From 89a294a0e93277e5f27fc96710f638a5ac85ab35 Mon Sep 17 00:00:00 2001 From: hrbrmstr Date: Mon, 3 Aug 2026 06:52:30 -0400 Subject: chore: weekly BPH update --- kevlar/2026-08-02/iocs/README.md | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 kevlar/2026-08-02/iocs/README.md (limited to 'kevlar/2026-08-02/iocs/README.md') diff --git a/kevlar/2026-08-02/iocs/README.md b/kevlar/2026-08-02/iocs/README.md new file mode 100644 index 0000000..7bef1c9 --- /dev/null +++ b/kevlar/2026-08-02/iocs/README.md @@ -0,0 +1,25 @@ +# Weekly BP Report -- 2026-08-02 + +Generated: 2026-08-03T03:43:00Z +ASNs covered: 26 +Sponge sessions found: 10,000+ across 21 active ASNs (capped per query) +Honeylabs events found: 8,400 (AS51396 PFCLOUD only; 25 ASNs: zero) +Censys IPs profiled: 6 ASNs (190K+ hosts, all BULLETPROOF-labeled) +Anomalies flagged: 1 (universal BULLETPROOF classification across all profiled ASNs) + +## Key Findings + +- Only 1 of 26 ASNs (PFCLOUD) generated honeypot events; the other 25 show + targeted scanning against real infrastructure +- All Censys-profiled ASNs are universally classified as BULLETPROOF +- KAOPU-HK (AS138915): 818K NTP/SSDP amplification scanning sessions +- PFCLOUD (AS51396): active proxy-checking (SOCKS5 + HTTP CONNECT) against honeypots +- HOSTKEY (AS57043) and AEZA (AS210644): largest infrastructure (100K+ and 69K hosts) +- PLI-AS (AS51852): massive Telnet brute-forcing (34K sessions) +- PROTON66 (AS198953): SSH/MSSQL/RDP scanning (102K sessions from single IP) + +## Data Sources + +- Sponge (Arkime): network sensor sessions across full deployment +- Honeylabs: global honeypot network, 7-day window (2026-07-27 to 2026-08-02) +- Censys: internet-wide host profiling -- cgit v1.2.3