aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-07-20/censys/aggregations-summary.ndjson
blob: c3912d452b652868a5ce1dd21a5016cc0ca090d8 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
{"_type":"aggregation_summary","asn":"AS57043","org":"Hostkey B.v.","labels":["BULLETPROOF","IPV6"],"top_ports":[{"port":22,"count":13114},{"port":443,"count":9060},{"port":80,"count":59213+59213},{"port":27015,"count":1282},{"port":53,"count":1102},{"port":2096,"count":987}],"total_hosts_census":24733,"software_top":["openssh","nginx","google_web_services","ghost","app_and_api_protector","dovecot","waf","cloudflare_load_balancer","caddy","uvicorn","traefik_proxy","express","fastpanel","exim","next.js","proftpd"],"os_distribution":{"linux":12507,"windows":6412,"routeros":103,"freebsd":34,"proxmox":7},"cert_issuers_top":["YE2 12441","YE1 11788","invalid2.invalid 11488","YR2 5455","YR1 3210","Microsoft TLS G2 2169","GeoTrust TLS RSA G1 2123","DigiCert Global G2 2092","TRAEFIK DEFAULT CERT 2029","WE1 1902","GlobalSign RSA OV SSL CA 2018 1803","hypervisor.hv 1797","E7 1755","E8 1695","Apple Public EV Server RSA CA 1 G1 1641","Sectigo Public Server Auth CA DV E36 1613","GlobalSign ECC OV SSL CA 2018 1454","DigiCert Global G3 TLS ECC SHA384 1200","GlobalSign Atlas R3 DV TLS CA 2025 1179","R12 1043"],"per_ip_enrichment_ip":"132.243.194.215","per_ip_enrichment_asn_census":"57043","per_ip_dns":"odamanov600.ru + sub.odamanov600.ru","per_ip_whois":"NETAXIS GROUP LTD (CY), reg 2026-03-06","per_ip_rdns":"sym-dot h3280","network_cidr":"132.243.194.0/24"}
{"_type":"aggregation_summary","asn":"AS209847","org":"(none matched in census): Sponge IP 45.144.28.70 actually in AS41745 FORTIS-AS - Baykov Ilya Sergeevich (RU)","labels":["BULLETPROOF","IPV6"],"top_ports":[{"port":22,"count":2968},{"port":443,"count":2076},{"port":80,"count":1634},{"port":53,"count":851},{"port":25,"count":289},{"port":587,"count":239},{"port":111,"count":236},{"port":993,"count":225},{"port":143,"count":194},{"port":8080,"count":181},{"port":110,"count":173},{"port":8443,"count":138},{"port":465,"count":134},{"port":21,"count":132},{"port":995,"count":110},{"port":9001,"count":103},{"port":3306,"count":98}],"total_hosts_census":4087,"software_top":["openssh","nginx","python","aiohttp","dovecot","bind","exim","google_web_services","proftpd","app_and_api_protector","ghost","http_server","waf","cloudflare_load_balancer","uvicorn","caddy","express","node_exporter","fastpanel","php"],"os_distribution":{"linux":2919,"windows":22,"routeros":18,"linux_kernel":6,"adaptive_security_appliance_software":5,"enterprise_linux":1,"freebsd":1,"ubuntu":1,"vmware_esxi_server":1},"cert_issuers_top":["YR2 537","invalid2.invalid 534","YR1 480","YE2 326","YE1 297","GlobalSign RSA OV SSL CA 2018 151","E8 90","E7 86","R13 84","R12 74","GeoTrust TLS RSA CA G1 66","Sectigo Public Server Authentication CA DV E36 63","DigiCert Global G2 TLS RSA SHA256 2020 CA1 44","DigiCert Global G3 TLS ECC SHA384 2020 CA1 43","Microsoft TLS G2 RSA OCSP 04 36","GlobalSign Atlas R3 DV TLS CA 2025 Q3 75","GlobalSign GCC R6 AlphaSSL CA 2025 37","WE1 38","vm15860670.example.com 