1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
|
# ASN 215540 (GCS-AS) -- Comprehensive Intelligence Report
**Date**: 2026-06-09
**Data Sources**: Censys (host search, host view), Honeylabs (IOC, ASN enrichment, top attackers, attack timeline)
**Scope**: Three target IPs (92.118.112.230, 89.185.80.144, 89.185.80.183) mapped to their full ASN infrastructure
---
## 1. Executive Summary
The three target IPs belong to ASN 215540, operated by **GLOBAL CONNECTIVITY SOLUTIONS LLP** (GCS-AS), a UK-registered shell company with Russian management (RIPE admin Evgenii M., Russian address on file). This ASN is a **large-scale proxy/VPN exit node hosting operation** with 1,000+ IPs across 22+ IP blocks in 13+ countries.
Key characteristics: massive SSH server farm (387 hosts sharing the exact build/fingerprint of the targets), geographic diversity (US, DE, PL, LT, AM, TR, NL, DK, GB, HK, AL, CH, BR), mixed infrastructure (SOCKS5 proxy, credential harvesting panel, Caddy HTTP servers, nginx), and consistent scanning/probing behavior flagged by GreyNoise.
---
## 2. Target IP Analysis
### 2.1 Target IPs
| IP | Block | Location | SSH Build | HASSH | PTR | GreyNoise |
|---|---|---|---|---|---|---|
| 92.118.112.230 | 92.118.112.0/24 | Atlanta, US | 9.6p1 Ubuntu-3ubuntu13.16 | e42184b0... | 157279.ip-ptr.tech | Suspicious |
| 89.185.80.144 | 89.185.80.0/24 | Phoenix, US | 9.6p1 Ubuntu-3ubuntu13.16 | e42184b0... | 157279.ip-ptr.tech | Suspicious |
| 89.185.80.183 | 89.185.80.0/24 | Phoenix, US | 9.6p1 Ubuntu-3ubuntu13.16 | e42184b0... | 157279.ip-ptr.tech | Suspicious |
### 2.2 GreyNoise Classification (All Three)
All classified as **suspicious** with identical tags:
- Web Crawler, TLS/SSL Crawler
- Carries HTTP Referer
- Generic Login Attempt
- Palo Alto Networks PAN-OS CVE-2020-2034 Crawler
- F5 BIG-IP Crawler
- Generic SQL Commands in Request
- Generic Sensitive File Access Attempt (.183 only)
- Generic Path Traversal Attempt (.183 only)
- Generic Suspicious Linux Command in Request (.144, .183)
### 2.3 Censys Reputation
All three rated **"benign"** by Censys reputation model (v0.1.0) -- likely because they only expose SSH:22 and do not host malicious web content.
### 2.4 CVE Exposure
All run OpenSSH 9.6p1, exposing them to:
- CVE-2024-6387 (regreSSHion) -- CVSS 8.1, EPSS 0.658 (98.5th percentile)
- CVE-2025-26465 -- CVSS 6.8, EPSS 0.617 (98.4th percentile)
- CVE-2025-26466 -- CVSS 5.9, EPSS 0.624 (98.4th percentile)
- CVE-2025-32728 -- CVSS 4.3
- CVE-2026-35385-35388, 35414 -- various recent CVEs
---
## 3. Provider Profile
### 3.1 Registration Details
| Field | Value |
|---|---|
| ASN | 215540 |
| Legal Name | GLOBAL CONNECTIVITY SOLUTIONS LLP |
| Also Known As | GLOBAL INTERNET SOLUTIONS LLC |
| RIPE Handle | ORG-GCSL7-RIPE |
| RIPE Admin | Evgenii M. (admin@gir.network) |
| Abuse Contacts | abuse@globconnex.com, abuse@gir.network |
| UK Address | Suite 310, 21 Hill Street, Haverfordwest, Pembrokeshire, SA61 1QQ |
