aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-08-17/changes/anomalies.csv
diff options
context:
space:
mode:
Diffstat (limited to 'kevlar/2026-08-17/changes/anomalies.csv')
-rw-r--r--kevlar/2026-08-17/changes/anomalies.csv9
1 files changed, 9 insertions, 0 deletions
diff --git a/kevlar/2026-08-17/changes/anomalies.csv b/kevlar/2026-08-17/changes/anomalies.csv
new file mode 100644
index 0000000..0ce74b3
--- /dev/null
+++ b/kevlar/2026-08-17/changes/anomalies.csv
@@ -0,0 +1,9 @@
+severity,asn,anomaly,rationale
+high,AS198953,MSSQL-TDS brute force +594% to ~1700 events,176.120.22.61 swept 289 distinct ports (was 17); Win box has exposed DCERPC+NetBIOS - likely compromised
+high,AS200651,SPARK C2 beacon observed,185.100.87.136 POST /api/client/update w/ commit+secret header, /eventmanager, /ajax, agent UUID path; HASSH e54ef3ec; Tor exit + C2 combo
+high,AS51396,Cloned infra + attribution crossover,"204.76.203.224/226 identical ClickHouse+proxy banner hashes; 77.83.39.6 shares HASSH 41ff3ecd w/ prior clone pair; .env exfil attributed to PFCLOUD per Censys vs KPRONET per honeylabs"
+high,AS214940,.git/.env exfil campaign resumed,77.83.39.6/.94 hammer /.env + /.git/HEAD over TLS 443 with rotating UAs; high-confidence malicious verdict from honeylabs (25 exploit-path hits)
+medium,AS14956,PPTP campaign ended - SMBv1 surge,PPTP 1723 dropped to 1 event; SMB 445 brute from 3 IPs + Minecraft 25565 + SIP 5060/5061
+medium,AS138915,New WinRM attack vector,Python WinRM client POST /wsman from 154.93.53.239 (SC) - first non-amplification attack observed
+medium,AS210644,qBittorrent peer scanning,77.110.106.52 swept 16663 repeatedly (qB5230 fingerprint); P2P probing pattern new this week
+low,AS51396,ClickHouse exposed on 9009,Proxy nodes run public ClickHouse web UI - data exfil surface