39"],"per_ip_enrichment_ip":"45.144.28.70","per_ip_whois":"Baykov Ilya Sergeevich (RU), network created 2026-06-06 (very recent)","per_ip_censys_asn":"41745 FORTIS-AS","per_ip_greynoise":"malicious -- tags: Web Crawler, HTTP OPTIONS Crawler, Go HTTP Client, Generic Brute Force Attempt, Generic Login Attempt, TLS/SSL Crawler","per_ip_services_running":"OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 (single service, no web)","per_ip_ssh_hassh_server":"41ff3ecd1458b0bf86e1b4891636213e","per_ip_known_cves":["CVE-2024-6387 (regreSSHion, KEV, HIGH)","CVE-2025-32728","CVE-2026-35385","CVE-2023-38408 (KEV)","CVE-2023-28531","CVE-2025-26465 (PingPong MITM)"],"notes":"Real ASN has 4087 censed hosts -- AS209847 viewpoint is via Sponge/IPv4 routing only; BULLETPROOF label is on IP not on AS-census IP pool. 998 Sponge sessions = scanning across many HTTPS ports. Critical new infra"}
{"_type":"aggregation_summary","asn":"AS138915","org":"KAOPU Cloud HK Limited","labels":["BULLETPROOF","IPV6"],"top_ports":[{"port":22,"count":6539},{"port":443,"count":3410},{"port":80,"count":1305},{"port":27015,"count":1282},{"port":2096,"count":1052},{"port":8443,"count":478},{"port":2222,"count":206},{"port":8080,"count":193},{"port":3389,"count":188},{"port":2053,"count":180},{"port":25,"count":111},{"port":8000,"count":93},{"port":1080,"count":89},{"port":51821,"count":81},{"port":587,"count":75},{"port":9443,"count":73},{"port":53,"count":71}],"total_hosts_census":7929,"cert_issuers_top":["invalid2.invalid 1079","YE1 866","YE2 824","DigiCert Global G2 291","YR2 202","WE1 152","Microsoft TLS G2 04 141","YR1 141","GeoTrust TLS RSA CA G1 127","GlobalSign RSA OV SSL CA 2018 126","GlobalSign Atlas R3 DV TLS CA 2025 Q3 114","E7 111","E8 103","Apple Public EV Server RSA CA 1 G1 89","GlobalSign ECC OV SSL CA 2018 111","Sectigo Public Server Authentication CA DV E36 104","WR1 74","DigiCert Global G3 TLS ECC SHA384 74","user 61"],"os_distribution":{"linux":5293,"windows":41,"routeros":24,"adaptive_security_appliance_software":10,"freebsd":4,"linux_kernel":4},"notable_unusual":"IPv6 support 1 host (vs 0 prior) -- no IPv4 multi-cast shift user notable. Sponge top IP 38.54.2.209 fires 51,461 sessions (cap exceeded) -- NTP/SSDP/LLMNR amplification suspected"}
{"_type":"aggregation_summary","asn":"AS51396","org":"Pfcloud UG","labels":["BULLETPROOF","IPV6"],"top_ports":[{"port":22,"count":1577},{"port":5335,"count":834},{"port":5050,"count":669},{"port":80,"count":355},{"port":222,"count":254},{"port":443,"count":240},{"port":2000-2015","count":[186,180,186,186,179,178,179,180,166,166]}],"total_hosts_census":2909,"software_top":["openssh","python","wg-easy","werkzeug","nginx","express","http_server","dovecot","virtual_environment","http_api","aiohttp","php","postfix","uvicorn","next.js","mariadb","traefik_proxy","traefik_proxy","litespeed_web_server","postgresql","authoritative_server"],"cert_issuers_top":["YE1 99","YE2 75","YR2 57","YR1 46","Proxmox Virtual Environment 24","R13 23","WIN-TVJFV24LUKT 22","TRAEFIK DEFAULT CERT 21","XUI.one 18","R12 13","WIN-IK7N6SD2UBU 22","WIN-OU0SUKQBJN2 9","ad0bipluh-in.store 9","onliiinbox.store 9","aapanel.com 8","E7 8","void 8","R11 7","localhost 7"],"os_distribution":{"linux":577,"windows":29,"proxmox":26,"routeros":4,"linux_kernel":1},"notes":"NEW softwares observed this week -- virtual_environment, aiohttp growing. XUI.one panel certificate (illegal IPTV dashboard platform). TRAEFIK DEFAULT CERT appears 21 times -- default-config load balancers without cert customization. WIN-TVJFV24LUKT hostname 22 -- Windows hostnames showing in cert CN ceded hostnames."}