| Russian Address | Vn.Ter.G. Gagarinsky Municipal District, Mayachnaya St., 13. |
| WHOIS Created | Various blocks 2021-2025 |
### 3.2 IP Blocks (23 total)
| Prefix | Location | WHOIS Created |
|---|---|---|
| 45.89.60.0/24 | Tirana, AL | -- |
| 62.60.232.0/24 | Hong Kong, HK | -- |
| 77.83.246.0/24 | Warsaw, PL | -- |
| 78.153.131.0/24 | Siauliai, LT | -- |
| 78.153.155.0/24 | Atlanta, US | -- |
| 81.17.159.0/24 | Copenhagen, DK | -- |
| 81.177.215.0/24 | Istanbul, TR | -- |
| 85.234.100.0/24 | Frankfurt, DE | -- |
| 87.120.219.0/24 | London, GB | -- |
| 87.120.222.0/24 | Zurich, CH | -- |
| 87.121.47.0/24 | Tsovasar, AM | 2025-07-03 |
| 89.185.80.0/24 | Phoenix, US | 2024-06-28 |
| 89.185.81.0/24 | Sandefjord, NO | 2024-06-28 |
| 92.118.112.0/24 | Atlanta, US | 2021-12-24 |
| 109.172.55.0/24 | Paris, FR | 2025-04-23 |
| 141.98.234.0/24 | Hong Kong, HK | -- |
| 145.249.115.0/24 | Amsterdam, NL | -- |
| 147.45.50.0/24 | Kerkrade, NL | 2024-02-20 |
| 147.45.60.0/24 | Atlanta, US | 2024-02-22 |
| 147.45.86.0/24 | -- | -- |
| 147.45.116.0/24 | Sao Paulo, BR | -- |
| 147.45.204.0/24 | Kerkrade, NL | -- |
| 147.45.217.0/24 | Siauliai, LT | -- |
| 153.80.242.0/24 | Frankfurt, DE | -- |
| 170.168.136.0/22 | -- | -- |
| 178.17.53.0/24 | Helsinki, FI | 2025-08-07 |
| 178.17.58.0/24 | Frankfurt, DE | -- |
| 178.130.46.0/24 | Kerkrade, NL | 2025-04-23 |
| 178.130.47.0/24 | Phoenix, US | -- |
| 185.39.204.0/24 | Istanbul, TR | -- |
| 185.75.132.0/24 | -- | -- |
| 185.100.159.0/24 | Frankfurt, DE | -- |
| 185.161.251.0/24 | Frankfurt, DE | -- |
| 185.214.74.0/24 | Kerkrade, NL | 2021-11-24 |
| 188.130.196.0/22 | -- | -- |
| 193.39.208.0/24 | Kerkrade, NL | -- |
| 193.233.74.0/24 | Frankfurt, DE | -- |
| 2a05:541:121::/48 | IPv6 | -- |
---
## 4. Signature-Based Companion Analysis
### 4.1 Signature Set from Target IPs
| Signature | Value | Coverage |
|---|---|---|
| ASN | 215540 | 1,000+ hosts |
| SSH Build | OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 | 387 hosts |
| HASSH | e42184b06d45385a906f0803d04c83da | 387 hosts |
| PTR | 157279.ip-ptr.tech | 4 hosts |
| PTR Domain | *.ip-ptr.tech | ~168 hosts |
| JA4t Scan | 65160_2-4-8-1-3_1460_7_1-2-4-8-16 | All 3 originals |
| GreyNoise Tags | Login Scanner, PAN-OS, F5, SQLi | 3 originals + 1 companion |
### 4.2 Tier 1: Exact Signature Twins (4 hosts)
These share PTR `157279.ip-ptr.tech`, identical SSH build, identical HASSH:
| IP | Block | Location | GreyNoise |
|---|---|---|---|
| 92.118.112.230 | 92.118.112.0/24 | Atlanta, US | Suspicious |
| 89.185.80.144 | 89.185.80.0/24 | Phoenix, US | Suspicious |
| 89.185.80.183 | 89.185.80.0/24 | Phoenix, US | Suspicious |
| **147.45.60.25** | 147.45.60.0/24 | Atlanta, US | Suspicious (same tags) + domain `zubat.org` |
### 4.3 Tier 2: Same /24 + Same Build
**92.118.112.0/24** -- 103 hosts with matching SSH build
**89.185.80.0/24** -- 97 hosts with matching SSH build
Complete listings in `companions-tier2.md`.
