# Weekly BP Report -- 2026-08-02 Generated: 2026-08-03T04:00:00Z ASNs covered: 26 Sponge sessions found: 10,000+ across 21 active ASNs (capped per query) Honeylabs events found: 8,400+ across 7 ASNs (PFCLOUD, HOSTKEY, ROUTERHOSTING, PLI-AS, PROTON66, FLOKINET, KPRONET, AUROLOGIC) Censys IPs profiled: 6 ASN-level + 3 per-IP enrichments (190K+ hosts, all BULLETPROOF-labeled) Anomalies flagged: 1 (FLOKINET operates Tor exit relay with concurrent brute-force activity) ## Key Findings - 7 of 26 ASNs generated Honeylabs events (not 1 as initially reported) - All Censys-profiled hosts are universally classified as BULLETPROOF - KPRONET: .git/.env exfiltration campaign with 20+ spoofed user agents - PLI-AS: Multi-modal attack (DCE/RPC, RDP brute, tRPC, WordPress scanning) - FLOKINET: Tor exit relay (185.100.87.136) with SSH/Telnet brute-force - HOSTKEY: RTSP camera credential stuffing against Hikvision cameras - PROTON66: MSSQL-TDS brute-force on non-standard ports - PFCLOUD: Consistent proxy checking with port-paired infrastructure - KAOPU-HK: 818K NTP/SSDP amplification scanning sessions (zero Honeylabs) ## Data Sources - Sponge (Arkime): network sensor sessions across full deployment - Honeylabs: global honeypot network, 7-day window (2026-07-27 to 2026-08-02) - Censys: internet-wide host profiling + per-IP enrichment