{"_type":"aggregation_summary","asn":"AS214940","org":"Kprohost LLC","labels":["BULLETPROOF"],"top_ports":[{"port":22,"count":24},{"port":443,"count":9},{"port":80,"count":3}],"total_hosts_census":48,"software_top":["http_api","openssh","http_server","nginx","virtual_environment","internet_information_services","dovecot","anydesk","php","asp.net","fastpanel","anydesk","php","asp.net","fastpanel","exim","parallels_plesk_panel","plesk","postfix","proftpd"],"cert_issuers_top":[],"os_distribution":{"linux":10,"windows":3,"proxmox":6},"per_ip_enrichment_ip":"77.83.39.119","per_ip_whois":"Lanedonet Datacenter (NL); network 77.83.39.0/24 created 2025-12-17","per_ip_greynoise":"malicious -- tags: Web Crawler, TLS/SSL Crawler, ENV Crawler, GoogleBot Pretender, Java HTTP Client","per_ip_hassh_server":"41ff3ecd1458b0bf86e1b4891636213e -- OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 -- SAME as AS209847/FORTIS, AS51852/PLI, AS216139 -- uniform Ubuntu 22 LTS across bulletproof providers"}
{"_type":"aggregation_summary","asn":"AS200651","org":"FlokiNET ehf","labels":["BULLETPROOF","IPV6"],"top_ports":[{"port":22,"count":3388},{"port":80,"count":2319},{"port":443,"count":2149},{"port":53,"count":1754},{"port":21,"count":928},{"port":1500,"count":774},{"port":25,"count":670},{"port":993,"count":645},{"port":143,"count":643},{"port":587,"count":635},{"port":110,"count":632},{"port":3000,"count":619},{"port":65534,"count":491},{"port":8080,"count":447},{"port":995,"count":428},{"port":465,"count":427},{"port":8443,"count":360},{"port":1050","count":263},{"port":10000,"count":260}],"total_hosts_census":5587,"software_top":["openssh","nginx","dovecot","http_server","cpanel","exim","openresty","webmail","authoritative_server","caddy","postfix","traefik_proxy","ghost","php","app_and_api_protector","express","next.js","google_web_services","litespeed_web_server","wordpress"],"cert_issuers_top":["YR2 643","YR1 544","YE2 519","YE1 507","R12 153","E8 152","R13 138","TRAEFIK DEFAULT CERT 136","E7 122","invalid2.invalid 89","GlobalSign Atlas R3 DV TLS CA 2025 Q3 46","localhost 44","Microsoft TLS G2 RSA OCSP 04 41","WE1 35","aapanel.com 31","www.example.com 30","Apple Public EV Server RSA CA 1 G1 28","fin01.m-cr.org 28","ZeroSSL ECC DV SSL CA 2 27","Proxmox Virtual Environment 26"],"os_distribution":{"linux":2116,"windows":29,"proxmox":29,"routeros":25,"freebsd":11,"enterprise_linux":6,"idrac_linux":1,"sonicos":1,"ilo_3":1,"openmediavault":1,"windows_server_2008_r2":3},"per_ip_enrichment_ip":"185.100.87.136","per_ip_whois":"FlokiNET Ltd (ICELAND + Romania routing) -- this is a registered TOR exit node (PremiumTorExit)","per_ip_greynoise":"malicious -- tags: Web