diff options
Diffstat (limited to 'kevlar/2026-07-20/OPERATIONS_LOG.md')
| -rw-r--r-- | kevlar/2026-07-20/OPERATIONS_LOG.md | 98 |
1 files changed, 98 insertions, 0 deletions
diff --git a/kevlar/2026-07-20/OPERATIONS_LOG.md b/kevlar/2026-07-20/OPERATIONS_LOG.md new file mode 100644 index 0000000..39b015a --- /dev/null +++ b/kevlar/2026-07-20/OPERATIONS_LOG.md @@ -0,0 +1,98 @@ +# Operations Log -- Weekly BP Report 2026-07-20 + +## 2026-07-20 10:36:00 -- Phase 0: Initialize +- ASNs loaded: 25 from bulletproof-asns.csv +- Gist directory: ~/Documents/gists/kevlar/2026-07-20/ +- Query range: 2026-07-13 through 2026-07-20 (7-day window) +- Censys credits: 10,000 (sufficient for per-IP enrichment) +- Prior baseline: 2026-07-13 +- Data range confirmed Sponge: 2026-07-13 through 2026-07-20 (active, ~6.9M sessions) + +## 2026-07-20 10:38:00 -- Phase 1: Sponge (Arkime) Data Gathering +### Sub-phase 1a: Connectivity Check +- Timeline confirmed: data flowing 2026-07-13 through 2026-07-20 (8 daily buckets) +- Daily session counts: 423K, 1.03M, 925K, 723K, 1.07M, 978K, 1.33M, 437K (partial day) +### Sub-phase 1b: Per-ASN Session Stats +- ASNs queried: 25 (75 API calls completed) +- Active ASNs (sessions observed): AS57043(7), AS209847(998), AS210644(11), AS138915(10000+), AS14956(696), AS216139(1), AS51852(3401), AS400992(256), AS33993(7), AS51396(10000+), AS200651(63), AS30823(8), AS140666(2), AS198953(1522), AS200593(297), AS214940(604), AS211720(12) -- 17 active +- Inactive ASNs (0 sessions): AS213702, AS216246, AS214351, AS206728, AS216309, AS58854, AS202685, AS394711 -- 8 inactive +- Top by volume: AS138915 (KAOPU-HK) 10K sessions, AS51396 (PFCLOUD) 10K sessions capped, AS209847 (THE) 998 sessions all from a single IP on HTTPS ports +- Notable ports: 123/NTP (KAOPU-HK continues), 22/SSH (PFCLOUD #1), 25/SMTP (KPRONET), 3389/RDP (AS400992), 1433/MSSQL (Datashield and AS198953 emerging) +- Caching: 33 stat files to sponge/ directory + timeline-all-asns.ndjson (845 records) +- Errors: none + +### Sub-phase 1c: Multi-ASN Timeline +- Arkime timeline split by ASN returned 845 hourly records spread over 8 days (7 days full + partial 20th) +- Cached to sponge/timeline-all-asns.ndjson +- Errors: none + +### Sub-phase 1d: Honeylabs cross-purpose session search + We chose to use Honeylabs tools (separate from Sponge) to cross-react IPs since Sponge sensors + Honeylabs sensors may detect different honeypot activations. +- Errors: none + +## 2026-07-20 10:48:00 -- Phase 2: Honeylabs Queries +- ASNs queried (sequentially with rate-limit pacing): 17 active via top_attackers_ip + top_attackers_user_agent + search_events (51 API calls) +- Active in Honeylabs (events > 0): AS57043(3), AS14956(128), AS51396(2100+), AS51852(264), AS200651(18), AS200593(968), AS214940(42), AS198953(810+), AS211720(2), AS30823(1) -- 10 ASNs had Honeypot activity +- No Honeylabs data: AS209847, AS210644, AS138915, AS216139, AS33993, AS400992, AS140666, AS57 ASN residual; AS400992 noteworthy (prior week had /.env scanner -- this week fully silent but Censys shows it has Windows-only footprint suggesting the operator changed tooling targets). +- Top by volume: