diff options
Diffstat (limited to 'kevlar/2026-08-17/changes/anomalies.csv')
| -rw-r--r-- | kevlar/2026-08-17/changes/anomalies.csv | 9 |
1 files changed, 9 insertions, 0 deletions
diff --git a/kevlar/2026-08-17/changes/anomalies.csv b/kevlar/2026-08-17/changes/anomalies.csv new file mode 100644 index 0000000..0ce74b3 --- /dev/null +++ b/kevlar/2026-08-17/changes/anomalies.csv @@ -0,0 +1,9 @@ +severity,asn,anomaly,rationale +high,AS198953,MSSQL-TDS brute force +594% to ~1700 events,176.120.22.61 swept 289 distinct ports (was 17); Win box has exposed DCERPC+NetBIOS - likely compromised +high,AS200651,SPARK C2 beacon observed,185.100.87.136 POST /api/client/update w/ commit+secret header, /eventmanager, /ajax, agent UUID path; HASSH e54ef3ec; Tor exit + C2 combo +high,AS51396,Cloned infra + attribution crossover,"204.76.203.224/226 identical ClickHouse+proxy banner hashes; 77.83.39.6 shares HASSH 41ff3ecd w/ prior clone pair; .env exfil attributed to PFCLOUD per Censys vs KPRONET per honeylabs" +high,AS214940,.git/.env exfil campaign resumed,77.83.39.6/.94 hammer /.env + /.git/HEAD over TLS 443 with rotating UAs; high-confidence malicious verdict from honeylabs (25 exploit-path hits) +medium,AS14956,PPTP campaign ended - SMBv1 surge,PPTP 1723 dropped to 1 event; SMB 445 brute from 3 IPs + Minecraft 25565 + SIP 5060/5061 +medium,AS138915,New WinRM attack vector,Python WinRM client POST /wsman from 154.93.53.239 (SC) - first non-amplification attack observed +medium,AS210644,qBittorrent peer scanning,77.110.106.52 swept 16663 repeatedly (qB5230 fingerprint); P2P probing pattern new this week +low,AS51396,ClickHouse exposed on 9009,Proxy nodes run public ClickHouse web UI - data exfil surface |