Crawler, TLS/SSL Crawler, SPARKRAT Client Update Scanner (NEW), QUIC Protocol, SSH Connection Attempt, Ping Scanner, DNS Protocol, ICMPv4 Protocol, Generic XSS Commands","per_ip_services_running2":"HTTP port 80 with 'This is a Tor Exit Router' HTML body ('tor-exit' alt), SSH on alt port 7288 (not 22), TLS 1.3 on port 9001 with self-signed cert CN=www.3qgf34k26durwzv.net (issued by www.4j7f273r.com)","per_ip_cert_extras":"jarm 2ad2ad16d2ad2ad00042d42d000000332dc9cd7d90589195193c8bb05d84fa (stable Tor preset)","notes":"Confirmed Tor exit running 0.4.9.11. The HASSH of OpenSSH_10.2p1 (e54ef3ec27fe1fea7ab64d3fa05359fd) is NEW -- upgrade from 10.1 last week. The SPARK_COMMIT UA is unusual -- appears to be a Go-style 'Spark' RAT (or modular beacon) checking in via POST /api/client/update with arch=amd64 commit=08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17&os=windows -- suggests Win64 RAT beaconing through the Tor exit. /eventmanager path strongly suggests SparkRAT manager endpoint."}
{"_type":"aggregation_summary","asn":"AS400992","org":"ZhouyiSat Communications","labels":["BULLETPROOF"],"top_ports":[{"port":3389,"count":95},{"port":5985,"count":90},{"port":135,"count":90},{"port":139,"count":89},{"port":445,"count":88},{"port":47001,"count":87},{"port":22,"count":44},{"port":80,"count":30},{"port":137,"count":20},{"port":5357,"count":18},{"port":5986,"count":16},{"port":111,"count":14},{"port":443,"count":13}],"total_hosts_census":151,"software_top":["http_api","openssh","http_server","nginx","virtual_environment","internet_information_services","anydesk","php","asp.net","fastpanel","dovecot","exim","mariadb","mysql","openresty","parallels_plesk_panel","plesk","postfix","proftpd"],"cert_issuers_top":[],"os_distribution":{"windows":88,"linux":40,"proxmox":6},"notes":"Pure WINDOWS administration recon profile: WinRM(5985/47001+5986), RPC(135), SMB(445+139+137), WMI(5357). Linux only 40 hosts. Confirms prior-week /.env scanner has shifted to broader Windows-server brute-expansion -- the absence of honeypot events this week doesn't mean quiet, just that their scanning hit fewer honeypots"}
{"_type":"aggregation_summary","asn":"AS200593","org":"Prospero Ooo","labels":[],"top_ports":[],"total_hosts_census":0,"notes":"Asn query returned 0 hosts in Censys this week -- vanished from public scanscape (anonymized/withdrawn). Yet Honeylabs sees 91.202.233.79 (TM) generating 968 brute events, plus 1 hit from 91.215.85.104 (RU) with Python aiohttp UA. Honeylabs UA last week: 9 sources; this week mostly same scan bomb rapid-fire on diverse high-numbered ports (3558/3392/3636/6666/3388). Cross-source anomaly -- they are running tools from an IP that is no longer visible in Censys"}