### 4.4 Tier 3: Same Build Across Entire ASN
**387 hosts total** with HASSH `e42184b06d45385a906f0803d04c83da` by country:
| Country | Hosts | Key Blocks |
|---|---|---|
| Germany | 145 | 185.100.159.0/24, 193.233.74.0/24, 178.17.58.0/24, 153.80.242.0/24 |
| United States | 58 | 78.153.155.0/24, 92.118.112.0/24, 178.130.47.0/24 |
| Lithuania | 58 | 147.45.217.0/24, 78.153.131.0/24 |
| Poland | 52 | 77.83.246.0/24 |
| Armenia | 43 | 87.121.47.0/24 |
| Turkey | 42 | 185.39.204.0/24, 81.177.215.0/24 |
| Netherlands | 28 | 193.39.208.0/24, 147.45.204.0/24 |
| Denmark | 26 | 81.17.159.0/24 |
| United Kingdom | 25 | 87.120.219.0/24 |
| Hong Kong | 17 | 62.60.232.0/24 |
| Albania | 4 | 45.89.60.0/24 |
| Brazil | 1 | 147.45.116.0/24 |
| Switzerland | 1 | 87.120.222.0/24 |
---
## 5. Special-Purpose Infrastructure in ASN 215540
### 5.1 Proxy/Tunneling Services
| IP | Block | Service | Details |
|---|---|---|---|
| 178.130.46.2 | 178.130.46.0/24 | SOCKS5 :1080 | Username/password auth. Domains: games-oracle.ru, 7neth.solonettochka.ru |
| 185.100.159.193 | 185.100.159.0/24 | Tunneling | PTR: de05.tunnely.ru |
### 5.2 Credential Harvesting / Admin Panels
| IP | Block | Service | Notes |
|---|---|---|---|
| 147.45.50.108 | 147.45.50.0/24 | Gunicorn :8080 | **GreyNoise: MALICIOUS**. Admin Login page (username + password + TOTP). Tags: SSH bruteforcer, path traversal, ThinkPHP RCE, PHP CVE-2024-4577, Docker scanner, Telnet, IoT |
| 147.45.50.147 | 147.45.50.0/24 | -- | Active in honeypot (48 events) |
| 147.45.50.171 | 147.45.50.0/24 | -- | Active in honeypot (47 events) |
### 5.3 Web Servers
| IP | Block | Service | Details |
|---|---|---|---|
| 92.118.112.178 | 92.118.112.0/24 | Caddy HTTP | Ports 1337, 9091, 10095. JSON error responses |
| 185.214.74.251 | 185.214.74.0/24 | nginx :80,443 | Domain: dnau-getfkdwhocares123.xyz |
| 147.45.60.22 | 147.45.60.0/24 | HTTPS :2096 | Let's Encrypt cert, 404 |
| 87.121.47.94 | 87.121.47.0/24 | HTTPS :443, :2096, :55421 | Sectigo cert (github.com CN -- likely spoofed), Let's Encrypt (igorarmsrv.duckdns.org) |
### 5.4 Notable PTR Artifacts
| PTR | Block | Implication |
|---|---|---|
| fbi.com | 77.83.246.0/24, 89.185.80.0/24, 147.45.49.0/24 | Fake PTR (trolling/masquerading) |
| ya.ru | 77.83.246.0/24 | Masquerading as Yandex |
| *.4server.su | Various | Russian hosting infrastructure domains |
| *.my-server.app | Various | Infra domain (usa1-pho-monitor, lt1-cloned, etc.) |
| *.servera.info | Various | Infra domain |
| *.itg.top | 92.118.112.0/24 | us.itg.top |
| *.tunnely.ru | 185.100.159.0/24 | Tunneling service |
| *.4host.su | 92.118.112.0/24 | Infra domain |
---
## 6. Honeylabs Telemetry
### 6.1 ASN 215540 in Honeypot (30 days: May 9 - Jun 9)
| Metric | Value |
|---|---|
| Total Events | 724 |
| Unique IPs | 21 |
| First Seen | 2026-05-09 |
| Last Seen | 2026-06-09 |
| Source Countries | FI, NL, NO, FR, US |
### 6.2 Top Attacking IPs from ASN 215540 (30 days)
| IP | Events | Block | Location | Service |
|---|---|---|---|---|
| 178.17.53.215 | 278 | 178.17.53.0/24 | Helsinki, FI | SSH (different build) |
| 89.185.81.112 | 95 | 89.185.81.0/24 | Sandefjord, NO | No visible services |
| 5.253.59.171 | 48 | -- | -- | -- |
| 147.45.50.147 | 48 | 147.45.50.0/24 | Kerkrade, NL | Same block as admin panel |
| 147.45.50.171 | 47 | 147.45.50.0/24 | Kerkrade, NL | Same block as admin panel |
| 147.45.50.108 | 47 | 147.45.50.0/24 | Kerkrade, NL | **GreyNoise MALICIOUS** admin panel |
| 194.87.216.198 | 46 | 194.87.216.0/24 | Kerkrade, NL | No visible services |
| 109.172.55.64 | 46 | 109.172.55.0/24 | Paris, FR | SSH (same build as targets) |
