From 71ff7fc1ef9e742b78d3b04a23b487fcf478ff50 Mon Sep 17 00:00:00 2001 From: hrbrmstr Date: Mon, 3 Aug 2026 07:11:48 -0400 Subject: chore: weekly BPH update --- kevlar/2026-08-02/iocs/README.md | 27 ++++++++++++++------------- 1 file changed, 14 insertions(+), 13 deletions(-) (limited to 'kevlar/2026-08-02/iocs/README.md') diff --git a/kevlar/2026-08-02/iocs/README.md b/kevlar/2026-08-02/iocs/README.md index 7bef1c9..d255f51 100644 --- a/kevlar/2026-08-02/iocs/README.md +++ b/kevlar/2026-08-02/iocs/README.md @@ -1,25 +1,26 @@ # Weekly BP Report -- 2026-08-02 -Generated: 2026-08-03T03:43:00Z +Generated: 2026-08-03T04:00:00Z ASNs covered: 26 Sponge sessions found: 10,000+ across 21 active ASNs (capped per query) -Honeylabs events found: 8,400 (AS51396 PFCLOUD only; 25 ASNs: zero) -Censys IPs profiled: 6 ASNs (190K+ hosts, all BULLETPROOF-labeled) -Anomalies flagged: 1 (universal BULLETPROOF classification across all profiled ASNs) +Honeylabs events found: 8,400+ across 7 ASNs (PFCLOUD, HOSTKEY, ROUTERHOSTING, PLI-AS, PROTON66, FLOKINET, KPRONET, AUROLOGIC) +Censys IPs profiled: 6 ASN-level + 3 per-IP enrichments (190K+ hosts, all BULLETPROOF-labeled) +Anomalies flagged: 1 (FLOKINET operates Tor exit relay with concurrent brute-force activity) ## Key Findings -- Only 1 of 26 ASNs (PFCLOUD) generated honeypot events; the other 25 show - targeted scanning against real infrastructure -- All Censys-profiled ASNs are universally classified as BULLETPROOF -- KAOPU-HK (AS138915): 818K NTP/SSDP amplification scanning sessions -- PFCLOUD (AS51396): active proxy-checking (SOCKS5 + HTTP CONNECT) against honeypots -- HOSTKEY (AS57043) and AEZA (AS210644): largest infrastructure (100K+ and 69K hosts) -- PLI-AS (AS51852): massive Telnet brute-forcing (34K sessions) -- PROTON66 (AS198953): SSH/MSSQL/RDP scanning (102K sessions from single IP) +- 7 of 26 ASNs generated Honeylabs events (not 1 as initially reported) +- All Censys-profiled hosts are universally classified as BULLETPROOF +- KPRONET: .git/.env exfiltration campaign with 20+ spoofed user agents +- PLI-AS: Multi-modal attack (DCE/RPC, RDP brute, tRPC, WordPress scanning) +- FLOKINET: Tor exit relay (185.100.87.136) with SSH/Telnet brute-force +- HOSTKEY: RTSP camera credential stuffing against Hikvision cameras +- PROTON66: MSSQL-TDS brute-force on non-standard ports +- PFCLOUD: Consistent proxy checking with port-paired infrastructure +- KAOPU-HK: 818K NTP/SSDP amplification scanning sessions (zero Honeylabs) ## Data Sources - Sponge (Arkime): network sensor sessions across full deployment - Honeylabs: global honeypot network, 7-day window (2026-07-27 to 2026-08-02) -- Censys: internet-wide host profiling +- Censys: internet-wide host profiling + per-IP enrichment -- cgit v1.2.3