{"_type":"aggregation_summary","asn":"AS51852","org":"Private Layer INC","labels":["BULLETPROOF","IPV6"],"top_ports":[{"port":80,"count":4886},{"port":443,"count":4534},{"port":22,"count":4300},{"port":53,"count":3540}],"total_hosts_census":8648,"software_top":["nginx","openssh","dovecot","http_server","cpanel","exim","openresty","webmail","authoritative_server","caddy","postfix","traefik_proxy","ghost","php","app_and_api_protector","express","next.js","google_web_services","litespeed_web_server","wordpress"],"cert_issuers_top":["server 1963","YR2 1347","Hydra Authentication RSA SubCA #153 860","Hydra Authentication RSA SubCA #152 237","Hydra Authentication RSA SubCA #151 102","server.domain.com 808","server.ibras.eu 360","YE1 399","'' 332","YE2 310","invalid2.invalid 304","R12 195","Proxmox Virtual Environment 167","Plesk 156","R13 114","server.xtreme-results.net 107","Sectigo Public Server Auth CA DV E36 105","localhost 104","DigiCert Global G2 76"],"os_distribution":{"linux":3150,"windows":187,"proxmox":157,"routeros":24,"freebsd":23,"vmware_esxi_server":18,"idrac_linux":8,"adaptive_security_appliance_software":3,"windows_server_2012_r2":3,"ap7821":2,"ios":2,"macos":2,"fedora_core":1,"windows_server_2003":1,"xenserver":1},"per_ip_enrichment_ip":"81.17.28.130","per_ip_whois":"Private Layer INC (PANAMA-based); 81.17.28.128/27 -- previously unseen host","per_ip_dns":"none (blank rDNS through Sponge)","per_ip_ssh_hassh_server":"41ff3ecd1458b0bf86e1b4891636213e (OpenSSH_8.9p1 Ubuntu-3) -- same HASSH as AS214940, AS209847/FORTIS","per_ip_greynoise":"unclassified"}
{"_type":"aggregation_summary","asn":"AS198953","org":"Proton66 OOO","labels":["BULLETPROOF","IPV6"],"top_ports":[{"port":22,"count":61341},{"port":443,"count":38051},{"port":80,"count":17479},{"port":2096,"count":12967},{"port":8443,"count":8702},{"port":8080,"count":6912},{"port":2053,"count":3586},{"port":2222,"count":1973},{"port":3389,"count":1969},{"port":51821,"count":1350},{"port":3000,"count":1240},{"port":8000,"count":1222},{"port":25,"count":1117},{"port":53,"count":1102},{"port":2083,"count":899},{"port":587,"count":880},{"port":993,"count":870},{"port":9443,"count":854},{"port":1080,"count":835}],"total_hosts_census":70945,"software_top":["openssh","nginx","google_web_services","ghost","app_and_api_protector","dovecot","waf","cloudflare_load_balancer","caddy","http_server","uvicorn","traefik_proxy","express","fastpanel","exim","python","next.js","portainer","openresty","proftpd"],"cert_issuers_top":[],"os_distribution":{"linux":70693,"windows":574,"routeros":283,"proxmox":179,"linux_kernel":148,"adaptive_security_appliance_software":104,"freebsd":54,"vmware_esxi_server":42,"ios":38,"enterprise_linux":23,"linux_ami":5,"windows_server_2008_r2":2,"windows_server_2012_r2":1,junos":1,"macos":1,"openmediavault":1,"ubuntu":1,"unifi":1},"per_ip_enrichment_ip_176_120_22_16":"Primary Bramfordsee Top-IP. Reverse dns blank. GreyNoise: suspicious -- tags MySQL Protocol, TLS/SSL Crawler, Python Requests Client, Web Crawler, Generic Suspicious Linux Command in Request","notes":"Volume shrank (census from 100106 prior to 70945 -- a -29% drop -- aggressive darkening / migration). RDP/SSH/MSSQL/Redis (6379) all in active brute. Notable: 176.120.22.16 first time in top IP slot -- rotated from 176.120.22.61 -> 16. Pattern: the most aggressive IP is not in Honeylabs usually (so brute) but maintained GreyNoise malicious flag."}
