From bd417023bfb20a65052611064b6df9e6bf9ad597 Mon Sep 17 00:00:00 2001 From: hrbrmstr Date: Tue, 9 Jun 2026 20:44:52 -0400 Subject: add: asn-report --- 2026/asn215540-report/README.md | 311 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 311 insertions(+) create mode 100644 2026/asn215540-report/README.md (limited to '2026/asn215540-report/README.md') diff --git a/2026/asn215540-report/README.md b/2026/asn215540-report/README.md new file mode 100644 index 0000000..1f0396c --- /dev/null +++ b/2026/asn215540-report/README.md @@ -0,0 +1,311 @@ +# ASN 215540 (GCS-AS) -- Comprehensive Intelligence Report + +**Date**: 2026-06-09 +**Data Sources**: Censys (host search, host view), Honeylabs (IOC, ASN enrichment, top attackers, attack timeline) +**Scope**: Three target IPs (92.118.112.230, 89.185.80.144, 89.185.80.183) mapped to their full ASN infrastructure + +--- + +## 1. Executive Summary + +The three target IPs belong to ASN 215540, operated by **GLOBAL CONNECTIVITY SOLUTIONS LLP** (GCS-AS), a UK-registered shell company with Russian management (RIPE admin Evgenii M., Russian address on file). This ASN is a **large-scale proxy/VPN exit node hosting operation** with 1,000+ IPs across 22+ IP blocks in 13+ countries. + +Key characteristics: massive SSH server farm (387 hosts sharing the exact build/fingerprint of the targets), geographic diversity (US, DE, PL, LT, AM, TR, NL, DK, GB, HK, AL, CH, BR), mixed infrastructure (SOCKS5 proxy, credential harvesting panel, Caddy HTTP servers, nginx), and consistent scanning/probing behavior flagged by GreyNoise. + +--- + +## 2. Target IP Analysis + +### 2.1 Target IPs + +| IP | Block | Location | SSH Build | HASSH | PTR | GreyNoise | +|---|---|---|---|---|---|---| +| 92.118.112.230 | 92.118.112.0/24 | Atlanta, US | 9.6p1 Ubuntu-3ubuntu13.16 | e42184b0... | 157279.ip-ptr.tech | Suspicious | +| 89.185.80.144 | 89.185.80.0/24 | Phoenix, US | 9.6p1 Ubuntu-3ubuntu13.16 | e42184b0... | 157279.ip-ptr.tech | Suspicious | +| 89.185.80.183 | 89.185.80.0/24 | Phoenix, US | 9.6p1 Ubuntu-3ubuntu13.16 | e42184b0... | 157279.ip-ptr.tech | Suspicious | + +### 2.2 GreyNoise Classification (All Three) + +All classified as **suspicious** with identical tags: + +- Web Crawler, TLS/SSL Crawler +- Carries HTTP Referer +- Generic Login Attempt +- Palo Alto Networks PAN-OS CVE-2020-2034 Crawler +- F5 BIG-IP Crawler +- Generic SQL Commands in Request +- Generic Sensitive File Access Attempt (.183 only) +- Generic Path Traversal Attempt (.183 only) +- Generic Suspicious Linux Command in Request (.144, .183) + +### 2.3 Censys Reputation + +All three rated **"benign"** by Censys reputation model (v0.1.0) -- likely because they only expose SSH:22 and do not host malicious web content. + +### 2.4 CVE Exposure + +All run OpenSSH 9.6p1, exposing them to: + +- CVE-2024-6387 (regreSSHion) -- CVSS 8.1, EPSS 0.658 (98.5th percentile) +- CVE-2025-26465 -- CVSS 6.8, EPSS 0.617 (98.4th percentile) +- CVE-2025-26466 -- CVSS 5.9, EPSS 0.624 (98.4th percentile) +- CVE-2025-32728 -- CVSS 4.3 +- CVE-2026-35385-35388, 35414 -- various recent CVEs + +--- + +## 3. Provider Profile + +### 3.1 Registration Details + +| Field | Value | +|---|---| +| ASN | 215540 | +| Legal Name | GLOBAL CONNECTIVITY SOLUTIONS LLP | +| Also Known As | GLOBAL INTERNET SOLUTIONS LLC | +| RIPE Handle | ORG-GCSL7-RIPE | +| RIPE Admin | Evgenii M. (admin@gir.network) | +| Abuse Contacts | abuse@globconnex.com, abuse@gir.network | +| UK Address | Suite 310, 21 Hill