aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-08-02/iocs
diff options
context:
space:
mode:
Diffstat (limited to 'kevlar/2026-08-02/iocs')
-rw-r--r--kevlar/2026-08-02/iocs/README.md25
-rw-r--r--kevlar/2026-08-02/iocs/all-observed-ips.txt157
-rw-r--r--kevlar/2026-08-02/iocs/c2-paths.txt15
-rw-r--r--kevlar/2026-08-02/iocs/fingerprints.txt8
4 files changed, 205 insertions, 0 deletions
diff --git a/kevlar/2026-08-02/iocs/README.md b/kevlar/2026-08-02/iocs/README.md
new file mode 100644
index 0000000..7bef1c9
--- /dev/null
+++ b/kevlar/2026-08-02/iocs/README.md
@@ -0,0 +1,25 @@
+# Weekly BP Report -- 2026-08-02
+
+Generated: 2026-08-03T03:43:00Z
+ASNs covered: 26
+Sponge sessions found: 10,000+ across 21 active ASNs (capped per query)
+Honeylabs events found: 8,400 (AS51396 PFCLOUD only; 25 ASNs: zero)
+Censys IPs profiled: 6 ASNs (190K+ hosts, all BULLETPROOF-labeled)
+Anomalies flagged: 1 (universal BULLETPROOF classification across all profiled ASNs)
+
+## Key Findings
+
+- Only 1 of 26 ASNs (PFCLOUD) generated honeypot events; the other 25 show
+ targeted scanning against real infrastructure
+- All Censys-profiled ASNs are universally classified as BULLETPROOF
+- KAOPU-HK (AS138915): 818K NTP/SSDP amplification scanning sessions
+- PFCLOUD (AS51396): active proxy-checking (SOCKS5 + HTTP CONNECT) against honeypots
+- HOSTKEY (AS57043) and AEZA (AS210644): largest infrastructure (100K+ and 69K hosts)
+- PLI-AS (AS51852): massive Telnet brute-forcing (34K sessions)
+- PROTON66 (AS198953): SSH/MSSQL/RDP scanning (102K sessions from single IP)
+
+## Data Sources
+
+- Sponge (Arkime): network sensor sessions across full deployment
+- Honeylabs: global honeypot network, 7-day window (2026-07-27 to 2026-08-02)
+- Censys: internet-wide host profiling
diff --git a/kevlar/2026-08-02/iocs/all-observed-ips.txt b/kevlar/2026-08-02/iocs/all-observed-ips.txt
new file mode 100644
index 0000000..964b94f
--- /dev/null
+++ b/kevlar/2026-08-02/iocs/all-observed-ips.txt
@@ -0,0 +1,157 @@
+# AS57043 - HOSTKEY-AS
+193.17.95.129
+66.248.205.4
+82.22.175.192
+82.24.19.158
+91.239.211.68
+
+# AS209847 - THE
+45.144.28.70
+45.82.252.106
+92.118.233.6
+5.181.20.206
+45.12.129.166
+
+# AS210644 - AEZA-AS
+77.221.153.3
+85.192.31.14
+138.124.99.219
+77.221.158.41
+212.113.102.0
+
+# AS138915 - KAOPU-HK (Kaopu Cloud HK Limited)
+38.54.2.209
+38.54.2.232
+38.54.2.61
+38.54.2.13
+38.54.2.170
+
+# AS14956 - ROUTERHOSTING (RouterHosting LLC)
+107.189.27.179
+167.88.166.32
+167.88.165.33
+172.86.123.8
+167.88.165.44
+
+# AS216139 - IRONHOST
+109.120.141.207
+185.72.10.233
+178.208.88.6
+46.30.46.130
+178.208.78.17
+
+# AS51852 - PLI-AS
+190.211.255.210
+179.43.133.154
+179.43.163.26
+179.43.186.223
+179.43.134.114
+
+# AS400992 - ZHOUYISAT-COMMUNICATIONS
+23.172.217.77
+23.172.217.87
+185.121.15.184
+185.219.7.27
+23.177.185.239
+
+# AS33993 - UFO-AS
+45.144.31.247
+185.235.242.122
+141.98.189.206
+45.150.64.125
+193.201.126.15
+
+# AS51396 - PFCLOUD (Pfcloud UG)
+204.76.203.231