{"_type":"aggregation_summary","asn":"AS14956","org":"RouterHosting LLC","labels":["BULLETPROOF","IPV6"],"top_ports":[{"port":22,"count":2784},{"port":443,"count":2038},{"port":80,"count":1828},{"port":53,"count":354},{"port":25,"count":281},{"port":587,"count":239},{"port":111,"count":236},{"port":993,"count":225},{"port":143,"count":194},{"port":8080,"count":181},{"port":110,"count":173},{"port":2096,"count":157},{"port":8443,"count":138},{"port":465,"count":134},{"port":21,"count":132}],"total_hosts_census":3711,"software_top":["nginx","openssh","dovecot","http_server","cpanel","exim","openresty","webmail","authoritative_server","caddy","postfix","traefik_proxy","ghost","php","app_and_api_protector","express","next.js","google_web_services","litespeed_web_server","wordpress"],"cert_issuers_top":["YR2 928","YR1 854","YE2 422","YE1 399","Sectigo Public Server Authentication CA DV E36 285","GlobalSign RSA OV SSL CA 2018 220","E8 195","issssrt.ru 183","GlobalSign GCC R3 DV TLS CA 2020 181","WE1 157","E7 134","R13 121","TRAEFIK DEFAULT CERT 107","GlobalSign ECC OV SSL CA 2018 105","invalid2.invalid 98","etc 73","HARICA DV TLS RSA 72","WR1 61","GlobalSign GCC R6 AlphaSSL CA 2025 57"],"os_distribution":{"linux":2116,"windows":29,"proxmox":29,"routeros":24,"freebsd":11,"enterprise_linux":6,"idrac_linux":1,"sonicos":1,"windows_server_2008_r2":3,"openmediavault":1,"ilo_3":1},"per_ip_enrichment_ip":"216.126.239.17","per_ip_whois":"RouterHosting LLC (Cloudzy-branded Wyoming shell). 216.126.239.0/24 reg 2025-06-25 (recent)","per_ip_greynoise":"unclassified","per_ip_ssh_hassh_server":"e42184b06d45385a906f0803d04c83da (OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 -- quite modern; not vulnerable to regreSSHion)","per_ip_service_5000_werkzeug":"Werkzeug 3.1.8 + Python 3.12.3 with HTTP 401 Basic realm=\"fofa_monitor\" -- a fofa-search-style monitoring panel exposed (rare; Censys flagged Unencrypted HTTP Weak Auth HIGH)","per_ip_known_cve_high":"CVE-2024-6387 (regreSSHion, KEV)","per_ip_known_cve_med_low":"CVE-2025-32728, CVE-2026-35385, CVE-2026-35414, CVE-2026-XXXX+","notes":"Substantial cPanel/Plesk/cPanel-ghost stack + multi-platform honeypot reconnaissance. cPanel/cPanel stack fully populated. Highly aggressive on multi-CVE exploit testing. Note the fofa_monitor panel -- new addition to scan infrastructure."}
{"_type":"aggregation_summary","asn":"AS210644","org":"Aeza Group LLC","labels":["BULLETPROOF"],"top_ports":[],"total_hosts_census":0,"notes":"Massive infrastructure drop from 6800 -> 0 census hosts -- AS has withdrawn from Internet-visible scanscape entirely. 11 Sponge sessions remaining from 5 IPs. Honeypot data: 0 events. Pattern: Aeza may have shifted IPs to a different AS (or simply turned off public-facing ports entirely). Status: full infra blackout / migration suspected."}
