aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-07-20/censys/fleet-correlation.csv
blob: f66f28e8ca5459228255fb71c004c613c7ffb911 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
correlation_type,ip_a,asn_a,ip_b,asn_b,shared_attribute,confidence,notes
shared-hassh-apache-openssh-8.9p1,45.144.28.70,AS41745/FORTIS (mistagged AS209847),81.17.28.130,AS51852,"41ff3ecd1458b0bf86e1b4891636213e = OpenSSH_8.9p1 Ubuntu-3ubuntu0.16",high,"Standard Ubuntu 22 LTS OpenSSH baseline fingerprint shared across ALL bulletproof providers running Ubuntu 22 LTS (default install). Not unique but indicates uniform fleet provisioning."
shared-hassh-apache-openssh-8.9p1,45.144.28.70,AS41745/FORTIS (mistagged AS209847),77.83.39.119,AS214940,"41ff3ecd1458b0bf86e1b4891636213e = OpenSSH_8.9p1 Ubuntu-3ubuntu0.16",high,"Stable across KPREnet and FORTIS/AS209847 -- uniform provisioning."
shared-jarm,185.231.33.46,AS211720,none,n/a,07d19d12d21d21d07c42d43d000000f50d155305214cf247147c43c0f1a823,medium,"Solitary distinctive JARM TLS handshake -- does not collide with any of AS51852, AS200651, AS51396 baselines."
sequential-port-cluster,46.30.46.124,AS216139,none,n/a,"ports 6001-6050 each ~345 events uniformly",high,"HIGHLY anomalous: pristine uniform session counts across sequential port range 6001-6050 (within +/-3 events) -- consistent with backconnect-C2 listener infrastructure OR a single-client scanner IP potentially acting as a backconnect cluster harness."
tor-exit-c2-flare,185.100.87.136,AS200651,none,n/a,"SPARKRAT Client Update Scanner + 'PremiumTorExit' nickname + Tor 0.4.9.11",high,"Confirmed Tor exit running 0.4.9.11 with SPARKRAT beacon traffic pattern (POST /api/client/update) -- the exit is BOTH an exit AND a SPARKRAT C2 callback planner. Company abuse@flokinet.is has not throttled."
shared-jarm,185.100.87.136,AS200651,none,n/a,"jarm=2ad2ad16d2ad2ad00042d42d000000332dc9cd7d90589195193c8bb05d84fa",medium,"Tor-default 9001 listener jarm -- same across all Tor exit nodes."
shared-fofa-monitor,216.126.239.17,AS14956,none,n/a,"Werkzeug 3.1.8 + Basic realm=\"fofa_monitor\" panel on port 5000",high,"First-time obeservation: fofa-search-style monitoring panel exposed with weak Basic auth -- the honeypot scanners on the same IP have a fofa-search reconnaissance dashboard stored unlabeled on TCP 5000."
self-signed-cert,185.231.33.46,AS211720,none,n/a,"prohaska.beatty.biz (self-signed, fake Prohaska-Beatty US HI entity)",high,"Reused this week -- stable persistent cert on previously single-interaction MSSQL probe host. Indicates this host acts as both active scanner (port 1433) AND long-lived TLS host forwarding as a Stationary covert listener."
ipv6-forty-host-contraction,38.54.2.x,AS138915,none,n/a,"IPv6 support: 0 prior -> 37 current hosts (no IPv4 internet)",low,"Modest IPv6 leakage to census suggests dual-stack provisioning in some AS138915 hosts; not a security event per se."
scan-cluster-pfcloud-204-76-203-x,204.76.203.18,AS51396,none,n/a,"13K+ Sponge sessions from .209 alone, .232 with 13K, multiple .2.x peers",high,"Cluster persists across weeks but IPs rotated: 78/79/80 last week -> 18/.30/.49/.81 this week. NOT a one-shot event -- a long-term coordinated scan deployment platform."
mssql-tds-brute-pivot,176.120.22.192,AS198953,185.231.33.46,AS211720,"port 1433 MSSQL TDS probing",medium,"Both AS198953/AS211720 launched port 1433 binary probes this week -- indicates coordination or sell-through of bots within BP ecosystem."