blob: 5ad0bd3a2a56e36f3a4908fcd6dac46094e70ad8 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
|
# Weekly BP Report -- 2026-07-13
Generated: 2026-07-13T12:00:00Z
ASNs covered: 26
Query range: 2026-07-05 through 2026-07-11
Sponge sessions found: ~21,000+ (15 active ASNs)
Honeylabs events found: ~16,000+ (12 active ASNs)
Censys IPs enriched: 10 (per-host enrichment via censys_get_host)
Anomalies flagged: 11 (2 critical, 4 high, 3 medium, 2 low)
## Directory Structure
- `sponge/` -- Arkime/Sponge session stats per ASN (77 files)
- `honeylabs/` -- Honeylabs top attackers and fingerprints (2 files)
- `censys/` -- Censys aggregations, IP enrichments, fleet correlation (3 files)
- `changes/` -- Change detection vs prior week (2 files)
- `iocs/` -- Structured IoC files: IPs, fingerprints, C2 paths
## Key Findings
- PFCLOUD (AS51396) remains dominant with 10K+ events and a new coordinated scan cluster (204.76.203.78/79/80)
- Prospero Ooo (AS200593) surged from 2 to 3890 events -- single IP scan bomb
- Proton66 (AS198953) expanded from RDP-only to multi-protocol bruteforcing (RDP+SSH+Telnet+FTP)
- Datashield Inc. (AS211720) new entrant performing Exchange /ews/ reconnaissance
- ZhouyiSat (AS400992) observed scanning for /.env files to steal credentials
- FlokiNET (AS200651) Tor exit node (185.100.87.136) actively scanning HTTP/SSH
- Active ASNs expanded from 9 to 15 (+67%) week over week
- 11 unique fingerprints collected (4 HASSH, 4 JA4/JA3, 3 JA4H) -- major improvement over prior week
## Web Access
https://git.sr.ht/~hrbrmstr/gists/tree/main/item/kevlar/2026-07-13/
|