{"_type":"aggregation_summary","asn":"AS209847","org":"FORTIS-AS Baykov Ilya Sergeevich (real AS -- AS209847 in CSV has been a tagging-error)",labels":["BULLETPROOF","IPV6"],"top_ports":[{"port":22,"count":3395}],"total_hosts_census_in_as41745_only:0,"per_ip_enrichment_ip":"45.144.28.70","per_ip_whois":"Baykov Ilya Sergeevich (RU), BGP prefix 45.144.28.0/24 created 2026-06-06 (very recent network registration)","per_ip_greynoise":"malicious -- tags: Web Crawler, HTTP OPTIONS Crawler, Go HTTP Client, Generic Brute Force, Generic Login Attempt, TLS/SSL Crawler","per_ip_ssh_hassh_server":"41ff3ecd1458b0bf86e1b4891636213e","per_ip_known_cves":["CVE-2024-6387 (regreSSHion, KEV)","CVE-2025-26465","CVE-2025-32728","CVE-2026-35385","CVE-2023-28531","CVE-2023-38408","CVE-2023-48795","CVE-2023-51384","CVE-2023-51385"],"per_ip_reverse_dns":"none","per_ip_operating_system":"Linux (Ubuntu per ssh comment)","per_ip_location":"Paris, France","per_ip_hosted":"IPINFO hosting=true","per_ip_reputation":"benign (reputation.sdk only)","per_ip_neighbors_label":"BULLETPROOF only","per_ip_service_count":1,"notes":"Single service exposed (SSH on 22 only). Driven 998 Sponge sessions from this one host. Classic scanning appliance with one honeypot-trigger host. BGP network is 6 weeks old, marked BULLETPROOF via Censys IP labeling. Major new infra expansion of the FORTIS/Baykov actor -- was 0 last week."}
{"_type":"aggregation_summary","asn":"AS211720","org":"Datashield, Inc.","labels":["BULLETPROOF","IPV6"],"top_ports":[],"per_ip_enrichment_ip":"185.231.33.46","per_ip_whois":"Datashield Inc -- Mikail Gairbekov admin (SEYCHELLES); PO BOX 121 Victoria Mahe","per_ip_dns":"none public","per_ip_greynoise":"unclassified","per_ip_location":"Switzerland -- ZUG (Seychelles-owned, Sweden registered-loc","per_ip_service_count":1,"per_ip_service_443_cert":"SELF-SIGNED -- subject CN=prohaska.beatty.biz, O=Prohaska-Beatty, OU=compress, ST=HI, C=US, email compress@prohaska.beatty.biz -- a fake US business entity (no domain eponym)","per_ip_tls_versions":["TLSv1.0","TLSv1.1","TLSv1.2","TLSv1.3"],"per_ip_misconfigurations":["CENSYS-2026-1196 Self-Signed Certificate","CENSYS-2024-1026 No Trusted Path Certificate","CENSYS-2022-1013 Downgrade Attack Possible (TLS 1.0/1.1 still enabled)"],"per_ip_jarm":"07d19d12d21d21d07c42d43d000000f50d155305214cf247147c43c0f1a823","notes":"Previously conducting Exchange /ews/ recon (week 2026-07-13). This week shifted to MSSQL TDS port 1433 only -- a domain SQL database password bruteforce probe set. Source hostname 'short-tan-rat' hardcoded in packets. Self-signed prohaska.beatty.biz cert still active. Continuation of datashield as an MSSQL bruteforce platform -- via TLS 1.0/1.1 enabled Oracle-level downgrade flaws"}
{"_type":"aggregation_summary","asn":"AS216139","org":"Iron Hosting Centre LTD","labels":["BULLETPROOF","IPV6"],"top_ports":[{"port":22,"count":1407},{"port":443,"count":711},{"port":80,"count":546},{"port":"6001-6050 sequential","count":345-348 each}],"total_hosts_census":2358,"per_ip:"46.30.46.124 -- only Sponge IP observed; 1 session on port 19898 (random-listener probe)","notes":"NEW THIS WEEK -- sequential port 6001-6024 cluster showing in Censys aggregations (345-348 events each). This is anomalous -- backconnect-C2 listener pattern OR intrusive port-range scanning. Each port fires the same number of sessions (very tight +/-3 count drift) telling same client-set acts in concert. Cannot confirm without per-IP enumeration but suspicious. Censys data for this ASN shows no port-specific software fingerprint (no openssh in software list -- confirms these are not servers but listeners)."}
