# Weekly BP Report -- 2026-07-13 # Notable HTTP URL paths observed # Query range: 2026-07-05 through 2026-07-11 # .env file scanning (credentials exfiltration) /.env # Source: 185.228.72.109 (AS400992 ZhouyiSat) via HTTP GET # JA4H: ge11nn0500_2d30dc89d981 # Intent: Retrieve environment variable files containing database credentials, API keys # Exchange /ews/ reconnaissance /ews/ # Source: 185.231.33.46 (AS211720 Datashield) via HTTP HEAD # JA4H: he11nn0500_2d30dc89d981 # Intent: Enumerate Exchange Web Services endpoints for vulnerability exploitation # Tor exit node transparentpix.gif probing /transparentpix.gif # Source: 185.100.87.136 (AS200651 FlokiNET) via HTTP GET on port 444 # JA4H: ge11nn0400_88d30a62b7ad # Intent: Tor exit node connectivity testing or pixel tracking