Street, Haverfordwest, Pembrokeshire, SA61 1QQ | +| Russian Address | Vn.Ter.G. Gagarinsky Municipal District, Mayachnaya St., 13. | +| WHOIS Created | Various blocks 2021-2025 | + +### 3.2 IP Blocks (23 total) + +| Prefix | Location | WHOIS Created | +|---|---|---| +| 45.89.60.0/24 | Tirana, AL | -- | +| 62.60.232.0/24 | Hong Kong, HK | -- | +| 77.83.246.0/24 | Warsaw, PL | -- | +| 78.153.131.0/24 | Siauliai, LT | -- | +| 78.153.155.0/24 | Atlanta, US | -- | +| 81.17.159.0/24 | Copenhagen, DK | -- | +| 81.177.215.0/24 | Istanbul, TR | -- | +| 85.234.100.0/24 | Frankfurt, DE | -- | +| 87.120.219.0/24 | London, GB | -- | +| 87.120.222.0/24 | Zurich, CH | -- | +| 87.121.47.0/24 | Tsovasar, AM | 2025-07-03 | +| 89.185.80.0/24 | Phoenix, US | 2024-06-28 | +| 89.185.81.0/24 | Sandefjord, NO | 2024-06-28 | +| 92.118.112.0/24 | Atlanta, US | 2021-12-24 | +| 109.172.55.0/24 | Paris, FR | 2025-04-23 | +| 141.98.234.0/24 | Hong Kong, HK | -- | +| 145.249.115.0/24 | Amsterdam, NL | -- | +| 147.45.50.0/24 | Kerkrade, NL | 2024-02-20 | +| 147.45.60.0/24 | Atlanta, US | 2024-02-22 | +| 147.45.86.0/24 | -- | -- | +| 147.45.116.0/24 | Sao Paulo, BR | -- | +| 147.45.204.0/24 | Kerkrade, NL | -- | +| 147.45.217.0/24 | Siauliai, LT | -- | +| 153.80.242.0/24 | Frankfurt, DE | -- | +| 170.168.136.0/22 | -- | -- | +| 178.17.53.0/24 | Helsinki, FI | 2025-08-07 | +| 178.17.58.0/24 | Frankfurt, DE | -- | +| 178.130.46.0/24 | Kerkrade, NL | 2025-04-23 | +| 178.130.47.0/24 | Phoenix, US | -- | +| 185.39.204.0/24 | Istanbul, TR | -- | +| 185.75.132.0/24 | -- | -- | +| 185.100.159.0/24 | Frankfurt, DE | -- | +| 185.161.251.0/24 | Frankfurt, DE | -- | +| 185.214.74.0/24 | Kerkrade, NL | 2021-11-24 | +| 188.130.196.0/22 | -- | -- | +| 193.39.208.0/24 | Kerkrade, NL | -- | +| 193.233.74.0/24 | Frankfurt, DE | -- | +| 2a05:541:121::/48 | IPv6 | -- | + +--- + +## 4. Signature-Based Companion Analysis + +### 4.1 Signature Set from Target IPs + +| Signature | Value | Coverage | +|---|---|---| +| ASN | 215540 | 1,000+ hosts | +| SSH Build | OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 | 387 hosts | +| HASSH | e42184b06d45385a906f0803d04c83da | 387 hosts | +| PTR | 157279.ip-ptr.tech | 4 hosts | +| PTR Domain | *.ip-ptr.tech | ~168 hosts | +| JA4t Scan | 65160_2-4-8-1-3_1460_7_1-2-4-8-16 | All 3 originals | +| GreyNoise Tags | Login Scanner, PAN-OS, F5, SQLi | 3 originals + 1 companion | + +### 4.2 Tier 1: Exact Signature Twins (4 hosts) + +These share PTR `157279.ip-ptr.tech`, identical SSH build, identical HASSH: + +| IP | Block | Location | GreyNoise | +|---|---|---|---| +| 92.118.112.230 | 92.118.112.0/24 | Atlanta, US | Suspicious | +| 89.185.80.144 | 89.185.80.0/24 | Phoenix, US | Suspicious | +| 89.185.80.183 | 89.185.80.0/24 | Phoenix, US | Suspicious | +| **147.45.60.25** | 147.45.60.0/24 | Atlanta, US | Suspicious (same tags) + domain `zubat.org` | + +### 4.3 Tier 2: Same /24 + Same Build + +**92.118.112.0/24** -- 103 hosts with matching SSH build +**89.185.80.0/24** -- 97 hosts with matching SSH build + +Complete listings in `companions-tier2.md`. + +### 4.4 Tier 3: Same Build Across Entire ASN + +**387 hosts total** with HASSH `e42184b06d45385a906f0803d04c83da` by country: + +| Country | Hosts | Key Blocks | +|---|---|---| +| Germany | 145 | 185.100.159.0/24, 193.233.74.0/24, 178.17.58.0/24, 153.80.242.0/24 | +| United States | 58 | 78.153.155.0/24, 92.118.112.0/24, 178.130.47.0/24 | +| Lithuania | 58 | 147.45.217.0/24, 78.153.131.0/24 | +| Poland | 52 | 