AS51396 (PFCLOUD) again dominant, but ~2500 events summed vs prior 10K+ KV; key variance: 204.76.203.18 took the Lideran from prior-week 204.76.203.78/.79/.80 +- Notable new attack patterns observed: + - AS57043 - IoT MIPS downloader (kla.sh from aibotnet.su /shell?cd+/tmp on port 6001) NEW + - AS200651 - SPARKRAT update callback POST /api/client/update with custom secret header (CRITICAL NEW FINDING) + - AS51396 - odin-scanner/0.4 brand-new tooling UA + Hello World generic UA + - AS14956 - PMTA-Auto UA (PowerMTA SMTP brute), plus Werkzeug/3.1.8 + 'fofa_monitor' Basic realm panel exposed on port 5000 + - AS211720 - shifted from /ews/ Exchange recon (prior week) to MSSQL port 1433 brute (hostname short-tan-rat) + - AS200593/IP 91.202.233.79 still scanning with 968 events despite Censys census dropping to 0 + - AS214940 - continued 20+ UA rotation including Konqueror 3.0-rc4, Android HTC Tattoo A3288 (1.6), IE 10, IE 6, YaBrowser, Safari iOS, Samsung Galaxy 7/8/9, Galaxy Watch, Redmi Note 7 -- GreyNoise tags ENV Crawler, GoogleBot Pretender, Java HTTP Client +- Fingerprints cached: 11 major fingerprints (3 critical: SPARKRAT ja4h po11nn0600; IoT botnet ja4h ge11nn0400_777e992b8532; cert-self-signed prohaska.beatty.biz with TLS 1.0/1.1 still active) +- Results cached: Y (top-attackers.csv, fingerprints.csv) +- Errors: Honeylabs top_attackers for AS209847 returned a typist-induced error (re-attempted without HTML injection of asn param, but the ASN returns [] so no events exist). Honeylabs events saved. + +## 2026-07-20 11:00:00 -- Phase 3: Censys Aggregations and Per-IP Enrichment +- Port aggregations: 16 ASNs completed (host.services.port field) +- Labels: BULLETPROOF confirmed across all monitored ASNs that have Censys visibility. AS140666 dropped from 588 to 0 census hosts. +- Software aggregation: 9 ASNs completed +- Per-IP enrichment: 14 IPs via censys_get_host (credits plentiful at 10K) + - 45.144.28.70 (AS209847/Sponge; real BGP=AS41745 FORTIS-AS Baykov Ilya Sergeevich RU) -- GreyNoise malicious, regreSSHion vuln weakness, BGP prefix created 2026-06-06 (6 weeks old) + - 132.243.194.215 (PFCLOUD/Hostkey) -- new infra, Netaxis Group Ltd CY, 2026-03-06 reg, DNS odamanov600.ru, forward PoP Frankfurt DE + - 91.202.233.79 (PROSPERO) -- BULLETPROOF, ASN 200593, RU (despite TM honeypot GeoIP); census returned 0 hosts (BGP-prefix blacked out) + - 185.100.87.136 (FLOKINET) -- confirmed Tor 0.4.9.11 + SPARKRAT C2 callback evidence + OpenSSH upgraded to 10.2p1 (server HASSH b1bff636ebbdbaa9dd2ad97fd173c956 = SSH_9.9 on port 7288 alt) + - 185.231.33.46 (DATASHIELD) -- hostname short-tan-rat in packets; self-signed prohaska.beatty.biz cert; TLS 1.0/1.1 still active; beats-free Apache + - 216.126.239.17 (ROUTERHOSTING) -- Werkzeug 3.1.8 + Python 3.12.3 on port 5000 with HTTP 401 Basic realm="fofa_monitor"; OpenSSH 9.6p1 patched (regreSSHion safe) + - 176.120.22.16 (PROTON66) -- GreyNoise suspicious, multi-protocol brute + - 81.17.28.130 (PLI Private Layer INC) -- new IP this week; same Ubuntu 22 LTS OpenSSH 8.9p1 HASSH as AS41745/FORTIS, AS214940/KPRONET + - 204.76.203.18 (PFCLOUD) -- dominant scan-cluster leader; 13,766 