1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
|
# Operations Log -- Weekly BP Report 2026-07-20
## 2026-07-20 10:36:00 -- Phase 0: Initialize
- ASNs loaded: 25 from bulletproof-asns.csv
- Gist directory: ~/Documents/gists/kevlar/2026-07-20/
- Query range: 2026-07-13 through 2026-07-20 (7-day window)
- Censys credits: 10,000 (sufficient for per-IP enrichment)
- Prior baseline: 2026-07-13
- Data range confirmed Sponge: 2026-07-13 through 2026-07-20 (active, ~6.9M sessions)
## 2026-07-20 10:38:00 -- Phase 1: Sponge (Arkime) Data Gathering
### Sub-phase 1a: Connectivity Check
- Timeline confirmed: data flowing 2026-07-13 through 2026-07-20 (8 daily buckets)
- Daily session counts: 423K, 1.03M, 925K, 723K, 1.07M, 978K, 1.33M, 437K (partial day)
### Sub-phase 1b: Per-ASN Session Stats
- ASNs queried: 25 (75 API calls completed)
- Active ASNs (sessions observed): AS57043(7), AS209847(998), AS210644(11), AS138915(10000+), AS14956(696), AS216139(1), AS51852(3401), AS400992(256), AS33993(7), AS51396(10000+), AS200651(63), AS30823(8), AS140666(2), AS198953(1522), AS200593(297), AS214940(604), AS211720(12) -- 17 active
- Inactive ASNs (0 sessions): AS213702, AS216246, AS214351, AS206728, AS216309, AS58854, AS202685, AS394711 -- 8 inactive
- Top by volume: AS138915 (KAOPU-HK) 10K sessions, AS51396 (PFCLOUD) 10K sessions capped, AS209847 (THE) 998 sessions all from a single IP on HTTPS ports
- Notable ports: 123/NTP (KAOPU-HK continues), 22/SSH (PFCLOUD #1), 25/SMTP (KPRONET), 3389/RDP (AS400992), 1433/MSSQL (Datashield and AS198953 emerging)
- Caching: 33 stat files to sponge/ directory + timeline-all-asns.ndjson (845 records)
- Errors: none
### Sub-phase 1c: Multi-ASN Timeline
- Arkime timeline split by ASN returned 845 hourly records spread over 8 days (7 days full + partial 20th)
- Cached to sponge/timeline-all-asns.ndjson
- Errors: none
### Sub-phase 1d: Honeylabs cross-purpose session search
We chose to use Honeylabs tools (separate from Sponge) to cross-react IPs since Sponge sensors + Honeylabs sensors may detect different honeypot activations.
- Errors: none
## 2026-07-20 10:48:00 -- Phase 2: Honeylabs Queries
- ASNs queried (sequentially with rate-limit pacing): 17 active via top_attackers_ip + top_attackers_user_agent + search_events (51 API calls)
- Active in Honeylabs (events > 0): AS57043(3), AS14956(128), AS51396(2100+), AS51852(264), AS200651(18), AS200593(968), AS214940(42), AS198953(810+), AS211720(2), AS30823(1) -- 10 ASNs had Honeypot activity
- No Honeylabs data: AS209847, AS210644, AS138915, AS216139, AS33993, AS400992, AS140666, AS57 ASN residual; AS400992 noteworthy (prior week had /.env scanner -- this week fully silent but Censys shows it has Windows-only footprint suggesting the operator changed tooling targets).