77.83.246.0/24 | +| Armenia | 43 | 87.121.47.0/24 | +| Turkey | 42 | 185.39.204.0/24, 81.177.215.0/24 | +| Netherlands | 28 | 193.39.208.0/24, 147.45.204.0/24 | +| Denmark | 26 | 81.17.159.0/24 | +| United Kingdom | 25 | 87.120.219.0/24 | +| Hong Kong | 17 | 62.60.232.0/24 | +| Albania | 4 | 45.89.60.0/24 | +| Brazil | 1 | 147.45.116.0/24 | +| Switzerland | 1 | 87.120.222.0/24 | + +--- + +## 5. Special-Purpose Infrastructure in ASN 215540 + +### 5.1 Proxy/Tunneling Services + +| IP | Block | Service | Details | +|---|---|---|---| +| 178.130.46.2 | 178.130.46.0/24 | SOCKS5 :1080 | Username/password auth. Domains: games-oracle.ru, 7neth.solonettochka.ru | +| 185.100.159.193 | 185.100.159.0/24 | Tunneling | PTR: de05.tunnely.ru | + +### 5.2 Credential Harvesting / Admin Panels + +| IP | Block | Service | Notes | +|---|---|---|---| +| 147.45.50.108 | 147.45.50.0/24 | Gunicorn :8080 | **GreyNoise: MALICIOUS**. Admin Login page (username + password + TOTP). Tags: SSH bruteforcer, path traversal, ThinkPHP RCE, PHP CVE-2024-4577, Docker scanner, Telnet, IoT | +| 147.45.50.147 | 147.45.50.0/24 | -- | Active in honeypot (48 events) | +| 147.45.50.171 | 147.45.50.0/24 | -- | Active in honeypot (47 events) | + +### 5.3 Web Servers + +| IP | Block | Service | Details | +|---|---|---|---| +| 92.118.112.178 | 92.118.112.0/24 | Caddy HTTP | Ports 1337, 9091, 10095. JSON error responses | +| 185.214.74.251 | 185.214.74.0/24 | nginx :80,443 | Domain: dnau-getfkdwhocares123.xyz | +| 147.45.60.22 | 147.45.60.0/24 | HTTPS :2096 | Let's Encrypt cert, 404 | +| 87.121.47.94 | 87.121.47.0/24 | HTTPS :443, :2096, :55421 | Sectigo cert (github.com CN -- likely spoofed), Let's Encrypt (igorarmsrv.duckdns.org) | + +### 5.4 Notable PTR Artifacts + +| PTR | Block | Implication | +|---|---|---| +| fbi.com | 77.83.246.0/24, 89.185.80.0/24, 147.45.49.0/24 | Fake PTR (trolling/masquerading) | +| ya.ru | 77.83.246.0/24 | Masquerading as Yandex | +| *.4server.su | Various | Russian hosting infrastructure domains | +| *.my-server.app | Various | Infra domain (usa1-pho-monitor, lt1-cloned, etc.) | +| *.servera.info | Various | Infra domain | +| *.itg.top | 92.118.112.0/24 | us.itg.top | +| *.tunnely.ru | 185.100.159.0/24 | Tunneling service | +| *.4host.su | 92.118.112.0/24 | Infra domain | + +--- + +## 6. Honeylabs Telemetry + +### 6.1 ASN 215540 in Honeypot (30 days: May 9 - Jun 9) + +| Metric | Value | +|---|---| +| Total Events | 724 | +| Unique IPs | 21 | +| First Seen | 2026-05-09 | +| Last Seen | 2026-06-09 | +| Source Countries | FI, NL, NO, FR, US | + +### 6.2 Top Attacking IPs from ASN 215540 (30 days) + +| IP | Events | Block | Location | Service | +|---|---|---|---|---| +| 178.17.53.215 | 278 | 178.17.53.0/24 | Helsinki, FI | SSH (different build) | +| 89.185.81.112 | 95 | 89.185.81.0/24 | Sandefjord, NO | No visible services | +| 5.253.59.171 | 48 | -- | -- | -- | +| 147.45.50.147 | 48 | 147.45.50.0/24 | Kerkrade, NL | Same block as admin panel | +| 147.45.50.171 | 47 | 147.45.50.0/24 | Kerkrade, NL | Same block as admin panel | +| 147.45.50.108 | 47 | 147.45.50.0/24 | Kerkrade, NL | **GreyNoise MALICIOUS** admin panel | +| 194.87.216.198 | 46 | 194.87.216.0/24 | Kerkrade, NL | No visible services | +| 109.172.55.64 | 46 | 109.172.55.0/24 | Paris, FR | SSH (same build as targets) | +| 78.153.155.71 | 18 | 78.153.155.0/24 | Atlanta, US | Same block as target build hosts | +| 178.130.47.195 | 17 | 178.130.47.0/24 | Phoenix, US | Same block as target build hosts | + +### 6.3 