aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-08-02/iocs
diff options
context:
space:
mode:
Diffstat (limited to 'kevlar/2026-08-02/iocs')
-rw-r--r--kevlar/2026-08-02/iocs/README.md27
-rw-r--r--kevlar/2026-08-02/iocs/all-observed-ips.txt29
-rw-r--r--kevlar/2026-08-02/iocs/c2-paths.txt37
-rw-r--r--kevlar/2026-08-02/iocs/fingerprints.txt21
4 files changed, 81 insertions, 33 deletions
diff --git a/kevlar/2026-08-02/iocs/README.md b/kevlar/2026-08-02/iocs/README.md
index 7bef1c9..d255f51 100644
--- a/kevlar/2026-08-02/iocs/README.md
+++ b/kevlar/2026-08-02/iocs/README.md
@@ -1,25 +1,26 @@
# Weekly BP Report -- 2026-08-02
-Generated: 2026-08-03T03:43:00Z
+Generated: 2026-08-03T04:00:00Z
ASNs covered: 26
Sponge sessions found: 10,000+ across 21 active ASNs (capped per query)
-Honeylabs events found: 8,400 (AS51396 PFCLOUD only; 25 ASNs: zero)
-Censys IPs profiled: 6 ASNs (190K+ hosts, all BULLETPROOF-labeled)
-Anomalies flagged: 1 (universal BULLETPROOF classification across all profiled ASNs)
+Honeylabs events found: 8,400+ across 7 ASNs (PFCLOUD, HOSTKEY, ROUTERHOSTING, PLI-AS, PROTON66, FLOKINET, KPRONET, AUROLOGIC)
+Censys IPs profiled: 6 ASN-level + 3 per-IP enrichments (190K+ hosts, all BULLETPROOF-labeled)
+Anomalies flagged: 1 (FLOKINET operates Tor exit relay with concurrent brute-force activity)
## Key Findings
-- Only 1 of 26 ASNs (PFCLOUD) generated honeypot events; the other 25 show
- targeted scanning against real infrastructure
-- All Censys-profiled ASNs are universally classified as BULLETPROOF
-- KAOPU-HK (AS138915): 818K NTP/SSDP amplification scanning sessions
-- PFCLOUD (AS51396): active proxy-checking (SOCKS5 + HTTP CONNECT) against honeypots
-- HOSTKEY (AS57043) and AEZA (AS210644): largest infrastructure (100K+ and 69K hosts)
-- PLI-AS (AS51852): massive Telnet brute-forcing (34K sessions)
-- PROTON66 (AS198953): SSH/MSSQL/RDP scanning (102K sessions from single IP)
+- 7 of 26 ASNs generated Honeylabs events (not 1 as initially reported)
+- All Censys-profiled hosts are universally classified as BULLETPROOF
+- KPRONET: .git/.env exfiltration campaign with 20+ spoofed user agents
+- PLI-AS: Multi-modal attack (DCE/RPC, RDP brute, tRPC, WordPress scanning)
+- FLOKINET: Tor exit relay (185.100.87.136) with SSH/Telnet brute-force
+- HOSTKEY: RTSP camera credential stuffing against Hikvision cameras
+- PROTON66: MSSQL-TDS brute-force on non-standard ports
+- PFCLOUD: Consistent proxy checking with port-paired infrastructure
+- KAOPU-HK: 818K NTP/SSDP amplification scanning sessions (zero Honeylabs)
## Data Sources
- Sponge (Arkime): network sensor sessions across full deployment
- Honeylabs: global honeypot network, 7-day window (2026-07-27 to 2026-08-02)
-- Censys: internet-wide host profiling
+- Censys: internet-wide host profiling + per-IP enrichment
diff --git a/kevlar/2026-08-02/iocs/all-observed-ips.txt b/kevlar/2026-08-02/iocs/all-observed-ips.txt
index 964b94f..640acbd 100644
--- a/kevlar/2026-08-02/iocs/all-observed-ips.txt
+++ b/kevlar/2026-08-02/iocs/all-observed-ips.txt
@@ -155,3 +155,32 @@
# AS58854 - KAOPY (Kaopu Cloud)
103.236.255.202
+# === IPs from Honeylabs events ===
+# AS57043 - HOSTKEY (RTSP camera brute-forcing)
+163.5.29.40
+
+# AS14956 - ROUTERHOSTING (binary protocol + TLS browser)
+144.172.100.235
+167.88.168.121
+
+# AS51852 - PLI-AS (DCE/RPC, RDP, tRPC, WordPress)
+81.17.28.130
+179.43.186.199
+179.43.150.26
+179.43.158.246
+
+# AS198953 - PROTON66 (MSSQL brute-force)
+176.120.22.61
+
+# AS200651 - FLOKINET (SSH/Telnet brute, Tor exit relay)
+185.100.87.136
+185.246.188.74
+185.246.190.66
+
+# AS30823 - AUROLOGIC (SIP scanning)
+216.126.229.131
+
+# AS214940 - KPRONET (.git/.env exfiltration)
+77.83.39.94
+77.83.39.6
+77.83.39.24
diff --git a/kevlar/2026-08-02/iocs/c2-paths.txt b/kevlar/2026-08-02/iocs/c2-paths.txt
index 2b9aae3..0432430 100644
--- a/kevlar/2026-08-02/iocs/c2-paths.txt
+++ b/kevlar/2026-08-02/iocs/c2-paths.txt
@@ -1,15 +1,22 @@
-# HTTP URL Paths Observed (from prior week Honeylabs data)
-
-/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php -- PHPUnit RCE probe
-/dana-na/auth/url_default/welcome.cgi -- Pulse Secure VPN enumeration
-/global-protect/login.esp -- Palo Alto GlobalProtect enumeration
-/sslvpnLogin.html -- SSL VPN portal enumeration
-/guacamole/ -- Apache Guacamole RDP gateway probing
-/remote/login -- Generic remote access login probe
-/auth/login -- Authentication endpoint probing
-/login -- Login page enumeration
-
-# Note: No URL paths were observed in Honeylabs events from monitored ASNs
-# this week. All non-PFCLOUD ASNs registered zero honeypot events.
