (limited to 'kevlar/2026-07-13/iocs/README.md')
| -rw-r--r-- | kevlar/2026-07-13/iocs/README.md | 32 |
1 files changed, 32 insertions, 0 deletions
diff --git a/kevlar/2026-07-13/iocs/README.md b/kevlar/2026-07-13/iocs/README.md new file mode 100644 index 0000000..5ad0bd3 --- /dev/null +++ b/kevlar/2026-07-13/iocs/README.md @@ -0,0 +1,32 @@ +# Weekly BP Report -- 2026-07-13 + +Generated: 2026-07-13T12:00:00Z +ASNs covered: 26 +Query range: 2026-07-05 through 2026-07-11 +Sponge sessions found: ~21,000+ (15 active ASNs) +Honeylabs events found: ~16,000+ (12 active ASNs) +Censys IPs enriched: 10 (per-host enrichment via censys_get_host) +Anomalies flagged: 11 (2 critical, 4 high, 3 medium, 2 low) + +## Directory Structure + +- `sponge/` -- Arkime/Sponge session stats per ASN (77 files) +- `honeylabs/` -- Honeylabs top attackers and fingerprints (2 files) +- `censys/` -- Censys aggregations, IP enrichments, fleet correlation (3 files) +- `changes/` -- Change detection vs prior week (2 files) +- `iocs/` -- Structured IoC files: IPs, fingerprints, C2 paths + +## Key Findings + +- PFCLOUD (AS51396) remains dominant with 10K+ events and a new coordinated scan cluster (204.76.203.78/79/80) +- Prospero Ooo (AS200593) surged from 2 to 3890 events -- single IP scan bomb +- Proton66 (AS198953) expanded from RDP-only to multi-protocol bruteforcing (RDP+SSH+Telnet+FTP) +- Datashield Inc. (AS211720) new entrant performing Exchange /ews/ reconnaissance +- ZhouyiSat (AS400992) observed scanning for /.env files to steal credentials +- FlokiNET (AS200651) Tor exit node (185.100.87.136) actively scanning HTTP/SSH +- Active ASNs expanded from 9 to 15 (+67%) week over week +- 11 unique fingerprints collected (4 HASSH, 4 JA4/JA3, 3 JA4H) -- major improvement over prior week + +## Web Access + +https://git.sr.ht/~hrbrmstr/gists/tree/main/item/kevlar/2026-07-13/ |