+204.76.203.18
+176.65.148.147
+45.153.34.235
+45.156.87.204
+176.65.148.242
+176.65.149.64
+176.65.148.95
+176.65.148.29
+176.65.148.96
+176.65.148.177
+176.65.149.220
+176.65.148.132
+176.65.148.2
+176.65.149.30
+176.65.149.236
+176.65.149.182
+176.65.149.27
+176.65.149.31
+176.65.149.212
+176.65.134.3
+204.76.203.80
+204.76.203.79
+204.76.203.78
+
+# AS213702 - QWINS-LTD
+89.125.48.168
+78.40.209.57
+80.253.249.170
+95.164.53.44
+89.125.48.64
+
+# AS216246 - RU-AEZA-AS
+82.117.87.156
+138.124.14.150
+77.110.105.96
+185.103.100.48
+79.137.192.106
+
+# AS200651 - FLOKINET
+185.100.87.136
+185.100.84.164
+185.10.68.96
+185.246.190.66
+185.100.85.79
+
+# AS30823 - AUROLOGIC (aurologic GmbH)
+172.86.94.49
+172.86.93.75
+45.153.243.249
+41.216.188.21
+45.138.173.7
+
+# AS140666 - ADPL-AS-AP (ANY DIGITAL PTE. LTD.)
+154.94.68.6
+204.3.179.3
+204.3.179.2
+204.3.250.24
+
+# AS214351 - FEMOIT
+62.60.226.79
+62.60.226.176
+
+# AS198953 - PROTON66
+37.77.150.67
+176.120.22.16
+176.120.22.61
+37.77.150.119
+176.120.22.147
+
+# AS200593 - PROSPERO-AS
+91.215.85.104
+91.202.233.79
+91.215.85.193
+91.215.85.106
+91.202.233.82
+
+# AS214940 - KPRONET
+77.83.39.197
+77.83.39.94
+45.144.212.53
+77.83.39.36
+77.83.39.42
+
+# AS211720 - Datashield, Inc.
+185.231.33.30
+185.231.33.46
+185.231.33.22
+185.231.32.24
+185.231.32.25
+
+# AS58854 - KAOPY (Kaopu Cloud)
+103.236.255.202
diff --git a/kevlar/2026-08-02/iocs/c2-paths.txt b/kevlar/2026-08-02/iocs/c2-paths.txt
new file mode 100644
index 0000000..2b9aae3
--- /dev/null
+++ b/kevlar/2026-08-02/iocs/c2-paths.txt
@@ -0,0 +1,15 @@
+# HTTP URL Paths Observed (from prior week Honeylabs data)
+
+/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php -- PHPUnit RCE probe
+/dana-na/auth/url_default/welcome.cgi -- Pulse Secure VPN enumeration
+/global-protect/login.esp -- Palo Alto GlobalProtect enumeration
+/sslvpnLogin.html -- SSL VPN portal enumeration
+/guacamole/ -- Apache Guacamole RDP gateway probing
+/remote/login -- Generic remote access login probe
+/auth/login -- Authentication endpoint probing
+/login -- Login page enumeration
+
+# Note: No URL paths were observed in Honeylabs events from monitored ASNs
+# this week. All non-PFCLOUD ASNs registered zero honeypot events.
+# PFCLOUD Honeylabs events were proxy-checking (HTTP CONNECT tunnels, SOCKS5)
+# rather than HTTP path-based exploitation.
diff --git a/kevlar/2026-08-02/iocs/fingerprints.txt b/kevlar/2026-08-02/iocs/fingerprints.txt
new file mode 100644
index 0000000..bd25290
--- /dev/null
+++ b/kevlar/2026-08-02/iocs/fingerprints.txt
@@ -0,0 +1,8 @@
+# JA4H HTTP Fingerprints
+
+ge11nn0400_9c3956fad5da -- PFCLOUD Go-http-client/1.1 proxy checker, 204.76.203.78-80
+ge11nn0400_88d30a62b7ad -- PFCLOUD zgrab/0.x web scanner, 176.65.149.236
+
+# Note: No JA4 TLS or HASSH SSH fingerprints were observed in Honeylabs events
+# from monitored ASNs this week. All non-PFCLOUD ASNs registered zero honeypot
+# events in the 2026-07-27 to 2026-08-02 observation window.