- Top by volume: AS51396 (PFCLOUD) again dominant, but ~2500 events summed vs prior 10K+ KV; key variance: 204.76.203.18 took the Lideran from prior-week 204.76.203.78/.79/.80
- Notable new attack patterns observed:
- AS57043 - IoT MIPS downloader (kla.sh from aibotnet.su /shell?cd+/tmp on port 6001) NEW
- AS200651 - SPARKRAT update callback POST /api/client/update with custom secret header (CRITICAL NEW FINDING)
- AS51396 - odin-scanner/0.4 brand-new tooling UA + Hello World generic UA
- AS14956 - PMTA-Auto UA (PowerMTA SMTP brute), plus Werkzeug/3.1.8 + 'fofa_monitor' Basic realm panel exposed on port 5000
- AS211720 - shifted from /ews/ Exchange recon (prior week) to MSSQL port 1433 brute (hostname short-tan-rat)
- AS200593/IP 91.202.233.79 still scanning with 968 events despite Censys census dropping to 0
- AS214940 - continued 20+ UA rotation including Konqueror 3.0-rc4, Android HTC Tattoo A3288 (1.6), IE 10, IE 6, YaBrowser, Safari iOS, Samsung Galaxy 7/8/9, Galaxy Watch, Redmi Note 7 -- GreyNoise tags ENV Crawler, GoogleBot Pretender, Java HTTP Client
- Fingerprints cached: 11 major fingerprints (3 critical: SPARKRAT ja4h po11nn0600; IoT botnet ja4h ge11nn0400_777e992b8532; cert-self-signed prohaska.beatty.biz with TLS 1.0/1.1 still active)
- Results cached: Y (top-attackers.csv, fingerprints.csv)
- Errors: Honeylabs top_attackers for AS209847 returned a typist-induced error (re-attempted without HTML injection of asn param, but the ASN returns [] so no events exist). Honeylabs events saved.
## 2026-07-20 11:00:00 -- Phase 3: Censys Aggregations and Per-IP Enrichment
- Port aggregations: 16 ASNs completed (host.services.port field)
- Labels: BULLETPROOF confirmed across all monitored ASNs that have Censys visibility. AS140666 dropped from 588 to 0 census hosts.
- Software aggregation: 9 ASNs completed
- Per-IP enrichment: 14 IPs via censys_get_host (credits plentiful at 10K)
- 45.144.28.70 (AS209847/Sponge; real BGP=AS41745 FORTIS-AS Baykov Ilya Sergeevich RU) -- GreyNoise malicious, regreSSHion vuln weakness, BGP prefix created 2026-06-06 (6 weeks old)
- 132.243.194.215 (PFCLOUD/Hostkey) -- new infra, Netaxis Group Ltd CY, 2026-03-06 reg, DNS odamanov600.ru, forward PoP Frankfurt DE
- 91.202.233.79 (PROSPERO) -- BULLETPROOF, ASN 200593, RU (despite TM honeypot GeoIP); census returned 0 hosts (BGP-prefix blacked out)
- 185.100.87.136 (FLOKINET) -- confirmed Tor 0.4.9.11 + SPARKRAT C2 callback evidence + OpenSSH upgraded to 10.2p1 (server HASSH b1bff636ebbdbaa9dd2ad97fd173c956 = SSH_9.9 on port 7288 alt)
- 185.231.33.46 (DATASHIELD) -- hostname short-tan-rat in packets; self-signed prohaska.beatty.biz cert; TLS 1.0/1.1 still active; beats-free Apache
- 216.126.239.17 (ROUTERHOSTING) -- Werkzeug 3.1.8 + Python 3.12.3 on port 5000 with HTTP 401 Basic realm="fofa_monitor"; OpenSSH 9.6p1 patched (regreSSHion safe)
- 176.120.22.16 (PROTON66) -- GreyNoise suspicious, multi-protocol brute
- 81.17.28.130 (PLI Private Layer INC) -- new IP this week; same Ubuntu 22 LTS OpenSSH 8.9p1 HASSH as AS41745/FORTIS, AS214940/KPRONET