{"_type":"aggregation_summary","asn":"AS30823","org":"aurologic GmbH","labels":[],"top_ports":[{"port":22,"count":9704},{"port":443,"count":5083},{"port":80,"count":2998},{"port":51821,"count":1519},{"port":53,"count":1406},{"port":21,"count":991},{"port":2096,"count":987},{"port":25,"count":734},{"port":993,"count":692},{"port":143,"count":682},{"port":110,"count":674},{"port":2053,"count":635},{"port":587,"count":630},{"port":3306,"count":617},{"port":500,"count":553},{"port":8443,"count":545},{"port":123,"count":522},{"port":1500,"count":506},{"port":995,"count":388},{"port":161,"count":384}],"total_hosts_census":12058,"cert_issuers_top":["GlobalSign GCC R3 OV TLS CA 2024 5702","localhost 2620","prod-vpn.example.com 2507","GlobalSign RSA OV SSL CA 2018 2255","GlobalSign GCC R46 OV TLS CA 2025 1605","Sectigo Public Server Authentication CA DV R36 1228","WoTrus RSA DV SSL CA 2 540","WIN-9QFKHJ39QE9 463","NONE 432","QY 232","WIN-U1V7GLUG3JJ 238","WIN-QPBU6973Q4A 221","YR1 219","YE1 218","宝塔面板 207 (BT-Panel China)","YE2 198","YR2 192","R13 191","RapidSSL TLS RSA CA G1 160","tls.internal.ypc.org 160"],"os_distribution":{"linux":6791,"routeros":104,"windows 98,"enterprise_linux":72,"adaptive_security_appliance_software":17,"freebsd":13,"linux_ami":3,"windows":4},"notes":"New commercial hosting provider appearance -- hosts up 12058 -- SPONGE events markedly low (8) -- but Honeylabs events (1 single benign Android GET /) shows the ASN barely acts directly. Distinctive features: '宝塔面板' (BaoTa Panel / China-based web hosting panel) appearing in 207 cert CNs. WoTrus RSA DV (Chinese CA) issuing certs. tls.internal.ypc.org -- infrastructure-style China-origin hostname consistent with YPC. Activity level is INCIDENTALLY observed -- likely the full ASN is a commercial China-targeting hosting zone with inactive honey interaction."}
{"_type":"aggregation_summary","asn":"AS33993","org":"UFO-AS (Mir International LTD)","labels":["BULLETPROOF","IPV6"],"top_ports":[{"port":22,"count":1082},{"port":443,"count":821},{"port":80,"count":581},{"port":3389,"count":287},{"port":53,"count":277},{"port":27015,"count":148},{"port":8443,"count":112},{"port":25,"count":105},{"port":2096,"count":80},{"port":8080,"count":77},{"port":111,"count":63},{"port":135,"count":58},{"port":2222,"count":54},{"port":445,"count":50},{"port":3000,"count":50},{"port":3306,"count":45},{"port":21,"count":39},{"port":139,"count":38},{"port":5985,"count":38},{"port":3128","count":37}],"total_hosts_census":1806,"notes":"Slight decrease in census hosts and persistent Honeylabs inactivity. Minecraft (27015) persistent -- recreational/entertainment hosting alongside legitimate hosting footprint. AS covers 1806 hosts but only 2 sponge sessions / 0 honeypot events = dark infra"}
{"_type":"aggregation_summary","asn":"AS140666","org":"ANY DIGITAL PTE. LTD.","labels":[],"top_ports":[],"total_hosts_census":0,"notes":"2 sponge sessions from 2 IPs (154.94.68.6, 204.3.179.2) on port 0 -- trivial activity. Conservative observe: catalog-listed but no census coverage yet -- AS poised for infr ready in the future."}