| 78.153.155.71 | 18 | 78.153.155.0/24 | Atlanta, US | Same block as target build hosts |
| 178.130.47.195 | 17 | 178.130.47.0/24 | Phoenix, US | Same block as target build hosts |
### 6.3 Top Targeted Ports (ASN 215540, 30 days)
| Port | Service | Notes |
|---|---|---|
| 80 | HTTP | Most targeted |
| 443 | HTTPS | |
| 22 | SSH | Self-referential (SSH farm scanning SSH) |
| 2087 | cPanel | |
| 2375 | Docker | Unsecured Docker API scanning |
| 2086 | cPanel | |
| 5002 | -- | |
| 2222 | SSH alt | |
| 2443 | HTTPS alt | |
| 18789 | -- | |
### 6.4 Broader Honeypot Context (90 days: Mar 11 - Jun 9)
- ASN 215540 had **1,973 events** from **58 unique IPs** (90-day window)
- Peak activity source countries: NL > FI > US > RU > NO
- Top ports hit: 443, 80, 1723 (PPTP), 2087, 22, 2375, 2222, 2086, 8443, 25565 (Minecraft)
---
## 7. Infrastructure Domains & Ownership Chain
### 7.1 Domain Infrastructure
| Domain | IP | Use |
|---|---|---|
| zubat.org | 147.45.60.25 | Companion to target IPs |
| dnau-getfkdwhocares123.xyz | 185.214.74.251 | Trolling domain |
| games-oracle.ru | 178.130.46.2 | SOCKS proxy domain |
| 7neth.solonettochka.ru | 178.130.46.2 | SOCKS proxy domain |
| igorarmsrv.duckdns.org | 87.121.47.94 | Let's Encrypt cert |
| nl1fast.netgo.su | 185.214.74.251 | -- |
| various .4server.su | Multiple | Russian hosting infra |
| various .my-server.app | Multiple | Infra monitoring |
| various .servera.info | Multiple | Infra |
| tunnely.ru | 185.100.159.193 | Tunneling service |
### 7.2 PTR Infrastructure
The PTR pattern `*.ip-ptr.tech` is the dominant reverse DNS infrastructure across the ASN, used by ~168 of the 387 same-build hosts. Individual numeric IDs (e.g. `157279`, `148100`, `118799`) appear to be customer/session identifiers.
---
## 8. Conclusions
1. **ASN 215540 is a large-scale proxy/VPN exit node service**, not a traditional bulletproof hoster. The SSH server farm (387 hosts with identical software, unique host keys) is consistent with a proxy rotation service where each customer gets an ephemeral SSH listener.
2. **The three target IPs are nodes in this proxy farm**, indistinguishable from 384+ other hosts running identical software. The shared PTR `157279.ip-ptr.tech` across the 3 originals plus `147.45.60.25` suggests these 4 are a specific deployment batch or customer allocation.
3. **The infrastructure is globally distributed** across 13+ countries with concentration in Germany (Frankfurt), US (Atlanta/Phoenix), Poland (Warsaw), and Lithuania (Siauliai).
4. **Notable criminal infrastructure in the same ASN** includes: a credential harvesting panel with TOTP support (147.45.50.108), a SOCKS5 proxy (178.130.46.2), and multiple hosts flagged by GreyNoise for login scanning, vulnerability exploitation, and path traversal.
5. **The provider has a Russian nexus** despite UK registration: Russian physical address, Russian RIPE admin (Evgenii M.), Russian infrastructure domains (.4server.su, .4host.su, .tunnely.ru), and Russian-language PTR entries.
---
## 9. File Index
| File | Contents |
|---|---|
| README.md | This report |
| companions-tier1.md | 4 exact signature twins (same PTR + same build) |
| companions-tier2-same24.md | Hosts in same /24 blocks with same build |
| companions-tier2-same24-92.118.112.md | Full listing for 92.118.112.0/24 same-build hosts |
| companions-tier2-same24-89.185.80.md | Full listing for 89.185.80.0/24 same-build hosts |
| companions-tier3-by-block.md | All 387 hosts by block |
| honeylabs-data.md | Raw honeylabs telemetry extracts |
| censys-cli-queries.md | Censys CLI queries used |
|