- 204.76.203.18 (PFCLOUD) -- dominant scan-cluster leader; 13,766 Sponge sessions; Censys shows OpenSSH 9.2p1 Debian-2 with HASSH 425d29fe50d8e4f5e37efb6e24bcf660
- 77.83.39.119 (KPRONET) -- Lanedonet Datacenter NL; OpenSSH 8.9p1 Ubuntu-3ubuntu0.16 with shared HASSH 41ff3ecd1458b0bf86e1b4891636213e
- 41.216.188.21 (AUROLOGIC) -- single benign-looking Android 9 mobile HTTPS GET / on port 443
- Fleet correlation: sequential port 6001-6050 cluster in AS216139 (CRITICAL NEW FINDING), SPARKRAT retrofit on Tor exit (AS200651), shared OpenSSH Ubuntu-22-LTS HASSH across multiple BP providers (41745/FORTIS, 214940, 51852), MSSQL brute correlation across Proton66 + Datashield
- Cache files: aggregations-summary.ndjson, fleet-correlation.csv
- Credits remaining: ~9,940 (only 60 spent on per-IP + aggregations)
- Errors: none
## 2026-07-20 11:15:00 -- Phase 4: Change Detection
- Prior baseline: 2026-07-13
- Active ASNs: 15 -> 17 (+2: AS209847/FORTIS, AS30823/aurologic; 2 dropped: AS140666 census wiped to 0)
- AS51396 (PFCLOUD): IP rotation within 204.76.203.0/24 cohort (.78/.79/.80 -> .18/.30/.49/.81); new tooling odin-scanner/0.4 and Hello World UAs
- AS200593 (PROSPERO): 3890 -> 968 Honeylabs events (-75%); Censys wiped to 0 (full infra darkening)
- AS198953 (PROTON66): Top IP rotated 176.120.22.240 -> 176.120.22.16; new IPs 193.143.1.66 + 176.120.22.192 + 37.77.150.83 (Redis port 6379 NEW for this ASIC)
- AS51852 (PLI): 81.17.28.130 (new segment) replaces 179.43.134.114
- AS57043 (HOSTKEY): 1 -> 3 events (+200%); IoT MIPS downloader is NEW pattern
- AS200651 (FLOKINET): OpenSSH upgrade + SPARKRAT retrofit
- AS211720 (DATASHIELD): Exchange /ews/ recon -> MSSQL port 1433 brute
- AS400992 (ZHOUYISAT): /.env scanner silent; Censys shows pure-Windows admin port profile (3389/5985/135/139/445/47001)
- AS14956 (ROUTERHOSTING): PMTA-Auto mail brute UA + fofa_monitor panel exposed (HIGH misconfig)
- AS214940 (KPRONET): UA rotation expanded to 20+ browser strings including ancient/UAs
- New anomalies flagged: 11 (3 critical: SPARKRAT retrofit, backconnect-cluster port pattern, IoT MIPS downloader; 5 high: FORTIS regreSSHion, Datashield MSSQL, Pfcloud odin-scanner, RouterHosting fofa_panel, PFCLOUD cluster lead IP rotation; 3 medium: PLI IP segment rotation, Proton66 Redis recon, ZHOUYISAT behavioral shift)
- Files: diff-vs-prior-week.csv, anomalies.csv
- Errors: none
## 2026-07-20 11:45:00 -- Phase 5: Blog Post Written
- Blog: src/data/blog/2026-07-20-weekly-bulletproof-report.md (12K bytes, 50+ paragraphs)
- Build: PASS (`npm run build` -- 170 pages built in 17.87s, exit 0)
- Errors: one unrelated warning about a stray HTML element in an unrelated 2026-04-04 post (pre-existing) -- not blocking the new post
## 2026-07-20 11:50:00 -- Phase 6: IoC Archival
- all-observed-ips.txt: ~140 unique IPs across 16 ASNs
- fingerprints.txt: 14 fingerprints (HASSH server + client; JARM; cert indicators; UA tooling signatures; JA4/JA3/JA4H; fofa-monitor-realm; greynoise tags)
- c2-paths.txt: 4 paths (IoT MIPS downloader /shell?, SPARKRAT /api/client/update, /eventmanager, MSSQL TDS binary handshake)
- README.md: Run summary
- Status: COMPLETE
|