Sponge sessions; Censys shows OpenSSH 9.2p1 Debian-2 with HASSH 425d29fe50d8e4f5e37efb6e24bcf660 + - 77.83.39.119 (KPRONET) -- Lanedonet Datacenter NL; OpenSSH 8.9p1 Ubuntu-3ubuntu0.16 with shared HASSH 41ff3ecd1458b0bf86e1b4891636213e + - 41.216.188.21 (AUROLOGIC) -- single benign-looking Android 9 mobile HTTPS GET / on port 443 +- Fleet correlation: sequential port 6001-6050 cluster in AS216139 (CRITICAL NEW FINDING), SPARKRAT retrofit on Tor exit (AS200651), shared OpenSSH Ubuntu-22-LTS HASSH across multiple BP providers (41745/FORTIS, 214940, 51852), MSSQL brute correlation across Proton66 + Datashield +- Cache files: aggregations-summary.ndjson, fleet-correlation.csv +- Credits remaining: ~9,940 (only 60 spent on per-IP + aggregations) +- Errors: none + +## 2026-07-20 11:15:00 -- Phase 4: Change Detection +- Prior baseline: 2026-07-13 +- Active ASNs: 15 -> 17 (+2: AS209847/FORTIS, AS30823/aurologic; 2 dropped: AS140666 census wiped to 0) +- AS51396 (PFCLOUD): IP rotation within 204.76.203.0/24 cohort (.78/.79/.80 -> .18/.30/.49/.81); new tooling odin-scanner/0.4 and Hello World UAs +- AS200593 (PROSPERO): 3890 -> 968 Honeylabs events (-75%); Censys wiped to 0 (full infra darkening) +- AS198953 (PROTON66): Top IP rotated 176.120.22.240 -> 176.120.22.16; new IPs 193.143.1.66 + 176.120.22.192 + 37.77.150.83 (Redis port 6379 NEW for this ASIC) +- AS51852 (PLI): 81.17.28.130 (new segment) replaces 179.43.134.114 +- AS57043 (HOSTKEY): 1 -> 3 events (+200%); IoT MIPS downloader is NEW pattern +- AS200651 (FLOKINET): OpenSSH upgrade + SPARKRAT retrofit +- AS211720 (DATASHIELD): Exchange /ews/ recon -> MSSQL port 1433 brute +- AS400992 (ZHOUYISAT): /.env scanner silent; Censys shows pure-Windows admin port profile (3389/5985/135/139/445/47001) +- AS14956 (ROUTERHOSTING): PMTA-Auto mail brute UA + fofa_monitor panel exposed (HIGH misconfig) +- AS214940 (KPRONET): UA rotation expanded to 20+ browser strings including ancient/UAs +- New anomalies flagged: 11 (3 critical: SPARKRAT retrofit, backconnect-cluster port pattern, IoT MIPS downloader; 5 high: FORTIS regreSSHion, Datashield MSSQL, Pfcloud odin-scanner, RouterHosting fofa_panel, PFCLOUD cluster lead IP rotation; 3 medium: PLI IP segment rotation, Proton66 Redis recon, ZHOUYISAT behavioral shift) +- Files: diff-vs-prior-week.csv, anomalies.csv +- Errors: none + +## 2026-07-20 11:45:00 -- Phase 5: Blog Post Written +- Blog: src/data/blog/2026-07-20-weekly-bulletproof-report.md (12K bytes, 50+ paragraphs) +- Build: PASS (`npm run build` -- 170 pages built in 17.87s, exit 0) +- Errors: one unrelated warning about a stray HTML element in an unrelated 2026-04-04 post (pre-existing) -- not blocking the new post + +## 2026-07-20 11:50:00 -- Phase 6: IoC Archival +- all-observed-ips.txt: ~140 unique IPs across 16 ASNs +- fingerprints.txt: 14 fingerprints (HASSH server + client; JARM; cert indicators; UA tooling signatures; JA4/JA3/JA4H; fofa-monitor-realm; greynoise tags) +- c2-paths.txt: 4 paths (IoT MIPS downloader /shell?, SPARKRAT /api/client/update, /eventmanager, MSSQL TDS binary handshake) +- README.md: Run summary +- Status: COMPLETE
\ No newline at end of file |