-# PFCLOUD Honeylabs events were proxy-checking (HTTP CONNECT tunnels, SOCKS5)
-# rather than HTTP path-based exploitation.
+# C2 and Exploitation Paths Observed
+
+# PLI-AS (AS51852)
+/api/trpc/setup.setup -- tRPC setup endpoint targeting, POST with JSON body, port 3000
+/wp-login.php -- WordPress credential enumeration, TLS, Go-http-client/1.1
+
+# HOSTKEY (AS57043)
+/ISAPI/Streaming/channels/10101 -- Hikvision camera streaming, RTSP DESCRIBE, Basic auth credential stuffing
+/Streaming/Channels/10201 -- Hikvision camera streaming (alternate path)
+
+# KPRONET (AS214940)
+/.git/HEAD -- Git repository discovery, secret harvesting
+/.git/index -- Git index file enumeration
+/.git/config -- Git remote configuration extraction
+/.env -- Environment file exfiltration (database creds, API keys, secrets)
+
+# From prior week, still relevant:
+/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php -- PHPUnit RCE
+/dana-na/auth/url_default/welcome.cgi -- Pulse Secure VPN
+/global-protect/login.esp -- Palo Alto GlobalProtect
+/sslvpnLogin.html -- SSL VPN portal enumeration
+/guacamole/ -- Apache Guacamole RDP gateway probing
diff --git a/kevlar/2026-08-02/iocs/fingerprints.txt b/kevlar/2026-08-02/iocs/fingerprints.txt
index bd25290..264c0b2 100644
--- a/kevlar/2026-08-02/iocs/fingerprints.txt
+++ b/kevlar/2026-08-02/iocs/fingerprints.txt
@@ -1,8 +1,19 @@
+# JA4 TLS Fingerprints
+
+t13i190800_9dc949149365_97f8aa674fd9 -- KPRONET .env exfiltration campaign, 77.83.39.x, Ukraine
+t13i251000_b78ed14e2fd0_ab7e3b40a677 -- KPRONET .git/HEAD scanning, 77.83.39.94, Ukraine
+t13i190900_9dc949149365_e7c285222651 -- PLI-AS WordPress login scan, 179.43.158.246, Switzerland
+t13i1310h1_f57a46bbacb6_e7c285222651 -- ROUTERHOSTING TLS Firefox browser, 167.88.168.121, US
+
# JA4H HTTP Fingerprints
-ge11nn0400_9c3956fad5da -- PFCLOUD Go-http-client/1.1 proxy checker, 204.76.203.78-80
-ge11nn0400_88d30a62b7ad -- PFCLOUD zgrab/0.x web scanner, 176.65.149.236
+ge11nn0500_9af7e0472034 -- KPRONET .env/.git exfiltration (detects despite 20+ UA rotations), 77.83.39.x
+po11nr09en_94d98df401ed -- PLI-AS tRPC setup endpoint attack, 179.43.150.26
+ge11nn0400_9c3956fad5da -- PFCLOUD Go-http-client/1.1 proxy checker, 204.76.203.78-80
+ge11nn0400_88d30a62b7ad -- PFCLOUD zgrab/0.x web scanner, 176.65.149.236
+ge11nn0300_0db47b7d240d -- PLI-AS Go-http-client/1.1 wordpress scanner, 179.43.158.246
+
+# HASSH SSH Fingerprints
-# Note: No JA4 TLS or HASSH SSH fingerprints were observed in Honeylabs events
-# from monitored ASNs this week. All non-PFCLOUD ASNs registered zero honeypot
-# events in the 2026-07-27 to 2026-08-02 observation window.
+e54ef3ec27fe1fea7ab64d3fa05359fd -- FLOKINET OpenSSH 10.1 SSH brute client, 185.100.87.136
+b1bff636ebbdbaa9dd2ad97fd173c956 -- FLOKINET Tor relay OpenSSH 9.9, 185.100.87.136:7288