Top Targeted Ports (ASN 215540, 30 days) + +| Port | Service | Notes | +|---|---|---| +| 80 | HTTP | Most targeted | +| 443 | HTTPS | | +| 22 | SSH | Self-referential (SSH farm scanning SSH) | +| 2087 | cPanel | | +| 2375 | Docker | Unsecured Docker API scanning | +| 2086 | cPanel | | +| 5002 | -- | | +| 2222 | SSH alt | | +| 2443 | HTTPS alt | | +| 18789 | -- | | + +### 6.4 Broader Honeypot Context (90 days: Mar 11 - Jun 9) + +- ASN 215540 had **1,973 events** from **58 unique IPs** (90-day window) +- Peak activity source countries: NL > FI > US > RU > NO +- Top ports hit: 443, 80, 1723 (PPTP), 2087, 22, 2375, 2222, 2086, 8443, 25565 (Minecraft) + +--- + +## 7. Infrastructure Domains & Ownership Chain + +### 7.1 Domain Infrastructure + +| Domain | IP | Use | +|---|---|---| +| zubat.org | 147.45.60.25 | Companion to target IPs | +| dnau-getfkdwhocares123.xyz | 185.214.74.251 | Trolling domain | +| games-oracle.ru | 178.130.46.2 | SOCKS proxy domain | +| 7neth.solonettochka.ru | 178.130.46.2 | SOCKS proxy domain | +| igorarmsrv.duckdns.org | 87.121.47.94 | Let's Encrypt cert | +| nl1fast.netgo.su | 185.214.74.251 | -- | +| various .4server.su | Multiple | Russian hosting infra | +| various .my-server.app | Multiple | Infra monitoring | +| various .servera.info | Multiple | Infra | +| tunnely.ru | 185.100.159.193 | Tunneling service | + +### 7.2 PTR Infrastructure + +The PTR pattern `*.ip-ptr.tech` is the dominant reverse DNS infrastructure across the ASN, used by ~168 of the 387 same-build hosts. Individual numeric IDs (e.g. `157279`, `148100`, `118799`) appear to be customer/session identifiers. + +--- + +## 8. Conclusions + +1. **ASN 215540 is a large-scale proxy/VPN exit node service**, not a traditional bulletproof hoster. The SSH server farm (387 hosts with identical software, unique host keys) is consistent with a proxy rotation service where each customer gets an ephemeral SSH listener. + +2. **The three target IPs are nodes in this proxy farm**, indistinguishable from 384+ other hosts running identical software. The shared PTR `157279.ip-ptr.tech` across the 3 originals plus `147.45.60.25` suggests these 4 are a specific deployment batch or customer allocation. + +3. **The infrastructure is globally distributed** across 13+ countries with concentration in Germany (Frankfurt), US (Atlanta/Phoenix), Poland (Warsaw), and Lithuania (Siauliai). + +4. **Notable criminal infrastructure in the same ASN** includes: a credential harvesting panel with TOTP support (147.45.50.108), a SOCKS5 proxy (178.130.46.2), and multiple hosts flagged by GreyNoise for login scanning, vulnerability exploitation, and path traversal. + +5. **The provider has a Russian nexus** despite UK registration: Russian physical address, Russian RIPE admin (Evgenii M.), Russian infrastructure domains (.4server.su, .4host.su, .tunnely.ru), and Russian-language PTR entries. + +--- + +## 9. File Index + +| File | Contents | +|---|---| +| README.md | This report | +| companions-tier1.md | 4 exact signature twins (same PTR + same build) | +| companions-tier2-same24.md | Hosts in same /24 blocks with same build | +| companions-tier2-same24-92.118.112.md | Full listing for 92.118.112.0/24 same-build hosts | +| companions-tier2-same24-89.185.80.md | Full listing for 89.185.80.0/24 same-build hosts | +| companions-tier3-by-block.md | All 387 hosts by block | +| honeylabs-data.md | Raw honeylabs telemetry extracts | +| censys-cli-queries.md | Censys CLI queries used | -- cgit v1.2.3